Bruce Schneier author of (the terrific)"Beyond Fear: Thinking Sensibly About Security in an Uncertain World" writes an op ed at NewsDay.
"Unfortunately, the debate often gets mischaracterized as a question
about how much privacy we need to give up in order to be secure.
People ask: "Should we use this new surveillance technology to
catch terrorists and criminals, or should we favor privacy and ban its
use?"
This is the wrong question. We know that new technology gives law
enforcement new search techniques, and makes existing techniques
cheaper and easier. We know that we are all safer when the police
can use them...
...What we need are corresponding mechanisms to prevent abuse. This
is the proper question: "Should we allow law enforcement to use new
technology without any judicial oversight, or should we demand that
they be overseen and accountable?" And the Fourth Amendment
already provides for this in its requirement of a warrant...
...The key is independent judicial
oversight; the warrant process is itself a security measure protecting
us from abuse and making us more secure.
Much of the rhetoric on the "security" side of the debate cloaks one
of its real aims: increasing law enforcement powers by decreasing its
oversight and accountability. It's a very dangerous road to take, and
one that will make us all less secure. The more surveillance
technologies that require a warrant before use, the safer we all are."
Schneier should be compulsory reading especially for lawmakers and journalists. They'd be much better informed though I doubt they'd be any less prone to engaging in the usual rhetoric. Rhetoric after all sells papers and wins arguments.
Tuesday, May 18, 2004
The Guardian is reporting that now that the EU council of foreign ministers has rubber stamped the Commission agreement to hand over airline passenger data to the US, the EU parliament's European Court of Justice challenge to the deal is rendered invalid.
Surely that can't be right? The processes involved need a serious review if it is. I don't care whether you're one of Jerry Kang's 'market' or 'dignity' ideologists in the privacy debate, allowing the circus of ministers to nod through an agreement to bypass that kind of ECJ challenge on principle doesn't work for me.
How does it stack against Kang's questions?
a) Who gets the initial entitlement? Well, it's a get out of jail card for the airlines who were caught between large US fines for not sharing data for homeland security and large EU fines for breaching data protection rules. On ideologies it's a nod to the market and the war on terrorism. The individual gets relegated to the choice of not flying if they don't want personal data transferred.
b) How will the choices get made? How is it ensured that the decisionmaker is fortified to do it well/effectively? I don't see much fortification for the individual here. How, for example can someone correct errors that may occur and accumulate? How can an individual opt out? The only way I can see is as above - don't fly.
c) What are the societal overrides? What are the allowable contexts within which we can override the rights/market actions of individuals? How to pick/adjudicate/etc. The article says "dietary requirements that could reveal religion, race or health" will not be included in the data transfers. We don't have any further detailed information on the small print here. One important 'how to' process - the ECJ challenge - would appear to have been neutered?
d) How much supporting information infrastructure needed to enforce? Quite a lot from a technical perspective alone and this is rapidly evolving on both sides of the atlantic with no fly lists and CAPPS II, for example. There are lots of issues of substance related to the development and deployment of these infrastructures alone e.g the design, collection rules, access rules, maintainance, error correction, identification, authentication, restrictive purpose, function creep etc.
Prof Kang would like us to explore issues of substance on all four questions rather than getting distracted by unproductive ideology. As he says, the key thing is the "fortifying of the individual" i.e. can you say yes(or no)?
That's an off the top of the head application of the Kang framework, so don't look too closely for holes.
Privacy International have been pretty quick to respond by updating their comprehensive report on the subject. They are disgusted.
"This report outlines how the European Commission failed outright at protecting EU interests and upholding EU laws within the negotiations with the U.S. Government. As a result, the U.S. Government
managed to get the Commission to concede European privacy rights and burdening EU carriers, even while U.S. carriers and U.S. citizens are exempt from these rules..." The report goes on to say that
The US Dept for Homeland Security get access to data from EU airlines but does not require similar access to US airline databases
The US therefore gets to test CAPPS II with EU data. (The Commission "believe" that the data will be removed from CAPPS II when the tests are complete. The actual agreement with the US is silent on this point).
The Commission is contemplating a central EU database to make the transfer of this data to the US easier.
The Commission wants EU law changed to allow law enforcement access to airline passenger data.
The Commission want access to US airline passenger data but have not negotiated this yet (Currently there don't seem to be any grounds in US law to allow such transfers).
The Commission are supporting a global airline passenger surveillance system through the Internation Civil Aviation Organisation.
The report goes on to say that the case for collecting all this information has never been made and that it is neither necessary nor proportionate (especially the collection of information in the pretence that it is to combat terrorism, when it will also be used for other purposes).
It certainly paints the EU delegation as pretty poor negotiators at best or active conspirators in the dismantling of the EU's proud privacy-as-fundamental-right (or as Prof Kang would call them, 'dignity') principles at worst.
Surely that can't be right? The processes involved need a serious review if it is. I don't care whether you're one of Jerry Kang's 'market' or 'dignity' ideologists in the privacy debate, allowing the circus of ministers to nod through an agreement to bypass that kind of ECJ challenge on principle doesn't work for me.
How does it stack against Kang's questions?
a) Who gets the initial entitlement? Well, it's a get out of jail card for the airlines who were caught between large US fines for not sharing data for homeland security and large EU fines for breaching data protection rules. On ideologies it's a nod to the market and the war on terrorism. The individual gets relegated to the choice of not flying if they don't want personal data transferred.
b) How will the choices get made? How is it ensured that the decisionmaker is fortified to do it well/effectively? I don't see much fortification for the individual here. How, for example can someone correct errors that may occur and accumulate? How can an individual opt out? The only way I can see is as above - don't fly.
c) What are the societal overrides? What are the allowable contexts within which we can override the rights/market actions of individuals? How to pick/adjudicate/etc. The article says "dietary requirements that could reveal religion, race or health" will not be included in the data transfers. We don't have any further detailed information on the small print here. One important 'how to' process - the ECJ challenge - would appear to have been neutered?
d) How much supporting information infrastructure needed to enforce? Quite a lot from a technical perspective alone and this is rapidly evolving on both sides of the atlantic with no fly lists and CAPPS II, for example. There are lots of issues of substance related to the development and deployment of these infrastructures alone e.g the design, collection rules, access rules, maintainance, error correction, identification, authentication, restrictive purpose, function creep etc.
Prof Kang would like us to explore issues of substance on all four questions rather than getting distracted by unproductive ideology. As he says, the key thing is the "fortifying of the individual" i.e. can you say yes(or no)?
That's an off the top of the head application of the Kang framework, so don't look too closely for holes.
Privacy International have been pretty quick to respond by updating their comprehensive report on the subject. They are disgusted.
"This report outlines how the European Commission failed outright at protecting EU interests and upholding EU laws within the negotiations with the U.S. Government. As a result, the U.S. Government
managed to get the Commission to concede European privacy rights and burdening EU carriers, even while U.S. carriers and U.S. citizens are exempt from these rules..." The report goes on to say that
The US Dept for Homeland Security get access to data from EU airlines but does not require similar access to US airline databases
The US therefore gets to test CAPPS II with EU data. (The Commission "believe" that the data will be removed from CAPPS II when the tests are complete. The actual agreement with the US is silent on this point).
The Commission is contemplating a central EU database to make the transfer of this data to the US easier.
The Commission wants EU law changed to allow law enforcement access to airline passenger data.
The Commission want access to US airline passenger data but have not negotiated this yet (Currently there don't seem to be any grounds in US law to allow such transfers).
The Commission are supporting a global airline passenger surveillance system through the Internation Civil Aviation Organisation.
The report goes on to say that the case for collecting all this information has never been made and that it is neither necessary nor proportionate (especially the collection of information in the pretence that it is to combat terrorism, when it will also be used for other purposes).
It certainly paints the EU delegation as pretty poor negotiators at best or active conspirators in the dismantling of the EU's proud privacy-as-fundamental-right (or as Prof Kang would call them, 'dignity') principles at worst.
ILAW 2004 was on last week at the Berkman Center at Harvard. The usual suspects, Larry Lessig, Jonathan Zittrain, Charles Nesson, Yochai Benkler and William Fisher enjoyed themselves educating the latest cohort of delegates in the intricacies of internet law. Frank Field was there and reports on many of the sessions.
Donna, though, sees Jerry Kang's session as one of the higlights. She pegs him the Larry Lessig of privacy:
"UCLA law professor/Harvard law visiting professor Jerry Kang is the Larry Lessig of privacy, in that he was able very quickly
and powerfully to communicate that there are extremes in the debate that result largely from the culture-born clash between
"property talk" (U.S.-take on privacy) and "dignity talk" (Euro approach). He lifted the discussion out of the dreaded "tin foil
hat" arena -- that is, beyond "paranoid freaks v. reasonable people" nonsense that stops people from truly engaging with the
problem/issues at hand. He's one to learn from. (Check out Frank Field's comprehensive ILAW notes for a remarkably
detailed transcript of his talk.)"
Kang talked about the unproductive ideologies in the privacy debate and how to get round them.
"A clash of civilizations (america v europe)
america - market talk; privacy is a widget; let the market do it; exercise your freedom in the market; exchange for value; and in a good market, we get allocative efficiency - kind of a caricature, but this is a good short term mechanism
europe - dignity talk; privacy is a fundamental human right; we do not auction off babies; we let the law decide what it a fundamental human right.
Substance - turning to the substance suggests that the ultimate elements are the same.
at the core, they seem to be the same.
- Dignity talk says (consent is required) (apparatus to ensure that there is a process to protect consent)
- Market talks says (clear property rights needed/so who gets initial entitlement?/many possible results/these days, it’s largely in the commons)
there are good reasons to think that efficiency emerges when you give the entitlement to the individual – same result as dignity talk...
...Dignity talk hates the market approach because there’s too little control for individuals to exert; individuals have a hard time making a good bargain. Rather, the system is set up to fortify the individual’s position in these situations...
...Market approach says that the dignity approach is too stilted – there are situations where the balance of interests should go against privacy; the market achieves that balance more efficiently
But dignity talk leads to systems that explicitly generate exceptions to the dignity right within the supporting instutions created...
...So, it may be that we will all end up in the same place; and it may be that rather than arguing about which regime is “right” we should move on to the real, mechanical issues that are the same for both...
...What can we do to reframe this debate?
1) soft pedal the concern about market talk/dignity talk - unproductive
2) the substance is something we ought to be focusing on
a) who gets the “thing” - the initial entitlement
b) how will the choices get made, and how to ensure that the decisionmaker is fortified to do it well/effectively - this is where inalienability may emerge (can’t ask, can’t tell) - there are lots of intermediate forms of the way we might frame/constrain the kinds of exchanges that we will allow; ability to correct
c) what are the societal overrides; what is allowable contexts within which we can override the rights/market actions of individuals. How to pick/adjudicate/etc.
d) How much supporting information infrastructure needed to enforce - various flavors
That;s the claim – answer these four question, rather than talking to me about dignity or markets"
Donna, though, sees Jerry Kang's session as one of the higlights. She pegs him the Larry Lessig of privacy:
"UCLA law professor/Harvard law visiting professor Jerry Kang is the Larry Lessig of privacy, in that he was able very quickly
and powerfully to communicate that there are extremes in the debate that result largely from the culture-born clash between
"property talk" (U.S.-take on privacy) and "dignity talk" (Euro approach). He lifted the discussion out of the dreaded "tin foil
hat" arena -- that is, beyond "paranoid freaks v. reasonable people" nonsense that stops people from truly engaging with the
problem/issues at hand. He's one to learn from. (Check out Frank Field's comprehensive ILAW notes for a remarkably
detailed transcript of his talk.)"
Kang talked about the unproductive ideologies in the privacy debate and how to get round them.
"A clash of civilizations (america v europe)
america - market talk; privacy is a widget; let the market do it; exercise your freedom in the market; exchange for value; and in a good market, we get allocative efficiency - kind of a caricature, but this is a good short term mechanism
europe - dignity talk; privacy is a fundamental human right; we do not auction off babies; we let the law decide what it a fundamental human right.
Substance - turning to the substance suggests that the ultimate elements are the same.
at the core, they seem to be the same.
- Dignity talk says (consent is required) (apparatus to ensure that there is a process to protect consent)
- Market talks says (clear property rights needed/so who gets initial entitlement?/many possible results/these days, it’s largely in the commons)
there are good reasons to think that efficiency emerges when you give the entitlement to the individual – same result as dignity talk...
...Dignity talk hates the market approach because there’s too little control for individuals to exert; individuals have a hard time making a good bargain. Rather, the system is set up to fortify the individual’s position in these situations...
...Market approach says that the dignity approach is too stilted – there are situations where the balance of interests should go against privacy; the market achieves that balance more efficiently
But dignity talk leads to systems that explicitly generate exceptions to the dignity right within the supporting instutions created...
...So, it may be that we will all end up in the same place; and it may be that rather than arguing about which regime is “right” we should move on to the real, mechanical issues that are the same for both...
...What can we do to reframe this debate?
1) soft pedal the concern about market talk/dignity talk - unproductive
2) the substance is something we ought to be focusing on
a) who gets the “thing” - the initial entitlement
b) how will the choices get made, and how to ensure that the decisionmaker is fortified to do it well/effectively - this is where inalienability may emerge (can’t ask, can’t tell) - there are lots of intermediate forms of the way we might frame/constrain the kinds of exchanges that we will allow; ability to correct
c) what are the societal overrides; what is allowable contexts within which we can override the rights/market actions of individuals. How to pick/adjudicate/etc.
d) How much supporting information infrastructure needed to enforce - various flavors
That;s the claim – answer these four question, rather than talking to me about dignity or markets"
Monday, May 17, 2004
Bloggers have set up a defence fund for the professor from Tokyo University who was arrested last week for copyright infringements arising out of the use of the P2P file sharing software he created, Winny.
The Washington Post reports that the EU Commission has agreed to hand over airline passenger data to the US, even though they're being challenged through the courts by the EU parliament on the issue.
"Angry midwives defy order to inform on asylum seekers" says the Gaurdian. Good for them say I. More power to their elbows and I hope they seriously embarrass the UK government over this. Just another example of the insidious nature of the national ID card proposals.
Meanwhile, on the other side of the Atlantic, "A federal advisory committee says Congress should pass laws to protect the civil liberties of Americans when the government sifts through computer records and data files for information about terrorists.", according to the NYT.
Finally on ID cards for today, The Scotsman reports that a large consultancy firm that advised the UK government on the introduction of the ID card stands to make a lot of money from the government process of implementing odious system. Deloite is one of the remaining two bidders in deciding what company will be the government's main commercial adviser on the scheme.
Take advice from the company that wants sell you whatever snake oil you currently crave and then buy the snake oil from them and their buddies. Just good business as far as Deloite and other similar placed bidders are concerned and I don't blame them for exploiting the technology-will-solve-the-problem-even-if-you-don't-know-what-the-problem-is snake oil junkies in government. The fault lies squarely with the junkies and the rest of us, who frankly are getting the government we deserve, as we're letting them get away with it.
"Angry midwives defy order to inform on asylum seekers" says the Gaurdian. Good for them say I. More power to their elbows and I hope they seriously embarrass the UK government over this. Just another example of the insidious nature of the national ID card proposals.
Meanwhile, on the other side of the Atlantic, "A federal advisory committee says Congress should pass laws to protect the civil liberties of Americans when the government sifts through computer records and data files for information about terrorists.", according to the NYT.
Finally on ID cards for today, The Scotsman reports that a large consultancy firm that advised the UK government on the introduction of the ID card stands to make a lot of money from the government process of implementing odious system. Deloite is one of the remaining two bidders in deciding what company will be the government's main commercial adviser on the scheme.
Take advice from the company that wants sell you whatever snake oil you currently crave and then buy the snake oil from them and their buddies. Just good business as far as Deloite and other similar placed bidders are concerned and I don't blame them for exploiting the technology-will-solve-the-problem-even-if-you-don't-know-what-the-problem-is snake oil junkies in government. The fault lies squarely with the junkies and the rest of us, who frankly are getting the government we deserve, as we're letting them get away with it.
Groklaw is reporting that Germany are going to vote against the EU's software directive, which the Irish presidency has been trying to slip through.
FFII say:
NB. See FFII breaking news wiki for very latest information, at
http://kwiki.ffii.org/SwpatcninoEn
It looks as though there's a chance things may be moving in our favour.
The agenda for the Competitiveness Council meeting has been published,
with a full discussion now scheduled on the Software Patents directive;
furthermore the discussion is to be in public, ie with press and
visitors able to listen in with 11-way translation.
http://ue.eu.int/cms3_applications/Applications/newsRoom/loadbook.asp?BID=880&LANG=1&cmsId=364
We don't yet know whether there's any chance of it being webcast.
This a big step forward from the official EU media briefing, published
only on Friday morning, which said the directive was due to be
rubberstamped as an 'A-item' without discussion.
http://europa.eu.int/rapid/start/cgi/guestfr.ksh?p_action.gettxt=gt&doc=MEMO/04/114%7C0%7CRAPID&lg=EN&display=
The EU media briefing also tries very hard to play the play up the Irish
draft as a 'compromise' position.
But it's clear from this report from Paul Meller that by the time of the
press conference this afternoon journalists were obviously well enough
briefed that the EU spokesman had to confirm everything we'd said:
http://www.itworld.com/Man/2687/040514eupatents/
The national positions won't finally be clear until we hear what
actually gets said on Tuesday, but there are signs that there may be an
increasing number of ministers with concerns about the text, and a very
real possibility that a number of countries may seek a delay to give time to
* achieve more unity;
* investigate further the concerns about
- freedom of discussion
- interoperability
- scope of what is and what is not 'technical';
* produce a text more likely to pass the European Parliament.
On the other hand, as best we know, the UK and Ireland are still pushing
all-out for the Presidency text.
FFII say:
NB. See FFII breaking news wiki for very latest information, at
http://kwiki.ffii.org/SwpatcninoEn
It looks as though there's a chance things may be moving in our favour.
The agenda for the Competitiveness Council meeting has been published,
with a full discussion now scheduled on the Software Patents directive;
furthermore the discussion is to be in public, ie with press and
visitors able to listen in with 11-way translation.
http://ue.eu.int/cms3_applications/Applications/newsRoom/loadbook.asp?BID=880&LANG=1&cmsId=364
We don't yet know whether there's any chance of it being webcast.
This a big step forward from the official EU media briefing, published
only on Friday morning, which said the directive was due to be
rubberstamped as an 'A-item' without discussion.
http://europa.eu.int/rapid/start/cgi/guestfr.ksh?p_action.gettxt=gt&doc=MEMO/04/114%7C0%7CRAPID&lg=EN&display=
The EU media briefing also tries very hard to play the play up the Irish
draft as a 'compromise' position.
But it's clear from this report from Paul Meller that by the time of the
press conference this afternoon journalists were obviously well enough
briefed that the EU spokesman had to confirm everything we'd said:
http://www.itworld.com/Man/2687/040514eupatents/
The national positions won't finally be clear until we hear what
actually gets said on Tuesday, but there are signs that there may be an
increasing number of ministers with concerns about the text, and a very
real possibility that a number of countries may seek a delay to give time to
* achieve more unity;
* investigate further the concerns about
- freedom of discussion
- interoperability
- scope of what is and what is not 'technical';
* produce a text more likely to pass the European Parliament.
On the other hand, as best we know, the UK and Ireland are still pushing
all-out for the Presidency text.
From Ian Brown of FIPR:
Where next for copyright in the new Europe?
-------------------------------------------
13 June 2004
Room H 2032, Technical University Berlin, main building
Strasse des 17. Juni, Berlin
(building 16 http://www.tu-berlin.de/karten/)
More information and updates at:
http://wizards-of-os.org/index.php?id=921
Associated with Wizards of OS 3: The Future of the Digital Commons 10-12
June, Berlin: http://wizards-of-os.org/index.php?id=50&L=3
Copyright law has become one of the most important and controversial
drivers of the Information Society. The Internet has made every user a
publisher, but copyright rules governing their activities are often
determined by opaque international bodies that decide rules with little
public input.
Join us in Berlin to debate where copyright *should* be going to ensure
that authors, musicians, film-makers and the public will all benefit.
Engage with leading international thinkers from across Europe and the
United States. Meet colleagues who are working to make sure all members
of society benefit from copyright.
Attendance is free thanks to sponsorship from the Open Society
Institute, but please send an e-mail to workshop@fipr.org to let us know
you will be coming for planning purposes.
Programme
=========
* Influencing the international agenda
Copyright policy has been a strongly international area of law since the
Berne convention was agreed in 1886. More recently, the World Trade
Organisation Agreement on Trade-Related aspects of Intellectual Property
Rights (TRIPS) and the World Intellectual Property Organisation
Copyright and Performances and Phonograms Treaties have changed
copyright law around the world. The European Union has passed five
copyright-related Directives in the last twelve years. How can civil
society play a full role in policy development in these fora?
1100 Teresa Hackett, Foundation for Information Policy Research:
International copyright bodies including the European Union and World
Intellectual Property Organisation
1110 Robin Gross, IP Justice: Free Trade Agreement of the Americas
experiences
1120 Simon Davies, Privacy International: European Union privacy
legislation experiences
1130 Sjoera Nas, Bits of Freedom: European Union spam legislation
experiences
1140 Audience
* Updating the Copyright Directive
The 2001 Copyright Directive is the key EU law that sets out how
copyright works are protected in Europe. A report on its operation
should be published by the Commission in the next 18 months, and can
recommend changes to improve its effect.
Which parts of the Directive is it most critical to change to benefit
the public interest? Given the controversy they have caused, are the
articles related to exceptions and technological protection measures
most vital? Where does civil society see the most urgency for change?
1200 Ian Brown, FIPR: Experiences in Canada, Australia and Japan
1210 Mindaugas Kiskis, Law University of Lithuania: Collecting societies
1220 Jonathan Griffiths*, Queen Mary, University of London: Protecting
free speech
1230 David Mann, Royal National Institute of the Blind: Collaborative
arrangements with publishers
1240 Lee Bygrave*, Norwegian Research Centre for Computers and Law:
Ensuring privacy
1250 Audience
1320-1430 Lunch
* Implementing the IPR Enforcement Directive
The controversial Intellectual Property Rights Enforcement Directive was
pushed through the European Parliament with no time to debate sweeping
last-minute changes from the EU Member States. It now covers any
infringement of any kind of intellectual property right. How can its
effects on civil society be minimised around the EU? Which countries
have the most to lose?
1430 Andreas Dietl, European Digital Rights: Remaining problems with the
Intellectual Property Rights Enforcement Directive
1440 Mariusz Kondrat*, Poland Office of the Committee for European
Integration: New member state issues and pharmaceuticals
1450 Georg Jakob, University of Salzburg: Winners and losers from the
Intellectual Property Rights Enforcement Directive
1500 Slobodan Markovic, Netcentar, Serbia*
1510 Audience
* Copyright beyond the EU
Countries aiming for EU membership in the next decade such as Romania,
Bulgaria and Turkey are updating their copyright laws as part of an
overall effort to harmonise law with the EU. What can they learn from
the experiences of new EU members like Slovenia that have already
harmonised their laws in the process of joining the EU? Countries
further east such as Armenia have signed Partnership and Cooperation
Agreements with the EU that include obligations to update copyright law,
and even those without formal obligations are influenced by the approach
of the EU. What positive and negative effects is this having? How can
civil society in the EU and beyond best work together to influence the
direction of copyright legislation?
1530 Maja Bogataj, University of Llubljana: Implementation of EU
copyright legislation in Slovenia
1540 David Sanduhkchyan, InterNews Armenia: Right holder demands on ISPs
in Armenia
1550 Teo Celakoski*, Multimedia Institute, Croatia: Civil society
cooperation in the EU and beyond
1600 Tattu Mambetalieva, Global Internet Policy Initiative, Kyrgyzstan:
Copyright convergence in central Asia
1610 Sacha Belyaeva, InterNews Russia: Russian copyright law and the All
of MP3 service
1620 Veni Markovski, Internet Society Bulgaria: Software company
lobbying in Bulgaria
1630 Audience
* Do we need a Digital Rights Directive?
Copyright law is often driven by the relatively small groups of right
holders whom it particularly benefits. Civil society and the general
public have had limited success in having their concerns taken into
account in such law. Should we instead push directly for an EU Digital
Rights Directive that would tip the balance back in our favour? What
would such a Directive contain? Or can we use existing human rights,
consumer and competition legislation to change the operation of
copyright legislation toward civil society interests?
1650 Ross Anderson, Cambridge University and FIPR: Enforcing competition
under trusted computing
1700 William Fisher, Berkman Center for Internet and Society: Reshaping
artist compensation
1710 Wendy Seltzer, Electronic Frontier Foundation and Berkman Center
for Internet and Society: Fixing the Digital Millennium Copyright Act
1720 Ville Oksanen, Helsinki Institute for Information Technology and
Electronic Frontier Finland: Balancing consumer and copyright law
1730 Audience
1800 Close
* Awaiting confirmation
Where next for copyright in the new Europe?
-------------------------------------------
13 June 2004
Room H 2032, Technical University Berlin, main building
Strasse des 17. Juni, Berlin
(building 16 http://www.tu-berlin.de/karten/)
More information and updates at:
http://wizards-of-os.org/index.php?id=921
Associated with Wizards of OS 3: The Future of the Digital Commons 10-12
June, Berlin: http://wizards-of-os.org/index.php?id=50&L=3
Copyright law has become one of the most important and controversial
drivers of the Information Society. The Internet has made every user a
publisher, but copyright rules governing their activities are often
determined by opaque international bodies that decide rules with little
public input.
Join us in Berlin to debate where copyright *should* be going to ensure
that authors, musicians, film-makers and the public will all benefit.
Engage with leading international thinkers from across Europe and the
United States. Meet colleagues who are working to make sure all members
of society benefit from copyright.
Attendance is free thanks to sponsorship from the Open Society
Institute, but please send an e-mail to workshop@fipr.org to let us know
you will be coming for planning purposes.
Programme
=========
* Influencing the international agenda
Copyright policy has been a strongly international area of law since the
Berne convention was agreed in 1886. More recently, the World Trade
Organisation Agreement on Trade-Related aspects of Intellectual Property
Rights (TRIPS) and the World Intellectual Property Organisation
Copyright and Performances and Phonograms Treaties have changed
copyright law around the world. The European Union has passed five
copyright-related Directives in the last twelve years. How can civil
society play a full role in policy development in these fora?
1100 Teresa Hackett, Foundation for Information Policy Research:
International copyright bodies including the European Union and World
Intellectual Property Organisation
1110 Robin Gross, IP Justice: Free Trade Agreement of the Americas
experiences
1120 Simon Davies, Privacy International: European Union privacy
legislation experiences
1130 Sjoera Nas, Bits of Freedom: European Union spam legislation
experiences
1140 Audience
* Updating the Copyright Directive
The 2001 Copyright Directive is the key EU law that sets out how
copyright works are protected in Europe. A report on its operation
should be published by the Commission in the next 18 months, and can
recommend changes to improve its effect.
Which parts of the Directive is it most critical to change to benefit
the public interest? Given the controversy they have caused, are the
articles related to exceptions and technological protection measures
most vital? Where does civil society see the most urgency for change?
1200 Ian Brown, FIPR: Experiences in Canada, Australia and Japan
1210 Mindaugas Kiskis, Law University of Lithuania: Collecting societies
1220 Jonathan Griffiths*, Queen Mary, University of London: Protecting
free speech
1230 David Mann, Royal National Institute of the Blind: Collaborative
arrangements with publishers
1240 Lee Bygrave*, Norwegian Research Centre for Computers and Law:
Ensuring privacy
1250 Audience
1320-1430 Lunch
* Implementing the IPR Enforcement Directive
The controversial Intellectual Property Rights Enforcement Directive was
pushed through the European Parliament with no time to debate sweeping
last-minute changes from the EU Member States. It now covers any
infringement of any kind of intellectual property right. How can its
effects on civil society be minimised around the EU? Which countries
have the most to lose?
1430 Andreas Dietl, European Digital Rights: Remaining problems with the
Intellectual Property Rights Enforcement Directive
1440 Mariusz Kondrat*, Poland Office of the Committee for European
Integration: New member state issues and pharmaceuticals
1450 Georg Jakob, University of Salzburg: Winners and losers from the
Intellectual Property Rights Enforcement Directive
1500 Slobodan Markovic, Netcentar, Serbia*
1510 Audience
* Copyright beyond the EU
Countries aiming for EU membership in the next decade such as Romania,
Bulgaria and Turkey are updating their copyright laws as part of an
overall effort to harmonise law with the EU. What can they learn from
the experiences of new EU members like Slovenia that have already
harmonised their laws in the process of joining the EU? Countries
further east such as Armenia have signed Partnership and Cooperation
Agreements with the EU that include obligations to update copyright law,
and even those without formal obligations are influenced by the approach
of the EU. What positive and negative effects is this having? How can
civil society in the EU and beyond best work together to influence the
direction of copyright legislation?
1530 Maja Bogataj, University of Llubljana: Implementation of EU
copyright legislation in Slovenia
1540 David Sanduhkchyan, InterNews Armenia: Right holder demands on ISPs
in Armenia
1550 Teo Celakoski*, Multimedia Institute, Croatia: Civil society
cooperation in the EU and beyond
1600 Tattu Mambetalieva, Global Internet Policy Initiative, Kyrgyzstan:
Copyright convergence in central Asia
1610 Sacha Belyaeva, InterNews Russia: Russian copyright law and the All
of MP3 service
1620 Veni Markovski, Internet Society Bulgaria: Software company
lobbying in Bulgaria
1630 Audience
* Do we need a Digital Rights Directive?
Copyright law is often driven by the relatively small groups of right
holders whom it particularly benefits. Civil society and the general
public have had limited success in having their concerns taken into
account in such law. Should we instead push directly for an EU Digital
Rights Directive that would tip the balance back in our favour? What
would such a Directive contain? Or can we use existing human rights,
consumer and competition legislation to change the operation of
copyright legislation toward civil society interests?
1650 Ross Anderson, Cambridge University and FIPR: Enforcing competition
under trusted computing
1700 William Fisher, Berkman Center for Internet and Society: Reshaping
artist compensation
1710 Wendy Seltzer, Electronic Frontier Foundation and Berkman Center
for Internet and Society: Fixing the Digital Millennium Copyright Act
1720 Ville Oksanen, Helsinki Institute for Information Technology and
Electronic Frontier Finland: Balancing consumer and copyright law
1730 Audience
1800 Close
* Awaiting confirmation
Thursday, May 13, 2004
In the Guardian,
"Brian Hadfield, the managing director of Unisys UK, a
US-based technology company that has worked on national
identity schemes in South Africa and Malaysia, questions the
usefulness of an ID card in countering the terror threat."
San Bernardino County in California are reportedly planning to defy an order by the Secretary of State banning the use of specific electronic voting machines in the presidential election in November. The county uses Sequoia machines, though, so I didn't think the order affected them anyway.
"Brian Hadfield, the managing director of Unisys UK, a
US-based technology company that has worked on national
identity schemes in South Africa and Malaysia, questions the
usefulness of an ID card in countering the terror threat."
San Bernardino County in California are reportedly planning to defy an order by the Secretary of State banning the use of specific electronic voting machines in the presidential election in November. The county uses Sequoia machines, though, so I didn't think the order affected them anyway.
Brendan O'Neill at Spiked has a conspiracy theory in his sights about the leaking of the torture photos from Abu Ghraib prison in Iraq.
The photos from Abu Ghraib may have only recently been published
but many in the American media have known of their existence for
months...
... Whether or not it was military figures in the Pentagon who leaked the
photos to the press, some of them have certainly used the ensuing
scandal to launch attacks against the civilian leadership in the
Department of Defence over the war in Iraq, specifically against
Donald Rumsfeld. One 'senior general at the Pentagon' told the
Washington Post: 'I do not believe we had a clearly defined war
strategy…. [Rumsfeld] refused to listen or adhere to military advice.'
A special forces officer said: 'Rumsfeld needs to go, as does Paul
Wolfowtiz [Rumsfeld's deputy].' (14)
In an unprecedented move, the Army Times, the US military
newspaper that gets distributed to American forces around the
world, published an editorial in the wake of the torture scandal calling
for Rumsfeld to resign, describing the torture scandal as 'a failure of
leadership from start to finish'. "
The photos from Abu Ghraib may have only recently been published
but many in the American media have known of their existence for
months...
... Whether or not it was military figures in the Pentagon who leaked the
photos to the press, some of them have certainly used the ensuing
scandal to launch attacks against the civilian leadership in the
Department of Defence over the war in Iraq, specifically against
Donald Rumsfeld. One 'senior general at the Pentagon' told the
Washington Post: 'I do not believe we had a clearly defined war
strategy…. [Rumsfeld] refused to listen or adhere to military advice.'
A special forces officer said: 'Rumsfeld needs to go, as does Paul
Wolfowtiz [Rumsfeld's deputy].' (14)
In an unprecedented move, the Army Times, the US military
newspaper that gets distributed to American forces around the
world, published an editorial in the wake of the torture scandal calling
for Rumsfeld to resign, describing the torture scandal as 'a failure of
leadership from start to finish'. "
From James Heald of FFII:
"See stories on the FFII 'breaking news' wiki at
http://kwiki.ffii.org/SwpatcninoEn
* Luxembourg has called in the text. There /will/ now be a
round-the-table discussion of it by the ministers.
It will now /not/ be taken as one of the 'A items' nodded through
en-bloc at the start of the agenda.
* The leading German official has confirmed Germany still opposes the
proposed text.
http://kwiki.ffii.org/?DemoBerlin040513En
* Belgium and Slovenia are also likely to follow Germany on this.
* Poland: Richard Stallmann and others have made a big impact at a
lengthy session in the Polish parliament.
Previously Poland appears to have been keeping its head down.
* France: Le Monde has reminded the French president that he had
previously promised to opposed software patents, before the French
presidential election in 2002
http://www.weblmi.com/news_store/2004_05_12_Bataille_sur_les_bre_18/News_view
The issue is very much "in play".
===================================================================
In the UK and Ireland, our best chance I think is to try to convince the
powers that be that the proposed draft will simply not go through the
European Parliament, however much the Patent Office is pushing for it,
because it gives *nothing at all* in the three most important areas
where the Parliament expressed concern:
-- *nothing* to give explicit reassurance that ordinary discussion of
algorithms in the form of code fragments will not be silenced by program
claims. (article 5.2). A provision that such discussion should be
considered 'fair use' would at least offer an olive branch here.
-- *nothing* to prevent dominant patent owners locking out specific
competitors for interoperability by refusing patent licences, short of a
full-scale EU Competition commission investigation. (article 6a). (The
EP wanted to allow automatic unfettered use. As a compromise Denmark
has suggested creating new fast-track procedures to allow compulsory
RAND licensing -- but this is rejected in the Irish draft)
-- most importantly, *nothing* to clarify what should be considered
"technical". The EP wanted a reference to "control of the forces of
nature" as the acid test, and a statement that the mere processing of
data is not technical.(articles 2, 3a and 4). But all the EP's
amendments in this area are rejected.
Past UK case law also supports the idea that methods which merely
address generic data relate to "computer programs as such", and only
become technical if the data has a specific technological relevance
beyond this; thus the current Patent Office manual states:
"1.26.4 The reference in Merrill Lynch to Vicom involving an
increase in speed (see 1.26.2) does not mean that an increase in speed
of itself is enough. This point was considered in Options Clearing Corpn
Inc's Application (unreported) when the hearing officer concluded that
Vicom was allowable because it produced an advance, namely an increase
in speed, in a technical field, namely the technical field of image
enhancement, and not simply because of the advance itself".
This principle should be upheld; but the EPO is already granting patents
far beyond this.
The European Parliament proposed a specific amendment that a mere
increase in the speed of data processing should not of itself be
considered technical; but this amendment is also to be rejected.
If the Council makes no attempt to engage with the Parliament on any of
these concerns, it seems quite likely to lose the entire Directive."
Bertie and the boys (i.e. the Irish government), as they say in Ireland, may not have as smooth a ride on EU software patents as they expected.
"See stories on the FFII 'breaking news' wiki at
http://kwiki.ffii.org/SwpatcninoEn
* Luxembourg has called in the text. There /will/ now be a
round-the-table discussion of it by the ministers.
It will now /not/ be taken as one of the 'A items' nodded through
en-bloc at the start of the agenda.
* The leading German official has confirmed Germany still opposes the
proposed text.
http://kwiki.ffii.org/?DemoBerlin040513En
* Belgium and Slovenia are also likely to follow Germany on this.
* Poland: Richard Stallmann and others have made a big impact at a
lengthy session in the Polish parliament.
Previously Poland appears to have been keeping its head down.
* France: Le Monde has reminded the French president that he had
previously promised to opposed software patents, before the French
presidential election in 2002
http://www.weblmi.com/news_store/2004_05_12_Bataille_sur_les_bre_18/News_view
The issue is very much "in play".
===================================================================
In the UK and Ireland, our best chance I think is to try to convince the
powers that be that the proposed draft will simply not go through the
European Parliament, however much the Patent Office is pushing for it,
because it gives *nothing at all* in the three most important areas
where the Parliament expressed concern:
-- *nothing* to give explicit reassurance that ordinary discussion of
algorithms in the form of code fragments will not be silenced by program
claims. (article 5.2). A provision that such discussion should be
considered 'fair use' would at least offer an olive branch here.
-- *nothing* to prevent dominant patent owners locking out specific
competitors for interoperability by refusing patent licences, short of a
full-scale EU Competition commission investigation. (article 6a). (The
EP wanted to allow automatic unfettered use. As a compromise Denmark
has suggested creating new fast-track procedures to allow compulsory
RAND licensing -- but this is rejected in the Irish draft)
-- most importantly, *nothing* to clarify what should be considered
"technical". The EP wanted a reference to "control of the forces of
nature" as the acid test, and a statement that the mere processing of
data is not technical.(articles 2, 3a and 4). But all the EP's
amendments in this area are rejected.
Past UK case law also supports the idea that methods which merely
address generic data relate to "computer programs as such", and only
become technical if the data has a specific technological relevance
beyond this; thus the current Patent Office manual states:
"1.26.4 The reference in Merrill Lynch to Vicom involving an
increase in speed (see 1.26.2) does not mean that an increase in speed
of itself is enough. This point was considered in Options Clearing Corpn
Inc's Application (unreported) when the hearing officer concluded that
Vicom was allowable because it produced an advance, namely an increase
in speed, in a technical field, namely the technical field of image
enhancement, and not simply because of the advance itself".
This principle should be upheld; but the EPO is already granting patents
far beyond this.
The European Parliament proposed a specific amendment that a mere
increase in the speed of data processing should not of itself be
considered technical; but this amendment is also to be rejected.
If the Council makes no attempt to engage with the Parliament on any of
these concerns, it seems quite likely to lose the entire Directive."
Bertie and the boys (i.e. the Irish government), as they say in Ireland, may not have as smooth a ride on EU software patents as they expected.
Wednesday, May 12, 2004
BIPlog reports on self destructing DVDs.
"What's the latest way to access expression in the film world? EZ-D, a DVD "purchase" with a timeclock that allows you to
watch the movie as many times as you want for 48 hours, then poof! -- the work disappears.
Question is, how happy are we about moving to a model where we buy things for two days at a time? Should we let the line
between ownership and not be so E-Zly blurred? Are imploding expressive goods a good idea?"
"What's the latest way to access expression in the film world? EZ-D, a DVD "purchase" with a timeclock that allows you to
watch the movie as many times as you want for 48 hours, then poof! -- the work disappears.
Question is, how happy are we about moving to a model where we buy things for two days at a time? Should we let the line
between ownership and not be so E-Zly blurred? Are imploding expressive goods a good idea?"
Clay Shirky thinks Groklaw may be the MVP in the SCO v IBM linux legal dispute.
"GrokLaw: MVP of the SCO Wars
Liz has convinced me that one of the most profound effects of weblogs is the communal workings of those who publish them,
and that they contribute significant new value to collaboration across disciplines and boundaries...
...By way of background, SCO, once a technology company,
has become a company devoted to a single legal strategy:
1. Assert rights to the Unix operating system
2. Assert infirnging contributions of Unix source code to Linux
3. Sue firms that sell or use Linux, especially deep-pocketed IBM
4. Profit!!!1! (or at least buyout by IBM, to save them the expense of the suit.)
Much of the matter is in dispute, and IANAL, but what is clear is this: a) many SCO employees contributed to the Linux kernel, back when SCO was a tech company (“oldSCO”), with the approval of their bosses, and b) the Groklaw is doing an astonishing, world-changing job of finding, documenting and publicizing these occurrences (alongside much other work on the case.)
Today’s entry reads:
Groklaw has reported before on contributions made to the Linux kernel by Christoph Hellwig while he was a Caldera employee. We have also offered some evidence of contributions by oldSCO employees as well. Alex Rosten decided to do
some more digging about the contributions of one kernel coder, Tigran Aivazian.
[…]
This paper is a group effort. Alex’s research was shared with others in the Groklaw community, who honed, edited, and added further research. Then the final draft was sent to Tigran himself, so he could correct and/or amplify, which he has done. Look at that second graf: “This paper is a group effort.” Everyone always says that about complex work, but this is different. This is the end of two-party law, where plaintiff and defendant duke it out in an arms race of $350/hr laywers and “Take that” counter-motions.
Instead, we have a third party, Groklaw, acting as a proxy for millions of Linux users, affecting the public perception of the case (and the outcome SCO wants has to do with its stock price, not redress in the courts.) Groklaw may also be affecting the case in the courts, by helping IBM with a distributed discovery effort that they, IBM, could never accomplish on their own, no matter how may lawyers they throw at it.
There are two ways to change the amount of leverage you have. The obvious one is to put more force on the lever, and this is what SCO thought they were doing — engaging IBM in a teeter-totter battle that would make it cheaper for IBM to simply buy SCO.
The other way to get more leverage is to move the fulcrum. Groklaw has moved the fulcrum of this battle considerably closer to SCO, making it easier for IBM to exert leverage, and harder for SCO to. I can’t predict how the current conflict will end, but the pattern Groklaw has established, of acting on behalf of the people who will be adversely affected by a two-party legal battle, has already been vindicated, even if SCO avoids bankruptcy."
How the Net can make a difference.
"GrokLaw: MVP of the SCO Wars
Liz has convinced me that one of the most profound effects of weblogs is the communal workings of those who publish them,
and that they contribute significant new value to collaboration across disciplines and boundaries...
...By way of background, SCO, once a technology company,
has become a company devoted to a single legal strategy:
1. Assert rights to the Unix operating system
2. Assert infirnging contributions of Unix source code to Linux
3. Sue firms that sell or use Linux, especially deep-pocketed IBM
4. Profit!!!1! (or at least buyout by IBM, to save them the expense of the suit.)
Much of the matter is in dispute, and IANAL, but what is clear is this: a) many SCO employees contributed to the Linux kernel, back when SCO was a tech company (“oldSCO”), with the approval of their bosses, and b) the Groklaw is doing an astonishing, world-changing job of finding, documenting and publicizing these occurrences (alongside much other work on the case.)
Today’s entry reads:
Groklaw has reported before on contributions made to the Linux kernel by Christoph Hellwig while he was a Caldera employee. We have also offered some evidence of contributions by oldSCO employees as well. Alex Rosten decided to do
some more digging about the contributions of one kernel coder, Tigran Aivazian.
[…]
This paper is a group effort. Alex’s research was shared with others in the Groklaw community, who honed, edited, and added further research. Then the final draft was sent to Tigran himself, so he could correct and/or amplify, which he has done. Look at that second graf: “This paper is a group effort.” Everyone always says that about complex work, but this is different. This is the end of two-party law, where plaintiff and defendant duke it out in an arms race of $350/hr laywers and “Take that” counter-motions.
Instead, we have a third party, Groklaw, acting as a proxy for millions of Linux users, affecting the public perception of the case (and the outcome SCO wants has to do with its stock price, not redress in the courts.) Groklaw may also be affecting the case in the courts, by helping IBM with a distributed discovery effort that they, IBM, could never accomplish on their own, no matter how may lawyers they throw at it.
There are two ways to change the amount of leverage you have. The obvious one is to put more force on the lever, and this is what SCO thought they were doing — engaging IBM in a teeter-totter battle that would make it cheaper for IBM to simply buy SCO.
The other way to get more leverage is to move the fulcrum. Groklaw has moved the fulcrum of this battle considerably closer to SCO, making it easier for IBM to exert leverage, and harder for SCO to. I can’t predict how the current conflict will end, but the pattern Groklaw has established, of acting on behalf of the people who will be adversely affected by a two-party legal battle, has already been vindicated, even if SCO avoids bankruptcy."
How the Net can make a difference.
Straight from the Source: Perspectives from the African Open Source Movement. Highly recommended. If you can't manage the full 17 pages, at least read the summary. Extract -
"For a software developer working in Africa, Philip Mbogo's problem is as basic as it gets: "I don't have a computer," he said. "I have to go for unpaid work in order just to get on a computer." Internet access is also an expensive rarity, so he counts himself fortunate to work as an intern at an Internet service provider where he takes as much advantage of the bandwidth as he can. "Anything I can get I download. I even got [a Linux distribution called] Debian, which takes two days [to download]."
African software developers face many obstacles as they struggle to work in this field. But these "coders", as a group, form a community marked less by their frustration and isolation than by their perseverance and resolve. This theme dominated AfricaSource, a workshop held in Namibia in March 2004 and organised by the Tactical Technology Collective, AllAfrica Foundation and SchoolNet Namibia. The meeting in the small town of Okahandja of 40 software developers from 25 countries was for many the first chance to collaborate and compare notes.
Lack of access to the means and tools of production is the issue African programmers most commonly identify as the greatest barrier to success in their work. But at this event, coders got a chance to share the innovative ways they work around the problem. "We buy computer parts bit by bit. In the space of three or four months we have a computer," says Ayeni Samuel Olaoluwa, a web developer from Nigeria, who saves up to 50% this way. Another method he has devised is keeping his freelance clients' work on computers he uses as part of his day job. "I am able to hide stuff on the server, but when I leave the company I'm in trouble."
The prohibitive costs of bandwidth and hardware are an obstruction most programmers face, but it affects coders most seriously at the time they are preparing to enter the job market. Without the opportunity to earn salaries that would help them afford equipment of their own, ambitious market entrants eager for work face the prospect of successive, often unpaid, internships just to prove their skills.
This predicament is widespread across Africa, says Ghanaian Guido Sohne, "There are not enough projects available to work on to employ the available talent…. In most African countries IT is not part of the economic production process. It's actually more expensive to computerise your accounting system than to hire more people to do it manually." So when programmers do find jobs, a large percentage tend to find themselves ushered into system administration and technical roles, where they are overworked and their skills are underutilised."
I complain that my office desktop computer crashes half a doxen times a day. I at least have the access and can always revert to the laptop when the inevitable Micrsoft blue screen of death makes its regular appearance.
"For a software developer working in Africa, Philip Mbogo's problem is as basic as it gets: "I don't have a computer," he said. "I have to go for unpaid work in order just to get on a computer." Internet access is also an expensive rarity, so he counts himself fortunate to work as an intern at an Internet service provider where he takes as much advantage of the bandwidth as he can. "Anything I can get I download. I even got [a Linux distribution called] Debian, which takes two days [to download]."
African software developers face many obstacles as they struggle to work in this field. But these "coders", as a group, form a community marked less by their frustration and isolation than by their perseverance and resolve. This theme dominated AfricaSource, a workshop held in Namibia in March 2004 and organised by the Tactical Technology Collective, AllAfrica Foundation and SchoolNet Namibia. The meeting in the small town of Okahandja of 40 software developers from 25 countries was for many the first chance to collaborate and compare notes.
Lack of access to the means and tools of production is the issue African programmers most commonly identify as the greatest barrier to success in their work. But at this event, coders got a chance to share the innovative ways they work around the problem. "We buy computer parts bit by bit. In the space of three or four months we have a computer," says Ayeni Samuel Olaoluwa, a web developer from Nigeria, who saves up to 50% this way. Another method he has devised is keeping his freelance clients' work on computers he uses as part of his day job. "I am able to hide stuff on the server, but when I leave the company I'm in trouble."
The prohibitive costs of bandwidth and hardware are an obstruction most programmers face, but it affects coders most seriously at the time they are preparing to enter the job market. Without the opportunity to earn salaries that would help them afford equipment of their own, ambitious market entrants eager for work face the prospect of successive, often unpaid, internships just to prove their skills.
This predicament is widespread across Africa, says Ghanaian Guido Sohne, "There are not enough projects available to work on to employ the available talent…. In most African countries IT is not part of the economic production process. It's actually more expensive to computerise your accounting system than to hire more people to do it manually." So when programmers do find jobs, a large percentage tend to find themselves ushered into system administration and technical roles, where they are overworked and their skills are underutilised."
I complain that my office desktop computer crashes half a doxen times a day. I at least have the access and can always revert to the laptop when the inevitable Micrsoft blue screen of death makes its regular appearance.
Ed Felten points to an op ed piece in CSO magazine by Simson Garfinkel that demonstrates, yet again, how careless we are in our use of computers.
"A FEW YEARS AGO, when
I was in Silicon Valley with
nothing to do, I stopped by
one of the valley's famed
stores that sell used and
"recycled" computers...
...But the real treasure trove that day wasn't on the store's display shelves; it was in the
warehouse. The cavernous space out back had several shelves stacked high with old hard
drives, each $5, "as is and untested," according to the sign...
...I bought 20 of them.
I took the drives home and started my own forensic analysis. Several of the drives had
source code from high-tech companies. One drive had a confidential memorandum
describing a biotech project; another had internal spreadsheets belonging to an
international shipping company.
Since then, I have repeatedly indulged my habit for procuring and then analyzing
secondhand hard drives. I bought recycled drives in Bellevue, Wash., that had internal
Microsoft e-mail (somebody who was working from home, apparently). Drives that I
found at an MIT swap meet had financial information on them from a Boston-area
investment firm. Last summer, I started buying drives en masse on eBay.
In all, I bought and analyzed the content of more than 150 drives with the help of Abhi
Shelat, another graduate student at MIT's Laboratory for Computer Science. We found
that between one-third and one-half of the drives still had significant amounts of
confidential data, even though many had been through a Format or FDisk operation. On
another third, someone had deleted the document files but left the applications behind. It
was a simple matter to undelete the data files and retrieve their secrets as well.
In fact, only 10 percent of the drives I purchased had been properly sanitized.
Much of the data we found was truly shocking. One of the drives once lived in an ATM. It
contained a year's worth of financial transactions—including account numbers and
withdrawal amounts—from a organization that had a legal requirement to not divulge such
information. Two other drives contained more than 5,000 credit card numbers—it looked
as if one had been inside a cash register. Another had e-mail and personal financial
records of a 45-year-old fellow in Georgia. The man is divorced, paying child support and
dating a woman he met in Savannah. And, oh yeah, he's really into pornography...
...Perhaps the saddest observation in our story is that erasing information from hard drives is
not difficult—with a little bit of Web searching, we found more than 50 programs that
purport to clean your hard drive so that the information on it cannot be recovered using
even the most advanced technical means...
...One key reason for today's poor disk sanitization practices is that it's very difficult to tell
the difference between a disk that has been properly sanitized and one that's simply been
reformatted...
...Another reason, we suspect, is that most people don't appreciate
the risk—the used-computer market is literally awash with
personal information from businesses and individuals, yet there
are relatively few cases of that information being used for
nefarious purposes."
ON the latter, it's only a matter of time. Garfinkel concludes:
"In the end, preventive technology is a better solution to the sanitization problem. If you use an encrypted file system, you can sanitize a disk simply by erasing the key. I'd like to see that sort of technology built in to hard drives. Or better, perhaps someday soon, all disk drives will come with a self-destruct feature—just like Star Trek's Enterprise did!"
"A FEW YEARS AGO, when
I was in Silicon Valley with
nothing to do, I stopped by
one of the valley's famed
stores that sell used and
"recycled" computers...
...But the real treasure trove that day wasn't on the store's display shelves; it was in the
warehouse. The cavernous space out back had several shelves stacked high with old hard
drives, each $5, "as is and untested," according to the sign...
...I bought 20 of them.
I took the drives home and started my own forensic analysis. Several of the drives had
source code from high-tech companies. One drive had a confidential memorandum
describing a biotech project; another had internal spreadsheets belonging to an
international shipping company.
Since then, I have repeatedly indulged my habit for procuring and then analyzing
secondhand hard drives. I bought recycled drives in Bellevue, Wash., that had internal
Microsoft e-mail (somebody who was working from home, apparently). Drives that I
found at an MIT swap meet had financial information on them from a Boston-area
investment firm. Last summer, I started buying drives en masse on eBay.
In all, I bought and analyzed the content of more than 150 drives with the help of Abhi
Shelat, another graduate student at MIT's Laboratory for Computer Science. We found
that between one-third and one-half of the drives still had significant amounts of
confidential data, even though many had been through a Format or FDisk operation. On
another third, someone had deleted the document files but left the applications behind. It
was a simple matter to undelete the data files and retrieve their secrets as well.
In fact, only 10 percent of the drives I purchased had been properly sanitized.
Much of the data we found was truly shocking. One of the drives once lived in an ATM. It
contained a year's worth of financial transactions—including account numbers and
withdrawal amounts—from a organization that had a legal requirement to not divulge such
information. Two other drives contained more than 5,000 credit card numbers—it looked
as if one had been inside a cash register. Another had e-mail and personal financial
records of a 45-year-old fellow in Georgia. The man is divorced, paying child support and
dating a woman he met in Savannah. And, oh yeah, he's really into pornography...
...Perhaps the saddest observation in our story is that erasing information from hard drives is
not difficult—with a little bit of Web searching, we found more than 50 programs that
purport to clean your hard drive so that the information on it cannot be recovered using
even the most advanced technical means...
...One key reason for today's poor disk sanitization practices is that it's very difficult to tell
the difference between a disk that has been properly sanitized and one that's simply been
reformatted...
...Another reason, we suspect, is that most people don't appreciate
the risk—the used-computer market is literally awash with
personal information from businesses and individuals, yet there
are relatively few cases of that information being used for
nefarious purposes."
ON the latter, it's only a matter of time. Garfinkel concludes:
"In the end, preventive technology is a better solution to the sanitization problem. If you use an encrypted file system, you can sanitize a disk simply by erasing the key. I'd like to see that sort of technology built in to hard drives. Or better, perhaps someday soon, all disk drives will come with a self-destruct feature—just like Star Trek's Enterprise did!"
Avi Rubin has had recent first hand experience of being on the receiving end of a false positive experience at an airport in California. The equipment detected non eixistent explosives in his belongings.
Prof Rubin also points to a slighly longer version of the hilarious clip from The Daily Show at Comedy Central on electronic voting.
Prof Rubin also points to a slighly longer version of the hilarious clip from The Daily Show at Comedy Central on electronic voting.
I always seem to come away from reading Noam Chomsky's ideas with deep concerns about the world we live in and that which our children are inheriting. This essay in the aftermath of the September 11, 2001 tragedies, invokes just those feelings. The mere mention of Chomsky causes some people to foam at the mouth, but even when I can't accept his theses, reading them is enlightening if also anxiety and depression inducing!
Donna is pleased that the antidote to the DMCA is getting a hearing on Capitol Hill.
Fair Use Gets Fair Play on Capitol Hill
This Wednesday, May 12th, marks the first time since the DMCA was enacted in 1998 that Congress will hold hearings on
legislation to reform it.
The Digital Media Consumers' Rights Act, or DMCRA, has three important goals:
#1: Warning: You're About to Pay Full Price for a Hobbled CD
The DMCRA would require labels on copy-protected "CDs," letting us know that we can't actually use what we've purchased
except under limited circumstances. That's right -- you get advance warning that you're paying the same price for less
functionality.
#2: You Get to Reclaim Fair Uses of Digital Media That You Already Have in Analog Media
The DMC_R_A would put the Rights back in the DMCA. The bill amends the DMCA to allow you to circumvent copyright
controls on digital media for legitimate purposes -- for example, to make the fair uses that copyright law ordinarily and
traditionally allows.
Among other things, this would mean that:
a.) when most scholarly communication, publishing, instruction etc., takes place using digital media/online, our ability to share
knowledge and learn from one another won't be a distant and fast-fading memory;
b.) when researchers want to "tinker" to advance our scientific knowledge, they won't face a significant barrier -- like the
repeated threat of litigation; and
c.) when librarians seek to preserve our history in digital media, they won't have to wait three years at a time to beg the
Copyright Office for the narrowly defined technical ability to do so.
#3: These Will Be Real, Not Phantom/Illusory Fair Use Rights
The DMCRA would affirmatively allow the creation/distribution of devices that circumvent copyright controls, when the devices
have substantial non-infringing uses. That means inventors will be able to invent the next VCR or TiVo without asking
Hollywood's permission first. And if a researcher has created a circumvention tool for the purposes of researching/testing
web-filtering mechanisms, the researcher won't be limited to describing the controversial results. He or she could share the tool
with the scholarly community.
Fair Use Gets Fair Play on Capitol Hill
This Wednesday, May 12th, marks the first time since the DMCA was enacted in 1998 that Congress will hold hearings on
legislation to reform it.
The Digital Media Consumers' Rights Act, or DMCRA, has three important goals:
#1: Warning: You're About to Pay Full Price for a Hobbled CD
The DMCRA would require labels on copy-protected "CDs," letting us know that we can't actually use what we've purchased
except under limited circumstances. That's right -- you get advance warning that you're paying the same price for less
functionality.
#2: You Get to Reclaim Fair Uses of Digital Media That You Already Have in Analog Media
The DMC_R_A would put the Rights back in the DMCA. The bill amends the DMCA to allow you to circumvent copyright
controls on digital media for legitimate purposes -- for example, to make the fair uses that copyright law ordinarily and
traditionally allows.
Among other things, this would mean that:
a.) when most scholarly communication, publishing, instruction etc., takes place using digital media/online, our ability to share
knowledge and learn from one another won't be a distant and fast-fading memory;
b.) when researchers want to "tinker" to advance our scientific knowledge, they won't face a significant barrier -- like the
repeated threat of litigation; and
c.) when librarians seek to preserve our history in digital media, they won't have to wait three years at a time to beg the
Copyright Office for the narrowly defined technical ability to do so.
#3: These Will Be Real, Not Phantom/Illusory Fair Use Rights
The DMCRA would affirmatively allow the creation/distribution of devices that circumvent copyright controls, when the devices
have substantial non-infringing uses. That means inventors will be able to invent the next VCR or TiVo without asking
Hollywood's permission first. And if a researcher has created a circumvention tool for the purposes of researching/testing
web-filtering mechanisms, the researcher won't be limited to describing the controversial results. He or she could share the tool
with the scholarly community.
Waldon O'Dell, Diebold's CEO, today admits in the NYT that he made a "huge mistake" last year in declaring he wanted to deliver the election for George Bush. He's getting out of politics and planning to stay out as long as Diebold are in the voting machine business. Good for him.
The Washington Post, last week, had a good article on the electronic voting shenanigans in the US. There was nothing new in it but lots of useful links to related stories.
There are lots of very experienced election registrars genuinely supporting electronic voting and suggesting there has been too much focus on the tecnology and not enough on the overall election process, which has other built in safeguards, not least of which are vast numbers of dedicated election officials of impeccable integrity. Whilst I understand that point of view and the need to 'get the job done', whilst critics complain about 'hypothetical scenarios that have never happened', there have been significant failures with these machines. Officials who have not experienced such failures believe that they will not happen on their watch. But the security of the system is only as good as the weakest link and at the moment the weakest link is the technology, as has been repeatedly demonstrated.
Folk like Avi Rubin and David Gill really do understand the technology. With people of that calibre saying it neither implements security that is possible nor even implement security safeguards that are easy, we should be taking serious notice. Deploying technology in such a mission critical way fundamentally requires an understanding of that technology.
Whilst I have every sympathy with election officials, I have none at all for those like the Information Technology Association of America (ITAA - the trade association representing amongst others, surprise suprise, the electronic voting machine vendors) spouting complete nonsense like "Electronic voting systems work, and work well. Our recent survey shows that over two thirds of Americans believe that electronic voting is a secure, reliable way to conduct elections." This reminds me of the line from one of my favorite BBC TV shows of all time, Yes Prime Minister where Sir Humphrey Appleby is persuading the Prime Minister that he should invest in Trident: "It's the biggest and the best and the British people must have the best." Also the following sequence where Sir Humphrey and Bernard are discussing opinion polls:
Bernard: "He thinks..he thinks it's a vote winner."
Sir Humphrey (Sir H).: "Ah, that's more serious. What makes him think that?"
Bernard: "Well the party have had an opinion poll done. It seems all the voters are in favour of bringing back national service."
Sir H.: "Well have another opinion poll done showing the voters are against bringing back national service."
Bernard: "They can't be for it and against it."
Sir H. : "Oh of course they can, Bernard. Have you ever been surveyed?"
Bernard : "Yes. Well not me actually, my house. Oh I see what you mean."
Sir H.: "Well Bernard you know what happens. Nice young lady comes up to you. Obviously you want to create a good
impression. You don't want to look a fool, do you?"
Bernard: "No."
Sir H.: "No. So she starts asking you some questions. Mr. Wooley, are you worried about the number of young people without
jobs?"
B: "Yes"
Sir H.: "Are you worried about the rise in crime among teenagers?"
Bernard: "Yes"
Sir H. "Do you think there is a lack of discipline in our comprehensive schools?"
Bernard: "Yes"
Sir H.: "Do you think young people welcome some authority and leadership in their lives?"
Bernard: "Yes."
Sir H.: "Do you think they respond to a challenge?"
Bernard: "Yes."
Sir H: "Would you be in favour of re-introducing national service?"
Bernard: "Y… oh ..well I suppose I might be."
Sir H.: "Yes or no?"
Bernard: "Yes"
Sir H. : "Of course you would, Bernard. After all you've told you can't say no to that. So they don't mention the first five
questions and they publish the last one."
Bernard: "Is that really what they do?"
Sir H.: Well no not the reputable ones no but there aren't many of those. So alternatively the young lady can get the opposite
result."
Bernard: "How?"
Sir H.: "Mr Wooley, are you worried about the danger of war?"
Bernard: "Yes"
Sir H. : "Are you worried about the growth of armaments?"
Bernard: "Yes."
Sir H. : "Do you think there is a danger in giving young people guns and teaching them how to kill?"
Bernard: "Yes."
Sir H. : "Do you think it is wrong to force people to take up arms against their will?"
Bernard: "Yes."
Sir H.: "Would you oppose the re-introduction of national service?"
Bernard : "Yes."
Sir H. : "There you are you see, Bernard, the perfect balanced sample. So we just commission our own survey for the ministry
of defence. See to it Bernard."
There are lots of very experienced election registrars genuinely supporting electronic voting and suggesting there has been too much focus on the tecnology and not enough on the overall election process, which has other built in safeguards, not least of which are vast numbers of dedicated election officials of impeccable integrity. Whilst I understand that point of view and the need to 'get the job done', whilst critics complain about 'hypothetical scenarios that have never happened', there have been significant failures with these machines. Officials who have not experienced such failures believe that they will not happen on their watch. But the security of the system is only as good as the weakest link and at the moment the weakest link is the technology, as has been repeatedly demonstrated.
Folk like Avi Rubin and David Gill really do understand the technology. With people of that calibre saying it neither implements security that is possible nor even implement security safeguards that are easy, we should be taking serious notice. Deploying technology in such a mission critical way fundamentally requires an understanding of that technology.
Whilst I have every sympathy with election officials, I have none at all for those like the Information Technology Association of America (ITAA - the trade association representing amongst others, surprise suprise, the electronic voting machine vendors) spouting complete nonsense like "Electronic voting systems work, and work well. Our recent survey shows that over two thirds of Americans believe that electronic voting is a secure, reliable way to conduct elections." This reminds me of the line from one of my favorite BBC TV shows of all time, Yes Prime Minister where Sir Humphrey Appleby is persuading the Prime Minister that he should invest in Trident: "It's the biggest and the best and the British people must have the best." Also the following sequence where Sir Humphrey and Bernard are discussing opinion polls:
Bernard: "He thinks..he thinks it's a vote winner."
Sir Humphrey (Sir H).: "Ah, that's more serious. What makes him think that?"
Bernard: "Well the party have had an opinion poll done. It seems all the voters are in favour of bringing back national service."
Sir H.: "Well have another opinion poll done showing the voters are against bringing back national service."
Bernard: "They can't be for it and against it."
Sir H. : "Oh of course they can, Bernard. Have you ever been surveyed?"
Bernard : "Yes. Well not me actually, my house. Oh I see what you mean."
Sir H.: "Well Bernard you know what happens. Nice young lady comes up to you. Obviously you want to create a good
impression. You don't want to look a fool, do you?"
Bernard: "No."
Sir H.: "No. So she starts asking you some questions. Mr. Wooley, are you worried about the number of young people without
jobs?"
B: "Yes"
Sir H.: "Are you worried about the rise in crime among teenagers?"
Bernard: "Yes"
Sir H. "Do you think there is a lack of discipline in our comprehensive schools?"
Bernard: "Yes"
Sir H.: "Do you think young people welcome some authority and leadership in their lives?"
Bernard: "Yes."
Sir H.: "Do you think they respond to a challenge?"
Bernard: "Yes."
Sir H: "Would you be in favour of re-introducing national service?"
Bernard: "Y… oh ..well I suppose I might be."
Sir H.: "Yes or no?"
Bernard: "Yes"
Sir H. : "Of course you would, Bernard. After all you've told you can't say no to that. So they don't mention the first five
questions and they publish the last one."
Bernard: "Is that really what they do?"
Sir H.: Well no not the reputable ones no but there aren't many of those. So alternatively the young lady can get the opposite
result."
Bernard: "How?"
Sir H.: "Mr Wooley, are you worried about the danger of war?"
Bernard: "Yes"
Sir H. : "Are you worried about the growth of armaments?"
Bernard: "Yes."
Sir H. : "Do you think there is a danger in giving young people guns and teaching them how to kill?"
Bernard: "Yes."
Sir H. : "Do you think it is wrong to force people to take up arms against their will?"
Bernard: "Yes."
Sir H.: "Would you oppose the re-introduction of national service?"
Bernard : "Yes."
Sir H. : "There you are you see, Bernard, the perfect balanced sample. So we just commission our own survey for the ministry
of defence. See to it Bernard."
The Boston Globe has picked up the story of the arrest of Japanese professor, Isamu Kaneko, over file sharing software Winny.
Tuesday, May 11, 2004
John Lettice is on the ID card case again at the Register, this time pointing out that Department for Homeland Security and a biometric company, Identix, which is is also supplying equipment for the UK Passport Service's ID card pilot, are on the receiving end of a lawsuit in the US. Two men are suing for slander and product liability as the Identix system helped to give them other people's criminal records.
One of the men actually got jailed for being a convicted felon carrying a gun, despite the fact that the crime on his record had been perpetrated by someone else who even had a completely different name, Kellogg as opposed to Benson.
How could that happen? Especially when UK Home Secretary, David Blunkett, seems to believe these seems are "impossible" to fool. It seems Benson had been fingerprinted for a traffic violation. Kellogg convicted of multiple crimes. But the admin number on their respective electronic fingerprint cards was accidentally duplicated. And when the records were entered on the criminal justice database, Benson got credited with Kellogg's crimes.
As Lettice concludes:
"For the rest of us, the real issue is how fallibility in software and human input can produce
extremely serious errors in systems which are intended to provide virtually infallible
identification. There is here no dispute that Benson's and Kellogg's biometric records are
entirely different (Benson has only nine fingertips, for starters), but the processes operated
in such a way that Benson's record got the convictions. These spread from Oregon to
California, and Benson's attorney claims that he is still recorded by the FBI as having
been arrested as a felon in possession of a firearm.
Organisations deploying such systems should of course be extremely concerned that they
are not subject to such errors. Aside from the impact on the victims, the creation of false
records will damage the integrity of the database they're used in initially, and the sharing of
this data will result in the corruption spreading into other systems. The further it gets, the
harder it will be to undo the damage. But the more sure the designers are that they've
ruled out problems like this, the harder it will be to have errors corrected. If it's
impossible, then the people complaining have got to be mad, right? The issue of how you
deal with the data is actually far more important than getting the technology to produce a
"unique" biometric."
One of the men actually got jailed for being a convicted felon carrying a gun, despite the fact that the crime on his record had been perpetrated by someone else who even had a completely different name, Kellogg as opposed to Benson.
How could that happen? Especially when UK Home Secretary, David Blunkett, seems to believe these seems are "impossible" to fool. It seems Benson had been fingerprinted for a traffic violation. Kellogg convicted of multiple crimes. But the admin number on their respective electronic fingerprint cards was accidentally duplicated. And when the records were entered on the criminal justice database, Benson got credited with Kellogg's crimes.
As Lettice concludes:
"For the rest of us, the real issue is how fallibility in software and human input can produce
extremely serious errors in systems which are intended to provide virtually infallible
identification. There is here no dispute that Benson's and Kellogg's biometric records are
entirely different (Benson has only nine fingertips, for starters), but the processes operated
in such a way that Benson's record got the convictions. These spread from Oregon to
California, and Benson's attorney claims that he is still recorded by the FBI as having
been arrested as a felon in possession of a firearm.
Organisations deploying such systems should of course be extremely concerned that they
are not subject to such errors. Aside from the impact on the victims, the creation of false
records will damage the integrity of the database they're used in initially, and the sharing of
this data will result in the corruption spreading into other systems. The further it gets, the
harder it will be to undo the damage. But the more sure the designers are that they've
ruled out problems like this, the harder it will be to have errors corrected. If it's
impossible, then the people complaining have got to be mad, right? The issue of how you
deal with the data is actually far more important than getting the technology to produce a
"unique" biometric."
Jonathan Wallace is fretting about president Bush again:
"Harry Truman understood that authority and responsibility are one, that they must lie in the same place. He put a sign on his desk that said, "The buck stops here." ...
...George Bush does not understand. It is impossible to determine where, if anywhere, in this administration the buck actually stops. The President too often seems to be the child of his vice president, Dick Cheney. The fact that they will be appearing together before the 9/11 Commission is not confidence inspiring. It is almost certainly planned this way so that Cheney can interrupt the president if he starts to blither...
...John later asks the president what his biggest mistake has been since September 11. "In the last campaign....you used to like to joke that it was trading Sammy Sosa."
And the President, God help us, replies:
Hmmm. I wish you'd given me this written question ahead of time so I could plan for it....I'm sure something will pop into my head here in the midst of this press conference with all the pressure of trying to come up with an answer, but it hadn't yet.
Which is why they won't send him before the experts on the 9/11 Commission without Dick Cheney there to interrupt and talk over him whenever necessary.
While we are all sweating it out, waiting for something to pop into the president's head, ask yourself the very serious question: where does the buck stop in this administration?"
"Harry Truman understood that authority and responsibility are one, that they must lie in the same place. He put a sign on his desk that said, "The buck stops here." ...
...George Bush does not understand. It is impossible to determine where, if anywhere, in this administration the buck actually stops. The President too often seems to be the child of his vice president, Dick Cheney. The fact that they will be appearing together before the 9/11 Commission is not confidence inspiring. It is almost certainly planned this way so that Cheney can interrupt the president if he starts to blither...
...John later asks the president what his biggest mistake has been since September 11. "In the last campaign....you used to like to joke that it was trading Sammy Sosa."
And the President, God help us, replies:
Hmmm. I wish you'd given me this written question ahead of time so I could plan for it....I'm sure something will pop into my head here in the midst of this press conference with all the pressure of trying to come up with an answer, but it hadn't yet.
Which is why they won't send him before the experts on the 9/11 Commission without Dick Cheney there to interrupt and talk over him whenever necessary.
While we are all sweating it out, waiting for something to pop into the president's head, ask yourself the very serious question: where does the buck stop in this administration?"
Out-Law reports on the UK government's proposals for a national ID card: ID Card Database emerges from the shadows
This piece nicely reminds us that in its original consultation exercise on what David Blunkett was then calling an "entitlement card" the government said “it is most unlikely that entitlement information relating to specific services would be held on the central register” which, of course, is the complete opposite of what it says in the draft bill on the subject published last week.
Chris Pounder of Masons (who also publish Out-Law) says:
“The Government’s proposals, if enacted in their current form,
could amount to the lawful, secret, unrecorded access by the
police and security services to centralised details which could,
over time, list all the important public and private services used
by each card-holder during his or her life-time”.
“This raises very serious and new privacy concerns about the
central registry database, as the two Commissioners charged with
protecting privacy in the ID Card scheme could be in the dark
about the volume and nature of the access requests to the central
registry database by the security service and police."
A society where we can map anyone in detail but not monitor everyone in detail. Hmmm, now where have I heard that one before?
This piece nicely reminds us that in its original consultation exercise on what David Blunkett was then calling an "entitlement card" the government said “it is most unlikely that entitlement information relating to specific services would be held on the central register” which, of course, is the complete opposite of what it says in the draft bill on the subject published last week.
Chris Pounder of Masons (who also publish Out-Law) says:
“The Government’s proposals, if enacted in their current form,
could amount to the lawful, secret, unrecorded access by the
police and security services to centralised details which could,
over time, list all the important public and private services used
by each card-holder during his or her life-time”.
“This raises very serious and new privacy concerns about the
central registry database, as the two Commissioners charged with
protecting privacy in the ID Card scheme could be in the dark
about the volume and nature of the access requests to the central
registry database by the security service and police."
A society where we can map anyone in detail but not monitor everyone in detail. Hmmm, now where have I heard that one before?
Ian Brown at FIPR has pointed me at a piece by Toby Young in the Times where he considers the downside of recording the minutiae of life, which is now (naturally) facilitated by technology.
THE first law of technology is: anything personal
invariably becomes public. So it will be with the
SenseCam, a miniature camera that can record a
person’s entire day and store it in a computerised
diary. Developed by Microsoft’s British engineers,
the SenseCam will allow us to keep our entire lives
on disk. What a treasure trove of memories!
Alternatively, what a catalogue of indiscretions for
others to peruse! "
"It is only a matter of time, probably after some
horrible and shocking event, before Parliament
sets up a Department of Personal Records
requiring citizens to download their weekly
behaviour on to a national database. Strictly in the
interests of national security, of course."
"There is a second law of technology: it goes wrong"
He should have added that the third law of technology is that we use it unthinkingly and carelessly leading to adverse emergent properties...
I had a bad day in the office yesterday, when I was supposed to be on study leave, sorting out some difficulties with the new electronic computer marked assignment for my Internet law course. (Difficulties created by a completely avoidable accumulation of minor errors which the system then made difficult to correct and leading to the perception of a right-and-left-hands communications breakdown).
THE first law of technology is: anything personal
invariably becomes public. So it will be with the
SenseCam, a miniature camera that can record a
person’s entire day and store it in a computerised
diary. Developed by Microsoft’s British engineers,
the SenseCam will allow us to keep our entire lives
on disk. What a treasure trove of memories!
Alternatively, what a catalogue of indiscretions for
others to peruse! "
"It is only a matter of time, probably after some
horrible and shocking event, before Parliament
sets up a Department of Personal Records
requiring citizens to download their weekly
behaviour on to a national database. Strictly in the
interests of national security, of course."
"There is a second law of technology: it goes wrong"
He should have added that the third law of technology is that we use it unthinkingly and carelessly leading to adverse emergent properties...
I had a bad day in the office yesterday, when I was supposed to be on study leave, sorting out some difficulties with the new electronic computer marked assignment for my Internet law course. (Difficulties created by a completely avoidable accumulation of minor errors which the system then made difficult to correct and leading to the perception of a right-and-left-hands communications breakdown).
Monday, May 10, 2004
More academics as criminals news from Slashdot. An assistant professor of computer science at the University of Tokyo has been arrested for encouraging copyright infringement. He created P2P software 'Winny' based on Freenet, which unfortunately for him it seems, became rather popular.
I wonder how much this arrest might be related to some sensitive Japanese police information getting distributed round the Net via Winny? Or whether this may have been a minor contributory factor in the decision to make the arrest? I'm sure most of us would be annoyed if sensitive information from our systems got p2p'd in a widespread fashion.
This might be an interesting case to watch, especially since the Japanese have a more relaxed attitude to copyright infringement, at least when it comes to comics. That's, no doubt, an unfair generalisation, as comics are a pretty specific area but then, as an old college friend of mine used to delight in pointing out, generalisations are generally wrong.
I wonder how much this arrest might be related to some sensitive Japanese police information getting distributed round the Net via Winny? Or whether this may have been a minor contributory factor in the decision to make the arrest? I'm sure most of us would be annoyed if sensitive information from our systems got p2p'd in a widespread fashion.
This might be an interesting case to watch, especially since the Japanese have a more relaxed attitude to copyright infringement, at least when it comes to comics. That's, no doubt, an unfair generalisation, as comics are a pretty specific area but then, as an old college friend of mine used to delight in pointing out, generalisations are generally wrong.
The UK chancellor is apparently going to spend £150 million this summer with a view to expanding evoting.
“E-voting is a key measure to tackle so-called disengagement among young people,” said a Whitehall source. “Given the rapidly increasing use of text messages it is crucial that this is properly developed as a method of voting.”
Let's get the Big Brother and Pop Idol fans on their mobiles and that will solve the electoral participation crisis.
Give me strength. I'm seriuosly tempted to change the title of my book to Technology is The Answer to Everything (And The Eegits who believe this).
“E-voting is a key measure to tackle so-called disengagement among young people,” said a Whitehall source. “Given the rapidly increasing use of text messages it is crucial that this is properly developed as a method of voting.”
Let's get the Big Brother and Pop Idol fans on their mobiles and that will solve the electoral participation crisis.
Give me strength. I'm seriuosly tempted to change the title of my book to Technology is The Answer to Everything (And The Eegits who believe this).
Frank Field's latest contribution to the DRM debate - DRM is a folding chair.
"Here’s the real point – the folding chair really draws its effectiveness from the cultural norms that have built up around
it. An experienced Cambridge driver knows not to mess with a parking space that has a folding chair in it, even though she/he
has never experienced the consequences that I describe above. Speaking personally, I can’t name a single person who has
actually had this problem, but every Cambridge resident collectively knows that it would happen — even though a folding chair
is, practically speaking, a completely ineffective limit on the use of a parking space."
"Here’s the real point – the folding chair really draws its effectiveness from the cultural norms that have built up around
it. An experienced Cambridge driver knows not to mess with a parking space that has a folding chair in it, even though she/he
has never experienced the consequences that I describe above. Speaking personally, I can’t name a single person who has
actually had this problem, but every Cambridge resident collectively knows that it would happen — even though a folding chair
is, practically speaking, a completely ineffective limit on the use of a parking space."
Friday, May 07, 2004
Frank Field on cynicism.
"DRM is part of a process to break us of the nasty habit of thinking culture is a common good. Like a speed bump, it’s not about making us stop; it’s about making us recognize that someone thinks what we’re doing is wrong. And then usingour own naïvité to get us to stop. "
Makes me feel better that I'm not necessarily being "cynical", in the OED sense of the word, just attributing self serving motives to politicians and lobbyists.
"DRM is part of a process to break us of the nasty habit of thinking culture is a common good. Like a speed bump, it’s not about making us stop; it’s about making us recognize that someone thinks what we’re doing is wrong. And then usingour own naïvité to get us to stop. "
Makes me feel better that I'm not necessarily being "cynical", in the OED sense of the word, just attributing self serving motives to politicians and lobbyists.
There's a fascinating exhange of views going on between Ernest Miller, Ed Felten, and Frank Field on the subject of DRM, the broadcast flag and the copyfight in general.
Ernest believes bright people pushing for drm and other expansions of intellectual property rights have got a hidden agenda because they basically can't be stupid enough to really believe drm is going to prevent copyright infringement. So they must have a hidden agenda.
Ed says the some of folk pushing this agenda that he has discussed the issues with are passionate about what they are doing, really do believe it will work and needs to work in order to balance all the interests involved.
Frank partly supports Ed in suggesting we should never underestimate the power of ideology.
"The fact that "the road to hell is paved with good intentions" derives from the fact that, in order to function in an increasingly complex world, everyone is forced to construct simplifying models of the way that the world works. When these models (a)
work and (b) are buttressed with rationalizing arguments, we get something more potent - an ideology.
The problem with ideologies is that, even though they work, they rely upon simplifications that will not obtain over time. These simplifications will eventually be the downfall of the ideology, but sometimes it takes a very long time before the failure of the ideology is recognized, meaning that a lot of bad (and potentially quite destructive) decisions get made in the interim...
Ernest is right; our opponents are not (all) stupid people. But they don't have nefarious ends. Rather, they're acting within the confines of the ideologies that they believe explain the way the world works. They aren't evil or stupid; they're just confused and frustrated. The old methods aren't working, even though they *know* their methods are "right." In fact, they're in exactly the same boat that we are. And we know we aren't evil.
Ideologies are hard to defeat, because they're invisible to those who hold them. To us, it's an ideology; to them, it's "the way the world works." Beating it will take time, being honest about what is happening and working really hard to devise a new way of looking at the world that we can collectively agree upon.
We can't afford to write them off as "evil." That's seductive, but dangerous because it simply isn't true. They're just doing what they think is right. We have to respect that as we work to show them that they're mistaken. "
Siva Vaidhyanathan makes some related commentsat the Lessig blog in telling the story of meeting someone who takes the view of "the other side". Some who thought Larry Lessig was "a kook". Siva now reckons elements on the two sides are beginning to understand each other because those pusshing for expanded protection of intellectual property rights are resorting to ad hominem attacks. Adn they are doing this because the Lessig's of the world are winning the argument. Interesting theory but as Seth Finkelstein says in commenting on Siva's post,
"Unfortunately, yes, I think you hang around too many people who actually read the books they criticize. You're a professor. Academics are *supposed* to be polite. Not that they always are. But there is a strong cultural belief there, as evident in what you?re writing, that ad-hominem arguments are "wrong". Again, it may be honored more in the breech than in the observance, it may be an ideal not always practiced, but it's part of the formal codes of conduct.
Hang out with lawyers and lobbyists and politicians more. To them, lying and smearing and ad-hominem attacks are *tactics*, debate *options*. Whether they use those approaches depends entirely on whether they think they can get away with it, that it'll work with the audience. It's a pure strategic calculation. They may decide they'll look bad if they lie. They may decide it's worth it. Situations vary. But the truth or intellectual strength of the argument bears a very tenuous relationship to the approaches employed.
I certainly don't see any change at all, in terms of Jack "Boston Strangler" Valenti style rhetoric.
And remember, a mosquito is slammed hard, but that doesn't mean it's powerful and influential.
So you can't derive "panic" from any of it. It may be that you just happened to run into a few people who think meanness is the way to go.
If the courts had been rebuffing the copyright extensions and the DMCA, then there might be panic. Otherwise, it's simply tactics."
Ernest believes bright people pushing for drm and other expansions of intellectual property rights have got a hidden agenda because they basically can't be stupid enough to really believe drm is going to prevent copyright infringement. So they must have a hidden agenda.
Ed says the some of folk pushing this agenda that he has discussed the issues with are passionate about what they are doing, really do believe it will work and needs to work in order to balance all the interests involved.
Frank partly supports Ed in suggesting we should never underestimate the power of ideology.
"The fact that "the road to hell is paved with good intentions" derives from the fact that, in order to function in an increasingly complex world, everyone is forced to construct simplifying models of the way that the world works. When these models (a)
work and (b) are buttressed with rationalizing arguments, we get something more potent - an ideology.
The problem with ideologies is that, even though they work, they rely upon simplifications that will not obtain over time. These simplifications will eventually be the downfall of the ideology, but sometimes it takes a very long time before the failure of the ideology is recognized, meaning that a lot of bad (and potentially quite destructive) decisions get made in the interim...
Ernest is right; our opponents are not (all) stupid people. But they don't have nefarious ends. Rather, they're acting within the confines of the ideologies that they believe explain the way the world works. They aren't evil or stupid; they're just confused and frustrated. The old methods aren't working, even though they *know* their methods are "right." In fact, they're in exactly the same boat that we are. And we know we aren't evil.
Ideologies are hard to defeat, because they're invisible to those who hold them. To us, it's an ideology; to them, it's "the way the world works." Beating it will take time, being honest about what is happening and working really hard to devise a new way of looking at the world that we can collectively agree upon.
We can't afford to write them off as "evil." That's seductive, but dangerous because it simply isn't true. They're just doing what they think is right. We have to respect that as we work to show them that they're mistaken. "
Siva Vaidhyanathan makes some related commentsat the Lessig blog in telling the story of meeting someone who takes the view of "the other side". Some who thought Larry Lessig was "a kook". Siva now reckons elements on the two sides are beginning to understand each other because those pusshing for expanded protection of intellectual property rights are resorting to ad hominem attacks. Adn they are doing this because the Lessig's of the world are winning the argument. Interesting theory but as Seth Finkelstein says in commenting on Siva's post,
"Unfortunately, yes, I think you hang around too many people who actually read the books they criticize. You're a professor. Academics are *supposed* to be polite. Not that they always are. But there is a strong cultural belief there, as evident in what you?re writing, that ad-hominem arguments are "wrong". Again, it may be honored more in the breech than in the observance, it may be an ideal not always practiced, but it's part of the formal codes of conduct.
Hang out with lawyers and lobbyists and politicians more. To them, lying and smearing and ad-hominem attacks are *tactics*, debate *options*. Whether they use those approaches depends entirely on whether they think they can get away with it, that it'll work with the audience. It's a pure strategic calculation. They may decide they'll look bad if they lie. They may decide it's worth it. Situations vary. But the truth or intellectual strength of the argument bears a very tenuous relationship to the approaches employed.
I certainly don't see any change at all, in terms of Jack "Boston Strangler" Valenti style rhetoric.
And remember, a mosquito is slammed hard, but that doesn't mean it's powerful and influential.
So you can't derive "panic" from any of it. It may be that you just happened to run into a few people who think meanness is the way to go.
If the courts had been rebuffing the copyright extensions and the DMCA, then there might be panic. Otherwise, it's simply tactics."
James Heald of Foundation for a Free Information Infrastructure (FFII) tells me that the Irish presidency of the EU are bypassing all the EU parliament and other objections to software patents and doing an end run round a vastly watered down software patents directive proposal.
"The powerful COREPER committee of EU member states' Permanent
Representatives in Brussels has provisionally agreed on a new draft for
the controversial Software Patent directive, overruling concerns from
the German, Belgian, and Danish delegations, and the Slovakian
non-voting observers. (The new accession countries only become full
voting members in November).
The new draft rejects all of the European Parliament's limiting
amendments, and is described by FFII as "the most uncompromisingly
pro-patent text yet".
The Coreper text also goes further than the original European Commission
text of 2002. In 2002 the Commission had agreed, in difficult
negotiations between DG Internal Market (Bolkestein) and DG Information
Society (Liikanen) not to allow program claims. Now it seems that DG
Information Society has rolled over to the united pressure of Bolkestein
and the Council's patent administrators.
A leaked document from Bolkestein's DG Internal Market suggests that DG
Information Society no longer objects to program claims. This concession
by Liikanen is needed in order to rush the Council working group
proposal through the ministers' session as an "A item", i.e. a consensus
point which does not need any discussion by the ministers.
Technically, the decision by COREPER on Wednesday is only a "forecast"
of the final decision, to be confirmed at the Competitiveness Council of
Ministers on 17-18 May. Until that date, Member states can still change
their minds (and their votes).
If confirmed by ministers, the text will form the basis for the
Directive's second reading in Parliament, after the EU elections. EU
rules make it far more difficult for the Parliament to make changes at
second reading.
Support for the text at a political level in some states is still said
to be quite soft; and decisions brokered in Coreper do fall apart (last
year's discussions on the Community Patent, for example).
FFII is therefore urging supporters to make their voices heard *now*,
especially software SMEs who make up the majority of the IT industry (eg
over 80% of IT jobs in Germany). In particular supporters should try to
mobilise organisations of which they are members, urgently try to meet
or contact local MPs and MEPs, and also Commissioner Liikanen's office
at DG Information Society."
Whatever your take on software patents, this is another example of the Irish presidency's slick understanding of and ability to exploit EU processes. As to their motivation, my perspective is that it is no more complicated than Bertie Ahern and co. wishing to be percieved as an "effective" presidency, "effectivenes" in this context being measured by how many things you get done, regardless of what those things are.
Boy I really am being cynical in the past couple of days. I should go an lie in a dark room and think about that book I should have been working on this week [and would have been if it had not been for my study leave being perpetually interrupted by administrative trivia].
"The powerful COREPER committee of EU member states' Permanent
Representatives in Brussels has provisionally agreed on a new draft for
the controversial Software Patent directive, overruling concerns from
the German, Belgian, and Danish delegations, and the Slovakian
non-voting observers. (The new accession countries only become full
voting members in November).
The new draft rejects all of the European Parliament's limiting
amendments, and is described by FFII as "the most uncompromisingly
pro-patent text yet".
The Coreper text also goes further than the original European Commission
text of 2002. In 2002 the Commission had agreed, in difficult
negotiations between DG Internal Market (Bolkestein) and DG Information
Society (Liikanen) not to allow program claims. Now it seems that DG
Information Society has rolled over to the united pressure of Bolkestein
and the Council's patent administrators.
A leaked document from Bolkestein's DG Internal Market suggests that DG
Information Society no longer objects to program claims. This concession
by Liikanen is needed in order to rush the Council working group
proposal through the ministers' session as an "A item", i.e. a consensus
point which does not need any discussion by the ministers.
Technically, the decision by COREPER on Wednesday is only a "forecast"
of the final decision, to be confirmed at the Competitiveness Council of
Ministers on 17-18 May. Until that date, Member states can still change
their minds (and their votes).
If confirmed by ministers, the text will form the basis for the
Directive's second reading in Parliament, after the EU elections. EU
rules make it far more difficult for the Parliament to make changes at
second reading.
Support for the text at a political level in some states is still said
to be quite soft; and decisions brokered in Coreper do fall apart (last
year's discussions on the Community Patent, for example).
FFII is therefore urging supporters to make their voices heard *now*,
especially software SMEs who make up the majority of the IT industry (eg
over 80% of IT jobs in Germany). In particular supporters should try to
mobilise organisations of which they are members, urgently try to meet
or contact local MPs and MEPs, and also Commissioner Liikanen's office
at DG Information Society."
Whatever your take on software patents, this is another example of the Irish presidency's slick understanding of and ability to exploit EU processes. As to their motivation, my perspective is that it is no more complicated than Bertie Ahern and co. wishing to be percieved as an "effective" presidency, "effectivenes" in this context being measured by how many things you get done, regardless of what those things are.
Boy I really am being cynical in the past couple of days. I should go an lie in a dark room and think about that book I should have been working on this week [and would have been if it had not been for my study leave being perpetually interrupted by administrative trivia].
The ACLU, EFF, ALA, CDT and PK have jointly criticised the proposed Fraudulent Online Identity Sanctions Act:
"... we write to express our concern that this bill will penalize and potentially jail Americans who seek only to protect their privacy and right to anonymous free speech online...
... The WHOIS database requires that individual Internet users, when they register domain names, make their names, home addresses, home phone numbers, and home email addresses available to the world, with no privacy protections. Users covered by this requirement include human rights activists, corporate whistleblowers seeking to avoid retribution, and ordinary Americans seeking to avoid spam, stalking or identity theft. As long as WHOIS lacks safeguards to protect their privacy and security these users will feel compelled to place inaccurate data in the database for reasons that have nothing to do with the furtherance of illegal activity.
However, HR 3754 would... create a presumption that inaccurately registered WHOIS data represents evidence of malicious intent... would make violations of copyright or trademark in conjunction with an inaccurately resistered domain "wilful," carrying the highest penalties, even if the activity were otherwise innocent...
... Under current law, the author of an anonymous web log who innocently quotes a portion of a news article that a judge later considers to be too long to qualify for "fair use" would be an "innocent infringer" and subject to reduced statutory damages. Under HR 3754 the same "blogger" would face damages up to $150,000 and potential criminal liability...
...Domain name holders who submit inaccurate WHOIS data: 1) on the basis of bona fide concerns with privacy, or 2) to protect their legitimate rights to anonymous free speech, should not be branded criminals."
"... we write to express our concern that this bill will penalize and potentially jail Americans who seek only to protect their privacy and right to anonymous free speech online...
... The WHOIS database requires that individual Internet users, when they register domain names, make their names, home addresses, home phone numbers, and home email addresses available to the world, with no privacy protections. Users covered by this requirement include human rights activists, corporate whistleblowers seeking to avoid retribution, and ordinary Americans seeking to avoid spam, stalking or identity theft. As long as WHOIS lacks safeguards to protect their privacy and security these users will feel compelled to place inaccurate data in the database for reasons that have nothing to do with the furtherance of illegal activity.
However, HR 3754 would... create a presumption that inaccurately registered WHOIS data represents evidence of malicious intent... would make violations of copyright or trademark in conjunction with an inaccurately resistered domain "wilful," carrying the highest penalties, even if the activity were otherwise innocent...
... Under current law, the author of an anonymous web log who innocently quotes a portion of a news article that a judge later considers to be too long to qualify for "fair use" would be an "innocent infringer" and subject to reduced statutory damages. Under HR 3754 the same "blogger" would face damages up to $150,000 and potential criminal liability...
...Domain name holders who submit inaccurate WHOIS data: 1) on the basis of bona fide concerns with privacy, or 2) to protect their legitimate rights to anonymous free speech, should not be branded criminals."
The conflict between the Korean mobile phone companies and the music industry over Mp3 playing phones is getting worse. The music indsutry are threatening to get an injunction banning sale of the very popular phones.
The European Commission has proposed a new recommendation of the EU parliament and Council of Ministers on the protection of minors and human dignity and the right of reply in the European audiovisual and information services industry.
Thursday, May 06, 2004
Finally for today, Larry Page's and Sregey Brin's letter to potential Google shareholders in their registration statement with the SEC makes fascinating reading.
"Google is not a conventional company. We do not intend to become one...
...Eric, Sergey and I intend to operate Google differently, applying the values it has developed as a private company to its future as a public company. Our mission and business description are available in the rest of the prospectus; we encourage you
to carefully read this information. We will optimize for the long term rather than trying to produce smooth earnings for each quarter. We will support selected high-risk, high-reward projects and manage our portfolio of projects. We will run the company collaboratively with Eric, our CEO, as a team of three. We are conscious of our duty as fiduciaries for our shareholders, and we will fulfill those responsibilities. We will
continue to attract creative, committed new employees, and we will welcome support from new shareholders. We will live up to our ?don?t be evil? principle by keeping user trust and not accepting payment for search results. We have a dual-class structure that is biased toward stability and independence and that requires investors to bet on the team, especially Sergey and me.
In this letter we have explained our thinking on why Google is better off going public. We have talked about our IPO auction method and our desire for stability and access for all investors. We have discussed our goal to have investors who determine a rational price and invest for the long term only if they can buy at that price. Finally, we have discussed our desire to create an ideal working environment that will ultimately drive the success of Google by retaining and attracting talented Googlers. "
You don't see many IPOs running on the principle "don't be evil."
"Google is not a conventional company. We do not intend to become one...
...Eric, Sergey and I intend to operate Google differently, applying the values it has developed as a private company to its future as a public company. Our mission and business description are available in the rest of the prospectus; we encourage you
to carefully read this information. We will optimize for the long term rather than trying to produce smooth earnings for each quarter. We will support selected high-risk, high-reward projects and manage our portfolio of projects. We will run the company collaboratively with Eric, our CEO, as a team of three. We are conscious of our duty as fiduciaries for our shareholders, and we will fulfill those responsibilities. We will
continue to attract creative, committed new employees, and we will welcome support from new shareholders. We will live up to our ?don?t be evil? principle by keeping user trust and not accepting payment for search results. We have a dual-class structure that is biased toward stability and independence and that requires investors to bet on the team, especially Sergey and me.
In this letter we have explained our thinking on why Google is better off going public. We have talked about our IPO auction method and our desire for stability and access for all investors. We have discussed our goal to have investors who determine a rational price and invest for the long term only if they can buy at that price. Finally, we have discussed our desire to create an ideal working environment that will ultimately drive the success of Google by retaining and attracting talented Googlers. "
You don't see many IPOs running on the principle "don't be evil."
The NYT yesterday reported the large Canadian telcos' concerns about their future in the era of Net telephony. It's the standard fare about VoIP but worth a read.
John Lettice at the Register has been thinking about the UK government's draft bill and consultation [which, just as a matter of interest, is unreadable from the old computer I happen to be using at the moment] exercise on the national identity card.
After lots of analysis including genuine puzzlement as to how Mr Blunkett, the Home Secretary, really believes he can convince people that the ID cards will cost them £4, when they actually pay £35, he concludes with a question,
"So do you want this? It's a system that won't achieve most of its objectives, and those it will achieve will be achieved via massive overdesign (secure passport system? Here, take this networked database and personal information register to go with it). You get a personal ID card you don't need. You pay vastly more than you need to for the ID documents you do need. It only addresses the immigration problem (most of the British public sees immigration as a problem) if you pretend to love it and use it all the time, in all sorts of areas where you don't need it and it's inappropriate. And you get the free centralised database of your personal information anyway, providing a locus for any number of government and private databases of your personal information. Don't worry you've nothing to hide - even from your bank, other banks, loan sharks and double glazing salespeople, right?
It costs £3.1bn for all this cool stuff. At least. Go and tell the Home Office how much you support it, you've got until the 20 July, and you'll find a link to the consultation document below. If you happen to agree with any of this article, paraphrase it, don't just copy it. If you do they'll just mark you down as a petition signer and disenfranchise you, like they did with the Stand objectors in the previous "consultation.""
Consultation document.
After lots of analysis including genuine puzzlement as to how Mr Blunkett, the Home Secretary, really believes he can convince people that the ID cards will cost them £4, when they actually pay £35, he concludes with a question,
"So do you want this? It's a system that won't achieve most of its objectives, and those it will achieve will be achieved via massive overdesign (secure passport system? Here, take this networked database and personal information register to go with it). You get a personal ID card you don't need. You pay vastly more than you need to for the ID documents you do need. It only addresses the immigration problem (most of the British public sees immigration as a problem) if you pretend to love it and use it all the time, in all sorts of areas where you don't need it and it's inappropriate. And you get the free centralised database of your personal information anyway, providing a locus for any number of government and private databases of your personal information. Don't worry you've nothing to hide - even from your bank, other banks, loan sharks and double glazing salespeople, right?
It costs £3.1bn for all this cool stuff. At least. Go and tell the Home Office how much you support it, you've got until the 20 July, and you'll find a link to the consultation document below. If you happen to agree with any of this article, paraphrase it, don't just copy it. If you do they'll just mark you down as a petition signer and disenfranchise you, like they did with the Stand objectors in the previous "consultation.""
Consultation document.
U.S. Releases 2004 Report on Intellectual Property Protection.
Ukraine cited as "priority foreign country"
U.S. Trade Representative (USTR) placed 33 trading partners on the "watch list" for IPR violations: Azerbaijan, Belarus, Bolivia, Bulgaria, Canada, Chile, Colombia, Costa Rica, Croatia, Dominican Republic, Ecuador, Guatemala, Hungary, Israel, Italy, Jamaica, Kazakhstan, Latvia, Lithuania, Malaysia, Mexico, Peru, Poland, Romania, Saudi Arabia, Slovak Republic, Tajikistan, Thailand, Turkmenistan, Uruguay, Uzbekistan, Venezuela and Vietnam.
Another 16 trading partners are on the "priority watch list," which entails greater
scrutiny. Eleven of these -- Argentina, Bahamas, Brazil, EU, India, Indonesia, Lebanon,
Philippines, Poland, Russia and Taiwan -- were on last year's priority list. The other five
-- Egypt, Korea, Kuwait, Pakistan and Turkey -- were moved this year from the watch
list to the priority list.
China and Paraguay get warned they're facing imminent trade sanctions for IP violations.
Ukraine cited as "priority foreign country"
U.S. Trade Representative (USTR) placed 33 trading partners on the "watch list" for IPR violations: Azerbaijan, Belarus, Bolivia, Bulgaria, Canada, Chile, Colombia, Costa Rica, Croatia, Dominican Republic, Ecuador, Guatemala, Hungary, Israel, Italy, Jamaica, Kazakhstan, Latvia, Lithuania, Malaysia, Mexico, Peru, Poland, Romania, Saudi Arabia, Slovak Republic, Tajikistan, Thailand, Turkmenistan, Uruguay, Uzbekistan, Venezuela and Vietnam.
Another 16 trading partners are on the "priority watch list," which entails greater
scrutiny. Eleven of these -- Argentina, Bahamas, Brazil, EU, India, Indonesia, Lebanon,
Philippines, Poland, Russia and Taiwan -- were on last year's priority list. The other five
-- Egypt, Korea, Kuwait, Pakistan and Turkey -- were moved this year from the watch
list to the priority list.
China and Paraguay get warned they're facing imminent trade sanctions for IP violations.
It seems that the start of trial of of the ten thousand (i.e. biometric national ID cards in the UK) was delayed by three months because the technology didn't work. Now it is going to for last three months rather than the planned six months.
David Blunkett has said that although the pilot scheme was late, "it is important to get it right rather than get it quickly?". I see. It does n't work. So delay the start. Then cut the time for the trial in half in case people notice there are lots of problems with it. And then claim you're trying to get it right. This is a joke. Right?
Ok, call me a cynic again. Hey, that's twice in one day.
David Blunkett has said that although the pilot scheme was late, "it is important to get it right rather than get it quickly?". I see. It does n't work. So delay the start. Then cut the time for the trial in half in case people notice there are lots of problems with it. And then claim you're trying to get it right. This is a joke. Right?
Ok, call me a cynic again. Hey, that's twice in one day.
My colleague, John Naughton, pointed me at this 10 minute interview, where an MIT student quizzed Jack Valenti. Jack genuinely didn't seem to know there were no DVDCCA licensed linux DVD players on the market.
"TT: But today, you still cannot on the market actually buy a licensed DVD player for Linux.
JV: I didn?t know that.
TT: So the question is, do you think people who go to Blockbuster, they rent a movie, they bring it
home, and they play it on Linux by circumventing the access control, are those people committing a
moral transgression?
JV: I do not believe that you have the right to override an encryption. Because if you have the right
to do it, everybody can do it. For whatever benign reason you have, somebody else has got one
even more benign. But once you let one person deal in a digital copy -- and I don?t have to tell you;
you know far better than I that, unlike in analog, the ten thousandth copy is as pure as the original --
it is a big problem. So once you let the barriers down for your perfectly sensible reason, you gotta
let it down for everybody.
I don?t want to get into the definition of morality. I never said anything was immoral in what I was
saying. I said it is wrong to take something that belongs to somebody else.
TT: Indeed, but are you doing that when you rent a movie from Blockbuster and you watch it at
home? ... I run Linux on my computer. There?s no product I can buy that?s licensed to watch
[DVDs]. If I go to Blockbuster and rent a movie and watch it, am I a bad person? Is that bad?
JV: No, you?re not a bad person. But you don?t have any right.
TT: But I rented the movie. Why should it be illegal?
JV: Well then, you have to get a machine that?s licensed to show it.
TT: Here?s one of these machines; it?s just not licensed.
[Winstein shows Valenti his six-line ?qrpff? DVD descrambler.]
TT: If you type that in, it?ll let you watch movies.
JV: You designed this?
TT: Yes.
JV: Un-fucking-believable.
TT: So the question is, if I just want to watch a movie--I rent it from Blockbuster--is that bad?
JV: No, that?s not bad. "
Valenti is going to be a hard act to follow when he leaves the MPAA.
"TT: But today, you still cannot on the market actually buy a licensed DVD player for Linux.
JV: I didn?t know that.
TT: So the question is, do you think people who go to Blockbuster, they rent a movie, they bring it
home, and they play it on Linux by circumventing the access control, are those people committing a
moral transgression?
JV: I do not believe that you have the right to override an encryption. Because if you have the right
to do it, everybody can do it. For whatever benign reason you have, somebody else has got one
even more benign. But once you let one person deal in a digital copy -- and I don?t have to tell you;
you know far better than I that, unlike in analog, the ten thousandth copy is as pure as the original --
it is a big problem. So once you let the barriers down for your perfectly sensible reason, you gotta
let it down for everybody.
I don?t want to get into the definition of morality. I never said anything was immoral in what I was
saying. I said it is wrong to take something that belongs to somebody else.
TT: Indeed, but are you doing that when you rent a movie from Blockbuster and you watch it at
home? ... I run Linux on my computer. There?s no product I can buy that?s licensed to watch
[DVDs]. If I go to Blockbuster and rent a movie and watch it, am I a bad person? Is that bad?
JV: No, you?re not a bad person. But you don?t have any right.
TT: But I rented the movie. Why should it be illegal?
JV: Well then, you have to get a machine that?s licensed to show it.
TT: Here?s one of these machines; it?s just not licensed.
[Winstein shows Valenti his six-line ?qrpff? DVD descrambler.]
TT: If you type that in, it?ll let you watch movies.
JV: You designed this?
TT: Yes.
JV: Un-fucking-believable.
TT: So the question is, if I just want to watch a movie--I rent it from Blockbuster--is that bad?
JV: No, that?s not bad. "
Valenti is going to be a hard act to follow when he leaves the MPAA.
California have allegedly toughened their stance on electronic voting. The devil is in the detail and I remain unconvinved this is anything more than political posturing at the moment, especially since California Secretary of State is reportedly calling Diebold reprehensible and calling for a criminal investigation of the company. Ok call me a cynic.
Meanwhile at least one county in California is suing the secretary state for the right to use electronic voting in the presidential election.
Meanwhile at least one county in California is suing the secretary state for the right to use electronic voting in the presidential election.
The Dutch data protection authority, CBP, have stated, that the Dutch entertainment industry's anti-piracy group BREIN's sharing of information [on file sharing] with US counterparts is in breach of Dutch data protection and privacy laws. Following on from the Dutch supreme court's decision in the Kazaa case, that won't make the Netherlands any more popular with the industry.
From the Scotsman via historian Professor Steve Hindle, Blunkett's 'Id Card' Was Around in 16th Century. Wonderful.
I've spent another couple days this week away from my office at the OU, helping some colleagues agree the final structure and content of our new cybervandalism course, T187. The facilities at the conference centre, Harben House, run by Initial, were fine. What did really irritate me, though, was trying to access my weblog from their internet cafe and discovering it was censored by their filter software, which declared that my thoughts here might be unsuitable for children.
Do contact them about inappropriate filtering, if you feel so inclined. I've complained and been told my complaint would be reviewed by a human being. I wonder how many other filter software packages block these pages, presumably because the url and blog title contain the letters 'xxx'?
Do contact them about inappropriate filtering, if you feel so inclined. I've complained and been told my complaint would be reviewed by a human being. I wonder how many other filter software packages block these pages, presumably because the url and blog title contain the letters 'xxx'?
I spent a couple of days in Barcelona last week, one at the terrific Univeritat Oberta de Catalunya (UOC), the virtual university, where I met a group of like minded enthusiasts for the deployment of technology in education, who actually understood what can and cannot be done with technology in that context.
I shouldn't be surprised at this but it is such a rarity in the thick of all the nonsense that gets talked, written about and done in the name of computers in education that it was an absolutely delightful day. UOC have grown from about 300 to 30000 students in about ten years. They have also in that time been learning the same lessons, as an institution, that those of us in the Open University in the UK who have been deeply engaged in deploying multimedia computer and Internet facilitated education with large numbers of students over a similar period have learnt about the potential, current limitations and practicalities of technological tools in an educational context.
I only hope our wonderful hosts, Sylvia Gonzalez and Ferran Gimenez Prado, found it as useful as we did.
I shouldn't be surprised at this but it is such a rarity in the thick of all the nonsense that gets talked, written about and done in the name of computers in education that it was an absolutely delightful day. UOC have grown from about 300 to 30000 students in about ten years. They have also in that time been learning the same lessons, as an institution, that those of us in the Open University in the UK who have been deeply engaged in deploying multimedia computer and Internet facilitated education with large numbers of students over a similar period have learnt about the potential, current limitations and practicalities of technological tools in an educational context.
I only hope our wonderful hosts, Sylvia Gonzalez and Ferran Gimenez Prado, found it as useful as we did.
Saturday, May 01, 2004
The NYT are reporting that the FBI were given millions of passenger records by airlines in the says after the September 11th tragedies. Seems like a pretty sensible course of action for the FBI to request such records given the circumstances. They used subpoenas, so it was all above board. The only question, I guess, is regarding the boundaries of the request and the quantity of information handed over. Apparently at least one airline provided a year's worth of records.
Monday, April 26, 2004
The ID card draft bill is proposing to create quite a few new offenses, like disobeying an order from the Secretary of State. I hope one of the draftsmen have put that in as a joke to test how well this thing is going to get scrutinised? Think of it - in a democracy there could actually be an offense of refusing to follow the orders of a public servant. It also includes little incentives like a £2500 fine every time someone fails to turn up for an appointment for a biometrics scan (Section 6(4)). Jailtime for having someone else's card in your possession (don't offer to look after a friend's belongings whilst they respond to the call of nature then). All this draconian stuff is just an initial extreme pitch, so that Mr Blunkett can be seen to be making "reasonable concessions" when the actual law gets passed. Simon Davies of Privacy International is right - this whole shambles is a "disgrace to democracy."
A draft bill for a national ID card is online. There are lots of stories round about the ID card in the UK press today. Ministers are peddling the usual propaganda in favour and by and large journalists are lapping it up unquestioningly. Regarding the test progamme with ten thousand volunteers I have mixed feelings. I'm irritated with it because it's a waste of money and primarily a PR exercise. But at the same time I think it's a good idea because proponents and ordinary people, to whom the idea is intuitively and superficially attractive, will finally get to see how bad this 'state of the art', 'impossible to fool' biometric technology is in reality. The Australians did an ID card trial in the 90s and quietly abandoned the notion, having discovered how many problems it caused. Let's hope the UK version goes the same way
On the day that the UK government launch their controversial pilot national ID card scheme with ten thousand volunteers, Privacy International have released an interim report on a study of the connection between ID cards and preventing terrorism. Not surprisingly, "Mistaken Identity; Exploring the Relationship Between National Identity Cards & the Prevention of Terrorism" concludes that ID cards do not help to prevent terrorism.
Friday, April 23, 2004
EUpolitix has a succinct report on MEPs taking on the Commission and the US over the deal on the transfer of airline passenger data.
Thursday, April 22, 2004
Brad Templeton, chairman of the EFF, amongst other things, has produced a thoughtful analysis of the 'GMail Saga'.
The Bush administration is apparently proposing to give ally countries another 2 years to devop biometric passports. Secretary of State Colin Powell says
"Rushing a solution to meet the current deadline virtually guarantees that we will have systems that are not operable... Such a result may undercut international acceptance of this new technology as well as compound rather than ease our overall challenge."
"Rushing a solution to meet the current deadline virtually guarantees that we will have systems that are not operable... Such a result may undercut international acceptance of this new technology as well as compound rather than ease our overall challenge."
The European Commission have issued a Communication on the Management of
Copyright and Related Rights. In it they eulogise digital rights management (DRM) as the solution to all ills of the copyright variety, most specifically this time royalty collection agencies problems. What is it about biometric national ID cards, DRM, RFIDs, electronic voting machines, computers, technology in general that make them superficially attractive solutions to everything? The right technology appropriately deployed can be a terrific boon but why can't people understand that it is not usually a particularly good idea to start with a [technological] 'solution' and then go looking for a problem, just so you can use the 'solution'?
Copyright and Related Rights. In it they eulogise digital rights management (DRM) as the solution to all ills of the copyright variety, most specifically this time royalty collection agencies problems. What is it about biometric national ID cards, DRM, RFIDs, electronic voting machines, computers, technology in general that make them superficially attractive solutions to everything? The right technology appropriately deployed can be a terrific boon but why can't people understand that it is not usually a particularly good idea to start with a [technological] 'solution' and then go looking for a problem, just so you can use the 'solution'?
A Barcelona night club is allegedly implanting RFID chips in VIP customers so they don't need to worry about carrying a wallet about. No comment.
Tuesday, April 20, 2004
Despite the pending lawsuit against ClearPlay and others by the Directors Guild of America and the movie studios, it appears as though Walmart is going to be selling DVD players with ClearPlay filters built in. I wonder what the demand will be like and how that will affect the dynamics of the court case?
The United States Institute of Peace, which I admit I'd never prviously heard of, have issued a paper saying terrorists use the Internet too but for more routine activities than the hyped-up cyberterrorism feedstuff of the mainstream media. Terrorist organisations are said to have three major audiences:
Current and potential supporters
International public opinion
Enemy publics (i.e. citizens of states they are fighting)
and use the Net in 8 different (sometimes overlapping) ways:
Psychological warfare
Publicity and propaganda
Data mining
Fundraising
Recruitment and mobilisation
Networking
Sharing information
Planning and coordination
The report does imply that steganography is in widespread use by terrorist organisations but there is no direct evidence offered to that effect. The mainstream media has periodically salivated at the notion of religeous fundamentalist terrorists hiding messages in online porn but no evidence to that effect has been forthcoming. Being only 12 pages long the paper is just an overview I assume but it might be interesting to hear more details of the study.
Current and potential supporters
International public opinion
Enemy publics (i.e. citizens of states they are fighting)
and use the Net in 8 different (sometimes overlapping) ways:
Psychological warfare
Publicity and propaganda
Data mining
Fundraising
Recruitment and mobilisation
Networking
Sharing information
Planning and coordination
The report does imply that steganography is in widespread use by terrorist organisations but there is no direct evidence offered to that effect. The mainstream media has periodically salivated at the notion of religeous fundamentalist terrorists hiding messages in online porn but no evidence to that effect has been forthcoming. Being only 12 pages long the paper is just an overview I assume but it might be interesting to hear more details of the study.
Wonderful Ed Helms skit at Comedy Central about e-voting. Not to be missed. This kind of comedy does more to communicate the problems with electronic voting than all the ranting that I do on the subject.
Jay Rosen has a thoughtful analysis of the recent furore over inappropriate comments by a Democrat-supporting blogger. Another example of the scandalmongering of mainstream politics and media out-manoeuvering the democratising potential of the net.
The Berkman Center at Harvard have done an interesting study on Apple's iTunes service focussing on
Interaction between Copyright and Contract Law
Digital Rights Management
Digital First Sale Doctrine
Fair Use Doctrine
Worth a look.
Interaction between Copyright and Contract Law
Digital Rights Management
Digital First Sale Doctrine
Fair Use Doctrine
Worth a look.
Monday, April 19, 2004
There are two lovely essays in Bruce Schneier's latest Crypto-Gram, one on national identity cards and the second on the economic incentives to rig electronic voting machines. On national ID cards:
"But my primary objection isn't the totalitarian potential of national
IDs, nor the likelihood that they'll create a whole immense new class
of social and economic dislocations. Nor is it the opportunities they
will create for colossal boondoggles by government contractors. My
objection to the national ID card, at least for the purposes of this
essay, is much simpler.
It won't work. It won't make us more secure.
In fact, everything I've learned about security over the last 20 years
tells me that once it is put in place, a national ID card program will
actually make us less secure.
My argument may not be obvious, but it's not hard to follow,
either. It centers around the notion that security must be evaluated
not based on how it works, but on how it fails.
It doesn't really matter how well an ID card works when used by the
hundreds of millions of honest people that would carry it. What
matters is how the system might fail when used by someone intent on
subverting that system: how it fails naturally, how it can be made to
fail, and how failures might be exploited.
The first problem is the card itself. No matter how unforgeable we
make it, it will be forged. And even worse, people will get legitimate
cards in fraudulent names...
... the main problem with any ID system is that it requires the
existence of a database. In this case it would have to be an immense
database of private and sensitive information on every American -- one
widely and instantaneously accessible from airline check-in stations,
police cars, schools, and so on.
The security risks are enormous. Such a database would be a kludge of
existing databases; databases that are incompatible, full of erroneous
data, and unreliable. As computer scientists, we do not know how to
keep a database of this magnitude secure, whether from outside hackers
or the thousands of insiders authorized to access it.
And when the inevitable worms, viruses, or random failures happen and
the database goes down, what then? Is America supposed to shut down
until it's restored?
Proponents of national ID cards want us to assume all these problems,
and the tens of billions of dollars such a system would cost -- for
what? For the promise of being able to identify someone?"
"But my primary objection isn't the totalitarian potential of national
IDs, nor the likelihood that they'll create a whole immense new class
of social and economic dislocations. Nor is it the opportunities they
will create for colossal boondoggles by government contractors. My
objection to the national ID card, at least for the purposes of this
essay, is much simpler.
It won't work. It won't make us more secure.
In fact, everything I've learned about security over the last 20 years
tells me that once it is put in place, a national ID card program will
actually make us less secure.
My argument may not be obvious, but it's not hard to follow,
either. It centers around the notion that security must be evaluated
not based on how it works, but on how it fails.
It doesn't really matter how well an ID card works when used by the
hundreds of millions of honest people that would carry it. What
matters is how the system might fail when used by someone intent on
subverting that system: how it fails naturally, how it can be made to
fail, and how failures might be exploited.
The first problem is the card itself. No matter how unforgeable we
make it, it will be forged. And even worse, people will get legitimate
cards in fraudulent names...
... the main problem with any ID system is that it requires the
existence of a database. In this case it would have to be an immense
database of private and sensitive information on every American -- one
widely and instantaneously accessible from airline check-in stations,
police cars, schools, and so on.
The security risks are enormous. Such a database would be a kludge of
existing databases; databases that are incompatible, full of erroneous
data, and unreliable. As computer scientists, we do not know how to
keep a database of this magnitude secure, whether from outside hackers
or the thousands of insiders authorized to access it.
And when the inevitable worms, viruses, or random failures happen and
the database goes down, what then? Is America supposed to shut down
until it's restored?
Proponents of national ID cards want us to assume all these problems,
and the tens of billions of dollars such a system would cost -- for
what? For the promise of being able to identify someone?"
Subscribe to:
Posts (Atom)