Wednesday, June 23, 2004
Clay Shirky on DNA, P2P, and Privacy. In the privacy debate about ubiquitous centralised databases,
"Databases have two key weaknesses...The first is that they deal badly with ambiguity, and generally have to issue a unique number, sometimes called a primary key, to every entity they store information on. The US Social Security number is a primary key that points to you,...second weakness: since each database maintains its own set of primary keys, creating interoperability between different databases is difficult and expensive, and generally requires significant advance coordination...
Privacy advocates have relied on these weaknesses in creating legal encumbrances to issuing and sharing primary keys. They believe, rightly, that widely shared primary keys pose a danger to privacy. (The recent case of Princeton using its high school applicants' Social Security numbers to log in to the Yale admittance database highlights these dangers.) The current worst-case scenario is a single universal database in which all records -- federal, state, and local, public and private -- would be unified with a single set of primary keys.
New technology brings new challenges however, and in the database world the new challenge is not a single unified database, but rather decentralized interoperability, interoperability brought about by a single universally used ID. The ID is DNA. The interoperability comes from the curious and unique advantages DNA has as a primary key. And the effect will put privacy advocates in a position analogous to that of the RIAA, forcing them to switch from fighting the creation of a single central database to fighting a decentralized and interoperable system of peer-to-peer information storage."
"Databases have two key weaknesses...The first is that they deal badly with ambiguity, and generally have to issue a unique number, sometimes called a primary key, to every entity they store information on. The US Social Security number is a primary key that points to you,...second weakness: since each database maintains its own set of primary keys, creating interoperability between different databases is difficult and expensive, and generally requires significant advance coordination...
Privacy advocates have relied on these weaknesses in creating legal encumbrances to issuing and sharing primary keys. They believe, rightly, that widely shared primary keys pose a danger to privacy. (The recent case of Princeton using its high school applicants' Social Security numbers to log in to the Yale admittance database highlights these dangers.) The current worst-case scenario is a single universal database in which all records -- federal, state, and local, public and private -- would be unified with a single set of primary keys.
New technology brings new challenges however, and in the database world the new challenge is not a single unified database, but rather decentralized interoperability, interoperability brought about by a single universally used ID. The ID is DNA. The interoperability comes from the curious and unique advantages DNA has as a primary key. And the effect will put privacy advocates in a position analogous to that of the RIAA, forcing them to switch from fighting the creation of a single central database to fighting a decentralized and interoperable system of peer-to-peer information storage."
Microsoft are suing, for defamation, the Brazilian government official promoting open source software use in the public services, Sergio Amadeu. His alleged crime is that he was too nasty when criticising Microsoft because they had
" a ‘drug-dealer practice’ for offering the operational system Windows to some governments and cities for digital inclusion programs. ‘This is a trojan horse, a form of securing critical mass to continue constraining the country’.”
" a ‘drug-dealer practice’ for offering the operational system Windows to some governments and cities for digital inclusion programs. ‘This is a trojan horse, a form of securing critical mass to continue constraining the country’.”
David Blunkett, UK Home Secretary, is the "Judicial equivalent of a football hooligan" according to Simon Jenkins in the Times.
The Washington Post had an article about RFID tags yesterday. It's the usual stuff about the potential of RFIDs to improve business and the worries of privacy advicates. But the thing that jumped out at me as an absolute classic misunderstanding was this:
'"If you know quickly who is in the area, you can customize their experience," said Paul McKeown, who heads IBM's global smart-card efforts. McKeown said he was inspired by an experience his mother had in her small town in England, where for years she was banking at the same branch and one day wasn't recognized and was challenged by a new teller.'
If ever there were folk "who didn't get it" about technology, it is people with this kind of attitude. The whole point about the small town where the banking staff knew and cared about the customers was that people were put in touch with and cared about people. No amount of technology facilitating a "customised experience" can bridge the unmeasurable qualitative difference between treating a person as a person and treating them as a customised number to be processed in accordance with the instructions on the employee's screen.
As Cory said in his DRM speech at Microsoft, "New media don't succeed because they're like the old media, only better: they succeed because they're worse than the old media at the stuff the old media is good at, and better at the stuff the old media are bad at." I'd like to offer an extension to this - new methods and technologies do not succeed because they are like people only better, they suceed because they are worse than people at the stuff people are good at (caring) and better at the stuff people are bad at (rapidly processing and moving around billions of bits). Try not to get confused about that. It's important.
The thing that makes my own organisation, the Open University, so unique and special was that we put people in touch with people. We recognised, 35 years ago, that the way for open and distance university education to work for students with no prior qualifications was to put good people (vast numbers in the OU) in touch with good people with unrecognised potential (our students) and that we could be all-inclusive. We've had well over a million graduates since then, many of whom would never have had the opportunity to take a university degree.
The thing that makes the Internet so special is that it puts people in touch with people. Sure it is a bottomless sink of information and a useful communications infrastructure for commerce but the key is that it is a many to many communcations medium putting people in touch with people.
I'll stop there lest I be accused of becoming too evangelistic...
'"If you know quickly who is in the area, you can customize their experience," said Paul McKeown, who heads IBM's global smart-card efforts. McKeown said he was inspired by an experience his mother had in her small town in England, where for years she was banking at the same branch and one day wasn't recognized and was challenged by a new teller.'
If ever there were folk "who didn't get it" about technology, it is people with this kind of attitude. The whole point about the small town where the banking staff knew and cared about the customers was that people were put in touch with and cared about people. No amount of technology facilitating a "customised experience" can bridge the unmeasurable qualitative difference between treating a person as a person and treating them as a customised number to be processed in accordance with the instructions on the employee's screen.
As Cory said in his DRM speech at Microsoft, "New media don't succeed because they're like the old media, only better: they succeed because they're worse than the old media at the stuff the old media is good at, and better at the stuff the old media are bad at." I'd like to offer an extension to this - new methods and technologies do not succeed because they are like people only better, they suceed because they are worse than people at the stuff people are good at (caring) and better at the stuff people are bad at (rapidly processing and moving around billions of bits). Try not to get confused about that. It's important.
The thing that makes my own organisation, the Open University, so unique and special was that we put people in touch with people. We recognised, 35 years ago, that the way for open and distance university education to work for students with no prior qualifications was to put good people (vast numbers in the OU) in touch with good people with unrecognised potential (our students) and that we could be all-inclusive. We've had well over a million graduates since then, many of whom would never have had the opportunity to take a university degree.
The thing that makes the Internet so special is that it puts people in touch with people. Sure it is a bottomless sink of information and a useful communications infrastructure for commerce but the key is that it is a many to many communcations medium putting people in touch with people.
I'll stop there lest I be accused of becoming too evangelistic...
Tuesday, June 22, 2004
It seems as if the Dutch parliament may consider revoking its support for the EU software patent directive because the Dutch minister responsible for agreeing to the directive in the Council of Ministers and for educating the parliament on the matter, Mr Brinkhorst, er ever so slightly misled them, or should I say "misinformed" them. He suggested in a letter to the Dutch parliament in advance of the vote in the Council of Ministers that there was "agreement" between the EU Parliament and the Commission on the issue, when the two were basically at loggerheads.
I won't suggest that Mr Brinkhorst lied as it would not be appropriate especially since there is a good bet that many of his contemporaries around the EU were equally "informative" with regard to educating their national parliaments on the matter.
The transcript of the discussions in the council of ministers makes interesting reading, if only for those seriously enmeshed in the ethics and politics of sw patents but the final part of this democratic discussion is a classic case of the Irish (IE)chairwoman pushing for the rubber stamping of the business at hand, regardless of the substance of the business.
"IE: And Denmark? Can I hear from Denmark please?
Denmark: I would really like to ask the commission why they couldn't accept the last sentence put forward by the Italians. It was in the original German proposal.
(19:13) IE: I think the Commissioner already answered that question, I'm sorry Denmark. So are you yes, no, abstain?
DK: I think we wouldn't, we're not hap...
IE: Can I assume you're a "yes"?
DK: We're not happy
IE: But are you 80% happy?
DK: But... I think we...
IE: We don't need you you to be totally happy. None of us are totally happy.
DK: I know that, I know that.
IE: If we were, we wouldn't be here
DK: I think we're not very happy, but I think we would, we would...
IE: Thank you very much
DK: ... we would like to see a solution today.
IE: Thank you very much, Denmark.
(19:45) IE: Spain, are you abstention or no?
ES: Sorry, no.
IE: Thank you Spain, Austria?
AT: Abstention.
(20:03) IE: Well, Ladies and Gentlemen, I'm happy to say that we have a qualified majority, so thank you all very very much indeed, and thank you to commissioner Bolkestein.
IE: France... The vote is over France, no more ... for France please
FR: I didn't want to cause confusion. I'm so happy that we've managed to reach this result thanks to your hard work and that of the Commission. I just wanted to say that I'd like to propose a declaration using the words I used in my first statement. A declaration appended to the Council minutes.
(21:04) IE: Yes, thank you France, it's fine."
Democracy in action. I particularly like the "We don't need you you to be totally happy. None of us are totally happy." I'm almost relieved that the Irish presidency of the EU is coming to an end.
I won't suggest that Mr Brinkhorst lied as it would not be appropriate especially since there is a good bet that many of his contemporaries around the EU were equally "informative" with regard to educating their national parliaments on the matter.
The transcript of the discussions in the council of ministers makes interesting reading, if only for those seriously enmeshed in the ethics and politics of sw patents but the final part of this democratic discussion is a classic case of the Irish (IE)chairwoman pushing for the rubber stamping of the business at hand, regardless of the substance of the business.
"IE: And Denmark? Can I hear from Denmark please?
Denmark: I would really like to ask the commission why they couldn't accept the last sentence put forward by the Italians. It was in the original German proposal.
(19:13) IE: I think the Commissioner already answered that question, I'm sorry Denmark. So are you yes, no, abstain?
DK: I think we wouldn't, we're not hap...
IE: Can I assume you're a "yes"?
DK: We're not happy
IE: But are you 80% happy?
DK: But... I think we...
IE: We don't need you you to be totally happy. None of us are totally happy.
DK: I know that, I know that.
IE: If we were, we wouldn't be here
DK: I think we're not very happy, but I think we would, we would...
IE: Thank you very much
DK: ... we would like to see a solution today.
IE: Thank you very much, Denmark.
(19:45) IE: Spain, are you abstention or no?
ES: Sorry, no.
IE: Thank you Spain, Austria?
AT: Abstention.
(20:03) IE: Well, Ladies and Gentlemen, I'm happy to say that we have a qualified majority, so thank you all very very much indeed, and thank you to commissioner Bolkestein.
IE: France... The vote is over France, no more ... for France please
FR: I didn't want to cause confusion. I'm so happy that we've managed to reach this result thanks to your hard work and that of the Commission. I just wanted to say that I'd like to propose a declaration using the words I used in my first statement. A declaration appended to the Council minutes.
(21:04) IE: Yes, thank you France, it's fine."
Democracy in action. I particularly like the "We don't need you you to be totally happy. None of us are totally happy." I'm almost relieved that the Irish presidency of the EU is coming to an end.
Siva's Response to a Senate Staffer on the p2p question,
"I have too much to say about p2p. And my opinions are beyond the pro and con simplifications that get laid out in newspapers...
...Copyright is by design a leaky regulatory system. If the leaks are too big, copyright fails to generate incentives. If they are too small, copyright fails to allow for democratic creativity and sharing -- the essence of culture. So managing leaks is important. But freaking out about them is counterproductive. So far, the content industries have been better at freaking than managing. And we are all worse off because of that...
...The best way to approach this issue is through serious and sincere ethical deliberation. That means avoiding harsh moralizing, threats of criminal or civil action, and blunt technological moves that will only create more problems and ill-will. The goal should be flourishing democratic culture and creativity. It should not be the artificial support of poorly run media companies. Nor should it be the unfettered proliferation of machines and code for the sake of more machines and code. We must be modest and patient -- an unpopular stance in this age of extremes."
Beautifully put.
"I have too much to say about p2p. And my opinions are beyond the pro and con simplifications that get laid out in newspapers...
...Copyright is by design a leaky regulatory system. If the leaks are too big, copyright fails to generate incentives. If they are too small, copyright fails to allow for democratic creativity and sharing -- the essence of culture. So managing leaks is important. But freaking out about them is counterproductive. So far, the content industries have been better at freaking than managing. And we are all worse off because of that...
...The best way to approach this issue is through serious and sincere ethical deliberation. That means avoiding harsh moralizing, threats of criminal or civil action, and blunt technological moves that will only create more problems and ill-will. The goal should be flourishing democratic culture and creativity. It should not be the artificial support of poorly run media companies. Nor should it be the unfettered proliferation of machines and code for the sake of more machines and code. We must be modest and patient -- an unpopular stance in this age of extremes."
Beautifully put.
Rather an obscure case relating to the 4th and 5th amendments to the US constitution was decided by the Supreme Court yesterday.
It about someone having a row in a truck with his daughter, who was stopped by the police (who had been tipped off about the row) and refusing to give his name to the officer who requested it. He was prosecuted and fined $250. Technically what was under scrutiny was the man's right not to incriminate himself (5th) and his right to be free of unreasonable search and seizure (4th). Plus, presumably his right to remain silent. The court decided 5-4 against the man's assertion of his right to remain silent in the circumstances.
Michael Froomkin briefly looks at the technicalities. Apparently it's quite a narrowly tailored decision which need not necessarily have wider implications than the specific case (though Froomkin suggests it might be a slippery slope).
Under a 1968 Supreme Court decision police are allowed to hold someone briefly (called a "Terry stop" after the case) in order to obtain more information, which seems fair enough. The thing that interested me about this particular case, though, is not the specific technicalities but the question of latent ambiguity. Presumably the justices in 1968 had an idea in their heads about the kind of information that an officer could find out about an individual during a brief detention. It would be fairly limited e.g. any parking tickets, was the vehicle stolen, did he match a suspect's description, was someone of that name wanted etc. 36 years on, however, with vasts amounts of information on everybody collected in public and private and networked databases makes the kind of information it is possible to find out about an individual, in a short space of time, qualitatively of a completely different order.
Should not the modern day justices be exploring the boundaries of the information it should be possible to find out? The decision doesn't affect us directly this side of the Atlantic and it would seem on the surface that there are no technological questions at issue in the case but this is a pretty clear example, imho, of where technology has changed things to such a degree that the questions it raises are not solved by a narrow mechanical application of existing laws (whether or not that mechanical application itself would/could provide grounds for dispute).
EPIC have a webpage devoted to the case.
It about someone having a row in a truck with his daughter, who was stopped by the police (who had been tipped off about the row) and refusing to give his name to the officer who requested it. He was prosecuted and fined $250. Technically what was under scrutiny was the man's right not to incriminate himself (5th) and his right to be free of unreasonable search and seizure (4th). Plus, presumably his right to remain silent. The court decided 5-4 against the man's assertion of his right to remain silent in the circumstances.
Michael Froomkin briefly looks at the technicalities. Apparently it's quite a narrowly tailored decision which need not necessarily have wider implications than the specific case (though Froomkin suggests it might be a slippery slope).
Under a 1968 Supreme Court decision police are allowed to hold someone briefly (called a "Terry stop" after the case) in order to obtain more information, which seems fair enough. The thing that interested me about this particular case, though, is not the specific technicalities but the question of latent ambiguity. Presumably the justices in 1968 had an idea in their heads about the kind of information that an officer could find out about an individual during a brief detention. It would be fairly limited e.g. any parking tickets, was the vehicle stolen, did he match a suspect's description, was someone of that name wanted etc. 36 years on, however, with vasts amounts of information on everybody collected in public and private and networked databases makes the kind of information it is possible to find out about an individual, in a short space of time, qualitatively of a completely different order.
Should not the modern day justices be exploring the boundaries of the information it should be possible to find out? The decision doesn't affect us directly this side of the Atlantic and it would seem on the surface that there are no technological questions at issue in the case but this is a pretty clear example, imho, of where technology has changed things to such a degree that the questions it raises are not solved by a narrow mechanical application of existing laws (whether or not that mechanical application itself would/could provide grounds for dispute).
EPIC have a webpage devoted to the case.
Monday, June 21, 2004
Some folks have added some links into Cory Doctorow's DRM talk to Microsoft researchers. Just a sample of what can be done to improve public domain work and facilitate open source learning and free flow of information.
Steven Wu at Lawmeme has been at a convention on the constitution and thinking of the use of software for gerrymandering, discussed by one panel.
"Almost every panelist at one point mentioned a piece of software that has become popular in state legislatures: Caliper's Maptitude for Redistricting, which the website advertises as:
'a special edition of Caliper Corporation's Maptitude GIS for Windows that includes everything you need to build and analyze redistricting plans. As you assign area features to a district, the district boundaries are redrawn and selected attributes are automatically summarized to reflect the district's characteristics.'
Basically, as one of the panelists put it today, Maptitude allows you to do just about anything you want with a redistricting plan, once you plug in the demographic data. You want districts that are as evenly balanced politically/racially/genderly as possible? How about a lot of majority-minority districts? How about districts that will protect incumbents, by filling them with people of the incumbents' political party? Whatever your preferences, Maptitude can generate the appropriate redistricting lines in half an hour or less."
...An unseen part of the evoting story that not too many people have been registering.
"Almost every panelist at one point mentioned a piece of software that has become popular in state legislatures: Caliper's Maptitude for Redistricting, which the website advertises as:
'a special edition of Caliper Corporation's Maptitude GIS for Windows that includes everything you need to build and analyze redistricting plans. As you assign area features to a district, the district boundaries are redrawn and selected attributes are automatically summarized to reflect the district's characteristics.'
Basically, as one of the panelists put it today, Maptitude allows you to do just about anything you want with a redistricting plan, once you plug in the demographic data. You want districts that are as evenly balanced politically/racially/genderly as possible? How about a lot of majority-minority districts? How about districts that will protect incumbents, by filling them with people of the incumbents' political party? Whatever your preferences, Maptitude can generate the appropriate redistricting lines in half an hour or less."
...An unseen part of the evoting story that not too many people have been registering.
Friday, June 18, 2004
The OECD has published their 386 page "Privacy Online" report. Definitely not bedtime reading but could have important policy implications. It's based on an OECD ministerial declaration from 1998 on the "Protection of Privacy on Global Networks" with the objective of ensuring "the effective protection of privacy and personal data as well as the continued transborder flow of personal data on global networks."
You could be forgiven for going "Pardon?" at that point.
Chapter 3, pages 27 - 35 gives the meat of the guidelines.
Legislation and self regulation each have advantages and disadvantages etc. OECD work suggests a mix of the two is best etc. Involvement of all is the key etc. OECD member countries should:
Ensure organisations adoption of privacy policies through internal review and linking to OECD site.
Ensure organisations post privacy policies online by encouraging them to do so and auditing them.
Ensure availability of enforcement and redress mechanisms in case of breach of privacy policies by encouraging the use of online alternative dispute mechanisms and actively fostering compliance with privacy policies by raising organisations' awareness..."
Sorry folks but I stopped at that point. This document does not actually appear to be saying anything at all about privacy or information flows in practice. Some people I have a great deal of respect for, like Ian Lloyd at the University of Strathclyde, are noted as having been involved in its production, so I'm sure there is more to it than the first 30 pages appear to promise (Prof Lloyd is mentioned re Chpt 14) but I'm going to allow somebody else to do the leg work on extracting the relevant information.
You could be forgiven for going "Pardon?" at that point.
Chapter 3, pages 27 - 35 gives the meat of the guidelines.
Legislation and self regulation each have advantages and disadvantages etc. OECD work suggests a mix of the two is best etc. Involvement of all is the key etc. OECD member countries should:
Ensure organisations adoption of privacy policies through internal review and linking to OECD site.
Ensure organisations post privacy policies online by encouraging them to do so and auditing them.
Ensure availability of enforcement and redress mechanisms in case of breach of privacy policies by encouraging the use of online alternative dispute mechanisms and actively fostering compliance with privacy policies by raising organisations' awareness..."
Sorry folks but I stopped at that point. This document does not actually appear to be saying anything at all about privacy or information flows in practice. Some people I have a great deal of respect for, like Ian Lloyd at the University of Strathclyde, are noted as having been involved in its production, so I'm sure there is more to it than the first 30 pages appear to promise (Prof Lloyd is mentioned re Chpt 14) but I'm going to allow somebody else to do the leg work on extracting the relevant information.
Can't wait to see the reaction of the libertarians to the news that a French court has fined AOL for 21 abusive and 11 illegal contract terms. It will be the usual outrage I would expect.
"the contracts said AOL could break the agreement without warning, while customers had no way of ending the relationship without paying a penalty."
'By their own', 'hoist' and 'petard' come to mind but not necessarily in that order.
"the contracts said AOL could break the agreement without warning, while customers had no way of ending the relationship without paying a penalty."
'By their own', 'hoist' and 'petard' come to mind but not necessarily in that order.
Cory Doctorow gave a great speech at Microsoft yesterday about digital rights management (DRM). A taster
"Here's what I'm here to convince you of:
1. That DRM systems don't work
2. That DRM systems are bad for society
3. That DRM systems are bad for business
4. That DRM systems are bad for artists
5. That DRM is a bad business-move for MSFT"
And that was just for starters. It's a bit esoteric if you have not been following the drm and copyright wars but still well worth a read.
"Cryptography -- secret writing -- is the practice of keeping
secrets. It involves three parties: a sender, a receiver and an
attacker (actually, there can be more attackers, senders and
recipients, but let's keep this simple). We usually call these
people Alice, Bob and Carol...
...with dual-key crypto it becomes a lot easier for Alice and Bob to keep their keys secret from Carol, even if they've never met...
...Now, let's apply this to DRM.
In DRM, the attacker is *also the recipient*. It's not Alice and
Bob and Carol, it's just Alice and Bob. Alice sells Bob a DVD.
She sells Bob a DVD player. The DVD has a movie on it -- say,
Pirates of the Caribbean -- and it's enciphered with an algorithm
called CSS -- Content Scrambling System. The DVD player has a CSS
un-scrambler.
Now, let's take stock of what's a secret here: the cipher is
well-known. The ciphertext is most assuredly in enemy hands, arrr.
So what? As long as the key is secret from the attacker, we're
golden.
But there's the rub. Alice wants Bob to buy Pirates of the
Caribbean from her. Bob will only buy Pirates of the Caribbean if
he can descramble the CSS-encrypted VOB -- video object -- on his
DVD player. Otherwise, the disc is only useful to Bob as a
drinks-coaster. So Alice has to provide Bob -- the attacker --
with the key, the cipher and the ciphertext.
Hilarity ensues...
...At the end of the day,
all DRM systems share a common vulnerability: they provide their
attackers with ciphertext, the cipher and the key. At this point,
the secret isn't a secret anymore...
...Here's the social reason that DRM fails: keeping an honest user
honest is like keeping a tall user tall. DRM vendors tell us that
their technology is meant to be proof against average users, not
organized criminal gangs like the Ukranian pirates who stamp out
millions of high-quality counterfeits. It's not meant to be proof
against sophisticated college kids. It's not meant to be proof
against anyone who knows how to edit her registry, or hold down
the shift key at the right moment, or use a search engine. At the
end of the day, the user DRM is meant to defend against is the
most unsophisticated and least capable among us."
Next he tells a story of an honest user a young mum who to avoid the kids getting jam on an expensive DVD tries to make a VHS copy, so that when that gets thoroughly kidified she can copy it again for their use and not have to fork out for another expensive copy of the DVD. This story rings very true with me. I've had to replace one of my son's favourite CDs four times in six years and I only count myself lucky that it has still been commercially available. Cory goes on:
"what this person will do in the long run: she'll find out about
Kazaa and the next time she wants to get a movie for the kids,
she'll download it from the net and burn it for them.
In order to delay that day for as long as possible, our lawmakers
and big rightsholder interests have come up with a disastrous
policy called anticircumvention.
Here's how anticircumvention works: if you put a lock -- an
access control -- around a copyrighted work, it is illegal to
break that lock. It's illegal to make a tool that breaks that
lock. It's illegal to tell someone how to make that tool. It's
illegal to tell someone where she can find out how to make that
tool.
Remember Schneier's Law? Anyone can come up with a security
system so clever that he can't see its flaws. The only way to
find the flaws in security is to disclose the system's workings
and invite public feedback. But now we live in a world where any
cipher used to fence off a copyrighted work is off-limits to that
kind of feedback. That's something that a Princeton engineering
prof named Ed Felten discovered when he submitted a paper to an
academic conference on the failings in the Secure Digital Music
Initiative, a watermarking scheme proposed by the recording
industry. The RIAA responded by threatening to sue his ass if he
tried it. We fought them because Ed is the kind of client that
impact litigators love: unimpeachable and clean-cut and the RIAA
folded. Lucky Ed. Maybe the next guy isn't so lucky...
...Here are the two most important things to know about computers
and the Internet:
1. A computer is a machine for rearranging bits
2. The Internet is a machine for moving bits from one place to
another very cheaply and quickly
Any new medium that takes hold on the Internet and with computers
will embrace these two facts, not regret them. A newspaper press
is a machine for spitting out cheap and smeary newsprint at
speed: if you try to make it output fine art lithos, you'll get
junk. If you try to make it output newspapers, you'll get the
basis for a free society.
And so it is with the Internet...
...
New media don't succeed because they're like the only media, only
better: they succeed because they're worse than the old media at
the stuff the old media is good at, and better at the stuff the
old media are bad at. Books are good at being paperwhite,
high-resolution, low-infrastructure, cheap and disposable. Ebooks
are good at being everywhere in the world at the same time for
free in a form that is so malleable that you can just pastebomb
it into your IM session or turn it into a page-a-day mailing
list.
The only really successful epublishing -- I mean, hundreds of
thousands, millions of copies distributed and read -- is the
bookwarez scene, where scanned-and-OCR'd books are distributed on
the darknet. The only legit publishers with any success at
epublishing are the ones whose books cross the Internet without
technological fetter: publishers like Baen Books and my own, Tor,
who are making some or all of their catalogs available in ASCII
and HTML and PDF.
The hardware-dependent ebooks, the DRM use-and-copy-restricted
ebooks, they're cratering. Sales measured in the tens, sometimes
the hundreds. Science fiction is a niche business, but when
you're selling copies by the ten, that's not even a business,
it's a hobby. "
And so he continues but you should read the original. It doesn't suffer from the indented formatting translation by Blogger. I'm going to have to do something about this template and get and RSS feed plus commenting enabled but time pressures are against me at the moment...
"Here's what I'm here to convince you of:
1. That DRM systems don't work
2. That DRM systems are bad for society
3. That DRM systems are bad for business
4. That DRM systems are bad for artists
5. That DRM is a bad business-move for MSFT"
And that was just for starters. It's a bit esoteric if you have not been following the drm and copyright wars but still well worth a read.
"Cryptography -- secret writing -- is the practice of keeping
secrets. It involves three parties: a sender, a receiver and an
attacker (actually, there can be more attackers, senders and
recipients, but let's keep this simple). We usually call these
people Alice, Bob and Carol...
...with dual-key crypto it becomes a lot easier for Alice and Bob to keep their keys secret from Carol, even if they've never met...
...Now, let's apply this to DRM.
In DRM, the attacker is *also the recipient*. It's not Alice and
Bob and Carol, it's just Alice and Bob. Alice sells Bob a DVD.
She sells Bob a DVD player. The DVD has a movie on it -- say,
Pirates of the Caribbean -- and it's enciphered with an algorithm
called CSS -- Content Scrambling System. The DVD player has a CSS
un-scrambler.
Now, let's take stock of what's a secret here: the cipher is
well-known. The ciphertext is most assuredly in enemy hands, arrr.
So what? As long as the key is secret from the attacker, we're
golden.
But there's the rub. Alice wants Bob to buy Pirates of the
Caribbean from her. Bob will only buy Pirates of the Caribbean if
he can descramble the CSS-encrypted VOB -- video object -- on his
DVD player. Otherwise, the disc is only useful to Bob as a
drinks-coaster. So Alice has to provide Bob -- the attacker --
with the key, the cipher and the ciphertext.
Hilarity ensues...
...At the end of the day,
all DRM systems share a common vulnerability: they provide their
attackers with ciphertext, the cipher and the key. At this point,
the secret isn't a secret anymore...
...Here's the social reason that DRM fails: keeping an honest user
honest is like keeping a tall user tall. DRM vendors tell us that
their technology is meant to be proof against average users, not
organized criminal gangs like the Ukranian pirates who stamp out
millions of high-quality counterfeits. It's not meant to be proof
against sophisticated college kids. It's not meant to be proof
against anyone who knows how to edit her registry, or hold down
the shift key at the right moment, or use a search engine. At the
end of the day, the user DRM is meant to defend against is the
most unsophisticated and least capable among us."
Next he tells a story of an honest user a young mum who to avoid the kids getting jam on an expensive DVD tries to make a VHS copy, so that when that gets thoroughly kidified she can copy it again for their use and not have to fork out for another expensive copy of the DVD. This story rings very true with me. I've had to replace one of my son's favourite CDs four times in six years and I only count myself lucky that it has still been commercially available. Cory goes on:
"what this person will do in the long run: she'll find out about
Kazaa and the next time she wants to get a movie for the kids,
she'll download it from the net and burn it for them.
In order to delay that day for as long as possible, our lawmakers
and big rightsholder interests have come up with a disastrous
policy called anticircumvention.
Here's how anticircumvention works: if you put a lock -- an
access control -- around a copyrighted work, it is illegal to
break that lock. It's illegal to make a tool that breaks that
lock. It's illegal to tell someone how to make that tool. It's
illegal to tell someone where she can find out how to make that
tool.
Remember Schneier's Law? Anyone can come up with a security
system so clever that he can't see its flaws. The only way to
find the flaws in security is to disclose the system's workings
and invite public feedback. But now we live in a world where any
cipher used to fence off a copyrighted work is off-limits to that
kind of feedback. That's something that a Princeton engineering
prof named Ed Felten discovered when he submitted a paper to an
academic conference on the failings in the Secure Digital Music
Initiative, a watermarking scheme proposed by the recording
industry. The RIAA responded by threatening to sue his ass if he
tried it. We fought them because Ed is the kind of client that
impact litigators love: unimpeachable and clean-cut and the RIAA
folded. Lucky Ed. Maybe the next guy isn't so lucky...
...Here are the two most important things to know about computers
and the Internet:
1. A computer is a machine for rearranging bits
2. The Internet is a machine for moving bits from one place to
another very cheaply and quickly
Any new medium that takes hold on the Internet and with computers
will embrace these two facts, not regret them. A newspaper press
is a machine for spitting out cheap and smeary newsprint at
speed: if you try to make it output fine art lithos, you'll get
junk. If you try to make it output newspapers, you'll get the
basis for a free society.
And so it is with the Internet...
...
New media don't succeed because they're like the only media, only
better: they succeed because they're worse than the old media at
the stuff the old media is good at, and better at the stuff the
old media are bad at. Books are good at being paperwhite,
high-resolution, low-infrastructure, cheap and disposable. Ebooks
are good at being everywhere in the world at the same time for
free in a form that is so malleable that you can just pastebomb
it into your IM session or turn it into a page-a-day mailing
list.
The only really successful epublishing -- I mean, hundreds of
thousands, millions of copies distributed and read -- is the
bookwarez scene, where scanned-and-OCR'd books are distributed on
the darknet. The only legit publishers with any success at
epublishing are the ones whose books cross the Internet without
technological fetter: publishers like Baen Books and my own, Tor,
who are making some or all of their catalogs available in ASCII
and HTML and PDF.
The hardware-dependent ebooks, the DRM use-and-copy-restricted
ebooks, they're cratering. Sales measured in the tens, sometimes
the hundreds. Science fiction is a niche business, but when
you're selling copies by the ten, that's not even a business,
it's a hobby. "
And so he continues but you should read the original. It doesn't suffer from the indented formatting translation by Blogger. I'm going to have to do something about this template and get and RSS feed plus commenting enabled but time pressures are against me at the moment...
Nice Guardian article on biometrics, Biometrics - great hope for world security or triumph for Big Brother?
Liberty spokesman,Barry Hugill is quoted: "Once you begin to compile massive databases it's a matter of common sense that you are going to get the most horrendous mix-ups, with the wrong people being accused and the the wrong information being shared around the world."
Law enforcement must have enough technically well trained and experienced people and the best available technology to fight the bad guys and there also has to be checks and balances in the system. There is not a computer scientist in the world who knows how to create, secure and maintain the integrity in practice of massive international databases of the kind that are being discussed here. Blind faith in the technology is not going to work in this instance. The current state of affairs neither re-assures me that we have enough technically trained and experienced law enforcement personel or the best available technology appropriately focussed on the job of catching the real bad guys. It is a tough, complex systemic problem and it will not be addressed by an illusion that it is being tackled through huge investment in technologies that don't work
Liberty spokesman,Barry Hugill is quoted: "Once you begin to compile massive databases it's a matter of common sense that you are going to get the most horrendous mix-ups, with the wrong people being accused and the the wrong information being shared around the world."
Law enforcement must have enough technically well trained and experienced people and the best available technology to fight the bad guys and there also has to be checks and balances in the system. There is not a computer scientist in the world who knows how to create, secure and maintain the integrity in practice of massive international databases of the kind that are being discussed here. Blind faith in the technology is not going to work in this instance. The current state of affairs neither re-assures me that we have enough technically trained and experienced law enforcement personel or the best available technology appropriately focussed on the job of catching the real bad guys. It is a tough, complex systemic problem and it will not be addressed by an illusion that it is being tackled through huge investment in technologies that don't work
Thursday, June 17, 2004
Senator Orrin Hatch, praised in the final chapter of Larry Lessig's The Future of Ideas, is proposing the INDUCE Act, the latest in a long line of attempts at further draconian intellectual property legisation. I doubt Larry will be praising this initiative. I can't do better than Susan Crawford on this:
"The logic is that P2P applications inevitably lead to exploitation of children. With me so far? So the act is called the "Inducement Devolves into Unlawful Child Exploitation Act." I'm not even sure that's how "devolves" should be used. But the crimes here go far beyond the title.
The Act (to be proposed tomorrow by songwriter Sen. Hatch and others) amends the copyright law to say that anyone who "induces" copyright infringement is himself/itself an infringer.
"Induce" means intentionally aids, abets, counsels, or procures. So you can't even hire a lawyer if you're doing something risky.
This is amazing. Now we're waaaaaay beyond contributory and vicarious theories of liability, which are court-created and pretty darn broad on their own. See Napster 9th Circuit, Aimster 7th Circuit. It's not even clear what the limit to this is -- "aids" could mean that even something that would have been fair use under the Sony Betamax decision is now an illegal inducement.
And no one can talk to you if they think there's the slightest risk of copyright infringement liability.
We're back to the CBPTDA -- another hugely broad way of making sure that no unauthorized machines ever enter into our lives. If there was ever a moment to organize (see prior post) this might be it."
The CBDTPA was the now defunct proposal of then Sen Hollings in 2002, the Consumer Broadband and Digital Television Promotion Act wonderfully parodied by the EFF. Susan got the initials slightly out of synch but who can blame her. But the
"Inducement Devolves into Unlawful Child Exploitation Act", in the words of another well known American "You cannot be serious!"
"The logic is that P2P applications inevitably lead to exploitation of children. With me so far? So the act is called the "Inducement Devolves into Unlawful Child Exploitation Act." I'm not even sure that's how "devolves" should be used. But the crimes here go far beyond the title.
The Act (to be proposed tomorrow by songwriter Sen. Hatch and others) amends the copyright law to say that anyone who "induces" copyright infringement is himself/itself an infringer.
"Induce" means intentionally aids, abets, counsels, or procures. So you can't even hire a lawyer if you're doing something risky.
This is amazing. Now we're waaaaaay beyond contributory and vicarious theories of liability, which are court-created and pretty darn broad on their own. See Napster 9th Circuit, Aimster 7th Circuit. It's not even clear what the limit to this is -- "aids" could mean that even something that would have been fair use under the Sony Betamax decision is now an illegal inducement.
And no one can talk to you if they think there's the slightest risk of copyright infringement liability.
We're back to the CBPTDA -- another hugely broad way of making sure that no unauthorized machines ever enter into our lives. If there was ever a moment to organize (see prior post) this might be it."
The CBDTPA was the now defunct proposal of then Sen Hollings in 2002, the Consumer Broadband and Digital Television Promotion Act wonderfully parodied by the EFF. Susan got the initials slightly out of synch but who can blame her. But the
"Inducement Devolves into Unlawful Child Exploitation Act", in the words of another well known American "You cannot be serious!"
Apology
I have to apologise for some of the problems people have been seeing on this blog in recent weeks - in particular (but not limited to) double postings and broken links.
I've been trying to do my posting via my preferred browser, Opera. Unfortunately, however, it doesn't seem to interact too well with the Blogger site leading to the kinds of problems people have noticed, so as of today I'm giving up and sadly reverting to IE for weblog postings.
I have to apologise for some of the problems people have been seeing on this blog in recent weeks - in particular (but not limited to) double postings and broken links.
I've been trying to do my posting via my preferred browser, Opera. Unfortunately, however, it doesn't seem to interact too well with the Blogger site leading to the kinds of problems people have noticed, so as of today I'm giving up and sadly reverting to IE for weblog postings.
It seems I may have made a mistake when I reported recently that the EU Commission and Council of ministers had managed to see off the EU Parliament's court challenge to the decision on transfer of airline passenger data to the US.
According to the latest EDR-gram the legal affairs committee of the EU parliament (JURI) yesterday renewed their decision to take the Commission and the Council of ministers to the European Court of Justice on the issue.
"EU Parliament renews decision to take Commission to court ============================================================
The Legal Affairs Committee of the European Parliament (JURI) decided today to take the European Commission as well as the Council to court over the final agreement to transfer PNR data to the US without adequate guarantees for data protection.
The committee, which met today (16 June 2004) for an extraordinary meeting during the Parliament's present recession, voted to call upon the Luxembourg Court to defer the Commission's so-called adequacy finding. This finding claims that the data will find the same level of protection in the U.S. as in the EU. The committee also voted to take the international agreement to court that was signed by the EU Council with the U.S. Department of Homeland Security on 28 May 2004 (see EDRi-gram 2.11). Today's vote was taken with a two-thirds majority concerning the adequacy finding and 19 to 14 votes concerning the international agreement. This is an even clearer majority than in former votes on the same issue.
The JURI committee's decision must still be confirmed by the EU Parliament's Group leaders in a meeting this evening, but it is widely considered that this confirmation is only a formality after no less than six votes in the Parliament to stop the ongoing transfer.
There are however also indications that the Parliament's outgoing President, Pat Cox, has been trying to turn over the wide consensus against the transfer within the EU Parliament. Before the vote in the Committee, a member of the Parliament's judicial service, which is attached to the President's office and obliged to be politically neutral, tried to convince MEPs in a 25-minute speech that there was no legal basis for taking the other two EU institutions to court. Mr. Cox is one of the possible candidates for the presidency of the EU Commission and could thus become subject to an EU Court of Justice case himself. Outgoing Italian Radical MEP Marco Cappato criticised the Judicial Services' intervention as based 'more on political than on legal grounds' and therefore 'an abuse'.
EU-US air data row hots up (16.06.2004) http://www.eupolitix.com/EN/News/200406/8f1cbb0f-bc0c-4583-b514-4b029ed1f942.htm
PNR data deal signed by European Commission (02.06.2004) http://www.edri.org/cgi-bin/index?id=000100000151
(Contribution by Andreas Dietl, EDRI EU affairs director)"
Update: The FT have picked up the story.
According to the latest EDR-gram the legal affairs committee of the EU parliament (JURI) yesterday renewed their decision to take the Commission and the Council of ministers to the European Court of Justice on the issue.
"EU Parliament renews decision to take Commission to court ============================================================
The Legal Affairs Committee of the European Parliament (JURI) decided today to take the European Commission as well as the Council to court over the final agreement to transfer PNR data to the US without adequate guarantees for data protection.
The committee, which met today (16 June 2004) for an extraordinary meeting during the Parliament's present recession, voted to call upon the Luxembourg Court to defer the Commission's so-called adequacy finding. This finding claims that the data will find the same level of protection in the U.S. as in the EU. The committee also voted to take the international agreement to court that was signed by the EU Council with the U.S. Department of Homeland Security on 28 May 2004 (see EDRi-gram 2.11). Today's vote was taken with a two-thirds majority concerning the adequacy finding and 19 to 14 votes concerning the international agreement. This is an even clearer majority than in former votes on the same issue.
The JURI committee's decision must still be confirmed by the EU Parliament's Group leaders in a meeting this evening, but it is widely considered that this confirmation is only a formality after no less than six votes in the Parliament to stop the ongoing transfer.
There are however also indications that the Parliament's outgoing President, Pat Cox, has been trying to turn over the wide consensus against the transfer within the EU Parliament. Before the vote in the Committee, a member of the Parliament's judicial service, which is attached to the President's office and obliged to be politically neutral, tried to convince MEPs in a 25-minute speech that there was no legal basis for taking the other two EU institutions to court. Mr. Cox is one of the possible candidates for the presidency of the EU Commission and could thus become subject to an EU Court of Justice case himself. Outgoing Italian Radical MEP Marco Cappato criticised the Judicial Services' intervention as based 'more on political than on legal grounds' and therefore 'an abuse'.
EU-US air data row hots up (16.06.2004) http://www.eupolitix.com/EN/News/200406/8f1cbb0f-bc0c-4583-b514-4b029ed1f942.htm
PNR data deal signed by European Commission (02.06.2004) http://www.edri.org/cgi-bin/index?id=000100000151
(Contribution by Andreas Dietl, EDRI EU affairs director)"
Update: The FT have picked up the story.
"A Better Ballot Box" by Rebecca Mercuri, a highly respected electronic voting expert, from Bryn Mawr College explains very clearly the problems with electronic voting. She concludes:
"An observer of voting technology once remarked: "If you think technology can solve our voting problems, then you don't understand the problems and you don't understand the technology." Computerization alone cannot improve elections. Those designing and those buying election systems must be aware of their inherent limitations, mindful of the sometimes conflicting needs for privacy, auditability, and security in the election process, and willing to seek out-of-the-(ballot)-box solutions."
Incidently Rebecca Mercuri was proposing voter verified paper trails for electronic voting machines over ten years ago.
Rebecca was one of a select group of delegates invited to take part in Harvard University's Kennedy School of Government and National Science Foundation "Voting, Vote Capture, and Vote Counting" Digital Voting Symposium a couple of weeks ago.
Ron Rivest of RSA public key encryption fame was another in attendance and someone who sees the difficulties with electronic voting as a challenge which can be overcome with sufficient thought and effort.
"We see that innovations in voting systems are continuing, and will continue. We need to manage well this process of continual improvement. I believe that security in voting systems can be substantially improved. While some current DRE [direct recording electronic] systems definitely seem a step backwards in terms of security, it does appear probable that we can eventually have highly secure electronic voting systems, with a reduced or eliminated need to trust the voting machine equipment and software. We will be developing assurance and certification for the election results, rather than for the voting machines. While paper may not go away, we may be able to eventually have secure electronic ballots, rather than paper ballots."
The organisers of the symposium have drawn up a set of best practices that they believe fairly summarise the overall conclusions of the event. I hope they won't mind me reprinting these in full here. They deserve the widest possible circulation.
Certain immediate steps must be taken.
Election Assistance Commission and National Institute of Standards and Technology open standards must be developed and implemented.
The process is even more important than the underlying technology.
The educational process for given technologies must follow a "chain of trust" where the election workers trust their trainers and are trusted by the public.
Poll workers should be well chosen from a motivated pool with incentives, and monetary incentives have proven to work. Poll workers are more important than the technology.
Poll workers should be well trained to fully understand the technology and how to handle contingencies.
Poll workers should not have to rely solely on the vendors to address observed errors.
Speed and accuracy in the process are both achievable, but not simultaneously possible. The public should be educated about the distinction between the speed that allows immediate returns, and the accuracy required in the official tally.
There should be adequate time for determining the official tally.
There should be provisional voting mechanisms, and adequate time to evaluate provisional votes for the final tally.
A hybrid of paper and electronic systems provides the most effective voting system.
Electronic interfaces can meet the widest range of accessibility needs.
Electronic interfaces enable customized ballots by zip code, party, or disability.
Voter examination of a paper ballot allows the greatest degree of confidence that the ballot was cast as intended.
A paper ballot, when handled properly, allows a robust audit trail for a recount to ensure that the ballot was counted as cast.
Hybrid systems can be designed to accommodate provisional arrangements and contingencies for equipment failure. There are many possible implementations.
Good voting systems require good design standards.
There is no single voting interface that can meet everyone's needs.
An untrained voter should be able to know when voting equipment fails.
Access is critical: not to a specific, single technology, but to the ability to vote in a fashion that provides full civil rights.
Rigorous testing is needed for all voting system components to ensure security, reliability and usability.
Even with full auditing of each vote, testing for usability and reliability remain critical.
Openness of a voting process is critical for the perception of legitimacy of that process.
All security issues should be fully disclosed, although allowing vendors a limited, fixed time between notification and public disclosure could foster more public trust.
If underlying mechanics or software are not in the public domain, they must at least be available for inspection by the larger security research community.
The voting technology acquisition process should be open for public scrutiny from constituents.
The voting technology acquisition process should be open to allow jurisdictions to learn from each other; to be specific, records of difficulties should be made available to all election officials.
Election systems must have built-in auditing capabilities.
The reconciliation procedure must be clear, precise, authoritative, and binding.
The cast ballot must follow a "Chain of Custody" from the moment it is cast to the moment the vote is entered into the final official tally. This chain must be subject to audit and oversight at each step regardless of technology.
If some metric of voting irregularity is exceeded in a given jurisdiction, a court-supervised manual recount should be required.
Auditing should not be implemented by a vendor affiliated with the original system.
The general approach to building and implementing elections processes must carefully targeted.
Policymakers should first focus on the overall election process before selecting a specific technology. However, process details must then be tailored to meet the requirements of each specific technology. Technology neutral policies are inadequate in elections.
Policy makers must specify desirable priorities before designing an election system and its technologies. They must identify the problems they wish to solve and how each proposed solution will solve them.
There is an inevitable trade-off between authentication of voters and access. Requiring greater proof of the right to vote will prevent some from voting; removing any requirement for proof will allow those without the right to vote to cast ballot.
Elections and the surrounding systems should be explicitly designed to handle crises. Policy makers and elections officials should assume in every case that there will be a contested recount and plan accordingly.
Given that no voting system can ever be perfect it is crucial to incorporate technologically appropriate risk management tools into the design and evaluation of voting systems and implementation strategies.
"An observer of voting technology once remarked: "If you think technology can solve our voting problems, then you don't understand the problems and you don't understand the technology." Computerization alone cannot improve elections. Those designing and those buying election systems must be aware of their inherent limitations, mindful of the sometimes conflicting needs for privacy, auditability, and security in the election process, and willing to seek out-of-the-(ballot)-box solutions."
Incidently Rebecca Mercuri was proposing voter verified paper trails for electronic voting machines over ten years ago.
Rebecca was one of a select group of delegates invited to take part in Harvard University's Kennedy School of Government and National Science Foundation "Voting, Vote Capture, and Vote Counting" Digital Voting Symposium a couple of weeks ago.
Ron Rivest of RSA public key encryption fame was another in attendance and someone who sees the difficulties with electronic voting as a challenge which can be overcome with sufficient thought and effort.
"We see that innovations in voting systems are continuing, and will continue. We need to manage well this process of continual improvement. I believe that security in voting systems can be substantially improved. While some current DRE [direct recording electronic] systems definitely seem a step backwards in terms of security, it does appear probable that we can eventually have highly secure electronic voting systems, with a reduced or eliminated need to trust the voting machine equipment and software. We will be developing assurance and certification for the election results, rather than for the voting machines. While paper may not go away, we may be able to eventually have secure electronic ballots, rather than paper ballots."
The organisers of the symposium have drawn up a set of best practices that they believe fairly summarise the overall conclusions of the event. I hope they won't mind me reprinting these in full here. They deserve the widest possible circulation.
Certain immediate steps must be taken.
Election Assistance Commission and National Institute of Standards and Technology open standards must be developed and implemented.
The process is even more important than the underlying technology.
The educational process for given technologies must follow a "chain of trust" where the election workers trust their trainers and are trusted by the public.
Poll workers should be well chosen from a motivated pool with incentives, and monetary incentives have proven to work. Poll workers are more important than the technology.
Poll workers should be well trained to fully understand the technology and how to handle contingencies.
Poll workers should not have to rely solely on the vendors to address observed errors.
Speed and accuracy in the process are both achievable, but not simultaneously possible. The public should be educated about the distinction between the speed that allows immediate returns, and the accuracy required in the official tally.
There should be adequate time for determining the official tally.
There should be provisional voting mechanisms, and adequate time to evaluate provisional votes for the final tally.
A hybrid of paper and electronic systems provides the most effective voting system.
Electronic interfaces can meet the widest range of accessibility needs.
Electronic interfaces enable customized ballots by zip code, party, or disability.
Voter examination of a paper ballot allows the greatest degree of confidence that the ballot was cast as intended.
A paper ballot, when handled properly, allows a robust audit trail for a recount to ensure that the ballot was counted as cast.
Hybrid systems can be designed to accommodate provisional arrangements and contingencies for equipment failure. There are many possible implementations.
Good voting systems require good design standards.
There is no single voting interface that can meet everyone's needs.
An untrained voter should be able to know when voting equipment fails.
Access is critical: not to a specific, single technology, but to the ability to vote in a fashion that provides full civil rights.
Rigorous testing is needed for all voting system components to ensure security, reliability and usability.
Even with full auditing of each vote, testing for usability and reliability remain critical.
Openness of a voting process is critical for the perception of legitimacy of that process.
All security issues should be fully disclosed, although allowing vendors a limited, fixed time between notification and public disclosure could foster more public trust.
If underlying mechanics or software are not in the public domain, they must at least be available for inspection by the larger security research community.
The voting technology acquisition process should be open for public scrutiny from constituents.
The voting technology acquisition process should be open to allow jurisdictions to learn from each other; to be specific, records of difficulties should be made available to all election officials.
Election systems must have built-in auditing capabilities.
The reconciliation procedure must be clear, precise, authoritative, and binding.
The cast ballot must follow a "Chain of Custody" from the moment it is cast to the moment the vote is entered into the final official tally. This chain must be subject to audit and oversight at each step regardless of technology.
If some metric of voting irregularity is exceeded in a given jurisdiction, a court-supervised manual recount should be required.
Auditing should not be implemented by a vendor affiliated with the original system.
The general approach to building and implementing elections processes must carefully targeted.
Policymakers should first focus on the overall election process before selecting a specific technology. However, process details must then be tailored to meet the requirements of each specific technology. Technology neutral policies are inadequate in elections.
Policy makers must specify desirable priorities before designing an election system and its technologies. They must identify the problems they wish to solve and how each proposed solution will solve them.
There is an inevitable trade-off between authentication of voters and access. Requiring greater proof of the right to vote will prevent some from voting; removing any requirement for proof will allow those without the right to vote to cast ballot.
Elections and the surrounding systems should be explicitly designed to handle crises. Policy makers and elections officials should assume in every case that there will be a contested recount and plan accordingly.
Given that no voting system can ever be perfect it is crucial to incorporate technologically appropriate risk management tools into the design and evaluation of voting systems and implementation strategies.
Wednesday, June 16, 2004
In the wake of DirecTV's agreement with the EFF which I reported on yesterday, the 11th Circuit Court of Appeals has ruled that the company
can't sue people for "mere possession" of technology that might be used to freely access satellite broadcast signals. A cynic might suggest they saw it coming... but I wouldn't want to be seen as a cynic.
Findlaw has a link to the decision http://caselaw.findlaw.com/data2/circs/11th/0315313p.pdf
Acacia which has been quietly building a track record of success, suing pornographers and minor educational institutions for patent infringement, has decided the time is right to pick a fight with some of the big broadcasters. Acacia holds a patent on audio and visual transmission via the Net. The notion that anybody should get awarded such a patent is daft but it now gets to get tested by the big guys' lawyers.
can't sue people for "mere possession" of technology that might be used to freely access satellite broadcast signals. A cynic might suggest they saw it coming... but I wouldn't want to be seen as a cynic.
Findlaw has a link to the decision http://caselaw.findlaw.com/data2/circs/11th/0315313p.pdf
Acacia which has been quietly building a track record of success, suing pornographers and minor educational institutions for patent infringement, has decided the time is right to pick a fight with some of the big broadcasters. Acacia holds a patent on audio and visual transmission via the Net. The notion that anybody should get awarded such a patent is daft but it now gets to get tested by the big guys' lawyers.
A PhD student at Duke University has given what I would consider a pretty worrying analysis outlining the ease with which the electronic voting in November's presidential elections could be disrupted. He's entitled it President Nader.
Avi Rubin, meanwhile, who was one of those who brought the problems with electronic voting to public attention, has proposed an interesting challenge: he wants to know if a voting machine that was rigged in favour of a particular candidate could pass certification. What a good idea. Just like undercover agents testing the security at airports.
As Avi says, if a rigged machine makes it through the certifciation process in every state that it is tested, these machines need to be quickly eliminated from the election process.
Avi Rubin, meanwhile, who was one of those who brought the problems with electronic voting to public attention, has proposed an interesting challenge: he wants to know if a voting machine that was rigged in favour of a particular candidate could pass certification. What a good idea. Just like undercover agents testing the security at airports.
As Avi says, if a rigged machine makes it through the certifciation process in every state that it is tested, these machines need to be quickly eliminated from the election process.
The right way to use biometrics - Bruce Schneier is pleased to finally find someone thinking of an appropriate use for biometric technology - bioemtric IDs for airport employees.
" The strong suit of biometrics is authentication: is this person who he says he is. Issuing ID cards to people who require access to these sensitive areas is smart, and using biometrics to make those IDs harder to hack is smarter. There's no broad surveillance of the population; there are no civil liberties or privacy concerns.
And transportation employees are a weak link in airplane security. We're spending billions on passenger screening programs like CAPPS-II, but none of these measures will do any good if terrorists can just go around the systems. Current TSA policy is that airport workers can access secure areas of airports with no screening whatsoever except for a rudimentary background check. That includes the thousands of people who work for the stores and restaurants in airport terminals as well as the army of workers who clean and maintain aircraft, load baggage, and provide food service. Closing this massive security hole is a good idea.
All of this has to be balanced with cost, however. Issuing one million IDs, and probably tens of thousands of ID readers, isn't going to be cheap. But it would certainly give us more security, dollar for dollar, than yet another passenger security system.
Unfortunately, politicians tend to prefer security systems that affect broad swaths of the population. They like security that's visible; it demonstrates that they're serious about security and is more likely to get them votes. A security system for transportation workers, one that is largely hidden from view, is likely to garner less support than a more public system.
Let's hope U.S. lawmakers do the right thing regardless."
" The strong suit of biometrics is authentication: is this person who he says he is. Issuing ID cards to people who require access to these sensitive areas is smart, and using biometrics to make those IDs harder to hack is smarter. There's no broad surveillance of the population; there are no civil liberties or privacy concerns.
And transportation employees are a weak link in airplane security. We're spending billions on passenger screening programs like CAPPS-II, but none of these measures will do any good if terrorists can just go around the systems. Current TSA policy is that airport workers can access secure areas of airports with no screening whatsoever except for a rudimentary background check. That includes the thousands of people who work for the stores and restaurants in airport terminals as well as the army of workers who clean and maintain aircraft, load baggage, and provide food service. Closing this massive security hole is a good idea.
All of this has to be balanced with cost, however. Issuing one million IDs, and probably tens of thousands of ID readers, isn't going to be cheap. But it would certainly give us more security, dollar for dollar, than yet another passenger security system.
Unfortunately, politicians tend to prefer security systems that affect broad swaths of the population. They like security that's visible; it demonstrates that they're serious about security and is more likely to get them votes. A security system for transportation workers, one that is largely hidden from view, is likely to garner less support than a more public system.
Let's hope U.S. lawmakers do the right thing regardless."
The Commission for Racial Equality (CRE)is worried about the UK government's plans for a national ID card. They reckon it could cause a "great deal of unease" among ethnic minorities due to the potential for it to be used as a lever for racial abuse.
You might recall I mentioned some time ago that Mr Blunkett is kindly arranging for me and the rest of the UK-resident Irish diaspora to have a special ID card, unique to the Irish. Hmmm, why doesn't that fill me with confidence? I'd be interested to know the CRE's perspective on this.
You might recall I mentioned some time ago that Mr Blunkett is kindly arranging for me and the rest of the UK-resident Irish diaspora to have a special ID card, unique to the Irish. Hmmm, why doesn't that fill me with confidence? I'd be interested to know the CRE's perspective on this.
"CUTTING EDGE TECHNOLOGY TO MODERNISE UK BORDER CONTROL" shouts the Home Office press release.
"Cutting edge technology is set to revolutionise the UK's immigration controls, with the roll-out of a hi-tech iris recognition system to a number of key UK airports, Immigration Minister, Des Browne announced today.
The state-of-the-art system will store and verify the iris patterns of specially selected groups of travellers, giving watertight confirmation of their identity when they arrive in the UK. This will substantially increase security as well as speed their process through immigration control."
Complete nonsense. I'll say this slowly, Mr Browne, biometrics may be unique but they are not secret and the technology is not very reliable.
"Cutting edge technology is set to revolutionise the UK's immigration controls, with the roll-out of a hi-tech iris recognition system to a number of key UK airports, Immigration Minister, Des Browne announced today.
The state-of-the-art system will store and verify the iris patterns of specially selected groups of travellers, giving watertight confirmation of their identity when they arrive in the UK. This will substantially increase security as well as speed their process through immigration control."
Complete nonsense. I'll say this slowly, Mr Browne, biometrics may be unique but they are not secret and the technology is not very reliable.
Tuesday, June 15, 2004
The EU's Information society commissioner, Erkki Liikanen, has been appointed governor of the bank of Finland. he'll be leaving the Commission on 12 July.
Who comes next?
Who comes next?
Larry Lessig, who incidentally will be doing a short online visit to my Open University T182 course next week, is looking for stories to support the Stanford cyberlaw clinic case Kahle v Aschroft.
"To win the lawsuit, we need your help. We need more examples of people being burdened by these copyright-related barriers to the use of orphan works. You can help us if you have ever wanted to copy, distribute, perform, modify, sample, mash-up, or generally use an orphan work, but were prevented from doing so because:
The cost of trying to find the copyright holder was too high; or
You were unable to find the copyright holder; or
You were able to find the copyright holder and they refused to issue a license; or
You were able to find the copyright holder and you were issued a license, but you have a good story to tell about how difficult the process was."
"To win the lawsuit, we need your help. We need more examples of people being burdened by these copyright-related barriers to the use of orphan works. You can help us if you have ever wanted to copy, distribute, perform, modify, sample, mash-up, or generally use an orphan work, but were prevented from doing so because:
The cost of trying to find the copyright holder was too high; or
You were unable to find the copyright holder; or
You were able to find the copyright holder and they refused to issue a license; or
You were able to find the copyright holder and you were issued a license, but you have a good story to tell about how difficult the process was."
Tim Berners Lee has been deservedly awarded the Millennium Technology Prize from the Finnish Technology Award Foundation.
Always nice to see the good guys getting rewarded.
Always nice to see the good guys getting rewarded.
There's a major turnaround at the League of Women Voters. In the face of mass protest from the membership over their support for electronic voting machines with no paper trail, the leadership of the organisation has been forced into a U-turn. They have dropped their support for paperless voting and adopted a resolution in favour of ``voting systems and procedures that are secure, accurate, recountable and accessible.''
``My initial reaction is incredible joy and relief,'' said computer scientist Barbara Simons, 63, past president of the Association for Computing Machinery and a league member from a chapter in Palo Alto, Calif. ``This issue was threatening to split the league apart. ... The league now has a position that I feel very comfortable supporting.''
Well done Barbara (who I had the pleasure of meeting at a conference in Oxford in recent years) and your fellow protestors.
And meanwhile in Florida (wot won it for Bush, in Sun-speak)state officials have declared that "Touchscreen voting machines in 11 counties have a software flaw that could make manual recounts impossible in November's presidential election".
The story of electronic voting could fill more than one book.
``My initial reaction is incredible joy and relief,'' said computer scientist Barbara Simons, 63, past president of the Association for Computing Machinery and a league member from a chapter in Palo Alto, Calif. ``This issue was threatening to split the league apart. ... The league now has a position that I feel very comfortable supporting.''
Well done Barbara (who I had the pleasure of meeting at a conference in Oxford in recent years) and your fellow protestors.
And meanwhile in Florida (wot won it for Bush, in Sun-speak)state officials have declared that "Touchscreen voting machines in 11 counties have a software flaw that could make manual recounts impossible in November's presidential election".
The story of electronic voting could fill more than one book.
Looks as though the EFF and the Stanford Cyberlaw folks have had some success in getting through to satallite TV company DirecTV about their thousands of threats and lawsuits against innocent users of smart card technology.
"Over the past few years, DirecTV has orchestrated a nationwide legal campaign against hundreds of thousands of individuals, claiming that they were illegally intercepting its satellite TV signal. The company began its crusade by raiding smart card device distributors to obtain their customer lists, then sent over 170,000 demand letters to customers and eventually filed more than 24,000 federal lawsuits against them. Because DirecTV made little effort to distinguish legal uses of smart card technology from illegal ones, EFF and the CIS Cyberlaw Clinic received hundreds of calls and emails from panicked device purchasers.
n August 2003, EFF and CIS created the DirecTV Defense website to provide innocent users and their lawyers with the information necessary to defend themselves. The organizations also began a series of discussions with DirecTV about ways to reform its anti-piracy tactics and protect innocent consumers.
As a result, DirecTV has agreed to make several changes to its campaign. The company will no longer pursue people solely for purchasing smart card readers, writers, general-purpose programmers, and general-purpose emulators. It will maintain this policy into the forseeable future and file lawsuits only against people it suspects of actually pirating its satellite signal. DirecTV will, however, continue to investigate purchasers of devices that are often primarily designed for satellite signal interception, nicknamed “bootloaders” and “unloopers.”
DirecTV also agreed to change its pre-lawsuit demand letters to explain in detail how innocent recipients can get DirecTV to drop their cases. The company also promised that it will investigate every substantive claim of innocence it receives. If purchasers provide sufficient evidence demonstrating that they did not use their devices for signal theft, DirecTV will dismiss their cases. EFF and CIS will monitor reports of this process to confirm that innocent device purchasers are having their cases dismissed."
I suspect the EFF and Stanford people have ideological objections to DirecTV's 'guilty until you prove yourself innocent' stance but this constitutes major progress in the dispute and all concerned deserve credit.
"Over the past few years, DirecTV has orchestrated a nationwide legal campaign against hundreds of thousands of individuals, claiming that they were illegally intercepting its satellite TV signal. The company began its crusade by raiding smart card device distributors to obtain their customer lists, then sent over 170,000 demand letters to customers and eventually filed more than 24,000 federal lawsuits against them. Because DirecTV made little effort to distinguish legal uses of smart card technology from illegal ones, EFF and the CIS Cyberlaw Clinic received hundreds of calls and emails from panicked device purchasers.
n August 2003, EFF and CIS created the DirecTV Defense website to provide innocent users and their lawyers with the information necessary to defend themselves. The organizations also began a series of discussions with DirecTV about ways to reform its anti-piracy tactics and protect innocent consumers.
As a result, DirecTV has agreed to make several changes to its campaign. The company will no longer pursue people solely for purchasing smart card readers, writers, general-purpose programmers, and general-purpose emulators. It will maintain this policy into the forseeable future and file lawsuits only against people it suspects of actually pirating its satellite signal. DirecTV will, however, continue to investigate purchasers of devices that are often primarily designed for satellite signal interception, nicknamed “bootloaders” and “unloopers.”
DirecTV also agreed to change its pre-lawsuit demand letters to explain in detail how innocent recipients can get DirecTV to drop their cases. The company also promised that it will investigate every substantive claim of innocence it receives. If purchasers provide sufficient evidence demonstrating that they did not use their devices for signal theft, DirecTV will dismiss their cases. EFF and CIS will monitor reports of this process to confirm that innocent device purchasers are having their cases dismissed."
I suspect the EFF and Stanford people have ideological objections to DirecTV's 'guilty until you prove yourself innocent' stance but this constitutes major progress in the dispute and all concerned deserve credit.
My friend John Naughton is not impressed with WIPO's plans for a broadcasting treaty.
"When I first saw the draft (it was published in April), I assumed it must have been written by executives at Fox, NBC and other US TV networks while high on cocaine, because it read like a wish-list of everything a failing industry could want to protect it from the future.
It is a control-freak's charter. This is predictable, because an obsession with control has worked its way into the industry's DNA. Broadcasting is a few-to-many medium: a small number of content-providers decide what is to be offered, produce the content, and push it to passive consumers. Central to the broadcasting ethos is a desire to control the viewer, to restrict choice to the menus chosen by the industry - like Skinnerian pigeons pecking at coloured levers to obtain food...
...Experience over the last decade has shown us how established industries react when they are threatened by new technology. First they go into denial. Then they resort to legal countermeasures - which invariably fail. Finally they nobble legislators, seeking to persuade them to enact laws that will protect the old business models.
Which is where the draft broadcast treaty comes in. The great thing about Wipo, from the point of corporate lobbyists and their allies in certain national governments, is that it offers more bangs per buck. Instead of having to petition 50 or 100 national legislatures, you persuade Wipo to propose a draft treaty, which is submitted to a diplomatic conference and ratified. Then all the signatories are obliged to do what you want."
Cory Doctorow (cory@eff.org), Wendy Seltzer (wendy@eff.org) and David Tannenbaum (davidt@public-domain.org) attended the meeting that John refers to, as part of a public interest delegation and did a terrific job of making noteson the proceedings. The notes provide the first direct public insight into the making of international intellectual property regulations and makes fascinating reading.
"When I first saw the draft (it was published in April), I assumed it must have been written by executives at Fox, NBC and other US TV networks while high on cocaine, because it read like a wish-list of everything a failing industry could want to protect it from the future.
It is a control-freak's charter. This is predictable, because an obsession with control has worked its way into the industry's DNA. Broadcasting is a few-to-many medium: a small number of content-providers decide what is to be offered, produce the content, and push it to passive consumers. Central to the broadcasting ethos is a desire to control the viewer, to restrict choice to the menus chosen by the industry - like Skinnerian pigeons pecking at coloured levers to obtain food...
...Experience over the last decade has shown us how established industries react when they are threatened by new technology. First they go into denial. Then they resort to legal countermeasures - which invariably fail. Finally they nobble legislators, seeking to persuade them to enact laws that will protect the old business models.
Which is where the draft broadcast treaty comes in. The great thing about Wipo, from the point of corporate lobbyists and their allies in certain national governments, is that it offers more bangs per buck. Instead of having to petition 50 or 100 national legislatures, you persuade Wipo to propose a draft treaty, which is submitted to a diplomatic conference and ratified. Then all the signatories are obliged to do what you want."
Cory Doctorow (cory@eff.org), Wendy Seltzer (wendy@eff.org) and David Tannenbaum (davidt@public-domain.org) attended the meeting that John refers to, as part of a public interest delegation and did a terrific job of making noteson the proceedings. The notes provide the first direct public insight into the making of international intellectual property regulations and makes fascinating reading.
Looks as though the EFF and the Stanford Cyberlaw folks have had some success in getting through to satallite TV company DirecTV about their thousands of threats and lawsuits against innocent users of smart card technology.
"Over the past few years, DirecTV has orchestrated a nationwide legal campaign against hundreds of thousands of individuals, claiming that they were illegally intercepting its satellite TV signal. The company began its crusade by raiding smart card device distributors to obtain their customer lists, then sent over 170,000 demand letters to customers and eventually filed more than 24,000 federal lawsuits against them. Because DirecTV made little effort to distinguish legal uses of smart card technology from illegal ones, EFF and the CIS Cyberlaw Clinic received hundreds of calls and emails from panicked device purchasers.
n August 2003, EFF and CIS created the DirecTV Defense website to provide innocent users and their lawyers with the information necessary to defend themselves. The organizations also began a series of discussions with DirecTV about ways to reform its anti-piracy tactics and protect innocent consumers.
As a result, DirecTV has agreed to make several changes to its campaign. The company will no longer pursue people solely for purchasing smart card readers, writers, general-purpose programmers, and general-purpose emulators. It will maintain this policy into the forseeable future and file lawsuits only against people it suspects of actually pirating its satellite signal. DirecTV will, however, continue to investigate purchasers of devices that are often primarily designed for satellite signal interception, nicknamed “bootloaders” and “unloopers.”
DirecTV also agreed to change its pre-lawsuit demand letters to explain in detail how innocent recipients can get DirecTV to drop their cases. The company also promised that it will investigate every substantive claim of innocence it receives. If purchasers provide sufficient evidence demonstrating that they did not use their devices for signal theft, DirecTV will dismiss their cases. EFF and CIS will monitor reports of this process to confirm that innocent device purchasers are having their cases dismissed."
I suspect the EFF and Stanford people have ideological objections to DirecTV's 'guilty until you prove yourself innocent' stance but this constitutes major progress in the dispute and all concerned deserve credit.
"Over the past few years, DirecTV has orchestrated a nationwide legal campaign against hundreds of thousands of individuals, claiming that they were illegally intercepting its satellite TV signal. The company began its crusade by raiding smart card device distributors to obtain their customer lists, then sent over 170,000 demand letters to customers and eventually filed more than 24,000 federal lawsuits against them. Because DirecTV made little effort to distinguish legal uses of smart card technology from illegal ones, EFF and the CIS Cyberlaw Clinic received hundreds of calls and emails from panicked device purchasers.
n August 2003, EFF and CIS created the DirecTV Defense website to provide innocent users and their lawyers with the information necessary to defend themselves. The organizations also began a series of discussions with DirecTV about ways to reform its anti-piracy tactics and protect innocent consumers.
As a result, DirecTV has agreed to make several changes to its campaign. The company will no longer pursue people solely for purchasing smart card readers, writers, general-purpose programmers, and general-purpose emulators. It will maintain this policy into the forseeable future and file lawsuits only against people it suspects of actually pirating its satellite signal. DirecTV will, however, continue to investigate purchasers of devices that are often primarily designed for satellite signal interception, nicknamed “bootloaders” and “unloopers.”
DirecTV also agreed to change its pre-lawsuit demand letters to explain in detail how innocent recipients can get DirecTV to drop their cases. The company also promised that it will investigate every substantive claim of innocence it receives. If purchasers provide sufficient evidence demonstrating that they did not use their devices for signal theft, DirecTV will dismiss their cases. EFF and CIS will monitor reports of this process to confirm that innocent device purchasers are having their cases dismissed."
I suspect the EFF and Stanford people have ideological objections to DirecTV's 'guilty until you prove yourself innocent' stance but this constitutes major progress in the dispute and all concerned deserve credit.
Monday, June 14, 2004
The RIAA have added digital radio to their list of problem technology targets. They have to be really careful - they are going to eventually pick on one to many metaphorical straws and find their camel collapsing underneath.
Some libraries in New Hampshire are giving up the chance of federal funding because they don't want to install filter software on their computers.
"The New Hampshire Library Association encouraged forgoing federal funds in a statement posted on its Web site. It said filters block valuable information like research on breast cancer, sexually transmitted diseases and even Super Bowl XXX, and give a false sense of security."
Since this weblog has been subject to crude ship due to crude xxx filtering I'd say more power to their elbow!
Some libraries in New Hampshire are giving up the chance of federal funding because they don't want to install filter software on their computers.
"The New Hampshire Library Association encouraged forgoing federal funds in a statement posted on its Web site. It said filters block valuable information like research on breast cancer, sexually transmitted diseases and even Super Bowl XXX, and give a false sense of security."
Since this weblog has been subject to crude ship due to crude xxx filtering I'd say more power to their elbow!
Ernest Miller has another beauty on DRM: Incredibly Dumb DRM Tactics - iTunes Example #1
"So, here we have a DRM stripping program that is deliberately designed to encourage copyright compliance yet still enable fair use. What does Apple do? They deliberately make such stripping programs untenable...
...This helps encourage copyright compliance, how?"
Matthew Skala of CyberPatrol hack fame has a terrific essay on the colour (or lack of it) of bits and why lawyers and computer scientists don't understand each other. In the computer scientists' universe bits have no colour. In the lawyers' universe, bit must have colour because colour is what they base their reasoning on.
Larry Lessig tells, in the penultimate chapter of his first book Code and other laws of cyberspace, of a lesson he learnt from his uncle about the art of being a good lawyer. It's not about tactics or slight of hand but about using reason, through a story to persuade. Computer scientists and lawyers can communicate but each species needs to improve their use of reason through stories to persuade and help the other understand their respective universes.
"So, here we have a DRM stripping program that is deliberately designed to encourage copyright compliance yet still enable fair use. What does Apple do? They deliberately make such stripping programs untenable...
...This helps encourage copyright compliance, how?"
Matthew Skala of CyberPatrol hack fame has a terrific essay on the colour (or lack of it) of bits and why lawyers and computer scientists don't understand each other. In the computer scientists' universe bits have no colour. In the lawyers' universe, bit must have colour because colour is what they base their reasoning on.
Larry Lessig tells, in the penultimate chapter of his first book Code and other laws of cyberspace, of a lesson he learnt from his uncle about the art of being a good lawyer. It's not about tactics or slight of hand but about using reason, through a story to persuade. Computer scientists and lawyers can communicate but each species needs to improve their use of reason through stories to persuade and help the other understand their respective universes.
Thursday, June 10, 2004
The UK's Information Commissioner, Richard Thomas, has expressed his "increasing alarm" at the UK government's proposals for a national identity card.
The Home Office responded predictably by attacking the Commissioner and with the usual idiotic claptrap about modern ID cards in 21st century Britain.
"EU interior ministers have agreed that within 18 months passports from EU citizens will contain one or two pieces of biometric data, a digitised face photo (compulsory) and a fingerprint (optional)." Actually I've no problem with digital photos on passports. Now, the databases retaining the digital information from the photos and how, where, when, why and by whom they are deployed, they're different questions. No awkward questions like this are really going to get addressed by the likes of David Blunkett, though. Biometrics, the solution to all ills. Sigh.
The Home Office responded predictably by attacking the Commissioner and with the usual idiotic claptrap about modern ID cards in 21st century Britain.
"EU interior ministers have agreed that within 18 months passports from EU citizens will contain one or two pieces of biometric data, a digitised face photo (compulsory) and a fingerprint (optional)." Actually I've no problem with digital photos on passports. Now, the databases retaining the digital information from the photos and how, where, when, why and by whom they are deployed, they're different questions. No awkward questions like this are really going to get addressed by the likes of David Blunkett, though. Biometrics, the solution to all ills. Sigh.
Author Bruce Sterling says the net is a "god-awful mess" with virus writers, spammers and scammers and organised crime wreaking havoc.Author Bruce Sterling says the net is a "god-awful mess" with virus writers, spammers and scammers and organised crime wreaking havoc.Author Bruce Sterling says the net is a "god-awful mess" with virus writers, spammers and scammers and organised crime wreaking havoc.
"This is the birth of a genuine, no-kidding, for-profit ... multinational criminal underworld," he said. "I don't see any way it can't happen. We're going to end up getting pushed around by bands of international electronic thieves in a very similar way to the way we've been pushed around by gangs of international Mafia and international Mujahideen terrorists."
Sterling reckons we need a lot more tech savvy law enforcement forces on the ground and fewer dopey laws created by gesture politics.
I've always liked Sterling. Talks a lot of sense.
Meanwhile the EU are concentrating on introducing more laws to produce a uniform approach to combatting "cybercrime". Sigh. There's no such thing as "cybercrime" just crime. And crime is now facilitated by hi tech tools. We need sufficient numbers of law enforcement people enobled in the art and craft of new technology, not more inappropriate laws.
"This is the birth of a genuine, no-kidding, for-profit ... multinational criminal underworld," he said. "I don't see any way it can't happen. We're going to end up getting pushed around by bands of international electronic thieves in a very similar way to the way we've been pushed around by gangs of international Mafia and international Mujahideen terrorists."
Sterling reckons we need a lot more tech savvy law enforcement forces on the ground and fewer dopey laws created by gesture politics.
I've always liked Sterling. Talks a lot of sense.
Meanwhile the EU are concentrating on introducing more laws to produce a uniform approach to combatting "cybercrime". Sigh. There's no such thing as "cybercrime" just crime. And crime is now facilitated by hi tech tools. We need sufficient numbers of law enforcement people enobled in the art and craft of new technology, not more inappropriate laws.
Thursday, May 20, 2004
FIPR, Privacy International, Stand, Liberty, the Liberal Democrats and several other groups have launched a campaign to stop national identity cards in the UK. Their slogans (you need pithy slogans for a campaign these days):
An ID scheme won't stop terrorists
An ID scheme will not control illegal immigration
An ID scheme won't enable you to have anything you do not already have
An ID scheme will cost billions in taxpayers money and achieve nothing
An ID scheme will mean your most intimate details will be controlled by the government forever
An ID scheme will cost everyone £75 every year
More power to their elbow.
An ID scheme won't stop terrorists
An ID scheme will not control illegal immigration
An ID scheme won't enable you to have anything you do not already have
An ID scheme will cost billions in taxpayers money and achieve nothing
An ID scheme will mean your most intimate details will be controlled by the government forever
An ID scheme will cost everyone £75 every year
More power to their elbow.
The OECD working party on information security and privacy have published their report about biometrics. It's 66 pages and not bedtime reading unless you suffer from insomnia or have a really serious interest in biometrics and their possible implications. But it is worth pointing to their conclusion:
"The extent to which we are willing to incorporate statutory and policy and technological controls into these
systems and technologies will determine the extent to which they will improve our quality of life; providing convenience and security or conversely, the extent to which they threaten our liberty and freedom via actual or potential surveillance and control."
In other words, as with the deployment of all complex technologies, the devil is in the detail and it is time policy makers, like David Blunkett for example, started getting real about the detail.
"The extent to which we are willing to incorporate statutory and policy and technological controls into these
systems and technologies will determine the extent to which they will improve our quality of life; providing convenience and security or conversely, the extent to which they threaten our liberty and freedom via actual or potential surveillance and control."
In other words, as with the deployment of all complex technologies, the devil is in the detail and it is time policy makers, like David Blunkett for example, started getting real about the detail.
EFF news: The EFF have supplied an amicus brief in the lawsuit against California Secretary of State Kevin Shelley for decertifying specific electronic voting machines. The brief says the state can have secure electronic voting with an auditable paper trail by November and the presidential election.
There's quite a good editorial in the NYT about electronic voting. Extract:
"In an age when consumers expect to be offered a receipt every time they use an A.T.M. or buy gasoline, it is hard to believe that there is opposition to paper records for electronic voting. But the opposition has been strong. Many local election officials and voting machine companies are fighting paper trails, in part because they will create more work and will raise difficult questions if the paper and electronic tallies do not match. Officials in places that have invested heavily in electronic machines that do not produce a paper trail, like Florida and Georgia, have been particularly vehement.
As many computer scientists have explained, voters cannot trust electronic machines that do not produce voter-verifiable records. If New York throws its weight behind California, Ohio and several other states to require them, the odds are good that such records will become the national standard and that even states like Florida will have to retrofit their machines to produce them. It is too late for New York to lead the movement for reliable electronic voting, but if it acts in the next few weeks, it can still be an important part of the solution."
There's quite a good editorial in the NYT about electronic voting. Extract:
"In an age when consumers expect to be offered a receipt every time they use an A.T.M. or buy gasoline, it is hard to believe that there is opposition to paper records for electronic voting. But the opposition has been strong. Many local election officials and voting machine companies are fighting paper trails, in part because they will create more work and will raise difficult questions if the paper and electronic tallies do not match. Officials in places that have invested heavily in electronic machines that do not produce a paper trail, like Florida and Georgia, have been particularly vehement.
As many computer scientists have explained, voters cannot trust electronic machines that do not produce voter-verifiable records. If New York throws its weight behind California, Ohio and several other states to require them, the odds are good that such records will become the national standard and that even states like Florida will have to retrofit their machines to produce them. It is too late for New York to lead the movement for reliable electronic voting, but if it acts in the next few weeks, it can still be an important part of the solution."
Digital Media News For Europe reports
"Rotterdam-based website Dvdstream.nl is
using the Dutch copyright law that permits the
copying of films or music for private
consumption, to lawfully provide unlimited
film-downloads. "
I expect to hear more about this.
"Rotterdam-based website Dvdstream.nl is
using the Dutch copyright law that permits the
copying of films or music for private
consumption, to lawfully provide unlimited
film-downloads. "
I expect to hear more about this.
Sharman networks have been back in court in Australia, saying nobody has provided hard evidence of copyright infringement on Kazaa.
John Lettice continues to warm to his theme on ID cards over at the Register.
"Regular readers
will recall that Home Secretary David Blunkett justifies the ID card scheme on the basis
that most of the cost is money we'd have to spend anyway, because we need to upgrade
our passports to meet US and ICAO (International Civil Aviation Organisation)
standards...
...when David Blunkett tells us that what he is
proposing is necessitated almost entirely by the new passport regime, he is simply (as
we've pointed out before) not telling the truth. ICAO's requirements are for a biometric
machine-readable passport, with the face as the primary biometric, and ICAO is entirely
silent on the subject of vast interlocking National Identity Register databases - if you want
to implement one of these, that's up to you, it's not compulsory. Similarly, the US wants
visitors' passports to be ICAO standard, which is only reasonable, given that the ICAO
standard seems to have been devised more or less in accordance with State Department
wishes. Once you've done that the US will happily (we fear, very happily) collect personal
information on the bearers all by itself - you don't have to do anything, and you never
know, they might even share some of it with you.
The biometric passport system the US intends to use simply seems to be an addition of
the necessary machine readable capabilities to the existing system. Passport applications,
including photograph, will still be accepted via mail, and the picture will then be encoded,
added to the database and put onto the chip that goes in the passport. As you may note,
a picture is in these terms a biometric, while a camera is a biometric reader, which they
are. But don't noise it around, or you'll screw the revenues of an awful lot of snake-oil
salesmen."
It's worth repeating that last sentence: As you may not, a picture is in these terms a biometric, while a camera is a biometric reader, which they are. But don't noise it around, or you'll screw the revenues of an awful lot of snake-oil salesmen.
Keep up the good work, John.
"Regular readers
will recall that Home Secretary David Blunkett justifies the ID card scheme on the basis
that most of the cost is money we'd have to spend anyway, because we need to upgrade
our passports to meet US and ICAO (International Civil Aviation Organisation)
standards...
...when David Blunkett tells us that what he is
proposing is necessitated almost entirely by the new passport regime, he is simply (as
we've pointed out before) not telling the truth. ICAO's requirements are for a biometric
machine-readable passport, with the face as the primary biometric, and ICAO is entirely
silent on the subject of vast interlocking National Identity Register databases - if you want
to implement one of these, that's up to you, it's not compulsory. Similarly, the US wants
visitors' passports to be ICAO standard, which is only reasonable, given that the ICAO
standard seems to have been devised more or less in accordance with State Department
wishes. Once you've done that the US will happily (we fear, very happily) collect personal
information on the bearers all by itself - you don't have to do anything, and you never
know, they might even share some of it with you.
The biometric passport system the US intends to use simply seems to be an addition of
the necessary machine readable capabilities to the existing system. Passport applications,
including photograph, will still be accepted via mail, and the picture will then be encoded,
added to the database and put onto the chip that goes in the passport. As you may note,
a picture is in these terms a biometric, while a camera is a biometric reader, which they
are. But don't noise it around, or you'll screw the revenues of an awful lot of snake-oil
salesmen."
It's worth repeating that last sentence: As you may not, a picture is in these terms a biometric, while a camera is a biometric reader, which they are. But don't noise it around, or you'll screw the revenues of an awful lot of snake-oil salesmen.
Keep up the good work, John.
James Heald of FFII tells me:
"First indications are that the Irish presidency has secured political
approval for a new draft of the controversial software patents directive
in a meeting of the Council of Ministers today -- by 4 votes.
Belgium (5), Denmark (3), Italy (10), Spain (8) and Austria (4) refused
to support the new text.
Estonia (3) voted against.
That made 33 votes refusing to support the text -- a mere 4 votes short
of the 37 needed to block it.
The support of Germany, with 10 votes, was crucial.
The Irish were only able to get their proposal through with the support
of Germany, which had been previously been pressing for much tighter
restrictions.
It is believed that an amendment was found to satisfy German concerns,
but the details are still emerging."
So Germany voted for, in spite of previous speculation. And James later corrected this sligthly to say Estonia voted for and Spain actively voted against the proposal. ZDNet have a report on the vote.
Ian Brown at FIPR is asking for support on the issue of the EU software patents directive, which the Irish presidency of the EU is currently trying to push through. Incidentally, Bertie Ahern's interest in software patents, it seems may stem from a little (just a little) bit more than his 'pass as many EU laws as you can' stance to the presidency. I undertand that Microsoft are sponsoring the Irish presidency, not that I'm implying that such sponsorship is anything other than above board and purely public spirited, of course.
Ian writes:
The UK government position has been set for some time as generally pro the original Commission proposal. The best thing to do now if you are
concerned about the directive is:
(a) Sign the EuroLinux petition:
http://petition.eurolinux.org/index_html?LANG=en
(b) Write to your MP (see http://www.ffii.org.uk/council.html for a
guide on the best way to go about this).
(b) You can see how your MEP voted last September on the directive at
http://www.ffii.org.uk/uk_meps.html. If your MEP (listed at
http://www.europarl.org.uk/uk_meps/MembersMain.htm) voted along the
lines outlined by the FFII (as did Caroline Lucas and Jean Lambert
(Green), Jeffrey Titford, Graham Booth and Nigel Farage (UKIP), John
Purvis, Jacqueline Foster, Martin Callanan and Theresa Villiers
(Conservative)) write to support that decision and state that it will
have a strong influence in how you vote in the European elections on 10
June. If they voted against the FFII-supported amendments, write to
politely explain why you hope they will vote differently in the Second
Reading, and that you look forward to their response to help you to
choose who to support in the European elections. The small turnout in
these elections mean that you can make a big difference by doing this!
Many thanks,
Ian.
"First indications are that the Irish presidency has secured political
approval for a new draft of the controversial software patents directive
in a meeting of the Council of Ministers today -- by 4 votes.
Belgium (5), Denmark (3), Italy (10), Spain (8) and Austria (4) refused
to support the new text.
Estonia (3) voted against.
That made 33 votes refusing to support the text -- a mere 4 votes short
of the 37 needed to block it.
The support of Germany, with 10 votes, was crucial.
The Irish were only able to get their proposal through with the support
of Germany, which had been previously been pressing for much tighter
restrictions.
It is believed that an amendment was found to satisfy German concerns,
but the details are still emerging."
So Germany voted for, in spite of previous speculation. And James later corrected this sligthly to say Estonia voted for and Spain actively voted against the proposal. ZDNet have a report on the vote.
Ian Brown at FIPR is asking for support on the issue of the EU software patents directive, which the Irish presidency of the EU is currently trying to push through. Incidentally, Bertie Ahern's interest in software patents, it seems may stem from a little (just a little) bit more than his 'pass as many EU laws as you can' stance to the presidency. I undertand that Microsoft are sponsoring the Irish presidency, not that I'm implying that such sponsorship is anything other than above board and purely public spirited, of course.
Ian writes:
The UK government position has been set for some time as generally pro the original Commission proposal. The best thing to do now if you are
concerned about the directive is:
(a) Sign the EuroLinux petition:
http://petition.eurolinux.org/index_html?LANG=en
(b) Write to your MP (see http://www.ffii.org.uk/council.html for a
guide on the best way to go about this).
(b) You can see how your MEP voted last September on the directive at
http://www.ffii.org.uk/uk_meps.html. If your MEP (listed at
http://www.europarl.org.uk/uk_meps/MembersMain.htm) voted along the
lines outlined by the FFII (as did Caroline Lucas and Jean Lambert
(Green), Jeffrey Titford, Graham Booth and Nigel Farage (UKIP), John
Purvis, Jacqueline Foster, Martin Callanan and Theresa Villiers
(Conservative)) write to support that decision and state that it will
have a strong influence in how you vote in the European elections on 10
June. If they voted against the FFII-supported amendments, write to
politely explain why you hope they will vote differently in the Second
Reading, and that you look forward to their response to help you to
choose who to support in the European elections. The small turnout in
these elections mean that you can make a big difference by doing this!
Many thanks,
Ian.
Have to say I was pleased with Tony Blair's calm response to the purple flour attacks in the House of Commons at Prime Minister's questions yesterday, both at the time and afterwards.
His calmness is in deep contrast to that of many of his parliamentary colleagues and the media hysteria about lack of security.
I hope, though doubt, that calm reason will prevail. Hysteria leads to measures which create the illusion of security without the reality. And that can lead to poorer security. And whatever one thinks of politicians as a breed it is a relief that no one was hurt or seriously injured in the incident.
His calmness is in deep contrast to that of many of his parliamentary colleagues and the media hysteria about lack of security.
I hope, though doubt, that calm reason will prevail. Hysteria leads to measures which create the illusion of security without the reality. And that can lead to poorer security. And whatever one thinks of politicians as a breed it is a relief that no one was hurt or seriously injured in the incident.
Tuesday, May 18, 2004
Bruce Schneier author of (the terrific)"Beyond Fear: Thinking Sensibly About Security in an Uncertain World" writes an op ed at NewsDay.
"Unfortunately, the debate often gets mischaracterized as a question
about how much privacy we need to give up in order to be secure.
People ask: "Should we use this new surveillance technology to
catch terrorists and criminals, or should we favor privacy and ban its
use?"
This is the wrong question. We know that new technology gives law
enforcement new search techniques, and makes existing techniques
cheaper and easier. We know that we are all safer when the police
can use them...
...What we need are corresponding mechanisms to prevent abuse. This
is the proper question: "Should we allow law enforcement to use new
technology without any judicial oversight, or should we demand that
they be overseen and accountable?" And the Fourth Amendment
already provides for this in its requirement of a warrant...
...The key is independent judicial
oversight; the warrant process is itself a security measure protecting
us from abuse and making us more secure.
Much of the rhetoric on the "security" side of the debate cloaks one
of its real aims: increasing law enforcement powers by decreasing its
oversight and accountability. It's a very dangerous road to take, and
one that will make us all less secure. The more surveillance
technologies that require a warrant before use, the safer we all are."
Schneier should be compulsory reading especially for lawmakers and journalists. They'd be much better informed though I doubt they'd be any less prone to engaging in the usual rhetoric. Rhetoric after all sells papers and wins arguments.
"Unfortunately, the debate often gets mischaracterized as a question
about how much privacy we need to give up in order to be secure.
People ask: "Should we use this new surveillance technology to
catch terrorists and criminals, or should we favor privacy and ban its
use?"
This is the wrong question. We know that new technology gives law
enforcement new search techniques, and makes existing techniques
cheaper and easier. We know that we are all safer when the police
can use them...
...What we need are corresponding mechanisms to prevent abuse. This
is the proper question: "Should we allow law enforcement to use new
technology without any judicial oversight, or should we demand that
they be overseen and accountable?" And the Fourth Amendment
already provides for this in its requirement of a warrant...
...The key is independent judicial
oversight; the warrant process is itself a security measure protecting
us from abuse and making us more secure.
Much of the rhetoric on the "security" side of the debate cloaks one
of its real aims: increasing law enforcement powers by decreasing its
oversight and accountability. It's a very dangerous road to take, and
one that will make us all less secure. The more surveillance
technologies that require a warrant before use, the safer we all are."
Schneier should be compulsory reading especially for lawmakers and journalists. They'd be much better informed though I doubt they'd be any less prone to engaging in the usual rhetoric. Rhetoric after all sells papers and wins arguments.
Bruce Schneier author of (the terrific)"Beyond Fear: Thinking Sensibly About Security in an Uncertain World" writes an op ed at NewsDay.
"Unfortunately, the debate often gets mischaracterized as a question
about how much privacy we need to give up in order to be secure.
People ask: "Should we use this new surveillance technology to
catch terrorists and criminals, or should we favor privacy and ban its
use?"
This is the wrong question. We know that new technology gives law
enforcement new search techniques, and makes existing techniques
cheaper and easier. We know that we are all safer when the police
can use them...
...What we need are corresponding mechanisms to prevent abuse. This
is the proper question: "Should we allow law enforcement to use new
technology without any judicial oversight, or should we demand that
they be overseen and accountable?" And the Fourth Amendment
already provides for this in its requirement of a warrant...
...The key is independent judicial
oversight; the warrant process is itself a security measure protecting
us from abuse and making us more secure.
Much of the rhetoric on the "security" side of the debate cloaks one
of its real aims: increasing law enforcement powers by decreasing its
oversight and accountability. It's a very dangerous road to take, and
one that will make us all less secure. The more surveillance
technologies that require a warrant before use, the safer we all are."
Schneier should be compulsory reading especially for lawmakers and journalists. They'd be much better informed though I doubt they'd be any less prone to engaging in the usual rhetoric. Rhetoric after all sells papers and wins arguments.
"Unfortunately, the debate often gets mischaracterized as a question
about how much privacy we need to give up in order to be secure.
People ask: "Should we use this new surveillance technology to
catch terrorists and criminals, or should we favor privacy and ban its
use?"
This is the wrong question. We know that new technology gives law
enforcement new search techniques, and makes existing techniques
cheaper and easier. We know that we are all safer when the police
can use them...
...What we need are corresponding mechanisms to prevent abuse. This
is the proper question: "Should we allow law enforcement to use new
technology without any judicial oversight, or should we demand that
they be overseen and accountable?" And the Fourth Amendment
already provides for this in its requirement of a warrant...
...The key is independent judicial
oversight; the warrant process is itself a security measure protecting
us from abuse and making us more secure.
Much of the rhetoric on the "security" side of the debate cloaks one
of its real aims: increasing law enforcement powers by decreasing its
oversight and accountability. It's a very dangerous road to take, and
one that will make us all less secure. The more surveillance
technologies that require a warrant before use, the safer we all are."
Schneier should be compulsory reading especially for lawmakers and journalists. They'd be much better informed though I doubt they'd be any less prone to engaging in the usual rhetoric. Rhetoric after all sells papers and wins arguments.
The Guardian is reporting that now that the EU council of foreign ministers has rubber stamped the Commission agreement to hand over airline passenger data to the US, the EU parliament's European Court of Justice challenge to the deal is rendered invalid.
Surely that can't be right? The processes involved need a serious review if it is. I don't care whether you're one of Jerry Kang's 'market' or 'dignity' ideologists in the privacy debate, allowing the circus of ministers to nod through an agreement to bypass that kind of ECJ challenge on principle doesn't work for me.
How does it stack against Kang's questions?
a) Who gets the initial entitlement? Well, it's a get out of jail card for the airlines who were caught between large US fines for not sharing data for homeland security and large EU fines for breaching data protection rules. On ideologies it's a nod to the market and the war on terrorism. The individual gets relegated to the choice of not flying if they don't want personal data transferred.
b) How will the choices get made? How is it ensured that the decisionmaker is fortified to do it well/effectively? I don't see much fortification for the individual here. How, for example can someone correct errors that may occur and accumulate? How can an individual opt out? The only way I can see is as above - don't fly.
c) What are the societal overrides? What are the allowable contexts within which we can override the rights/market actions of individuals? How to pick/adjudicate/etc. The article says "dietary requirements that could reveal religion, race or health" will not be included in the data transfers. We don't have any further detailed information on the small print here. One important 'how to' process - the ECJ challenge - would appear to have been neutered?
d) How much supporting information infrastructure needed to enforce? Quite a lot from a technical perspective alone and this is rapidly evolving on both sides of the atlantic with no fly lists and CAPPS II, for example. There are lots of issues of substance related to the development and deployment of these infrastructures alone e.g the design, collection rules, access rules, maintainance, error correction, identification, authentication, restrictive purpose, function creep etc.
Prof Kang would like us to explore issues of substance on all four questions rather than getting distracted by unproductive ideology. As he says, the key thing is the "fortifying of the individual" i.e. can you say yes(or no)?
That's an off the top of the head application of the Kang framework, so don't look too closely for holes.
Privacy International have been pretty quick to respond by updating their comprehensive report on the subject. They are disgusted.
"This report outlines how the European Commission failed outright at protecting EU interests and upholding EU laws within the negotiations with the U.S. Government. As a result, the U.S. Government
managed to get the Commission to concede European privacy rights and burdening EU carriers, even while U.S. carriers and U.S. citizens are exempt from these rules..." The report goes on to say that
The US Dept for Homeland Security get access to data from EU airlines but does not require similar access to US airline databases
The US therefore gets to test CAPPS II with EU data. (The Commission "believe" that the data will be removed from CAPPS II when the tests are complete. The actual agreement with the US is silent on this point).
The Commission is contemplating a central EU database to make the transfer of this data to the US easier.
The Commission wants EU law changed to allow law enforcement access to airline passenger data.
The Commission want access to US airline passenger data but have not negotiated this yet (Currently there don't seem to be any grounds in US law to allow such transfers).
The Commission are supporting a global airline passenger surveillance system through the Internation Civil Aviation Organisation.
The report goes on to say that the case for collecting all this information has never been made and that it is neither necessary nor proportionate (especially the collection of information in the pretence that it is to combat terrorism, when it will also be used for other purposes).
It certainly paints the EU delegation as pretty poor negotiators at best or active conspirators in the dismantling of the EU's proud privacy-as-fundamental-right (or as Prof Kang would call them, 'dignity') principles at worst.
Surely that can't be right? The processes involved need a serious review if it is. I don't care whether you're one of Jerry Kang's 'market' or 'dignity' ideologists in the privacy debate, allowing the circus of ministers to nod through an agreement to bypass that kind of ECJ challenge on principle doesn't work for me.
How does it stack against Kang's questions?
a) Who gets the initial entitlement? Well, it's a get out of jail card for the airlines who were caught between large US fines for not sharing data for homeland security and large EU fines for breaching data protection rules. On ideologies it's a nod to the market and the war on terrorism. The individual gets relegated to the choice of not flying if they don't want personal data transferred.
b) How will the choices get made? How is it ensured that the decisionmaker is fortified to do it well/effectively? I don't see much fortification for the individual here. How, for example can someone correct errors that may occur and accumulate? How can an individual opt out? The only way I can see is as above - don't fly.
c) What are the societal overrides? What are the allowable contexts within which we can override the rights/market actions of individuals? How to pick/adjudicate/etc. The article says "dietary requirements that could reveal religion, race or health" will not be included in the data transfers. We don't have any further detailed information on the small print here. One important 'how to' process - the ECJ challenge - would appear to have been neutered?
d) How much supporting information infrastructure needed to enforce? Quite a lot from a technical perspective alone and this is rapidly evolving on both sides of the atlantic with no fly lists and CAPPS II, for example. There are lots of issues of substance related to the development and deployment of these infrastructures alone e.g the design, collection rules, access rules, maintainance, error correction, identification, authentication, restrictive purpose, function creep etc.
Prof Kang would like us to explore issues of substance on all four questions rather than getting distracted by unproductive ideology. As he says, the key thing is the "fortifying of the individual" i.e. can you say yes(or no)?
That's an off the top of the head application of the Kang framework, so don't look too closely for holes.
Privacy International have been pretty quick to respond by updating their comprehensive report on the subject. They are disgusted.
"This report outlines how the European Commission failed outright at protecting EU interests and upholding EU laws within the negotiations with the U.S. Government. As a result, the U.S. Government
managed to get the Commission to concede European privacy rights and burdening EU carriers, even while U.S. carriers and U.S. citizens are exempt from these rules..." The report goes on to say that
The US Dept for Homeland Security get access to data from EU airlines but does not require similar access to US airline databases
The US therefore gets to test CAPPS II with EU data. (The Commission "believe" that the data will be removed from CAPPS II when the tests are complete. The actual agreement with the US is silent on this point).
The Commission is contemplating a central EU database to make the transfer of this data to the US easier.
The Commission wants EU law changed to allow law enforcement access to airline passenger data.
The Commission want access to US airline passenger data but have not negotiated this yet (Currently there don't seem to be any grounds in US law to allow such transfers).
The Commission are supporting a global airline passenger surveillance system through the Internation Civil Aviation Organisation.
The report goes on to say that the case for collecting all this information has never been made and that it is neither necessary nor proportionate (especially the collection of information in the pretence that it is to combat terrorism, when it will also be used for other purposes).
It certainly paints the EU delegation as pretty poor negotiators at best or active conspirators in the dismantling of the EU's proud privacy-as-fundamental-right (or as Prof Kang would call them, 'dignity') principles at worst.
ILAW 2004 was on last week at the Berkman Center at Harvard. The usual suspects, Larry Lessig, Jonathan Zittrain, Charles Nesson, Yochai Benkler and William Fisher enjoyed themselves educating the latest cohort of delegates in the intricacies of internet law. Frank Field was there and reports on many of the sessions.
Donna, though, sees Jerry Kang's session as one of the higlights. She pegs him the Larry Lessig of privacy:
"UCLA law professor/Harvard law visiting professor Jerry Kang is the Larry Lessig of privacy, in that he was able very quickly
and powerfully to communicate that there are extremes in the debate that result largely from the culture-born clash between
"property talk" (U.S.-take on privacy) and "dignity talk" (Euro approach). He lifted the discussion out of the dreaded "tin foil
hat" arena -- that is, beyond "paranoid freaks v. reasonable people" nonsense that stops people from truly engaging with the
problem/issues at hand. He's one to learn from. (Check out Frank Field's comprehensive ILAW notes for a remarkably
detailed transcript of his talk.)"
Kang talked about the unproductive ideologies in the privacy debate and how to get round them.
"A clash of civilizations (america v europe)
america - market talk; privacy is a widget; let the market do it; exercise your freedom in the market; exchange for value; and in a good market, we get allocative efficiency - kind of a caricature, but this is a good short term mechanism
europe - dignity talk; privacy is a fundamental human right; we do not auction off babies; we let the law decide what it a fundamental human right.
Substance - turning to the substance suggests that the ultimate elements are the same.
at the core, they seem to be the same.
- Dignity talk says (consent is required) (apparatus to ensure that there is a process to protect consent)
- Market talks says (clear property rights needed/so who gets initial entitlement?/many possible results/these days, it’s largely in the commons)
there are good reasons to think that efficiency emerges when you give the entitlement to the individual – same result as dignity talk...
...Dignity talk hates the market approach because there’s too little control for individuals to exert; individuals have a hard time making a good bargain. Rather, the system is set up to fortify the individual’s position in these situations...
...Market approach says that the dignity approach is too stilted – there are situations where the balance of interests should go against privacy; the market achieves that balance more efficiently
But dignity talk leads to systems that explicitly generate exceptions to the dignity right within the supporting instutions created...
...So, it may be that we will all end up in the same place; and it may be that rather than arguing about which regime is “right” we should move on to the real, mechanical issues that are the same for both...
...What can we do to reframe this debate?
1) soft pedal the concern about market talk/dignity talk - unproductive
2) the substance is something we ought to be focusing on
a) who gets the “thing” - the initial entitlement
b) how will the choices get made, and how to ensure that the decisionmaker is fortified to do it well/effectively - this is where inalienability may emerge (can’t ask, can’t tell) - there are lots of intermediate forms of the way we might frame/constrain the kinds of exchanges that we will allow; ability to correct
c) what are the societal overrides; what is allowable contexts within which we can override the rights/market actions of individuals. How to pick/adjudicate/etc.
d) How much supporting information infrastructure needed to enforce - various flavors
That;s the claim – answer these four question, rather than talking to me about dignity or markets"
Donna, though, sees Jerry Kang's session as one of the higlights. She pegs him the Larry Lessig of privacy:
"UCLA law professor/Harvard law visiting professor Jerry Kang is the Larry Lessig of privacy, in that he was able very quickly
and powerfully to communicate that there are extremes in the debate that result largely from the culture-born clash between
"property talk" (U.S.-take on privacy) and "dignity talk" (Euro approach). He lifted the discussion out of the dreaded "tin foil
hat" arena -- that is, beyond "paranoid freaks v. reasonable people" nonsense that stops people from truly engaging with the
problem/issues at hand. He's one to learn from. (Check out Frank Field's comprehensive ILAW notes for a remarkably
detailed transcript of his talk.)"
Kang talked about the unproductive ideologies in the privacy debate and how to get round them.
"A clash of civilizations (america v europe)
america - market talk; privacy is a widget; let the market do it; exercise your freedom in the market; exchange for value; and in a good market, we get allocative efficiency - kind of a caricature, but this is a good short term mechanism
europe - dignity talk; privacy is a fundamental human right; we do not auction off babies; we let the law decide what it a fundamental human right.
Substance - turning to the substance suggests that the ultimate elements are the same.
at the core, they seem to be the same.
- Dignity talk says (consent is required) (apparatus to ensure that there is a process to protect consent)
- Market talks says (clear property rights needed/so who gets initial entitlement?/many possible results/these days, it’s largely in the commons)
there are good reasons to think that efficiency emerges when you give the entitlement to the individual – same result as dignity talk...
...Dignity talk hates the market approach because there’s too little control for individuals to exert; individuals have a hard time making a good bargain. Rather, the system is set up to fortify the individual’s position in these situations...
...Market approach says that the dignity approach is too stilted – there are situations where the balance of interests should go against privacy; the market achieves that balance more efficiently
But dignity talk leads to systems that explicitly generate exceptions to the dignity right within the supporting instutions created...
...So, it may be that we will all end up in the same place; and it may be that rather than arguing about which regime is “right” we should move on to the real, mechanical issues that are the same for both...
...What can we do to reframe this debate?
1) soft pedal the concern about market talk/dignity talk - unproductive
2) the substance is something we ought to be focusing on
a) who gets the “thing” - the initial entitlement
b) how will the choices get made, and how to ensure that the decisionmaker is fortified to do it well/effectively - this is where inalienability may emerge (can’t ask, can’t tell) - there are lots of intermediate forms of the way we might frame/constrain the kinds of exchanges that we will allow; ability to correct
c) what are the societal overrides; what is allowable contexts within which we can override the rights/market actions of individuals. How to pick/adjudicate/etc.
d) How much supporting information infrastructure needed to enforce - various flavors
That;s the claim – answer these four question, rather than talking to me about dignity or markets"
Monday, May 17, 2004
Bloggers have set up a defence fund for the professor from Tokyo University who was arrested last week for copyright infringements arising out of the use of the P2P file sharing software he created, Winny.
The Washington Post reports that the EU Commission has agreed to hand over airline passenger data to the US, even though they're being challenged through the courts by the EU parliament on the issue.
"Angry midwives defy order to inform on asylum seekers" says the Gaurdian. Good for them say I. More power to their elbows and I hope they seriously embarrass the UK government over this. Just another example of the insidious nature of the national ID card proposals.
Meanwhile, on the other side of the Atlantic, "A federal advisory committee says Congress should pass laws to protect the civil liberties of Americans when the government sifts through computer records and data files for information about terrorists.", according to the NYT.
Finally on ID cards for today, The Scotsman reports that a large consultancy firm that advised the UK government on the introduction of the ID card stands to make a lot of money from the government process of implementing odious system. Deloite is one of the remaining two bidders in deciding what company will be the government's main commercial adviser on the scheme.
Take advice from the company that wants sell you whatever snake oil you currently crave and then buy the snake oil from them and their buddies. Just good business as far as Deloite and other similar placed bidders are concerned and I don't blame them for exploiting the technology-will-solve-the-problem-even-if-you-don't-know-what-the-problem-is snake oil junkies in government. The fault lies squarely with the junkies and the rest of us, who frankly are getting the government we deserve, as we're letting them get away with it.
"Angry midwives defy order to inform on asylum seekers" says the Gaurdian. Good for them say I. More power to their elbows and I hope they seriously embarrass the UK government over this. Just another example of the insidious nature of the national ID card proposals.
Meanwhile, on the other side of the Atlantic, "A federal advisory committee says Congress should pass laws to protect the civil liberties of Americans when the government sifts through computer records and data files for information about terrorists.", according to the NYT.
Finally on ID cards for today, The Scotsman reports that a large consultancy firm that advised the UK government on the introduction of the ID card stands to make a lot of money from the government process of implementing odious system. Deloite is one of the remaining two bidders in deciding what company will be the government's main commercial adviser on the scheme.
Take advice from the company that wants sell you whatever snake oil you currently crave and then buy the snake oil from them and their buddies. Just good business as far as Deloite and other similar placed bidders are concerned and I don't blame them for exploiting the technology-will-solve-the-problem-even-if-you-don't-know-what-the-problem-is snake oil junkies in government. The fault lies squarely with the junkies and the rest of us, who frankly are getting the government we deserve, as we're letting them get away with it.
Groklaw is reporting that Germany are going to vote against the EU's software directive, which the Irish presidency has been trying to slip through.
FFII say:
NB. See FFII breaking news wiki for very latest information, at
http://kwiki.ffii.org/SwpatcninoEn
It looks as though there's a chance things may be moving in our favour.
The agenda for the Competitiveness Council meeting has been published,
with a full discussion now scheduled on the Software Patents directive;
furthermore the discussion is to be in public, ie with press and
visitors able to listen in with 11-way translation.
http://ue.eu.int/cms3_applications/Applications/newsRoom/loadbook.asp?BID=880&LANG=1&cmsId=364
We don't yet know whether there's any chance of it being webcast.
This a big step forward from the official EU media briefing, published
only on Friday morning, which said the directive was due to be
rubberstamped as an 'A-item' without discussion.
http://europa.eu.int/rapid/start/cgi/guestfr.ksh?p_action.gettxt=gt&doc=MEMO/04/114%7C0%7CRAPID&lg=EN&display=
The EU media briefing also tries very hard to play the play up the Irish
draft as a 'compromise' position.
But it's clear from this report from Paul Meller that by the time of the
press conference this afternoon journalists were obviously well enough
briefed that the EU spokesman had to confirm everything we'd said:
http://www.itworld.com/Man/2687/040514eupatents/
The national positions won't finally be clear until we hear what
actually gets said on Tuesday, but there are signs that there may be an
increasing number of ministers with concerns about the text, and a very
real possibility that a number of countries may seek a delay to give time to
* achieve more unity;
* investigate further the concerns about
- freedom of discussion
- interoperability
- scope of what is and what is not 'technical';
* produce a text more likely to pass the European Parliament.
On the other hand, as best we know, the UK and Ireland are still pushing
all-out for the Presidency text.
FFII say:
NB. See FFII breaking news wiki for very latest information, at
http://kwiki.ffii.org/SwpatcninoEn
It looks as though there's a chance things may be moving in our favour.
The agenda for the Competitiveness Council meeting has been published,
with a full discussion now scheduled on the Software Patents directive;
furthermore the discussion is to be in public, ie with press and
visitors able to listen in with 11-way translation.
http://ue.eu.int/cms3_applications/Applications/newsRoom/loadbook.asp?BID=880&LANG=1&cmsId=364
We don't yet know whether there's any chance of it being webcast.
This a big step forward from the official EU media briefing, published
only on Friday morning, which said the directive was due to be
rubberstamped as an 'A-item' without discussion.
http://europa.eu.int/rapid/start/cgi/guestfr.ksh?p_action.gettxt=gt&doc=MEMO/04/114%7C0%7CRAPID&lg=EN&display=
The EU media briefing also tries very hard to play the play up the Irish
draft as a 'compromise' position.
But it's clear from this report from Paul Meller that by the time of the
press conference this afternoon journalists were obviously well enough
briefed that the EU spokesman had to confirm everything we'd said:
http://www.itworld.com/Man/2687/040514eupatents/
The national positions won't finally be clear until we hear what
actually gets said on Tuesday, but there are signs that there may be an
increasing number of ministers with concerns about the text, and a very
real possibility that a number of countries may seek a delay to give time to
* achieve more unity;
* investigate further the concerns about
- freedom of discussion
- interoperability
- scope of what is and what is not 'technical';
* produce a text more likely to pass the European Parliament.
On the other hand, as best we know, the UK and Ireland are still pushing
all-out for the Presidency text.
From Ian Brown of FIPR:
Where next for copyright in the new Europe?
-------------------------------------------
13 June 2004
Room H 2032, Technical University Berlin, main building
Strasse des 17. Juni, Berlin
(building 16 http://www.tu-berlin.de/karten/)
More information and updates at:
http://wizards-of-os.org/index.php?id=921
Associated with Wizards of OS 3: The Future of the Digital Commons 10-12
June, Berlin: http://wizards-of-os.org/index.php?id=50&L=3
Copyright law has become one of the most important and controversial
drivers of the Information Society. The Internet has made every user a
publisher, but copyright rules governing their activities are often
determined by opaque international bodies that decide rules with little
public input.
Join us in Berlin to debate where copyright *should* be going to ensure
that authors, musicians, film-makers and the public will all benefit.
Engage with leading international thinkers from across Europe and the
United States. Meet colleagues who are working to make sure all members
of society benefit from copyright.
Attendance is free thanks to sponsorship from the Open Society
Institute, but please send an e-mail to workshop@fipr.org to let us know
you will be coming for planning purposes.
Programme
=========
* Influencing the international agenda
Copyright policy has been a strongly international area of law since the
Berne convention was agreed in 1886. More recently, the World Trade
Organisation Agreement on Trade-Related aspects of Intellectual Property
Rights (TRIPS) and the World Intellectual Property Organisation
Copyright and Performances and Phonograms Treaties have changed
copyright law around the world. The European Union has passed five
copyright-related Directives in the last twelve years. How can civil
society play a full role in policy development in these fora?
1100 Teresa Hackett, Foundation for Information Policy Research:
International copyright bodies including the European Union and World
Intellectual Property Organisation
1110 Robin Gross, IP Justice: Free Trade Agreement of the Americas
experiences
1120 Simon Davies, Privacy International: European Union privacy
legislation experiences
1130 Sjoera Nas, Bits of Freedom: European Union spam legislation
experiences
1140 Audience
* Updating the Copyright Directive
The 2001 Copyright Directive is the key EU law that sets out how
copyright works are protected in Europe. A report on its operation
should be published by the Commission in the next 18 months, and can
recommend changes to improve its effect.
Which parts of the Directive is it most critical to change to benefit
the public interest? Given the controversy they have caused, are the
articles related to exceptions and technological protection measures
most vital? Where does civil society see the most urgency for change?
1200 Ian Brown, FIPR: Experiences in Canada, Australia and Japan
1210 Mindaugas Kiskis, Law University of Lithuania: Collecting societies
1220 Jonathan Griffiths*, Queen Mary, University of London: Protecting
free speech
1230 David Mann, Royal National Institute of the Blind: Collaborative
arrangements with publishers
1240 Lee Bygrave*, Norwegian Research Centre for Computers and Law:
Ensuring privacy
1250 Audience
1320-1430 Lunch
* Implementing the IPR Enforcement Directive
The controversial Intellectual Property Rights Enforcement Directive was
pushed through the European Parliament with no time to debate sweeping
last-minute changes from the EU Member States. It now covers any
infringement of any kind of intellectual property right. How can its
effects on civil society be minimised around the EU? Which countries
have the most to lose?
1430 Andreas Dietl, European Digital Rights: Remaining problems with the
Intellectual Property Rights Enforcement Directive
1440 Mariusz Kondrat*, Poland Office of the Committee for European
Integration: New member state issues and pharmaceuticals
1450 Georg Jakob, University of Salzburg: Winners and losers from the
Intellectual Property Rights Enforcement Directive
1500 Slobodan Markovic, Netcentar, Serbia*
1510 Audience
* Copyright beyond the EU
Countries aiming for EU membership in the next decade such as Romania,
Bulgaria and Turkey are updating their copyright laws as part of an
overall effort to harmonise law with the EU. What can they learn from
the experiences of new EU members like Slovenia that have already
harmonised their laws in the process of joining the EU? Countries
further east such as Armenia have signed Partnership and Cooperation
Agreements with the EU that include obligations to update copyright law,
and even those without formal obligations are influenced by the approach
of the EU. What positive and negative effects is this having? How can
civil society in the EU and beyond best work together to influence the
direction of copyright legislation?
1530 Maja Bogataj, University of Llubljana: Implementation of EU
copyright legislation in Slovenia
1540 David Sanduhkchyan, InterNews Armenia: Right holder demands on ISPs
in Armenia
1550 Teo Celakoski*, Multimedia Institute, Croatia: Civil society
cooperation in the EU and beyond
1600 Tattu Mambetalieva, Global Internet Policy Initiative, Kyrgyzstan:
Copyright convergence in central Asia
1610 Sacha Belyaeva, InterNews Russia: Russian copyright law and the All
of MP3 service
1620 Veni Markovski, Internet Society Bulgaria: Software company
lobbying in Bulgaria
1630 Audience
* Do we need a Digital Rights Directive?
Copyright law is often driven by the relatively small groups of right
holders whom it particularly benefits. Civil society and the general
public have had limited success in having their concerns taken into
account in such law. Should we instead push directly for an EU Digital
Rights Directive that would tip the balance back in our favour? What
would such a Directive contain? Or can we use existing human rights,
consumer and competition legislation to change the operation of
copyright legislation toward civil society interests?
1650 Ross Anderson, Cambridge University and FIPR: Enforcing competition
under trusted computing
1700 William Fisher, Berkman Center for Internet and Society: Reshaping
artist compensation
1710 Wendy Seltzer, Electronic Frontier Foundation and Berkman Center
for Internet and Society: Fixing the Digital Millennium Copyright Act
1720 Ville Oksanen, Helsinki Institute for Information Technology and
Electronic Frontier Finland: Balancing consumer and copyright law
1730 Audience
1800 Close
* Awaiting confirmation
Where next for copyright in the new Europe?
-------------------------------------------
13 June 2004
Room H 2032, Technical University Berlin, main building
Strasse des 17. Juni, Berlin
(building 16 http://www.tu-berlin.de/karten/)
More information and updates at:
http://wizards-of-os.org/index.php?id=921
Associated with Wizards of OS 3: The Future of the Digital Commons 10-12
June, Berlin: http://wizards-of-os.org/index.php?id=50&L=3
Copyright law has become one of the most important and controversial
drivers of the Information Society. The Internet has made every user a
publisher, but copyright rules governing their activities are often
determined by opaque international bodies that decide rules with little
public input.
Join us in Berlin to debate where copyright *should* be going to ensure
that authors, musicians, film-makers and the public will all benefit.
Engage with leading international thinkers from across Europe and the
United States. Meet colleagues who are working to make sure all members
of society benefit from copyright.
Attendance is free thanks to sponsorship from the Open Society
Institute, but please send an e-mail to workshop@fipr.org to let us know
you will be coming for planning purposes.
Programme
=========
* Influencing the international agenda
Copyright policy has been a strongly international area of law since the
Berne convention was agreed in 1886. More recently, the World Trade
Organisation Agreement on Trade-Related aspects of Intellectual Property
Rights (TRIPS) and the World Intellectual Property Organisation
Copyright and Performances and Phonograms Treaties have changed
copyright law around the world. The European Union has passed five
copyright-related Directives in the last twelve years. How can civil
society play a full role in policy development in these fora?
1100 Teresa Hackett, Foundation for Information Policy Research:
International copyright bodies including the European Union and World
Intellectual Property Organisation
1110 Robin Gross, IP Justice: Free Trade Agreement of the Americas
experiences
1120 Simon Davies, Privacy International: European Union privacy
legislation experiences
1130 Sjoera Nas, Bits of Freedom: European Union spam legislation
experiences
1140 Audience
* Updating the Copyright Directive
The 2001 Copyright Directive is the key EU law that sets out how
copyright works are protected in Europe. A report on its operation
should be published by the Commission in the next 18 months, and can
recommend changes to improve its effect.
Which parts of the Directive is it most critical to change to benefit
the public interest? Given the controversy they have caused, are the
articles related to exceptions and technological protection measures
most vital? Where does civil society see the most urgency for change?
1200 Ian Brown, FIPR: Experiences in Canada, Australia and Japan
1210 Mindaugas Kiskis, Law University of Lithuania: Collecting societies
1220 Jonathan Griffiths*, Queen Mary, University of London: Protecting
free speech
1230 David Mann, Royal National Institute of the Blind: Collaborative
arrangements with publishers
1240 Lee Bygrave*, Norwegian Research Centre for Computers and Law:
Ensuring privacy
1250 Audience
1320-1430 Lunch
* Implementing the IPR Enforcement Directive
The controversial Intellectual Property Rights Enforcement Directive was
pushed through the European Parliament with no time to debate sweeping
last-minute changes from the EU Member States. It now covers any
infringement of any kind of intellectual property right. How can its
effects on civil society be minimised around the EU? Which countries
have the most to lose?
1430 Andreas Dietl, European Digital Rights: Remaining problems with the
Intellectual Property Rights Enforcement Directive
1440 Mariusz Kondrat*, Poland Office of the Committee for European
Integration: New member state issues and pharmaceuticals
1450 Georg Jakob, University of Salzburg: Winners and losers from the
Intellectual Property Rights Enforcement Directive
1500 Slobodan Markovic, Netcentar, Serbia*
1510 Audience
* Copyright beyond the EU
Countries aiming for EU membership in the next decade such as Romania,
Bulgaria and Turkey are updating their copyright laws as part of an
overall effort to harmonise law with the EU. What can they learn from
the experiences of new EU members like Slovenia that have already
harmonised their laws in the process of joining the EU? Countries
further east such as Armenia have signed Partnership and Cooperation
Agreements with the EU that include obligations to update copyright law,
and even those without formal obligations are influenced by the approach
of the EU. What positive and negative effects is this having? How can
civil society in the EU and beyond best work together to influence the
direction of copyright legislation?
1530 Maja Bogataj, University of Llubljana: Implementation of EU
copyright legislation in Slovenia
1540 David Sanduhkchyan, InterNews Armenia: Right holder demands on ISPs
in Armenia
1550 Teo Celakoski*, Multimedia Institute, Croatia: Civil society
cooperation in the EU and beyond
1600 Tattu Mambetalieva, Global Internet Policy Initiative, Kyrgyzstan:
Copyright convergence in central Asia
1610 Sacha Belyaeva, InterNews Russia: Russian copyright law and the All
of MP3 service
1620 Veni Markovski, Internet Society Bulgaria: Software company
lobbying in Bulgaria
1630 Audience
* Do we need a Digital Rights Directive?
Copyright law is often driven by the relatively small groups of right
holders whom it particularly benefits. Civil society and the general
public have had limited success in having their concerns taken into
account in such law. Should we instead push directly for an EU Digital
Rights Directive that would tip the balance back in our favour? What
would such a Directive contain? Or can we use existing human rights,
consumer and competition legislation to change the operation of
copyright legislation toward civil society interests?
1650 Ross Anderson, Cambridge University and FIPR: Enforcing competition
under trusted computing
1700 William Fisher, Berkman Center for Internet and Society: Reshaping
artist compensation
1710 Wendy Seltzer, Electronic Frontier Foundation and Berkman Center
for Internet and Society: Fixing the Digital Millennium Copyright Act
1720 Ville Oksanen, Helsinki Institute for Information Technology and
Electronic Frontier Finland: Balancing consumer and copyright law
1730 Audience
1800 Close
* Awaiting confirmation
Subscribe to:
Posts (Atom)