The IEEE Consumer Electronics have made a transcript of my keynote address to their international conference available on their website. The talk was entitled "Harry Potter, Armoured Car DRM and the Lawyers" (or linked as "IEEE talk.doc (92.0 kBytes" on the website). It covered some of the possible implications for the consumer electronics industry of developments in intellectual property law and digital technologies. The introduction gives a flavour:
"About 5 years ago I read about the music industry suing to get Diamond Multimedia’s Rio MP3 player outlawed. I was sufficiently irritated that somebody should want to kill off a neat bit of technology that I decided to look into the situation a bit more. In the end the Rio survived the assault but only on a legal technicality in the appeal court.
So the Rio case triggered my descent into a surreal nether land of lawyers and strange ideas. And in this strange lawyer-land one of the strangest outposts is an area with the eye-glazing title of intellectual property. Intellectual property covers things like copyrights and patents.
Lawyers just don’t see the world like the rest of us. A copyright lawyer thinks nothing of suing somebody for infringing the copyright in silence. Seriously. In 2002 Mike Batt, a music producer, found himself threatened with legal action by the estate of the late John Cage, for infringing the copyright in Cage’s composition 4 minutes and 33 seconds of silence. If you haven’t heard of John Cage or his silence, the Musical Score reads on an otherwise blank page:
“4 minutes 33 seconds silence for any instrument or combination of instruments”
Batt had included one minutes silence in a CD by a music group called the Planets.
Leaving aside the artistic merit or otherwise of the Cage piece and the sense of someone who would fork out the £4.50 or so that the score retails at, as Batt’s mother asked him - what part of the silence did they claim you were infringing?
Sounds funny except that the case involved substantial lawyers’ fees and eventually got settled out of court for a 5 figure sum. Possibly £10s of thousands.
Following the settlement Batt decided to register the copyrights in every period of silence between 1 second and 10 minutes, except for 4m 33s. Batt now figures he’s got Cage’s estate caged in - he’s threatened to sue anyone performing Cage’s work who overruns or underruns the 4m 33s..."
and so it continues with stories of dangerous monks, people trying to cash in on J.K Rowling's success and strange anomalies created by the state of the law and the current stage of evolution of the technologies.
Monday, December 06, 2004
The Yes Men, The BBC and Bhopal
The Yes Men managed to kid the BBC on Friday into believing they were representatives of Dow Chemicals and announced, from a Paris studio, that the company would be ploughing $12 billion into cleaning up the toxic waste and compensating victims of the Bhopal disaster in India 20 years ago. The Yes Men fake
"spokesperson appears live on the BBC World Service in front of the Eiffel Tower. He is ecstatic to make the announcement: Dow will accept full responsibility for the Bhopal disaster, and has a $12 billion dollar plan to compensate the victims and remediate the site. They will also push for the extradition to India of Warren Anderson, former Union Carbide CEO, who fled India following his arrest 20 years ago on multiple homicide charges.
When it's over, the studio technician is happy about what she has heard. "What a nice thing to announce," she says.
"I wouldn't work for Dow if I didn't believe in it," replies Andy matter-of-factly.
We expect the story to be retracted immediately, but Dow takes two hours to notice that alas and alack, it's done the right thing. The full interview therefore runs twice, and for two hours the story is the top item on news.google.com. After Dow notes emphatically that it is not in fact doing the right thing, the retraction remains the top Google story for the rest of the day.
Back at Andy's apartment, we help Dow express itself better by mailing out a more formal retraction: "Dow will NOT commit ANY funds to compensate and treat 120,000 Bhopal residents who require lifelong care.... Dow will NOT remediate (clean up) the Bhopal plant site.... Dow's sole and unique responsibility is to its shareholders, and Dow CANNOT do anything that goes against its bottom line unless forced to by law." For a while, this—as reprinted in something called "Men's News Daily"—becomes the top story on news.google.com.
"Whatever be the circumstances under which the news was aired, we will get $12 billion from Dow sooner than later," one Bhopali activist is quoted as saying. But the "false hope" question does come up in some articles. Much as we try to convince ourselves it was worth it, we cannot get rid of the nagging doubt. Did we deeply upset many Bhopalis? If so, we want to apologize. We were trying to show that another world is possible....
Throughout the day, we are deluged with email, almost all of it positive. Later, the BBC calls again: they want us back at the studio. Yeah, right! No, really—they want us on for another show, to talk about what has happened. Against our better judgment we go—and arrive to find four smiling staffers. "Where are the cops?" Andy asks, and the staffers actually laugh.
Another interview on Channel 4, and the day is finally over. Now all we can do is wait to see how it all pans out. Will our fondest hopes be met—will Dow be forced to concede? Or will the people of Bhopal have to wait twenty more years?
Visit Bhopal.net and help them keep the pressure on Dow."
Clever but hopefully, as they note, they did not create any false hope.
"spokesperson appears live on the BBC World Service in front of the Eiffel Tower. He is ecstatic to make the announcement: Dow will accept full responsibility for the Bhopal disaster, and has a $12 billion dollar plan to compensate the victims and remediate the site. They will also push for the extradition to India of Warren Anderson, former Union Carbide CEO, who fled India following his arrest 20 years ago on multiple homicide charges.
When it's over, the studio technician is happy about what she has heard. "What a nice thing to announce," she says.
"I wouldn't work for Dow if I didn't believe in it," replies Andy matter-of-factly.
We expect the story to be retracted immediately, but Dow takes two hours to notice that alas and alack, it's done the right thing. The full interview therefore runs twice, and for two hours the story is the top item on news.google.com. After Dow notes emphatically that it is not in fact doing the right thing, the retraction remains the top Google story for the rest of the day.
Back at Andy's apartment, we help Dow express itself better by mailing out a more formal retraction: "Dow will NOT commit ANY funds to compensate and treat 120,000 Bhopal residents who require lifelong care.... Dow will NOT remediate (clean up) the Bhopal plant site.... Dow's sole and unique responsibility is to its shareholders, and Dow CANNOT do anything that goes against its bottom line unless forced to by law." For a while, this—as reprinted in something called "Men's News Daily"—becomes the top story on news.google.com.
"Whatever be the circumstances under which the news was aired, we will get $12 billion from Dow sooner than later," one Bhopali activist is quoted as saying. But the "false hope" question does come up in some articles. Much as we try to convince ourselves it was worth it, we cannot get rid of the nagging doubt. Did we deeply upset many Bhopalis? If so, we want to apologize. We were trying to show that another world is possible....
Throughout the day, we are deluged with email, almost all of it positive. Later, the BBC calls again: they want us back at the studio. Yeah, right! No, really—they want us on for another show, to talk about what has happened. Against our better judgment we go—and arrive to find four smiling staffers. "Where are the cops?" Andy asks, and the staffers actually laugh.
Another interview on Channel 4, and the day is finally over. Now all we can do is wait to see how it all pans out. Will our fondest hopes be met—will Dow be forced to concede? Or will the people of Bhopal have to wait twenty more years?
Visit Bhopal.net and help them keep the pressure on Dow."
Clever but hopefully, as they note, they did not create any false hope.
Sunday, December 05, 2004
Software patents, the WMD of IP?
Donna Wentworth, at Copyfight, points to some interesting perspectives on software patents.
Professor Karl-Friedrich Lenz also has some advice for advocates opposed to intellectual property expansion, regarding being on the losing side in respect of the usual public rhethoric:
"Those working for the inflation of intellectual monopoly rights are using colorful rhetoric means. For example words as "pirate", "stealing", "Boston strangler", "dagger in the heart of the DMCA" etc.
So how can the other side fight back? I have a few suggestions.
1. "Enemy of Freedom"
Intellectual monopoly (IM) rights like patents, copyrights, trademarks all give the owner an exclusive right to use. This means everyone else's freedom is reduced. This in turn means that those working for stronger IM are opposed to everyone else's freedom, so they are enemies of freedom.
2. "Great Mastermind of Greed"
The point of this rhetoric figure is the alliteration. This might be used as a honorary title for those individuals who are working most efficiently for the enemies of freedom. Maybe someone could sponsor a yearly "mastermind award".
Why greed? Well, of course, people who create great ideas should be rewarded. Authors, musicians, inventors should get paid. But in unlimited quantity? And with most of the profit directed to publishers? The word "greed" may be defined as "excessive or reprehensible acquisitiveness". While the opinions about "reprehensible" might differ, there sure is much excessive acquisition based on IM rights.
3. "Slave Trader"
This is the counterpunch to "pirate". "Piracy" in the original meaning of the word is "an act of robbery on the high seas". This is a serious and violent crime. Copyright or patent violations are illegal, but they are obviously much less serious than real piracy. There is a difference between a kid trading illegal files and a bank robber. So this rhetorical figure serves the purpose to fool the listener..."
and so on. Worth a read.
Professor Karl-Friedrich Lenz also has some advice for advocates opposed to intellectual property expansion, regarding being on the losing side in respect of the usual public rhethoric:
"Those working for the inflation of intellectual monopoly rights are using colorful rhetoric means. For example words as "pirate", "stealing", "Boston strangler", "dagger in the heart of the DMCA" etc.
So how can the other side fight back? I have a few suggestions.
1. "Enemy of Freedom"
Intellectual monopoly (IM) rights like patents, copyrights, trademarks all give the owner an exclusive right to use. This means everyone else's freedom is reduced. This in turn means that those working for stronger IM are opposed to everyone else's freedom, so they are enemies of freedom.
2. "Great Mastermind of Greed"
The point of this rhetoric figure is the alliteration. This might be used as a honorary title for those individuals who are working most efficiently for the enemies of freedom. Maybe someone could sponsor a yearly "mastermind award".
Why greed? Well, of course, people who create great ideas should be rewarded. Authors, musicians, inventors should get paid. But in unlimited quantity? And with most of the profit directed to publishers? The word "greed" may be defined as "excessive or reprehensible acquisitiveness". While the opinions about "reprehensible" might differ, there sure is much excessive acquisition based on IM rights.
3. "Slave Trader"
This is the counterpunch to "pirate". "Piracy" in the original meaning of the word is "an act of robbery on the high seas". This is a serious and violent crime. Copyright or patent violations are illegal, but they are obviously much less serious than real piracy. There is a difference between a kid trading illegal files and a bank robber. So this rhetorical figure serves the purpose to fool the listener..."
and so on. Worth a read.
Friday, December 03, 2004
GTA - Global Trustmark Alliance
Richard Swetenham at QuickLinks reports on the creation of a new global umbrella group of trustmark organisations, called the Global Trustmark Alliance, GTA. From the GTA website, the GTA has been
"created to encourage cross border e-commerce by fostering consumer trust, encouraging good online business practices, and discouraging the development of burdensome disparate governmental regulation.
Members are local trustmark organizations worldwide and other organizations supporting the development of online trustmarks. Once fully operational, participating businesses in these member trustmark organizations will agree to abide by an international code of conduct for cross-border transactions, to participate in out-of-court dispute resolution procedures based on code standards, and to display an international seal on their website signaling their participation in the GTA"
"created to encourage cross border e-commerce by fostering consumer trust, encouraging good online business practices, and discouraging the development of burdensome disparate governmental regulation.
Members are local trustmark organizations worldwide and other organizations supporting the development of online trustmarks. Once fully operational, participating businesses in these member trustmark organizations will agree to abide by an international code of conduct for cross-border transactions, to participate in out-of-court dispute resolution procedures based on code standards, and to display an international seal on their website signaling their participation in the GTA"
Ed Felten calls for EULA doghouse
Having looked through Ben Edelman's assessment of Claria's (formerly Gator) end user licence agreement (EULA), entitled Gator's EULA Gone Bad, Edward Felten has some thoughts:
"To the extent that the EULA gives Gator legal leverage over its users, that leverage could be used to deter criticism of Gator, and not just lawsuits. Experience has shown that some companies, especially ones with dodgy products, do use what legal leverage they have against their critics. If I planned to criticize Gator in detail, I would worry about this issue.
There are two solutions to this overEULAfication problem. A court could throw out this kind of egregious EULA, or at least narrow its scope. Alternatively, users could raise the price of this behavior by refusing to use overEULAfied products. Realistically, this will only happen if users are given the tools to do so.
The best kind of tool for this purpose is information. I would love to see a "EULA doghouse" site that listed products with excessive EULAs, or that rated products by the content of their EULAs. At the very least, EULA evaluation could become standard procedure for people writing reviews of software products. Unfortunately, there hasn't been much progress on this front."
He suggested the EULA doghouse in more detail last week but I missed it at the time.
"To the extent that the EULA gives Gator legal leverage over its users, that leverage could be used to deter criticism of Gator, and not just lawsuits. Experience has shown that some companies, especially ones with dodgy products, do use what legal leverage they have against their critics. If I planned to criticize Gator in detail, I would worry about this issue.
There are two solutions to this overEULAfication problem. A court could throw out this kind of egregious EULA, or at least narrow its scope. Alternatively, users could raise the price of this behavior by refusing to use overEULAfied products. Realistically, this will only happen if users are given the tools to do so.
The best kind of tool for this purpose is information. I would love to see a "EULA doghouse" site that listed products with excessive EULAs, or that rated products by the content of their EULAs. At the very least, EULA evaluation could become standard procedure for people writing reviews of software products. Unfortunately, there hasn't been much progress on this front."
He suggested the EULA doghouse in more detail last week but I missed it at the time.
The Economics of Privacy
I've just re-discovered Alessandro Acquisti's page of links to resources on the economics of privacy. Excellent.
Kahle to appeal
Brewster Kahle has confirmed he will appeal the recent dismissal of his challenge to the Copyright Term Extension Act of 1998.
Who owns the knowledge economy?
Richard Clayton at FIPR tells me that an interesting website, The Corner House has just published a briefing paper from Peter Drahos and John Braitwaite,
Who Owns the Knowledge Economy?
Political Organising Behind TRIPS.
This is a substantial edited extract from their excellent book, Information Feudalism, published by Earthscan in 2002 and is well worth a read if you're interested in the international power dynamics underlying developments in intellectual property law. The Corner House summary of the paper follows:
"TRIPS -- the World Trade Organisation's agreement on Trade-Related Aspects of Intellectual Property Rights -- was the most important agreement on intellectual property of the 20th century. It revolutionised the way that property rights in information were defined and enforced. TRIPS effectively globalises the set of intellectual property principles it contains, because most countries are members of, or are seeking membership of, the World Trade Organisation that administers TRIPS.
When TRIPS was signed by more than one hundred government ministers in April 1994, the United States, the European Community and Japan had the world's dominant software, pharmaceutical, chemical and entertainment industries between them and the world's most important trade marks. The rest of the world had nothing much to gain by agreeing to terms of trade for intellectual property that offered these countries so much protection. Why did states sign up to TRIPS?
They did so because of a failure of democratic processes, both nationally and internationally. This enabled a small group of men within the United States to capture the US trade-agenda-setting process; then, in partnership with European and Japanese multinationals, to draft intellectual property principles that became the blueprint for TRIPS. The resistance of other countries was crushed through US trade power.
This briefing paper explores the background to TRIPS and the corporate political organising that orchestrated and paved the way for the agreement."
Who Owns the Knowledge Economy?
Political Organising Behind TRIPS.
This is a substantial edited extract from their excellent book, Information Feudalism, published by Earthscan in 2002 and is well worth a read if you're interested in the international power dynamics underlying developments in intellectual property law. The Corner House summary of the paper follows:
"TRIPS -- the World Trade Organisation's agreement on Trade-Related Aspects of Intellectual Property Rights -- was the most important agreement on intellectual property of the 20th century. It revolutionised the way that property rights in information were defined and enforced. TRIPS effectively globalises the set of intellectual property principles it contains, because most countries are members of, or are seeking membership of, the World Trade Organisation that administers TRIPS.
When TRIPS was signed by more than one hundred government ministers in April 1994, the United States, the European Community and Japan had the world's dominant software, pharmaceutical, chemical and entertainment industries between them and the world's most important trade marks. The rest of the world had nothing much to gain by agreeing to terms of trade for intellectual property that offered these countries so much protection. Why did states sign up to TRIPS?
They did so because of a failure of democratic processes, both nationally and internationally. This enabled a small group of men within the United States to capture the US trade-agenda-setting process; then, in partnership with European and Japanese multinationals, to draft intellectual property principles that became the blueprint for TRIPS. The resistance of other countries was crushed through US trade power.
This briefing paper explores the background to TRIPS and the corporate political organising that orchestrated and paved the way for the agreement."
Fingerprint system crash
It seems that the UK's national automated fingerprint identification system (Nafis) crashed on Wednesday, the 24th of November and was shut down until this Monday, 29th November. It's a coincidence that it happened in ths same week that the benefits system crashed and must have been a major pain particularly for the scenes of crimes officers who need it for their day to day work, as well as numerous others in the law enforcement chain.
Whilst sympathising with the folks who needed the system to work, you can't help but think of the irony that almost exactly a month earlier, on Monday, the 25th of October, the EU's Council of justice and home affairs ministers were deciding, at a meeting in Luxembourg, to force though fingerprints on passports for all EU citizens. The UK system, according to the Independent article, has 4 million entries and operated effectively trouble free until the recent crash. What happens when a system with entries relating to a population of 450 million collapses?
Whilst sympathising with the folks who needed the system to work, you can't help but think of the irony that almost exactly a month earlier, on Monday, the 25th of October, the EU's Council of justice and home affairs ministers were deciding, at a meeting in Luxembourg, to force though fingerprints on passports for all EU citizens. The UK system, according to the Independent article, has 4 million entries and operated effectively trouble free until the recent crash. What happens when a system with entries relating to a population of 450 million collapses?
Thursday, December 02, 2004
Firstly thanks to Yiango Yiangoullis for prompting me to enable an RSS feed. I know this blog is in need of a major overall to make it more user friendly. I'm sorry I have not had the time to do this yet but as an interim measure I've enabled Blogger's Atom site feed. The site feed link is on the left hand side of the page - scroll down and you'll find it at the bottom of my list of links. (I know - a red button would be easier to find...)
Secondly the latest edition of EDRI-gram is essential reading. It covers a range of really important stories from the shenanigans about rushing through biometrics (fingerprints and digital photographs) on EU passports through to a ISP in Belgium being ordered by a court to cut off P2P users.
Andreas Dietl, EDRI EU Affairs Director, covers the politics of the fingerprints in passports and hopefully he won't mind if I quote that section in full:
"1. Rush vote European Parliament on biometrics ============================================================
It is likely that the Council of European Justice and Home Affairs ministers will adopt a regulation tomorrow, on 3 December 2004, to fingerprint all EU citizens and residents, to take digital photographs of their faces and to store these data in a gigantic database of 450 million EU citizens. This will be the last step of a procedure that has exploited the democratic deficit of the European Union to an unheard extreme.
Today the European Parliament adopted the proposal but introduced a large number of limitations. MEPs voted to clearly limit the kinds of information to be stored on the passports, they voted against the storage of the data in a central database and in favour of giving Data Protection Authorities oversight over the whole process. But it is unlikely that the Council will take any of these amendments into consideration. Under the European Union's consultation procedure the Council can globally reject all of the Parliament's amendments. Though it is mandatory to at least look at the parliamentary suggestions, it will be almost impossible to do so in this case, since the Council plans to adopt its own plan tomorrow.
Members of the European Parliament were deeply angered by the Council's sudden and belated change of the draft that the Parliament had to vote on. On 25 October 2004, while the Parliament's LIBE (Civil Liberties, Justice and Home Affairs) Committee was voting on its report on the biometric issues, the EU's Justice and Home Affairs ministers met behind closed doors in Luxembourg. They decided to considerably change the document that LIBE was just voting on: Fingerprints were introduced as a second obligatory biometric identifier, and the data were to be stored in a central database. The draft Regulation adopted by the Council was transmitted to the Parliament only a month later, on 26 November 2004.
The Council then black-mailed the Parliament's Conference of Presidents, the body taking decisions on the plenary agenda, to behave as if the proposal had not undergone any significant changes and to leave it on the agenda of the plenary session of 1 and 2 December. If the Presidents had refused, the Council threatened to delay the introduction of the co-decision procedure for immigration and asylum issues. In stead of giving parliament this important power on 1 January, it was to be delayed to 1 April 2005. And if Parliament had decided to refer the new proposal back to the LIBE committee, the Council announced it would just completely ignore Parliament, under some obscure procedure.
More than seventy civil society organisations from the EU and abroad, nine national or regional Data Protection Commissioners and more than two hundred concerned citizens have signed an open letter by Privacy International, Statewatch and European Digital Rights opposing this proposal. It seems, however, quite unlikely that the Justice and Home Affairs Ministers of the European Union will take the declared will of the EU Parliament or of Civil Society into account when introducing the obligation to fingerprint all their citizens and to store their data in a central database.
PI, Statewatch and EDRI Open Letter (30.11.2004) http://www.edri.org/campaigns/biometrics/0411
EU governments blackmail European Parliament into quick adoption of its report on biometric passports (27.11.2004) http://www.statewatch.org/news/2004/nov/12biometric-passports-blackmail.htm
Council Draft regulation on biometric passports (23.11.04) http://www.statewatch.org/news/2004/nov/biometric-proposal.pdf
Parliament report on the Commission proposal for a Council regulation on standards for security features and biometrics in EU citizen's passports, including voting list and all amendments (25.11.2004) http://www.edri.org/files/BioPass_AllAmend_VoteList.pdf
Provisional agenda for the meeting of the JHA Council (2-3.12.2004) http://www.eu2004.nl/default.asp?CMS_TCP=tcpAsset&id=1FA5E817CB12484F986BEE41DBF7B5A9X1X56197X36
JHA Council press conference video stream (available after 2 December, 20:00, for one week) http://europa.eu.int/comm/ebs/bottom_schedule.cfm?jour=5&semaine=49&annee=2004#s37732
(Contribution by Andreas Dietl, EDRI EU Affairs Director)"
The Council of Ministers need to read the relevant sections of Ross Anderson's book and Bruce Schneier's too. Or perhaps just giving them an opportunity to sit down without any advisers and simply talk to Ross and Bruce about the differences between the realities and the illusion of security would be a first step?
Secondly the latest edition of EDRI-gram is essential reading. It covers a range of really important stories from the shenanigans about rushing through biometrics (fingerprints and digital photographs) on EU passports through to a ISP in Belgium being ordered by a court to cut off P2P users.
Andreas Dietl, EDRI EU Affairs Director, covers the politics of the fingerprints in passports and hopefully he won't mind if I quote that section in full:
"1. Rush vote European Parliament on biometrics ============================================================
It is likely that the Council of European Justice and Home Affairs ministers will adopt a regulation tomorrow, on 3 December 2004, to fingerprint all EU citizens and residents, to take digital photographs of their faces and to store these data in a gigantic database of 450 million EU citizens. This will be the last step of a procedure that has exploited the democratic deficit of the European Union to an unheard extreme.
Today the European Parliament adopted the proposal but introduced a large number of limitations. MEPs voted to clearly limit the kinds of information to be stored on the passports, they voted against the storage of the data in a central database and in favour of giving Data Protection Authorities oversight over the whole process. But it is unlikely that the Council will take any of these amendments into consideration. Under the European Union's consultation procedure the Council can globally reject all of the Parliament's amendments. Though it is mandatory to at least look at the parliamentary suggestions, it will be almost impossible to do so in this case, since the Council plans to adopt its own plan tomorrow.
Members of the European Parliament were deeply angered by the Council's sudden and belated change of the draft that the Parliament had to vote on. On 25 October 2004, while the Parliament's LIBE (Civil Liberties, Justice and Home Affairs) Committee was voting on its report on the biometric issues, the EU's Justice and Home Affairs ministers met behind closed doors in Luxembourg. They decided to considerably change the document that LIBE was just voting on: Fingerprints were introduced as a second obligatory biometric identifier, and the data were to be stored in a central database. The draft Regulation adopted by the Council was transmitted to the Parliament only a month later, on 26 November 2004.
The Council then black-mailed the Parliament's Conference of Presidents, the body taking decisions on the plenary agenda, to behave as if the proposal had not undergone any significant changes and to leave it on the agenda of the plenary session of 1 and 2 December. If the Presidents had refused, the Council threatened to delay the introduction of the co-decision procedure for immigration and asylum issues. In stead of giving parliament this important power on 1 January, it was to be delayed to 1 April 2005. And if Parliament had decided to refer the new proposal back to the LIBE committee, the Council announced it would just completely ignore Parliament, under some obscure procedure.
More than seventy civil society organisations from the EU and abroad, nine national or regional Data Protection Commissioners and more than two hundred concerned citizens have signed an open letter by Privacy International, Statewatch and European Digital Rights opposing this proposal. It seems, however, quite unlikely that the Justice and Home Affairs Ministers of the European Union will take the declared will of the EU Parliament or of Civil Society into account when introducing the obligation to fingerprint all their citizens and to store their data in a central database.
PI, Statewatch and EDRI Open Letter (30.11.2004) http://www.edri.org/campaigns/biometrics/0411
EU governments blackmail European Parliament into quick adoption of its report on biometric passports (27.11.2004) http://www.statewatch.org/news/2004/nov/12biometric-passports-blackmail.htm
Council Draft regulation on biometric passports (23.11.04) http://www.statewatch.org/news/2004/nov/biometric-proposal.pdf
Parliament report on the Commission proposal for a Council regulation on standards for security features and biometrics in EU citizen's passports, including voting list and all amendments (25.11.2004) http://www.edri.org/files/BioPass_AllAmend_VoteList.pdf
Provisional agenda for the meeting of the JHA Council (2-3.12.2004) http://www.eu2004.nl/default.asp?CMS_TCP=tcpAsset&id=1FA5E817CB12484F986BEE41DBF7B5A9X1X56197X36
JHA Council press conference video stream (available after 2 December, 20:00, for one week) http://europa.eu.int/comm/ebs/bottom_schedule.cfm?jour=5&semaine=49&annee=2004#s37732
(Contribution by Andreas Dietl, EDRI EU Affairs Director)"
The Council of Ministers need to read the relevant sections of Ross Anderson's book and Bruce Schneier's too. Or perhaps just giving them an opportunity to sit down without any advisers and simply talk to Ross and Bruce about the differences between the realities and the illusion of security would be a first step?
Wednesday, December 01, 2004
Nice quote from Paul Goldstein's Copyright's Highway: From Guttenberg to the Celestial Jukebox (1994) - he says copyright's goal is to give
"the public the widest variety of literary and artistic works at the lowest possible price." (p228)
On p224: "The capacity of the celestial jukebox to post a charge for access, and to shut off service if a subscriber does not pay his bills, should substantially reduce the spectre of transaction costs. As these costs dissolve, so, too, should the perceived need for safety valves like fair use. Indeed the economic logic of the celestial jukebox....might produce a law that contains no exemptions from liability at all.... as supplliers oblige their subscribers contractually to pay for now exempted uses of copyrighted material..... One problem with this logic is that the celestial jukebox will not entirely replace traditional copyright markets... Also, some of the 1976 Act's exemptions are there, not because of transaction costs, but because certain uses and users serve socially valuable ends. The statuatory exemption for classroom performances of copyrighted works in nonprofit educational institutions is one example. If copyright owners try to circumvent these copyright exemptions by contract - and there is every reason to expect they will - Congress will have to reconsider the distributional aspects of its copyright agenda and decide whether to outlaw such contracts...."
Goldstein would firmly reject Larry Lessig's notions about copyright extension being unnecessary. He is of the opinion that technological development eroded copyright revenues because e.g. people got used to using the VCR without paying for copies because Congress did not act quickly enough to deal with it. And once people are used to getting something for "free" they will not want to pay for it and Congress is unlikely to make them. So he says hand out the copyright scope extensions to prevent damage to copyright holders, then assess later the effect. Lessig on the other hand would say avoid handing out monoplies until the real effect of the technological development can be evaluated. After all, Jack Valenti was against VCRs and now videos provide huge revenues for the movie industry.
Goldstein's book is terrific, though I don't agree with his proposition that we should expand intellectual property laws until they do some noticable damage. Partly because there is very little empirical evidence/study of the impact of IP and partly because the onus should be on those who wish to change the law to demonstrate that the change deals with a particular problem or can demonstrably bring about a positive effect.
Goldstein concludes the book on p236: ".. and true to copyright's historic logic that the best prescription for connecting authors to their audiences is to extends rights into every corner where consumers derive value from literary and artistic works. If history is any measure, the result should be to promote political as well as cultural diversity, ensuring a plenitude of voices, with all the chance to be heard." Hmmmm.
"the public the widest variety of literary and artistic works at the lowest possible price." (p228)
On p224: "The capacity of the celestial jukebox to post a charge for access, and to shut off service if a subscriber does not pay his bills, should substantially reduce the spectre of transaction costs. As these costs dissolve, so, too, should the perceived need for safety valves like fair use. Indeed the economic logic of the celestial jukebox....might produce a law that contains no exemptions from liability at all.... as supplliers oblige their subscribers contractually to pay for now exempted uses of copyrighted material..... One problem with this logic is that the celestial jukebox will not entirely replace traditional copyright markets... Also, some of the 1976 Act's exemptions are there, not because of transaction costs, but because certain uses and users serve socially valuable ends. The statuatory exemption for classroom performances of copyrighted works in nonprofit educational institutions is one example. If copyright owners try to circumvent these copyright exemptions by contract - and there is every reason to expect they will - Congress will have to reconsider the distributional aspects of its copyright agenda and decide whether to outlaw such contracts...."
Goldstein would firmly reject Larry Lessig's notions about copyright extension being unnecessary. He is of the opinion that technological development eroded copyright revenues because e.g. people got used to using the VCR without paying for copies because Congress did not act quickly enough to deal with it. And once people are used to getting something for "free" they will not want to pay for it and Congress is unlikely to make them. So he says hand out the copyright scope extensions to prevent damage to copyright holders, then assess later the effect. Lessig on the other hand would say avoid handing out monoplies until the real effect of the technological development can be evaluated. After all, Jack Valenti was against VCRs and now videos provide huge revenues for the movie industry.
Goldstein's book is terrific, though I don't agree with his proposition that we should expand intellectual property laws until they do some noticable damage. Partly because there is very little empirical evidence/study of the impact of IP and partly because the onus should be on those who wish to change the law to demonstrate that the change deals with a particular problem or can demonstrably bring about a positive effect.
Goldstein concludes the book on p236: ".. and true to copyright's historic logic that the best prescription for connecting authors to their audiences is to extends rights into every corner where consumers derive value from literary and artistic works. If history is any measure, the result should be to promote political as well as cultural diversity, ensuring a plenitude of voices, with all the chance to be heard." Hmmmm.
Just came across MIT's MedialabThinkcycle project, described on the home page as
"an academic, non-profit initiative engaged in supporting distributed collaboration towards design challenges facing underserved communities and the environment. ThinkCycle seeks to create a culture of open source design innovation, with ongoing collaboration among individuals, communities and organizations around the world."
Nice idea. Practical open source learning and problem solving. Apparently it has come up with such things as a simple and effective water purification process, which can be used in areas of the world where clean water is not readily available.
"an academic, non-profit initiative engaged in supporting distributed collaboration towards design challenges facing underserved communities and the environment. ThinkCycle seeks to create a culture of open source design innovation, with ongoing collaboration among individuals, communities and organizations around the world."
Nice idea. Practical open source learning and problem solving. Apparently it has come up with such things as a simple and effective water purification process, which can be used in areas of the world where clean water is not readily available.
Simon Davies of Privacy International wrote an ID card FAQ paper in 1996(!) providing an analysis of the key aspects of ID cards and related technologies. Many of the issues remain current.
Michael Madison, a law professor at the University of Pittsburgh is disappointed by the Kahle v Ashcroft decision.
"The disappointing result in Kahle v. Ashcroft [pdf of the opinion available from Joe Gratz], rejecting constitutional challenges to changes to copyright law that dramatically decrease the likelihood that copyrighted works will fall into the public domain, highlights an issue considered more leisurely in a recent piece in the Fordham Law Review by NYU law professor Diane Zimmerman: Is the public domain constitutionally required? Do we have to have it? The argument of the various “Ashcroft” cases (Eldred, Golan, Kahle) boils down, I think, to the position that it is, and that we do: The public domain is itself a sort of fact, or an idea, or a thing, that is a given feature of the universe and that Congress lacks the power to take away.
As a philosophical matter, I want to chew on that a little bit. Is the public domain really “out there” in that sense, growing (theoretically) bit by bit with the accretion of new material? Or do we (we as society, or we as Congress) make the public domain, and if we do, how do we make it, and what legal and other limits constrain our behavior? As a litigation tactic, I wonder whether the implicit framing of these cases as preservation of “The Public Domain” (initial caps, like “Yosemite Valley” or “Yellowstone National Park") is really the most effective strategy. We know from the Court majority in Eldred v. Ashcroft itself that “The Public Domain” doesn’t sell as an intuitive matter."
"The disappointing result in Kahle v. Ashcroft [pdf of the opinion available from Joe Gratz], rejecting constitutional challenges to changes to copyright law that dramatically decrease the likelihood that copyrighted works will fall into the public domain, highlights an issue considered more leisurely in a recent piece in the Fordham Law Review by NYU law professor Diane Zimmerman: Is the public domain constitutionally required? Do we have to have it? The argument of the various “Ashcroft” cases (Eldred, Golan, Kahle) boils down, I think, to the position that it is, and that we do: The public domain is itself a sort of fact, or an idea, or a thing, that is a given feature of the universe and that Congress lacks the power to take away.
As a philosophical matter, I want to chew on that a little bit. Is the public domain really “out there” in that sense, growing (theoretically) bit by bit with the accretion of new material? Or do we (we as society, or we as Congress) make the public domain, and if we do, how do we make it, and what legal and other limits constrain our behavior? As a litigation tactic, I wonder whether the implicit framing of these cases as preservation of “The Public Domain” (initial caps, like “Yosemite Valley” or “Yellowstone National Park") is really the most effective strategy. We know from the Court majority in Eldred v. Ashcroft itself that “The Public Domain” doesn’t sell as an intuitive matter."
TT Arvind over at UEA's law blog, Displacement of Concepts, seems to think everyone needs to worry about English defamation law, in the wake of the outcome of the UK Court of Appeal Lewis v King case a few weeks ago.
I notice that my link to the decision at the UK Court Service now finds a page that tells you that the page has been moved due to a re-structuring of the website and gives a link to the Court Service home page. After an irritating 10 minutes searching I gave up and looked up the decision at the exellent Bailii site, where I located it in 10 seconds. The UK Court Service has a "Tell us what you think" link on their homepage, so I did, possibly unfairly? I've found them very useful in the past.
Anyway, after that unnecessary distraction, back to the subject at hand. TT Arvind also raised another defamation decision, Richardson v Schwarzenegger in the UK High Court, shortly after the Lewis decision. Both cases related to alleged defamatory statements in the US later published on the Internet. The Richardson decision deals with jurisdiction in Internet defamation cases from point 19 to point 31. The High Court judge, Mr justice Eady, said that
"First, it is well settled now that Internet publication takes place in any jurisdiction where the words are read or downloaded: see e.g. Gutnick v Dow Jones [2002] HCA 56; Lewis v King [2004] EWCA Civ 1329. There is no 'single publication rule' applying to trans-national libels."
Point 24. gives his clinching argument in favour of asserting jurisdiction over the alleged defamation - the claiment is a UK citizen, who works, resides and has an established reputation in the UK and has no comparable connections with the US or other jurisdictions.
And the UEA blog sums up the rest of the decision quite nicely,
"As the judge pointed out, in essence the court was being asked to subject to its jurisdiction a foreign spokesman for a foreign politician who was asked in a foreign location during a foreign domestic election campaign by a foreign newspaper to respond to a number of allegations, which he did with a generic statement not specifically naming the claimant. It was being asked to do this only because he could, at the time, have foreseen that that statement would be published on the internet and subsequently republished in England. Yet the court - despite its obvious sympathy for the defendant - held that under English law, this is exactly what it was required to do. The principles of legal responsibility for publication were settled, and an application of these made it clear that English courts could exercise jurisdiction."
And TT Arvind is concerned about the overall effect of the Lewis and Richardson cases:
"So let's put these two rulings together. If you say anything about anyone who has a reputation in England, and you could have foreseen that that statement would go up on the web, you're likely to be sued for libel in England. It doesn't matter that everyone concerned was in the US, it doesn't matter that you were talking to a US newspaper with no print circulation or target audience in England, it doesn't matter that what you said was permitted comment in US law and dealt with mainly US issues. You could still be dragged through expensive and lengthy proceedings in the English courts. Notwithstanding the protestations of the court in Lewis, a free-for-all is exactly what this creates.
On the bright side, though, this could mean that England is on its way to becoming a haven for American celebrities frustrated by the difficulty public figures have in suing for defamation in the US. If anyone wants to look for employment openings in libel litigation in London, this would be a good time."
I notice that my link to the decision at the UK Court Service now finds a page that tells you that the page has been moved due to a re-structuring of the website and gives a link to the Court Service home page. After an irritating 10 minutes searching I gave up and looked up the decision at the exellent Bailii site, where I located it in 10 seconds. The UK Court Service has a "Tell us what you think" link on their homepage, so I did, possibly unfairly? I've found them very useful in the past.
Anyway, after that unnecessary distraction, back to the subject at hand. TT Arvind also raised another defamation decision, Richardson v Schwarzenegger in the UK High Court, shortly after the Lewis decision. Both cases related to alleged defamatory statements in the US later published on the Internet. The Richardson decision deals with jurisdiction in Internet defamation cases from point 19 to point 31. The High Court judge, Mr justice Eady, said that
"First, it is well settled now that Internet publication takes place in any jurisdiction where the words are read or downloaded: see e.g. Gutnick v Dow Jones [2002] HCA 56; Lewis v King [2004] EWCA Civ 1329. There is no 'single publication rule' applying to trans-national libels."
Point 24. gives his clinching argument in favour of asserting jurisdiction over the alleged defamation - the claiment is a UK citizen, who works, resides and has an established reputation in the UK and has no comparable connections with the US or other jurisdictions.
And the UEA blog sums up the rest of the decision quite nicely,
"As the judge pointed out, in essence the court was being asked to subject to its jurisdiction a foreign spokesman for a foreign politician who was asked in a foreign location during a foreign domestic election campaign by a foreign newspaper to respond to a number of allegations, which he did with a generic statement not specifically naming the claimant. It was being asked to do this only because he could, at the time, have foreseen that that statement would be published on the internet and subsequently republished in England. Yet the court - despite its obvious sympathy for the defendant - held that under English law, this is exactly what it was required to do. The principles of legal responsibility for publication were settled, and an application of these made it clear that English courts could exercise jurisdiction."
And TT Arvind is concerned about the overall effect of the Lewis and Richardson cases:
"So let's put these two rulings together. If you say anything about anyone who has a reputation in England, and you could have foreseen that that statement would go up on the web, you're likely to be sued for libel in England. It doesn't matter that everyone concerned was in the US, it doesn't matter that you were talking to a US newspaper with no print circulation or target audience in England, it doesn't matter that what you said was permitted comment in US law and dealt with mainly US issues. You could still be dragged through expensive and lengthy proceedings in the English courts. Notwithstanding the protestations of the court in Lewis, a free-for-all is exactly what this creates.
On the bright side, though, this could mean that England is on its way to becoming a haven for American celebrities frustrated by the difficulty public figures have in suing for defamation in the US. If anyone wants to look for employment openings in libel litigation in London, this would be a good time."
Ross Anderson mentions some of the problems of the biometric identification techniques, so beloved of Tony Blair and David Blunkett and their pending ID card information system disaster, in his terrific book Security Engineering. For example iris scanners can be defeated by photographs or printed contact lenses. There are also systems issues eg. if one biometric technique, such as iris scanning, becomes the standard and everyone uses it, then terrorists can get Tony Blair's or George Bush's (but not David Blunkett's) from high quality photographs put out by their PR people! Fingerprint scanners don't work so well with the elderly or manual workers. Iris scanners don't work so well with dark eyed people such as Asians. That instantly raised questions relating to discrimination and racism. And the bad guys will get good ID anyway, through identity theft, forgery, having genuine IDs issued by overworked or even a small number of incompetent or corrupt government employees or by social engineering (my ID got stolen can you give me a temporary one while I'm waiting for the new one to come through?). Maybe if Blair , Blunkett and co. had a paint-by-numbers version of Ross's book read to them as a bedtime story, they might think twice about blowing mountains of taxpayers money on stupid ID schemes, in an attempt to create the illusion that they are 'doing something' about terrorism, immigration, benefit fraud, public services, social cohesion, parking fines, TV licenses, etc., etc, etc..
Tuesday, November 30, 2004
Michael Geist's terrific BNA Internet Law News points to the story of a user of the P2P file sharing software called "Winny" who has just been handed a 1 year suspended jail sentence.
I'm not sure where that leaves the software's creator, Tokyo University academic, Isamu Kaneko, who is facing trial for making a copyright infringement tool available to the public.
I'm not sure where that leaves the software's creator, Tokyo University academic, Isamu Kaneko, who is facing trial for making a copyright infringement tool available to the public.
The fine for refusing to register for an ID card will apparently be £2500. The estimated initial £39 fee, which came down to £35 as late as last week is now extimated in the published notes with the legislation as £85. Watch for that to creep up.
Some conspiracy theorists are seeing ID cards as Tony Blair's way of trying to ensure Gordon Brown never becomes prime minister - by the time the national ID card starts to really come crashing down around them, Tony Blair will be seeing out his final term in Downing Street and Labour will just get voted out of power at the following election.
A bit fanciful for me that one. Now David Blunkett seeing the ID card as his platform to launch a leadership bid, post Blair, would be a bit closer to the mark.
Some conspiracy theorists are seeing ID cards as Tony Blair's way of trying to ensure Gordon Brown never becomes prime minister - by the time the national ID card starts to really come crashing down around them, Tony Blair will be seeing out his final term in Downing Street and Labour will just get voted out of power at the following election.
A bit fanciful for me that one. Now David Blunkett seeing the ID card as his platform to launch a leadership bid, post Blair, would be a bit closer to the mark.
Monday, November 29, 2004
Brewster Kahle and the Stanford Center for Internet and Society have lost the first round of their challenge to the Sony Bono Copyright Term Extension Act of 1998.
John was railing against the Intellectual Property Protection Act in the US in the Observer yesterday:
"the IPPA in its current form proposes to make it a criminal offence to skip over adverts in digitally recorded content. If passed, this would mean that American viewers would be allowed to skip or block material containing sex, violence and bad language, but could be prosecuted if they so much as dared to skip an advertisement.
How's that for effrontery? But there's more - the PIRATE Act, for example, which would allow the Justice Department to file civil suits against copyright infringers. What this means is that the record and movie studios, blanching at their mounting legal bills, have pushed an act that would essentially turn the US Justice Department into their in-house litigation section.
Verily, you couldn't make this stuff up. Another section of the IPPA would make it a criminal offence to share any digital content with anyone. This is intended to stop people illicitly sharing music and movie files via peer-to-peer networks. But, as drafted, the act would actually criminalise the Apple iTunes store - that agreeable poster-child for legitimate music downloading."
Not to mention emailing your parents with a picture of their grandchildren...
"the IPPA in its current form proposes to make it a criminal offence to skip over adverts in digitally recorded content. If passed, this would mean that American viewers would be allowed to skip or block material containing sex, violence and bad language, but could be prosecuted if they so much as dared to skip an advertisement.
How's that for effrontery? But there's more - the PIRATE Act, for example, which would allow the Justice Department to file civil suits against copyright infringers. What this means is that the record and movie studios, blanching at their mounting legal bills, have pushed an act that would essentially turn the US Justice Department into their in-house litigation section.
Verily, you couldn't make this stuff up. Another section of the IPPA would make it a criminal offence to share any digital content with anyone. This is intended to stop people illicitly sharing music and movie files via peer-to-peer networks. But, as drafted, the act would actually criminalise the Apple iTunes store - that agreeable poster-child for legitimate music downloading."
Not to mention emailing your parents with a picture of their grandchildren...
The Times says the government's sums on the costing of the proposed ID card system don't add up because they don't include the costs of actually implementing the systems, let alone maintaining them.
There have been some dirty tricks going on at WIPO meetings on the proposed broadcasting treaty this week. Apparently, EFF and Public Knowledge tabled papers have been surrepticiously stolen and binned and the chair has been engaging in autocratic "democracy" with an agenda. Cory and others are blogging proceedings.
Speaking of biometric identifying documents, I ran a workshop at the weekend with a group of Open University associate lecturers on the UK's proposed national identity card. We focussed on the practicalities of the technology and didn't get into the complex debate on potential civil liberties implications.
I did a survey before we began and found about 28% of the audience were in favour of the proposals, 28% were undecided and 44% were against. Interestingly enough, at the end of the workshop we checked again and these numbers were unchanged. Yet nearly eveyone in the room was convinced that:
The national ID card is a "solution" looking to solve a huge range of problems (terrorism, benefit fraud, immigration, NHS and other public service access, unpaid parking fines... the list is endless)in vague unspecified ways.
That in their current stage of development biometric technologies are unreliable.
There is not a computer scientist in the world that could secure a centralised database of the size and complexity and with the remote access requirements of that needed to underpin the proposed ID card.
That the government has not got the best record in commissioning and implementing large information systems and has not done anything on this scale before.
That ID card system trials were severely hampered by technical problems, didn't get started until 3 months after the proposed start date, were rushed and had nowhere near the planned 10000 volunteers that were initally planned to include.
That at least one of the large existing goverment IT systems that the national ID card systmem will have to talk to, the benefits system, failed catatrophically just last week.
That the proposed system completely fails to solve any of the problems it is allegedly intended to deal with and in many instances will make the situation worse e.g. in relation to the already over-worked law enforcement authorities, who whilst processing the 20 to 95% of us who will have serious errors in our electronic profiles, will be so swamped with electronic garbage that they won't have sufficient time/resources to engage in the kind of intelligent policing required to target and apprehend so-called "bad actors."
That the system is so complex and so insecure, due to the need for hundreds of thousands (if not millions) of people in public service jobs requiring access just to do their job, that it will be error prone and repeatedly subject to malicious changes and intent, by a small number of inside and possiblly a larger number of external bad actors.
That there will be a whole serious of complex emergent properties, some positive and some negative.
That it will cost an absolute fortune and that it is clearly not worth the money, let alone the other costs alluded to above.
So why, amongst a group of smart, thoughtful people from a wide range of backgrounds (technology, science, arts, business, social science, languages) were 27% still in favour at the end of the discussions? This has to do with values and emotions rather than practicalities. And you see that's the thing - security, which is what a large part of the ID card debate is often reduced to, is about feelings as much as reality. On each occasion that I've done this workshop asking people to think about the practical implications of deploying the technologies in the way that is proposed, those in favour of the ID card rarely change their minds. Largely because the idea of an identity card "feels" right.
Tony Blair and David Blunkett understand the power of emotions and tailor their pro ID card campaign accordingly with soundbites like "nothing to hide, nothing to fear," which though meaningless, taps into people's feelings. The anti campaign are severely on the defensive, since they have not come up with anything like an equivalent soundbite, with the requisite pithiness. All I can offer is Jeffrey Rosen's "people have a right to avoid being judged out of context in a world of short attention spans." That takes 5 seconds to say. Blair and Blunkett's takes 1 second. Sadly 5 seconds is too long and in today's world if you have to explain, you've lost the argument...
I did a survey before we began and found about 28% of the audience were in favour of the proposals, 28% were undecided and 44% were against. Interestingly enough, at the end of the workshop we checked again and these numbers were unchanged. Yet nearly eveyone in the room was convinced that:
The national ID card is a "solution" looking to solve a huge range of problems (terrorism, benefit fraud, immigration, NHS and other public service access, unpaid parking fines... the list is endless)in vague unspecified ways.
That in their current stage of development biometric technologies are unreliable.
There is not a computer scientist in the world that could secure a centralised database of the size and complexity and with the remote access requirements of that needed to underpin the proposed ID card.
That the government has not got the best record in commissioning and implementing large information systems and has not done anything on this scale before.
That ID card system trials were severely hampered by technical problems, didn't get started until 3 months after the proposed start date, were rushed and had nowhere near the planned 10000 volunteers that were initally planned to include.
That at least one of the large existing goverment IT systems that the national ID card systmem will have to talk to, the benefits system, failed catatrophically just last week.
That the proposed system completely fails to solve any of the problems it is allegedly intended to deal with and in many instances will make the situation worse e.g. in relation to the already over-worked law enforcement authorities, who whilst processing the 20 to 95% of us who will have serious errors in our electronic profiles, will be so swamped with electronic garbage that they won't have sufficient time/resources to engage in the kind of intelligent policing required to target and apprehend so-called "bad actors."
That the system is so complex and so insecure, due to the need for hundreds of thousands (if not millions) of people in public service jobs requiring access just to do their job, that it will be error prone and repeatedly subject to malicious changes and intent, by a small number of inside and possiblly a larger number of external bad actors.
That there will be a whole serious of complex emergent properties, some positive and some negative.
That it will cost an absolute fortune and that it is clearly not worth the money, let alone the other costs alluded to above.
So why, amongst a group of smart, thoughtful people from a wide range of backgrounds (technology, science, arts, business, social science, languages) were 27% still in favour at the end of the discussions? This has to do with values and emotions rather than practicalities. And you see that's the thing - security, which is what a large part of the ID card debate is often reduced to, is about feelings as much as reality. On each occasion that I've done this workshop asking people to think about the practical implications of deploying the technologies in the way that is proposed, those in favour of the ID card rarely change their minds. Largely because the idea of an identity card "feels" right.
Tony Blair and David Blunkett understand the power of emotions and tailor their pro ID card campaign accordingly with soundbites like "nothing to hide, nothing to fear," which though meaningless, taps into people's feelings. The anti campaign are severely on the defensive, since they have not come up with anything like an equivalent soundbite, with the requisite pithiness. All I can offer is Jeffrey Rosen's "people have a right to avoid being judged out of context in a world of short attention spans." That takes 5 seconds to say. Blair and Blunkett's takes 1 second. Sadly 5 seconds is too long and in today's world if you have to explain, you've lost the argument...
Dr. Steve Peers, Professor of Law, University of Essex has written quite a damning critique of this proposed imposition of biometrics on EU passports, concluding:
"The proposed Regulation on EU passports, with or without mandatory fingerprinting requirements, exceeds the legal powers conferred upon the Community to adopt measures concerning checks at external borders. It furthermore exceeds any other powers conferred upon the Community.
If the Regulation includes mandatory fingerprinting requirements, it would also breach the principle of proportionality that is a requirement for the legality of Community acts, and the general principles of Community law, which include the protection of the right to private life."
"The proposed Regulation on EU passports, with or without mandatory fingerprinting requirements, exceeds the legal powers conferred upon the Community to adopt measures concerning checks at external borders. It furthermore exceeds any other powers conferred upon the Community.
If the Regulation includes mandatory fingerprinting requirements, it would also breach the principle of proportionality that is a requirement for the legality of Community acts, and the general principles of Community law, which include the protection of the right to private life."
An Open Letter to the European Parliament on Biometric Registration of all EU Citizens and Residents from the European Digital Rights coalition of civil liberties groups.
To the Members of the European Parliament,
We the undersigned are calling on you to reject the 'Draft Council Regulation on standards for security features and biometrics in passports and travel documents issued by Member States'. This is an unnecessary and rushed policy that will have hazardous effects on Europeans' right to privacy. This policy process requires additional oversight, and the eventual systems established will require significant controls and a strong legal framework to ensure that this is a proportionate response to the war on terrorism. In particular, we call for the removal of the requirement for fingerprinting all EU citizens.
We are quite alarmed by the political dynamics at play in this policy decision.
* The Council of the European Union pressed the European Parliament into including the Coelho reports on biometric identifiers on the agenda for the mini-session on Wednesday, 1 December 2004.
* Behind closed doors on October 25 the Justice and Home Affairs Council decided to introduce mandatory fingerprinting for all EU citizens into the draft regulation.
* The Parliament's response to this significant shift in policy is even more alarming: a majority of the Presidents of the Political Groups acccepted the claim that the change was not sufficient grounds for the report to be sent back to the LIBE Committee for further consideration.
* If the Presidents had refused to accept, the Council would have called for an urgency procedure.
* If the Presidents had refused, the Council would have also delayed the introduction of the co-decision procedure for immigration and asylum issues to April 1 instead of January 1.
These dynamics are irresponsible and unhealthy for a functioning democratic system.
Securing our passports from fraudulent use is indeed a pressing need, particularly considering the substantial number of blank passports lost every year. The proposed policy that is being presented to you for review will however have significant implications. This policy is dependent on an unprepared and under-developed technological infrastructure. It will therefore lead to an increased risk of abuse.
We are calling on the European Parliament to reject this policy. The European Parliament needs to provide sunlight to this policy process through oversight and an open deliberative process.
We are calling on the European Parliament to reject this policy. The case still has not been made openly and clearly as to why biometric passports are required. There is a lack of adequate safeguards. We urge the Parliament to oppose the creation of an EU-wide database of personal data. We further urge the Parliament to oppose mandatory fingerprinting as an unnecessary and disproportionate act. Finally, we are calling on the Parliament to reserve the right to question the legal basis of the proposal.
The European Parliament needs to provide sunlight to this policy process through oversight and an open deliberative process.
A Dangerous Policy
The grounds for changing our passport standards are many and varied. Yet the proposed changes in this policy are without foundation. U.S. law does require biometric passports programmes to be in place by the Autumn of 2005 in order for countries to remain part of the Visa-Waiver Programme. U.S. law also required the standard for these programmes to be established by the International Civil Aviation Organization. However, neither the U.S. nor the ICAO requires biometric passports in the form proposed by the Council.
We would like to take this opportunity to remind you that
* The Council is calling for the use of two biometrics, when the U.S. and the ICAO only require one, and this only involves a digital photograph. The inclusion of a fingerprint biometric is unprecedented.
* The U.S. has no intentions of implementing fingerprints in their passports. [1]
* The ICAO has itself noted that some States are legally barred from storing biometrics. [2]
* The U.S. Department of Homeland Security and the Department of State note that privacy issues need to be resolved prior to the implementation of these systems.[3]
* The French Government reached a similar conclusion, requiring that any implementation of biometric techniques is systematically subject to prior agreement from its national privacy commission.[4]
* The legal basis offered by the Commission and Council is fundamentally flawed. A legal analysis by Professor Steve Peers (University of Essex) concludes that: "The proposed Regulation on EU passports, with or without mandatory fingerprinting requirements, exceeds the legal powers conferred upon the Community to adopt measures concerning checks at external borders. It furthermore exceeds any other powers conferred upon the Community. If the Regulation includes mandatory fingerprinting requirements, it would also breach the principle of proportionality that is a requirement for the legality of Community acts, and the general principles of Community law, which include the protection of the right to private life."[5]
We are thus alarmed by the omission of these facts from the current debates.
Problematic Technologies
Lurking behind this policy is the creation of an EU-wide database system that will store the personal information of over 450 million people. This database is neither required nor is it technologically desirable. The European Commission previously advocated a centralised database solution, but even then the Commission noted that further research is necessary to "examine the impact of the establishment of such a European Register on the fundamental rights of European citizens, and in particular their right to data protection."[6]
Centralised EU databases covering passports, visa and residence permits will be linked through SIS II. This risks becoming a mass surveillance infrastructure tracking the movements of all residents and citizens. Plans to give access to all law enforcement and internal security agencies risks the misuse of sensitive personal information. To date, there have been too few studies, if any, of these problems and challenges. Policy as important and far-reaching as this requires more care before being adopted.
We would like to further remind you that the risks to privacy are well known. In particular, European Privacy and Data Protection Commissioners have long warned of the dangers of biometric data collection.
* The Article 29 Working Party on Data Protection rightly notes that fingerprints are usually collected from criminals. The increased collection of highly personal information will de-sensitize us to the effect that this processing will have on our daily life.[7]
* This proposal may not make us any safer and may in fact create more risks, and even greater potential of reuse and abuse. Centralised databases are prone to abuse, and fingerprints can easily be collected without consent, and are thus ideal for additional surveillance.[7]
* Even face recognition technology reveals racial or ethnic origin, [7] which under EU law is of a highly sensitive nature and deserves even greater privacy protection.
Additionally, the International Conference on Data Protection and Privacy Commissioners in 2003 declared that
"In the fight against terrorism and organized crime, countries should determine their responses paying full regard to fundamental data protection principles, which are integral parts of the values being defended."
They recommend that in situations where there are required interventions into the right to privacy,
"they should take place within a framework taking data protection into account, e.g. on the basis of an international agreement stipulating adequate data protection requirements, including clear purpose limitation, adequate and non-excessive data collection, limited data retention time, information provision to data subjects, the assurance of data subject rights and independent supervision."
The current proposal does not sufficiently address these most basic requirements. It lacks a legal framework to protect privacy rights. This deficiency is inexcusable, particularly as the personal information of Europeans is collected and transferred abroad.
Greater Implications
When the U.S. implemented its mass fingerprinting and face-scanning programme for all visitors, the world responded with alarm. All visitors over the age of 13 will now have their fingerprints taken and stored for 75 to 100 years by the Department of Homeland Security, and will be shared with other government departments and agencies, and other governments.[8]
The Council's proposed policy goes well beyond this already problematic US-VISIT programme. The U.S. Government is not fingerprinting its own citizens. The EU policy intends to fingerprint all EU citizens, residents, and visitors. The secondary effect of this policy is that whenever EU citizens travel abroad (not necessarily to the United States), they will again be required to register their fingeprints and face-scans with foreign governments as their passports are verified. As a result, the EU is drastically enlarging the US-VISIT programme by turning it against its own citizens and then globalising this practice.
We would also like to point to the practical implications of this policy.
* Citizens will now have to present themselves at an 'enrolment centre' to be 'processed and have their fingerprints taken by their National passport authority every time they want a passport. Previously, passport renewal could be achieved remotely, even through the post. The increased administrative costs to the authorities and to individuals are likely to be significant.
* The complexities of the database systems involved in the registration, issuance, and verification processes are unprecedented.
* There is no legal framework in this policy to prescribe how this information may be collected, processed, and transferred.
* Error rates in fingerprinting are significant, and poorly understood. Two percent of the general population do not even have fingerprints, while certain ethnic, and demographic groups are more difficult to fingerprint than others.[9] According to a recent overview of the current technological systems, the error rates are far from being minor, with false match error rates across products tested averaged 18 percent.[10]
According to one expert, our understanding of fingerprints "is dangerously flawed and risks causing miscarriages of justice".[10] Amongst the many cases of mistaken identification through fingerprinting, we would like to remind the Parliament of the recent case of Brandon Mayfield. After the Madrid Bombings of March 11, 2004, Spanish National Police managed to lift a fingerprint from an unexploded bomb. Three highly skilled FBI fingerprint experts declared that Oregon lawyer Brandon Mayfield's fingerprint matched. U.S. officials called it "absolutely incontrovertible" and a "bingo match." As a former U.S. soldier, his fingerprint was on the national fingerprint system. Mayfield was imprisoned for two weeks. The fingerprint, however, was not his. According to one law professor,
"The Mayfield misidentification also reveals the danger that extraneous knowledge might influence experts' evaluations. If any of those FBI fingerprint examiners who confidently declared the match already knew that Mayfield was himself a convert to Islam who had once represented a convicted Taliban sympathizer in a child custody dispute, this knowledge may have subconsciously primed them to "see" the match. ... No matter how accurate fingerprint identification turns out to be, it cannot be as perfect as they claim." [11]
When all of his personal information was combined, however, the FBI was convinced. Yet according to a recent panel of experts, they were wrong.[12] As we increase the database collection of biometric information away from criminals and other select groups, errors are likely to increase. The technology in our midst, and our methods, are not perfect.
The Council and the Commission are busy implementing many other systems of surveillance that will involve increased personal data collection, data mining, and data sharing. These policies together ensure that instead of achieving certainty and security, we only create more risk, danger, misplaced suspicion and abuse.
Greater Oversight is Required
The fatal flaw in this entire policy process is the lack of adequate supervision, oversight, and deliberation. This must be rectified. We call on the European Parliament to play this key role in democratic process.
We call on the European Parliament to:
* Re-establish essential safeguards for the proposed systems, including those that were set out in the Parliament's report, and in particular the abandonment of an EU-wide database.
* Require and/or establish a legal framework for the collection and use of personal information in travel documents and border programmes. This framework must be consistent with the European Convention of Human Rights, and in particular Article 8. This would include requiring clearer statements of purpose and use, so that the data collected is not used for generalised surveillance or other purposes.
* Require that this legal framework also ensure that the systems supporting this policy are secure, with clear lines of accountability, and that the collection procedures are well understood. Only then can we begin to understand the complexity of the system involved, and in turn the potentially severe cost implications.
* Call for the establishment of mechanisms for the oversight of the planning, implementation, testing, and use of biometrics in travel documents.
* Remove the unnecessary requirement of mass fingerprinting of EU residents and citizens.
* Review the technological implications of this and related policies. In establishing what could be one of the largest database systems in existence, we are alarmed by the lack of publication, public discourse, and scrutiny of the costs and implications of this policy. We need valid research of the problem, which can then be relayed to the Parliament, focussing on cost implications, legal implications, technological implications, and potentials for abuse.
* Call on the research and policy community to propose alternative solutions that are privacy-friendly. Alternative systems and technologies exist, as we already see that the U.S. is not intending on generating a fingerprint registry. Innovative solutions must be brought to the forefront to preserve European values, rights, democratic standards, and laws.
* Question the legal basis of the proposal in the first place.
The EU is embarking on a policy that will make our most personal information the currency of travel, while creating one of the world's largest surveillance infrastructures. This is unprecedented and unnecessary.
These are serious times and we need serious policy based on effective deliberation. Rushing this policy through the European Parliament is not required, when careful scrutiny is necessary. The EU's respect for privacy is often considered the global gold-standard, and yet now the EU is revolutionising surveillance. When combined with data profiling and data sharing proposals also being developed by the Commission and the Council, Europe faces the real prospect of creating a surveillance behemoth.
We call on MEPs to oppose this proposed policy, and we look forward to working with you in the future on establishing effective policies for securing our societies whilst simultaneously securing our rights and liberties.
Signed,
Gus Hosein
Privacy International
Tony Bunyan
Statewatch
Statewatch
Andreas Dietl
European Digital Rights
Additional Endorsements
(Individuals or organisations who wish to endorse this letter are kindly asked to send an e-mail to brussels email)
References
[1] U.S. Department of State, Abstract of Concept of Operations for the Integration of Contactless Chip in the U.S. Passport. Washington, April 26, 2004.
[2] ICAO BIOMETRICS DEPLOYMENT OF MACHINE READABLE TRAVEL DOCUMENTS ICAO TAG MRTD/NTWG TECHNICAL REPORT: Development and Specification of Globally Interoperable Biometric Standards for Machine Assisted Identity Confirmation using Machine Readable Travel Documents. Montreal: ICAO, May 12, 2003. ver 1.9.
[3] Tom Ridge and Colin Powell, Dear Mr. Chairman, letter to the Chairman of the House Committee of the Judiciary. Washington, D.C.: 2004. Archived at http://www.house.gov/judiciary/ridge031704.pdf
[4] French Government, Implementation of Biometric Techniques on French Airports. Cairo, Egypt: Presented to the ICAO summit in Cairo. March 18, 2004, FAL/12-IP/24. Archived at http://www.icao.int/icao/en/atb/fal/fal12/documentation/fal12ip024_en....
[5] Steve Peers, Commission’s EU biometric passport proposal exceeds the EC’s powers. Statewatch, November 26 2004. Archived at http://www.statewatch.org/news/2004/nov/11biometric-legal-analysis-htm...
[6] Commission of the European Communities, Proposal for a Council Regulation on standards for security features and biometrics in EU citizens' passports. Brussels: The European Commission, February 18 2004, COM(2004)116final. Archived at http://register.consilium.eu.int/pdf/en/04/st06/st06406-re01.en04.pdf
[7] Article 29 Working Party, Working document on biometrics. Brussels: Article 29 Data Protection Working Party, August 1, 2003. Archived at http://europa.eu.int/comm/internal_market/privacy/docs/wpdocs/2003/wp8...
[8] Privacy International, The enhanced US border surveillance system: an assessment of the implications of US-VISIT. London, September 28, 2004. Archived at http://www.privacyinternational.org/issues/terrorism/rpt/dangers_of_vi...
[9] United States General Accounting Office, Technology Assessment: Using Biometrics for Border Security, November 2002.
[10] Fingerprint Verification Competition 2004, Open Category Results: Average results over all databases, Preliminary results.
[11] J.L. Mnookin, "The Achilles' Heel of Fingerprints". Washington Post, May 29, 2004.
[12] B. Harden. "FBI Faulted in Arrest of Ore. Lawyer." Washington Post, November 16, 2004.
To the Members of the European Parliament,
We the undersigned are calling on you to reject the 'Draft Council Regulation on standards for security features and biometrics in passports and travel documents issued by Member States'. This is an unnecessary and rushed policy that will have hazardous effects on Europeans' right to privacy. This policy process requires additional oversight, and the eventual systems established will require significant controls and a strong legal framework to ensure that this is a proportionate response to the war on terrorism. In particular, we call for the removal of the requirement for fingerprinting all EU citizens.
We are quite alarmed by the political dynamics at play in this policy decision.
* The Council of the European Union pressed the European Parliament into including the Coelho reports on biometric identifiers on the agenda for the mini-session on Wednesday, 1 December 2004.
* Behind closed doors on October 25 the Justice and Home Affairs Council decided to introduce mandatory fingerprinting for all EU citizens into the draft regulation.
* The Parliament's response to this significant shift in policy is even more alarming: a majority of the Presidents of the Political Groups acccepted the claim that the change was not sufficient grounds for the report to be sent back to the LIBE Committee for further consideration.
* If the Presidents had refused to accept, the Council would have called for an urgency procedure.
* If the Presidents had refused, the Council would have also delayed the introduction of the co-decision procedure for immigration and asylum issues to April 1 instead of January 1.
These dynamics are irresponsible and unhealthy for a functioning democratic system.
Securing our passports from fraudulent use is indeed a pressing need, particularly considering the substantial number of blank passports lost every year. The proposed policy that is being presented to you for review will however have significant implications. This policy is dependent on an unprepared and under-developed technological infrastructure. It will therefore lead to an increased risk of abuse.
We are calling on the European Parliament to reject this policy. The European Parliament needs to provide sunlight to this policy process through oversight and an open deliberative process.
We are calling on the European Parliament to reject this policy. The case still has not been made openly and clearly as to why biometric passports are required. There is a lack of adequate safeguards. We urge the Parliament to oppose the creation of an EU-wide database of personal data. We further urge the Parliament to oppose mandatory fingerprinting as an unnecessary and disproportionate act. Finally, we are calling on the Parliament to reserve the right to question the legal basis of the proposal.
The European Parliament needs to provide sunlight to this policy process through oversight and an open deliberative process.
A Dangerous Policy
The grounds for changing our passport standards are many and varied. Yet the proposed changes in this policy are without foundation. U.S. law does require biometric passports programmes to be in place by the Autumn of 2005 in order for countries to remain part of the Visa-Waiver Programme. U.S. law also required the standard for these programmes to be established by the International Civil Aviation Organization. However, neither the U.S. nor the ICAO requires biometric passports in the form proposed by the Council.
We would like to take this opportunity to remind you that
* The Council is calling for the use of two biometrics, when the U.S. and the ICAO only require one, and this only involves a digital photograph. The inclusion of a fingerprint biometric is unprecedented.
* The U.S. has no intentions of implementing fingerprints in their passports. [1]
* The ICAO has itself noted that some States are legally barred from storing biometrics. [2]
* The U.S. Department of Homeland Security and the Department of State note that privacy issues need to be resolved prior to the implementation of these systems.[3]
* The French Government reached a similar conclusion, requiring that any implementation of biometric techniques is systematically subject to prior agreement from its national privacy commission.[4]
* The legal basis offered by the Commission and Council is fundamentally flawed. A legal analysis by Professor Steve Peers (University of Essex) concludes that: "The proposed Regulation on EU passports, with or without mandatory fingerprinting requirements, exceeds the legal powers conferred upon the Community to adopt measures concerning checks at external borders. It furthermore exceeds any other powers conferred upon the Community. If the Regulation includes mandatory fingerprinting requirements, it would also breach the principle of proportionality that is a requirement for the legality of Community acts, and the general principles of Community law, which include the protection of the right to private life."[5]
We are thus alarmed by the omission of these facts from the current debates.
Problematic Technologies
Lurking behind this policy is the creation of an EU-wide database system that will store the personal information of over 450 million people. This database is neither required nor is it technologically desirable. The European Commission previously advocated a centralised database solution, but even then the Commission noted that further research is necessary to "examine the impact of the establishment of such a European Register on the fundamental rights of European citizens, and in particular their right to data protection."[6]
Centralised EU databases covering passports, visa and residence permits will be linked through SIS II. This risks becoming a mass surveillance infrastructure tracking the movements of all residents and citizens. Plans to give access to all law enforcement and internal security agencies risks the misuse of sensitive personal information. To date, there have been too few studies, if any, of these problems and challenges. Policy as important and far-reaching as this requires more care before being adopted.
We would like to further remind you that the risks to privacy are well known. In particular, European Privacy and Data Protection Commissioners have long warned of the dangers of biometric data collection.
* The Article 29 Working Party on Data Protection rightly notes that fingerprints are usually collected from criminals. The increased collection of highly personal information will de-sensitize us to the effect that this processing will have on our daily life.[7]
* This proposal may not make us any safer and may in fact create more risks, and even greater potential of reuse and abuse. Centralised databases are prone to abuse, and fingerprints can easily be collected without consent, and are thus ideal for additional surveillance.[7]
* Even face recognition technology reveals racial or ethnic origin, [7] which under EU law is of a highly sensitive nature and deserves even greater privacy protection.
Additionally, the International Conference on Data Protection and Privacy Commissioners in 2003 declared that
"In the fight against terrorism and organized crime, countries should determine their responses paying full regard to fundamental data protection principles, which are integral parts of the values being defended."
They recommend that in situations where there are required interventions into the right to privacy,
"they should take place within a framework taking data protection into account, e.g. on the basis of an international agreement stipulating adequate data protection requirements, including clear purpose limitation, adequate and non-excessive data collection, limited data retention time, information provision to data subjects, the assurance of data subject rights and independent supervision."
The current proposal does not sufficiently address these most basic requirements. It lacks a legal framework to protect privacy rights. This deficiency is inexcusable, particularly as the personal information of Europeans is collected and transferred abroad.
Greater Implications
When the U.S. implemented its mass fingerprinting and face-scanning programme for all visitors, the world responded with alarm. All visitors over the age of 13 will now have their fingerprints taken and stored for 75 to 100 years by the Department of Homeland Security, and will be shared with other government departments and agencies, and other governments.[8]
The Council's proposed policy goes well beyond this already problematic US-VISIT programme. The U.S. Government is not fingerprinting its own citizens. The EU policy intends to fingerprint all EU citizens, residents, and visitors. The secondary effect of this policy is that whenever EU citizens travel abroad (not necessarily to the United States), they will again be required to register their fingeprints and face-scans with foreign governments as their passports are verified. As a result, the EU is drastically enlarging the US-VISIT programme by turning it against its own citizens and then globalising this practice.
We would also like to point to the practical implications of this policy.
* Citizens will now have to present themselves at an 'enrolment centre' to be 'processed and have their fingerprints taken by their National passport authority every time they want a passport. Previously, passport renewal could be achieved remotely, even through the post. The increased administrative costs to the authorities and to individuals are likely to be significant.
* The complexities of the database systems involved in the registration, issuance, and verification processes are unprecedented.
* There is no legal framework in this policy to prescribe how this information may be collected, processed, and transferred.
* Error rates in fingerprinting are significant, and poorly understood. Two percent of the general population do not even have fingerprints, while certain ethnic, and demographic groups are more difficult to fingerprint than others.[9] According to a recent overview of the current technological systems, the error rates are far from being minor, with false match error rates across products tested averaged 18 percent.[10]
According to one expert, our understanding of fingerprints "is dangerously flawed and risks causing miscarriages of justice".[10] Amongst the many cases of mistaken identification through fingerprinting, we would like to remind the Parliament of the recent case of Brandon Mayfield. After the Madrid Bombings of March 11, 2004, Spanish National Police managed to lift a fingerprint from an unexploded bomb. Three highly skilled FBI fingerprint experts declared that Oregon lawyer Brandon Mayfield's fingerprint matched. U.S. officials called it "absolutely incontrovertible" and a "bingo match." As a former U.S. soldier, his fingerprint was on the national fingerprint system. Mayfield was imprisoned for two weeks. The fingerprint, however, was not his. According to one law professor,
"The Mayfield misidentification also reveals the danger that extraneous knowledge might influence experts' evaluations. If any of those FBI fingerprint examiners who confidently declared the match already knew that Mayfield was himself a convert to Islam who had once represented a convicted Taliban sympathizer in a child custody dispute, this knowledge may have subconsciously primed them to "see" the match. ... No matter how accurate fingerprint identification turns out to be, it cannot be as perfect as they claim." [11]
When all of his personal information was combined, however, the FBI was convinced. Yet according to a recent panel of experts, they were wrong.[12] As we increase the database collection of biometric information away from criminals and other select groups, errors are likely to increase. The technology in our midst, and our methods, are not perfect.
The Council and the Commission are busy implementing many other systems of surveillance that will involve increased personal data collection, data mining, and data sharing. These policies together ensure that instead of achieving certainty and security, we only create more risk, danger, misplaced suspicion and abuse.
Greater Oversight is Required
The fatal flaw in this entire policy process is the lack of adequate supervision, oversight, and deliberation. This must be rectified. We call on the European Parliament to play this key role in democratic process.
We call on the European Parliament to:
* Re-establish essential safeguards for the proposed systems, including those that were set out in the Parliament's report, and in particular the abandonment of an EU-wide database.
* Require and/or establish a legal framework for the collection and use of personal information in travel documents and border programmes. This framework must be consistent with the European Convention of Human Rights, and in particular Article 8. This would include requiring clearer statements of purpose and use, so that the data collected is not used for generalised surveillance or other purposes.
* Require that this legal framework also ensure that the systems supporting this policy are secure, with clear lines of accountability, and that the collection procedures are well understood. Only then can we begin to understand the complexity of the system involved, and in turn the potentially severe cost implications.
* Call for the establishment of mechanisms for the oversight of the planning, implementation, testing, and use of biometrics in travel documents.
* Remove the unnecessary requirement of mass fingerprinting of EU residents and citizens.
* Review the technological implications of this and related policies. In establishing what could be one of the largest database systems in existence, we are alarmed by the lack of publication, public discourse, and scrutiny of the costs and implications of this policy. We need valid research of the problem, which can then be relayed to the Parliament, focussing on cost implications, legal implications, technological implications, and potentials for abuse.
* Call on the research and policy community to propose alternative solutions that are privacy-friendly. Alternative systems and technologies exist, as we already see that the U.S. is not intending on generating a fingerprint registry. Innovative solutions must be brought to the forefront to preserve European values, rights, democratic standards, and laws.
* Question the legal basis of the proposal in the first place.
The EU is embarking on a policy that will make our most personal information the currency of travel, while creating one of the world's largest surveillance infrastructures. This is unprecedented and unnecessary.
These are serious times and we need serious policy based on effective deliberation. Rushing this policy through the European Parliament is not required, when careful scrutiny is necessary. The EU's respect for privacy is often considered the global gold-standard, and yet now the EU is revolutionising surveillance. When combined with data profiling and data sharing proposals also being developed by the Commission and the Council, Europe faces the real prospect of creating a surveillance behemoth.
We call on MEPs to oppose this proposed policy, and we look forward to working with you in the future on establishing effective policies for securing our societies whilst simultaneously securing our rights and liberties.
Signed,
Gus Hosein
Privacy International
Tony Bunyan
Statewatch
Statewatch
Andreas Dietl
European Digital Rights
Additional Endorsements
(Individuals or organisations who wish to endorse this letter are kindly asked to send an e-mail to brussels email)
References
[1] U.S. Department of State, Abstract of Concept of Operations for the Integration of Contactless Chip in the U.S. Passport. Washington, April 26, 2004.
[2] ICAO BIOMETRICS DEPLOYMENT OF MACHINE READABLE TRAVEL DOCUMENTS ICAO TAG MRTD/NTWG TECHNICAL REPORT: Development and Specification of Globally Interoperable Biometric Standards for Machine Assisted Identity Confirmation using Machine Readable Travel Documents. Montreal: ICAO, May 12, 2003. ver 1.9.
[3] Tom Ridge and Colin Powell, Dear Mr. Chairman, letter to the Chairman of the House Committee of the Judiciary. Washington, D.C.: 2004. Archived at http://www.house.gov/judiciary/ridge031704.pdf
[4] French Government, Implementation of Biometric Techniques on French Airports. Cairo, Egypt: Presented to the ICAO summit in Cairo. March 18, 2004, FAL/12-IP/24. Archived at http://www.icao.int/icao/en/atb/fal/fal12/documentation/fal12ip024_en....
[5] Steve Peers, Commission’s EU biometric passport proposal exceeds the EC’s powers. Statewatch, November 26 2004. Archived at http://www.statewatch.org/news/2004/nov/11biometric-legal-analysis-htm...
[6] Commission of the European Communities, Proposal for a Council Regulation on standards for security features and biometrics in EU citizens' passports. Brussels: The European Commission, February 18 2004, COM(2004)116final. Archived at http://register.consilium.eu.int/pdf/en/04/st06/st06406-re01.en04.pdf
[7] Article 29 Working Party, Working document on biometrics. Brussels: Article 29 Data Protection Working Party, August 1, 2003. Archived at http://europa.eu.int/comm/internal_market/privacy/docs/wpdocs/2003/wp8...
[8] Privacy International, The enhanced US border surveillance system: an assessment of the implications of US-VISIT. London, September 28, 2004. Archived at http://www.privacyinternational.org/issues/terrorism/rpt/dangers_of_vi...
[9] United States General Accounting Office, Technology Assessment: Using Biometrics for Border Security, November 2002.
[10] Fingerprint Verification Competition 2004, Open Category Results: Average results over all databases, Preliminary results.
[11] J.L. Mnookin, "The Achilles' Heel of Fingerprints". Washington Post, May 29, 2004.
[12] B. Harden. "FBI Faulted in Arrest of Ore. Lawyer." Washington Post, November 16, 2004.
Friday, November 26, 2004
According to Intellectual Property Watch,
"In an October 15 speech, the Director of the U.S. Patent and Trademark Office (USPTO), Jonathan Dudas, vowed that the U.S. government will “fight” proposals that aim to “fundamentally change the WIPO charter and philosophy” away from its current focus on the promotion of intellectual property."
No surprises there but the strength of the comments suggest that the adoption of the development agenda by WIPO has caused some ripples.
"In an October 15 speech, the Director of the U.S. Patent and Trademark Office (USPTO), Jonathan Dudas, vowed that the U.S. government will “fight” proposals that aim to “fundamentally change the WIPO charter and philosophy” away from its current focus on the promotion of intellectual property."
No surprises there but the strength of the comments suggest that the adoption of the development agenda by WIPO has caused some ripples.
The front page of the Guardian reports that there has been a massive IT failure at the Department for Work and Pensions this week.
"Pension and benefit payments face disruption after what is being described as the biggest computer crash in government history left as many as 80,000 civil servants staring at blank screens and reverting to writing out giro cheques by hand in the latest blow to a hi-tech Whitehall revolution."
This is the system which will need to 'talk' to the proposed ID card system, that amongst other things according to David Blunkett, is going to solve the problem of benefit fraud. Mmmmm, a new IT catastrophe communicating with an old IT catastrophe. That sure does inspire a lot of confidence in the notion that ID cards will cut benefit fraud.
On another biometric related story, the EU Council of Ministers appear to be attempting ot pull a fast one by putting pressure on the EU Parliament to rush through the compulsory biometric passports for all EU citizens. Apparently the Dutch Presidency of the EU:
"are pushing hard for a decision at its plenary session in Brussels on 1-2 December on the grounds that a decision is urgently needed to meet the deadline set by the USA under its Visa Waiver Programme for:
"authentication idendifiers that comply with applicable biometric identifying standards established by the International Civil Aviation Organisation"
This begs a fundamental question as the ICAO standard says:
"Facial recognition was selected as the globally interoperable biometric for machine-assisted identity confirmation with MRTDs [Machine Readable Travel Documents]"
"Facial recognition" can be met by the simple digitisation of current passport photos - this is not a biometric. "Facial recognition", or "facial image" in the Council's draft, can refer either to simple digitisation or to a "facial scan" which is a biometric (the scan collects up to 1,820 characteristics from each individuals face). "Facial recognition" not fingerprints were selected as the global standard by the ICAO.
US demands can be met by the Council's old draft - mandatory facial image and optional fingerprinting - so how can the decision be termed "urgent"? The USA does not require fingerprints to be used in foreign countries passports.
More importantly the purported legal basis for the measure concerns control of the EU's external borders not the demands of a non-EU state."
Yet the EC (Nice) Treaty says any EU legislation on the free movement of EU citizens:
"shall not apply to provisions on passports, identity cards, residence permits or any other such document"
which presumably means the EU are expressly forbidden from legislating to introduce compulsory biometrics on passports. But given enough lawyers and politicians the meaning can no doubt be reversed.
"Pension and benefit payments face disruption after what is being described as the biggest computer crash in government history left as many as 80,000 civil servants staring at blank screens and reverting to writing out giro cheques by hand in the latest blow to a hi-tech Whitehall revolution."
This is the system which will need to 'talk' to the proposed ID card system, that amongst other things according to David Blunkett, is going to solve the problem of benefit fraud. Mmmmm, a new IT catastrophe communicating with an old IT catastrophe. That sure does inspire a lot of confidence in the notion that ID cards will cut benefit fraud.
On another biometric related story, the EU Council of Ministers appear to be attempting ot pull a fast one by putting pressure on the EU Parliament to rush through the compulsory biometric passports for all EU citizens. Apparently the Dutch Presidency of the EU:
"are pushing hard for a decision at its plenary session in Brussels on 1-2 December on the grounds that a decision is urgently needed to meet the deadline set by the USA under its Visa Waiver Programme for:
"authentication idendifiers that comply with applicable biometric identifying standards established by the International Civil Aviation Organisation"
This begs a fundamental question as the ICAO standard says:
"Facial recognition was selected as the globally interoperable biometric for machine-assisted identity confirmation with MRTDs [Machine Readable Travel Documents]"
"Facial recognition" can be met by the simple digitisation of current passport photos - this is not a biometric. "Facial recognition", or "facial image" in the Council's draft, can refer either to simple digitisation or to a "facial scan" which is a biometric (the scan collects up to 1,820 characteristics from each individuals face). "Facial recognition" not fingerprints were selected as the global standard by the ICAO.
US demands can be met by the Council's old draft - mandatory facial image and optional fingerprinting - so how can the decision be termed "urgent"? The USA does not require fingerprints to be used in foreign countries passports.
More importantly the purported legal basis for the measure concerns control of the EU's external borders not the demands of a non-EU state."
Yet the EC (Nice) Treaty says any EU legislation on the free movement of EU citizens:
"shall not apply to provisions on passports, identity cards, residence permits or any other such document"
which presumably means the EU are expressly forbidden from legislating to introduce compulsory biometrics on passports. But given enough lawyers and politicians the meaning can no doubt be reversed.
The British Phonographic Industry are reporting that the "third quarter of 2004 concluded the best 12 months for album sales in UK record industry history." Good for them. Now about that argument regarding P2P networks doing irreparable damage to the industry...
Wednesday, November 24, 2004
Larry Lessig on Bytes and Bullets. Briefly - if P2P software, PC and hardware suppliers are to be held liable for copyright infringement engaged in by users of their products (as is proposed under pending legislation), are gun manufacturers going to be held liable for the deaths and injuries arising from the use of their products?
Good question but quite an emotive and legally complex one for the US, where the Constitution apparently gaurantees the right to bear arms.
Good question but quite an emotive and legally complex one for the US, where the Constitution apparently gaurantees the right to bear arms.
Michael Geist says "Copyright Reform is Not a Spectator Sport" in his call to arms to Canadian academics.
"It is time for teachers, researchers, education administrators, librarians and students to speak out loudly against proposed policies that threaten the use of the Internet within Canadian schools by establishing unnecessary copyright license fees that seek to extend the term of copyright to the detriment of Canadian historians, and that introduce new legal protections that threaten to chill scientific and security research. They should further seize this opportunity by presenting a positive vision of reform that could benefit Canadian research and the broader community."
Actually, it's time UK academics also got involved. More power to his elbow.
"It is time for teachers, researchers, education administrators, librarians and students to speak out loudly against proposed policies that threaten the use of the Internet within Canadian schools by establishing unnecessary copyright license fees that seek to extend the term of copyright to the detriment of Canadian historians, and that introduce new legal protections that threaten to chill scientific and security research. They should further seize this opportunity by presenting a positive vision of reform that could benefit Canadian research and the broader community."
Actually, it's time UK academics also got involved. More power to his elbow.
Well, David Blunkett has got his way on ID cards with his plans to introduce the scheme included in the Queen's speech yesterday.
"The home secretary believes identity cards will help tackle international terrorism, identity theft and help the work of the UK immigration services."
Laudable aims, you would think but let's look at some of the planned verification uses of the ID cards that civil servants in the Home Office are working on:
Preventing underage sales of DVDs, cigarettes, lottery tickets and alcohol (also laudable but do we need a compulsory national ID card for this?)
Enforcing parking fines
Banking service and mortgage applications
TV license and car tax applications
Applications for benefits
Applications for driving tests
Access to public services such as GPs or hospitals
Applications for gun licenses
You can just hear those frightened international terrorists - uh oh, we better not try the UK, they'll make us pay our parking fines and we might find it hard to get a TV license. This would be amusing if it wasn't so serious.
"The home secretary believes identity cards will help tackle international terrorism, identity theft and help the work of the UK immigration services."
Laudable aims, you would think but let's look at some of the planned verification uses of the ID cards that civil servants in the Home Office are working on:
Preventing underage sales of DVDs, cigarettes, lottery tickets and alcohol (also laudable but do we need a compulsory national ID card for this?)
Enforcing parking fines
Banking service and mortgage applications
TV license and car tax applications
Applications for benefits
Applications for driving tests
Access to public services such as GPs or hospitals
Applications for gun licenses
You can just hear those frightened international terrorists - uh oh, we better not try the UK, they'll make us pay our parking fines and we might find it hard to get a TV license. This would be amusing if it wasn't so serious.
Malcolm Gladwell, the New Yorker journalist I mentioned yesterday, has done an interesting radio interview about the apparent plagiarism of one of his news profiles about a well know psychologist. He's joined in the studio by law professor Justin Hughes who provides a very clear analysis of intellectual property law.
Tuesday, November 23, 2004
John on Repetitive Failure Syndrome - or RFS. Spot on as ever:
"IT systems fail because those who design them don't understand the organisations into which the IT has to fit, seem incapable of involving the organisation's people meaningfully in the design process, fail to keep them informed of progress and pay little attention to training and support. It's laughably simple - yet time and again nobody does any of these things properly."
I'd just add that the decision makers within organisations who commission these IT systems get dazzled by vendors claims of magic and singularly fail to specify what they actually want them to do.
"IT systems fail because those who design them don't understand the organisations into which the IT has to fit, seem incapable of involving the organisation's people meaningfully in the design process, fail to keep them informed of progress and pay little attention to training and support. It's laughably simple - yet time and again nobody does any of these things properly."
I'd just add that the decision makers within organisations who commission these IT systems get dazzled by vendors claims of magic and singularly fail to specify what they actually want them to do.
James Boyle in the FT:
"Imagine a process of reviewing prescription drugs which goes like this: representatives from the drug company come to the regulators and argue that their drug works well and should be approved. They have no evidence of this beyond a few anecdotes about people who want to take it and perhaps some very simple models of how the drug might affect the human body. The drug is approved. No trials, no empirical evidence of any kind, no follow-up. Or imagine a process of making environmental regulations in which there were no data, and no attempts to gather data, about the effects of the particular pollutants being studied. Even the harshest critics of drug regulation or environmental regulation would admit we generally do better than this. But this is often the way we make intellectual property policy."
Read the article to get his wider perspective of the issue and his specific concerns relating to the 1996 EU Database directive and lobbyist attempts to push similar legislation in the US without any supporting empirical evidence about the potential benefits or disadvantages. I particularly like James' rules of thumb for regulators:
1. "when someone with a profit margin over 20% asks you for additional monopoly protection, pause before agreeing."
2. "Do no harm! Do not create rights without strong evidence that the incentive effect is worth the anti-competitive cost."
"Imagine a process of reviewing prescription drugs which goes like this: representatives from the drug company come to the regulators and argue that their drug works well and should be approved. They have no evidence of this beyond a few anecdotes about people who want to take it and perhaps some very simple models of how the drug might affect the human body. The drug is approved. No trials, no empirical evidence of any kind, no follow-up. Or imagine a process of making environmental regulations in which there were no data, and no attempts to gather data, about the effects of the particular pollutants being studied. Even the harshest critics of drug regulation or environmental regulation would admit we generally do better than this. But this is often the way we make intellectual property policy."
Read the article to get his wider perspective of the issue and his specific concerns relating to the 1996 EU Database directive and lobbyist attempts to push similar legislation in the US without any supporting empirical evidence about the potential benefits or disadvantages. I particularly like James' rules of thumb for regulators:
1. "when someone with a profit margin over 20% asks you for additional monopoly protection, pause before agreeing."
2. "Do no harm! Do not create rights without strong evidence that the incentive effect is worth the anti-competitive cost."
The British Medical Association are boycotting the new NHS computerised hospital appointment booking system due to fears about confidentiality of patient data. With government pumping about £6 billion into NHS computer systems and a general election looming there will be more than a few irritated government ministers.
"Something Borrowed" from the New Yorker tells an interesting story of Bryony Lavery's play "Frozen" and allegations of plagiarism. The author of the piece, Malcolm Gladwell, is quite sympathetic towards the playwright, despite apparently writing the piece that was one of Ms Lavery's main sources for the play.
Nice round-up at eGov monitor of David Blunkett's speech last week where he was extolling the virtues of ID cards and criticising supermarket loyalty cards. Also includes a note about other speeches made on the day including that of the Information Commissioner, Richard Thomas, who has serious concerns about the government's proposals.
"Microsoft alum Nathan Myhrvold runs a firm that doesn't make anything, but it's hoarding the key to a new business age: intellectual property" So says this piece at NewsWeek.
In yet another attempt to shift the goalposts on ID cards, David Blunkett tried a new tactic last week of expressing concern for personal privacy and calling for more checks on supermarket loyalty card data collection.
"In a speech, Mr Blunkett said the cards produced key details about people's shopping habits but were accepted because they were run by private firms.
People should not distrust ID cards because they are a state idea, he said."
His concern for our privacy is touching but like Mr Blunkett I don't have a supermarket loyalty card. I wonder why he doesn't have one?
"The scheme would be worthwhile if it reinforced identity and citizenship, he said. If not, he would "be remembered as one of the biggest political failures that Britain has ever produced"."
Political failure is right and by the time that comes to be generally accepted a huge amount of money will have been flushed away (billions of pounds), not to mention the other negative effects.
"In a speech, Mr Blunkett said the cards produced key details about people's shopping habits but were accepted because they were run by private firms.
People should not distrust ID cards because they are a state idea, he said."
His concern for our privacy is touching but like Mr Blunkett I don't have a supermarket loyalty card. I wonder why he doesn't have one?
"The scheme would be worthwhile if it reinforced identity and citizenship, he said. If not, he would "be remembered as one of the biggest political failures that Britain has ever produced"."
Political failure is right and by the time that comes to be generally accepted a huge amount of money will have been flushed away (billions of pounds), not to mention the other negative effects.
It seems that the recent breaking of the Internet data transmission record has energised the MPAA into starting talks with high speed Internet researchers, with view to keeping abreast of developments.
Some researchers at the University of California Berkeley have theorised, using statistics and publicly available election data, that President Bush may have got 130000 or more votes in Florida than he was entitled to, due to "irregularites associated with electronic voting machines". Bush won Florida by 350000 votes, so it would not have changed the outcome but the researchers suggest there is a need to examine currently depolyed evoting systems with a view to improving them.
How Hilary learned to love Larry - Hilary Rosen, former chief of the RIAA, has become persuaded of the value of creative commons.
The Internet Archive have offered to host creative commons licenced audio and video files free of charge. Creative Commons have taken advantage by creating software called the Publisher to let you drag and drop files into the Internet Archive.
Thursday, November 18, 2004
Ed Felten's recent Princeton President's Lecture, "Rip, Mix, Burn, Sue: Technology, Politics, and the Fight to Control Digital Media" is now online. He links to it from his Freedom-to Tinker blog.
Frank Field says Google are planning a new service for scientists and academic researchers.
"Google Scholar, which was scheduled to go online Wednesday evening at scholar.google.com, is a result of the company’s collaboration with a number of scientific and academic publishers and is intended as a first stop for researchers looking for scholarly literature like peer-reviewed papers, books, abstracts and technical reports.
Google executives declined to say how many additional documents and books had been indexed and made searchable through the service. While the great majority of recent scholarly papers and periodicals are indexed on the Web, many have not been easily accessible to the public."
"Google Scholar, which was scheduled to go online Wednesday evening at scholar.google.com, is a result of the company’s collaboration with a number of scientific and academic publishers and is intended as a first stop for researchers looking for scholarly literature like peer-reviewed papers, books, abstracts and technical reports.
Google executives declined to say how many additional documents and books had been indexed and made searchable through the service. While the great majority of recent scholarly papers and periodicals are indexed on the Web, many have not been easily accessible to the public."
Wednesday, November 17, 2004
Apparently nearly a thousand people have endorsed an online petition objecting to the implementation of a national identity card in the UK.
The British Airports Authority have lost in their attempt to get control of the gatwick.com domain name. A WIPO UDRP arbitration panel decided that
"The Respondent has never used the Complainant’s trademark. His website content is controlled by him and his US associates as an independent business, operating separately from the Complainant’s airport business. Using his own proprietary rights, he is therefore providing a legitimate directory of services in the Gatwick sub-regional area. He receives an income from this business, which he has the right to operate.
There is no risk of consumers being misled into believing that his site is an official BAA website. It does not display the BAA name nor indicate to those searching the Internet that they have arrived at the Gatwick Airport site. The Complainant cannot prove that the Respondent deliberately selected the name with the sole intention of gaining Internet traffic intended for the Complainant. He has had honest and fair use of the website address for 8 years without opposition from the Complainant.
The Respondent is a software engineer who registered the disputed domain name to provide a directory for a large variety of businesses in the area, initially through emails and public information sites."
In addition the panel refused to pass any judgement on the claim by the owner of the domain, Bob Larkin, that BAA had engaged in a dirty tricks campaign to try and wrestle the domain from his control. They also said BAA has not registered the trademark in the Gatwick name until a number of years after Gatwick.com was registered as a domain name.
"The Respondent has never used the Complainant’s trademark. His website content is controlled by him and his US associates as an independent business, operating separately from the Complainant’s airport business. Using his own proprietary rights, he is therefore providing a legitimate directory of services in the Gatwick sub-regional area. He receives an income from this business, which he has the right to operate.
There is no risk of consumers being misled into believing that his site is an official BAA website. It does not display the BAA name nor indicate to those searching the Internet that they have arrived at the Gatwick Airport site. The Complainant cannot prove that the Respondent deliberately selected the name with the sole intention of gaining Internet traffic intended for the Complainant. He has had honest and fair use of the website address for 8 years without opposition from the Complainant.
The Respondent is a software engineer who registered the disputed domain name to provide a directory for a large variety of businesses in the area, initially through emails and public information sites."
In addition the panel refused to pass any judgement on the claim by the owner of the domain, Bob Larkin, that BAA had engaged in a dirty tricks campaign to try and wrestle the domain from his control. They also said BAA has not registered the trademark in the Gatwick name until a number of years after Gatwick.com was registered as a domain name.
Seth Schoen uses the changes TiVo have embraced (ie drm) as a platform to explore the convergence of computers and consumer electronics devices, on Dave Farber's interesting people list.
"the smart cards and set-top boxes would decrypt the programming as it came into
your house and verify that you were authorized to receive it. But
then they would encrypt it again in order to enforce _copyright
holder_ policies about what you could do with it after you had
received it. That re-encryption makes the new generation of pay
TV services (after you've paid for them) different from free TV
services because the pay TV services can be subject to additional
controls after the point of lawful reception.
The FCC was asked to ban this re-encryption -- in a sense, to limit
the use of encryption under the 1996 Act to making sure that you
initially pay for pay TV, not to controlling what you do with it
afterward. In a decision in 2000, the Commission declined to do
this...
This decision was unfortunate in its implications because it vastly
increased the potential leverage that movie studios would have over
technology companies. If the FCC had forbidden re-encryption of
pay TV programming, companies like TiVo would not need to negotiate
with movie studios (or broadcast groups) in order to get lawful access
to pay TV...
And TiVo has chosen to do exactly that...
Of course, that negotiation has come at a corresponding cost: TiVo
implements digital rights management, takes steps (to date not very
strong steps) to control reverse engineering and aftermark
modifications, and generally implements a lot of restrictions on
recorded programming...
TiVo customers are obviously happy enough with this strategy that they
keep buying TiVos in large numbers, although there is a devoted
community of "TiVo hacking" enthusiasts who learn how to add
functionality to their TiVos -- and they have a very complicated
relationship with these restrictions...
There is an alternative -- if you only want to receive unencrypted
TV (free-to-air terrestrial broadcasting and basic-tier cable in
the U.S., and possibly these plus certain types of pay TV in Europe).
You can use a personal computer as a PVR by putting one or more TV
cards inside. Then you can run software that turns the PC into a PVR.
One of the most impressive programs along these lines is an open
source package called MythTV
http://www.mythtv.org/
which has already implemented functionality competitive with TiVo's
PVR functionality, plus features that TiVo won't touch...
The major movie
studios have persuaded the FCC to change the rules for unencrypted
digital television to apply DRM there, in the "broadcast flag" or
"digital broadcast content protection" proceeding. (That's why I
say that the FCC is unlikely to change the DRM requirement for
cable TV!) The result is that the equipment that makes a program
like MythTV work with U.S. digital television will be illegal to
manufacture here from July 1, 2005. If you want to use something
like MythTV for digital TV in the future, your best bet is to buy
the equipment before then. MythTV works well with the pcHDTV
HD-3000 card, which is finally shipping:
http://www.pchdtv.com/ ...
I would not get so worked up about any one action that TiVo takes.
We know their strategy, and it involves co-operating with movie
studios to impose restrictions on end users. The reasons why they
do this are not mysterious. If you want to criticize TiVo -- and
that's fine with me! -- the right place to start is much earlier in
the company's history.
But if you actually want to opt out of the DRM game, it seems to
me that the thing to do is to spread the remaining unrestricted
technologies as far and wide as possible while they're still legal...
I've often thought of writing an essay called "converging up,
converging down?" about the ambiguity of the "convergence" ideal.
PCs and consumer electronics (CE) devices have very different
characteristics -- beyond just the technical differences, veering
into cultural differences -- even though today they are usually
made out of the same chips. Among other things, PCs in the past
were friendlier to user innovation and third party innovation; you
could teach them to do more. CE devices in the past were much more
single-function and fixed-function, and upgrades (if available)
typically had to be provided by the manufacturer. Ultimately PCs
were much more under end user control and CE devices much more
under the manuacturer's control. Movie studios have appreciated
this distinction; they have better, older, and closer relationships
with the CE industries than with the PC industries...
If these device families actually do "converge", on whose terms
will they converge? Will the PC grow more like a DVD player (or
a TiVo), or will the PVR and cell phone grow more like PCs? And,
since "being like a PC" or "being like a CE box" is not just a
single dimension, in _which ways_ will they become more like one
another? Which particular characteristics will each now imitate...
In terms of end user control, there is an opportunity for CE devices
to converge up (enhancing customers' control) and a risk of PC
devices converging down (eroding it). I think the world the
entertainment companies have built is providing exactly the wrong
incentive at every point as this question is worked out."
Spread unrestricted technologies as far and wide as possible whilst they are still legal? Now where have I heard that before? Well Charles Nesson at the Berkman Center has taken this position the introduction of controls to the Internet - the message being don't waste your energy complaining about those terrible entities introducing restrictions for their own ends but rather get on with using the Net creatively and demonstrating to the world what potential it has.
"the smart cards and set-top boxes would decrypt the programming as it came into
your house and verify that you were authorized to receive it. But
then they would encrypt it again in order to enforce _copyright
holder_ policies about what you could do with it after you had
received it. That re-encryption makes the new generation of pay
TV services (after you've paid for them) different from free TV
services because the pay TV services can be subject to additional
controls after the point of lawful reception.
The FCC was asked to ban this re-encryption -- in a sense, to limit
the use of encryption under the 1996 Act to making sure that you
initially pay for pay TV, not to controlling what you do with it
afterward. In a decision in 2000, the Commission declined to do
this...
This decision was unfortunate in its implications because it vastly
increased the potential leverage that movie studios would have over
technology companies. If the FCC had forbidden re-encryption of
pay TV programming, companies like TiVo would not need to negotiate
with movie studios (or broadcast groups) in order to get lawful access
to pay TV...
And TiVo has chosen to do exactly that...
Of course, that negotiation has come at a corresponding cost: TiVo
implements digital rights management, takes steps (to date not very
strong steps) to control reverse engineering and aftermark
modifications, and generally implements a lot of restrictions on
recorded programming...
TiVo customers are obviously happy enough with this strategy that they
keep buying TiVos in large numbers, although there is a devoted
community of "TiVo hacking" enthusiasts who learn how to add
functionality to their TiVos -- and they have a very complicated
relationship with these restrictions...
There is an alternative -- if you only want to receive unencrypted
TV (free-to-air terrestrial broadcasting and basic-tier cable in
the U.S., and possibly these plus certain types of pay TV in Europe).
You can use a personal computer as a PVR by putting one or more TV
cards inside. Then you can run software that turns the PC into a PVR.
One of the most impressive programs along these lines is an open
source package called MythTV
http://www.mythtv.org/
which has already implemented functionality competitive with TiVo's
PVR functionality, plus features that TiVo won't touch...
The major movie
studios have persuaded the FCC to change the rules for unencrypted
digital television to apply DRM there, in the "broadcast flag" or
"digital broadcast content protection" proceeding. (That's why I
say that the FCC is unlikely to change the DRM requirement for
cable TV!) The result is that the equipment that makes a program
like MythTV work with U.S. digital television will be illegal to
manufacture here from July 1, 2005. If you want to use something
like MythTV for digital TV in the future, your best bet is to buy
the equipment before then. MythTV works well with the pcHDTV
HD-3000 card, which is finally shipping:
http://www.pchdtv.com/ ...
I would not get so worked up about any one action that TiVo takes.
We know their strategy, and it involves co-operating with movie
studios to impose restrictions on end users. The reasons why they
do this are not mysterious. If you want to criticize TiVo -- and
that's fine with me! -- the right place to start is much earlier in
the company's history.
But if you actually want to opt out of the DRM game, it seems to
me that the thing to do is to spread the remaining unrestricted
technologies as far and wide as possible while they're still legal...
I've often thought of writing an essay called "converging up,
converging down?" about the ambiguity of the "convergence" ideal.
PCs and consumer electronics (CE) devices have very different
characteristics -- beyond just the technical differences, veering
into cultural differences -- even though today they are usually
made out of the same chips. Among other things, PCs in the past
were friendlier to user innovation and third party innovation; you
could teach them to do more. CE devices in the past were much more
single-function and fixed-function, and upgrades (if available)
typically had to be provided by the manufacturer. Ultimately PCs
were much more under end user control and CE devices much more
under the manuacturer's control. Movie studios have appreciated
this distinction; they have better, older, and closer relationships
with the CE industries than with the PC industries...
If these device families actually do "converge", on whose terms
will they converge? Will the PC grow more like a DVD player (or
a TiVo), or will the PVR and cell phone grow more like PCs? And,
since "being like a PC" or "being like a CE box" is not just a
single dimension, in _which ways_ will they become more like one
another? Which particular characteristics will each now imitate...
In terms of end user control, there is an opportunity for CE devices
to converge up (enhancing customers' control) and a risk of PC
devices converging down (eroding it). I think the world the
entertainment companies have built is providing exactly the wrong
incentive at every point as this question is worked out."
Spread unrestricted technologies as far and wide as possible whilst they are still legal? Now where have I heard that before? Well Charles Nesson at the Berkman Center has taken this position the introduction of controls to the Internet - the message being don't waste your energy complaining about those terrible entities introducing restrictions for their own ends but rather get on with using the Net creatively and demonstrating to the world what potential it has.
Somebody has asked me if there is a quick way of understanding Larry Lessig's ideas on copyright. Well he's done lots of excellent public lectures and interviews, many available on the Internet, such as this KQED debate with intellectual property lawyer, Jeffrey Knowles.
Tuesday, November 16, 2004
Ernest Miller is dreaming about the server in the closet of every home.
"I remain enamored of a concept I think of as the "server in the closet." I believe that, eventually, every home will have a fairly sophisticated server as the locus of the many networked device in the home. Everything from the VoIP phone system, presence-enabled media (IM), multimedia (podcasts, broadcatch), etc., etc., etc. There will be fat and thin clients in the home, all of which can be (but not required to) coordinate through home's central server. More importantly, this "server in the closet" will be part of bi-directional communication with the rest of the world wide network, turning every home not only into a receiver, but a transmitter."
"I remain enamored of a concept I think of as the "server in the closet." I believe that, eventually, every home will have a fairly sophisticated server as the locus of the many networked device in the home. Everything from the VoIP phone system, presence-enabled media (IM), multimedia (podcasts, broadcatch), etc., etc., etc. There will be fat and thin clients in the home, all of which can be (but not required to) coordinate through home's central server. More importantly, this "server in the closet" will be part of bi-directional communication with the rest of the world wide network, turning every home not only into a receiver, but a transmitter."
James Grimmelmann has some strong words about "Two Skirmishes in the DRM Wars: Half-Life 2 and Halo 2" over at Lawmeme:
"people who tried to log in to Microsoft's X-Box Live service to play Halo 2 with hacked X-Boxes have found their accounts suspended.
And on the other hand, copies of Half-Life 2 have started hitting retail shelves in advance of the "official" release date of November 16. Gamers who rush out to buy (sometimes extortionately priced) copies early, however, are finding themselves stymied: the game won't install without verification from Steam, the online platform Valve (Half-Life 2's creator) uses to deliver its games and coordinate online play. But Steam won't turn the game on until the 16th, per instructions from Vivendi (Half-Life 2's distributor).
Let's call these schemes by their right name: these are both examples of digital rights management working as intended. This is the future of digital media, here today: your copy of the product checks in with home base to determine what you can and can't do with it. And when the company that runs home base decides that it doesn't like what you're doing (be it tampering with your device's hardware or trying--oh the temerity!--to play a game a few days early), it can cut you off at the knees and disable your access to the game. That's what DRM does. Hey, gamers: you're getting a taste of the treatment the music industry has planned for us all. Do you like it?
Now, not all DRM is created equal. Microsoft's choice here was reasonably fair, I think. You can do whatever you want to your 'Box, but don't expect to be able to use a modded 'Box to compete against people who are playing by the rules. I look at X-Box Live as a kind of virtual world; it's not unreasonable for Microsoft to act as a referee by insisting that everyone who enters that world enter it on the same terms...
...The Steam lockout is more frightening, though. First off, note why it is that Valve won't turn the key: a contractual dispute with Vivendi. In fact, Valve and Vivendi are locked in a fierce legal struggle over distribution terms, with Vivendi furious that Steam might undercut its revenues from store-based sales. That's right: your ability to play Half-Life 2 is being held hostage to a licensing fight between two corporations."
"people who tried to log in to Microsoft's X-Box Live service to play Halo 2 with hacked X-Boxes have found their accounts suspended.
And on the other hand, copies of Half-Life 2 have started hitting retail shelves in advance of the "official" release date of November 16. Gamers who rush out to buy (sometimes extortionately priced) copies early, however, are finding themselves stymied: the game won't install without verification from Steam, the online platform Valve (Half-Life 2's creator) uses to deliver its games and coordinate online play. But Steam won't turn the game on until the 16th, per instructions from Vivendi (Half-Life 2's distributor).
Let's call these schemes by their right name: these are both examples of digital rights management working as intended. This is the future of digital media, here today: your copy of the product checks in with home base to determine what you can and can't do with it. And when the company that runs home base decides that it doesn't like what you're doing (be it tampering with your device's hardware or trying--oh the temerity!--to play a game a few days early), it can cut you off at the knees and disable your access to the game. That's what DRM does. Hey, gamers: you're getting a taste of the treatment the music industry has planned for us all. Do you like it?
Now, not all DRM is created equal. Microsoft's choice here was reasonably fair, I think. You can do whatever you want to your 'Box, but don't expect to be able to use a modded 'Box to compete against people who are playing by the rules. I look at X-Box Live as a kind of virtual world; it's not unreasonable for Microsoft to act as a referee by insisting that everyone who enters that world enter it on the same terms...
...The Steam lockout is more frightening, though. First off, note why it is that Valve won't turn the key: a contractual dispute with Vivendi. In fact, Valve and Vivendi are locked in a fierce legal struggle over distribution terms, with Vivendi furious that Steam might undercut its revenues from store-based sales. That's right: your ability to play Half-Life 2 is being held hostage to a licensing fight between two corporations."
One of my students has reminded me that the November issue (12.11) of Wired magazine comes with a CD containing a collection of songs released under a creative commons license.
Microsoft have launched a global egovernment network, called the "Solutions Sharing Network" or SSN.
In the same spirit of sharing, the NHS National Programme for IT (NPFIT)will be rolling out the PR department next year to let people know about the new NHS IT systems and the implications regarding sharing of personal data. I wonder if they'll be referring to doctors concerns about the lack of security of records the new systems may be displaying? Sorry - cheap shot - but I couldn't resist it.
In the same spirit of sharing, the NHS National Programme for IT (NPFIT)will be rolling out the PR department next year to let people know about the new NHS IT systems and the implications regarding sharing of personal data. I wonder if they'll be referring to doctors concerns about the lack of security of records the new systems may be displaying? Sorry - cheap shot - but I couldn't resist it.
Sun are trying the open source business model with their new operating system, Solaris 10, which they are giving away free, in the hope that it will greatly expand the user base.
Cindy Cohn and Annalee Newitz at the EFF have written a very interesting and thoughtful paper on spam:
Noncommercial Email Lists:Collateral Damage in the Fight Against Spam, suggesting that non commercial mailing lists are suffering disproportionate "collateral damage" in the fight against spam.
My own organisation, the Open University, uses spam management filters and I'm grateful for these because I deal with tens of thousands of emails each year. The result of this avalanche of email is that unless an individual email gains my attention virtually immediately it gets deleted. And anything flagged by spam filters gets instantly deleted.
Cohn and Newitz are right to question the principles, processes and mechanics of spam filtering tools but just as we have information management systems in organisations to filter the right bits of paper and the right phone calls through to the most appropriate people we need information management systems in the electronic realm. How to square that with a sensitivity to be aware of and committment to avoid censorship and maintenance of the end to end architecture of the Net is a complex question to which there are no simple answers.
Noncommercial Email Lists:Collateral Damage in the Fight Against Spam, suggesting that non commercial mailing lists are suffering disproportionate "collateral damage" in the fight against spam.
My own organisation, the Open University, uses spam management filters and I'm grateful for these because I deal with tens of thousands of emails each year. The result of this avalanche of email is that unless an individual email gains my attention virtually immediately it gets deleted. And anything flagged by spam filters gets instantly deleted.
Cohn and Newitz are right to question the principles, processes and mechanics of spam filtering tools but just as we have information management systems in organisations to filter the right bits of paper and the right phone calls through to the most appropriate people we need information management systems in the electronic realm. How to square that with a sensitivity to be aware of and committment to avoid censorship and maintenance of the end to end architecture of the Net is a complex question to which there are no simple answers.
Monday, November 15, 2004
Bruce Schneier on electronic voting, essential reading.
"After 2000, voting machine problems made
international headlines. The government appropriated money to fix the
problems nationwide. Unfortunately, electronic voting machines --
although presented as the solution -- have largely made the problem
worse. This doesn't mean that these machines should be abandoned, but
they need to be designed to increase both their accuracy, and people's
trust in their accuracy. This is difficult, but not impossible...
...Computer security experts are unanimous on what to do. (Some voting
experts disagree, but I think we're all much better off listening to
the computer security experts. The problems here are with the
computer, not with the fact that the computer is being used in a voting
application.) And they have two recommendations:
1. DRE machines must have a voter-verifiable paper audit trails
(sometimes called a voter-verified paper ballot). This is a paper
ballot printed out by the voting machine, which the voter is allowed to
look at and verify. He doesn't take it home with him. Either he looks
at it on the machine behind a glass screen, or he takes the paper and
puts it into a ballot box. The point of this is twofold. One, it
allows the voter to confirm that his vote was recorded in the manner he
intended. And two, it provides the mechanism for a recount if there
are problems with the machine.
2. Software used on DRE machines must be open to public
scrutiny. This also has two functions. One, it allows any interested
party to examine the software and find bugs, which can then be
corrected. This public analysis improves security. And two, it
increases public confidence in the voting process. If the software is
public, no one can insinuate that the voting system has unfairness
built into the code. (Companies that make these machines regularly
argue that they need to keep their software secret for security
reasons. Don't believe them. In this instance, secrecy has nothing to
do with security.)...
...Proponents of DREs often point to successful elections as "proof" that
the systems work. That completely misses the point. The fear is that
errors in the software -- either accidental or deliberately introduced
-- can undetectably alter the final tallies. An election without any
detected problems is no more a proof the system is reliable and secure
than a night that no one broke into your house is proof that your door
locks work. Maybe no one tried, or maybe someone tried and
succeeded...and you don't know it.
Even if we get the technology right, we still won't be done. If the
goal of a voting system is to accurately translate voter intent into a
final tally, the voting machine is only one part of the overall
system. In the 2004 U.S. election, problems with voter registration,
untrained poll workers, ballot design, and procedures for handling
problems resulted in far more votes not being counted than problems
with the technology. But if we're going to spend money on new voting
technology, it makes sense to spend it on technology that makes the
problem easier instead of harder."
"After 2000, voting machine problems made
international headlines. The government appropriated money to fix the
problems nationwide. Unfortunately, electronic voting machines --
although presented as the solution -- have largely made the problem
worse. This doesn't mean that these machines should be abandoned, but
they need to be designed to increase both their accuracy, and people's
trust in their accuracy. This is difficult, but not impossible...
...Computer security experts are unanimous on what to do. (Some voting
experts disagree, but I think we're all much better off listening to
the computer security experts. The problems here are with the
computer, not with the fact that the computer is being used in a voting
application.) And they have two recommendations:
1. DRE machines must have a voter-verifiable paper audit trails
(sometimes called a voter-verified paper ballot). This is a paper
ballot printed out by the voting machine, which the voter is allowed to
look at and verify. He doesn't take it home with him. Either he looks
at it on the machine behind a glass screen, or he takes the paper and
puts it into a ballot box. The point of this is twofold. One, it
allows the voter to confirm that his vote was recorded in the manner he
intended. And two, it provides the mechanism for a recount if there
are problems with the machine.
2. Software used on DRE machines must be open to public
scrutiny. This also has two functions. One, it allows any interested
party to examine the software and find bugs, which can then be
corrected. This public analysis improves security. And two, it
increases public confidence in the voting process. If the software is
public, no one can insinuate that the voting system has unfairness
built into the code. (Companies that make these machines regularly
argue that they need to keep their software secret for security
reasons. Don't believe them. In this instance, secrecy has nothing to
do with security.)...
...Proponents of DREs often point to successful elections as "proof" that
the systems work. That completely misses the point. The fear is that
errors in the software -- either accidental or deliberately introduced
-- can undetectably alter the final tallies. An election without any
detected problems is no more a proof the system is reliable and secure
than a night that no one broke into your house is proof that your door
locks work. Maybe no one tried, or maybe someone tried and
succeeded...and you don't know it.
Even if we get the technology right, we still won't be done. If the
goal of a voting system is to accurately translate voter intent into a
final tally, the voting machine is only one part of the overall
system. In the 2004 U.S. election, problems with voter registration,
untrained poll workers, ballot design, and procedures for handling
problems resulted in far more votes not being counted than problems
with the technology. But if we're going to spend money on new voting
technology, it makes sense to spend it on technology that makes the
problem easier instead of harder."
It's a subscription only sevice but the Wall Street Journal is reporting that the cross jurisdictional Gutnick v Dow Jones internet defamation case has been settled out of court. Dow Jones lost their fight to have the Australian courts declare that the case should have been heard in the US. Interesting timing in the light of the UK Court of Appeal decision in the Don King v Lennox Lewis case last week.
Coincidentally, a Canadian archaeologist was awarded large damages in another Net libel case last week. The report claims there has been very little case law in the area of Internet defamation but actually there have been quite a few cases in the US streching back to Cubby v Compuserve in the early 1990s, Stratton v Prodigy and a string of others since. In Autralia Gutnick v Dow Jones has been the precendent setter and in the UK it was Godfrey v Demon. So there are plenty of legal arguments available for Canadian judges to peruse on matters of principle and law, albeit from different juridictions.
Coincidentally, a Canadian archaeologist was awarded large damages in another Net libel case last week. The report claims there has been very little case law in the area of Internet defamation but actually there have been quite a few cases in the US streching back to Cubby v Compuserve in the early 1990s, Stratton v Prodigy and a string of others since. In Autralia Gutnick v Dow Jones has been the precendent setter and in the UK it was Godfrey v Demon. So there are plenty of legal arguments available for Canadian judges to peruse on matters of principle and law, albeit from different juridictions.
Rohde to Srebrenica is a human rights case study project of the Columbia Graduate School of
Journalism, based on David Rohde’s reporting on mass graves in Bosnia.
Journalism, based on David Rohde’s reporting on mass graves in Bosnia.
Computer loophole hits hi-tech NHS trial says the Sunday Times. Apparently there are security problems with the appointments booking system, which gives all doctors access to all GPs' patient records and the facility to edit them.
Also from Sunday, Dan Gillmor laments Microsoft's ability to buy its way out of trouble.
"Microsoft's $536 million settlement with Novell, which had sued on antitrust claims, was big money for Novell. It was less than pocket change for Microsoft, which at last count had nearly $65 billion in cash and short-term investments -- and not a dime of debt.
In a slew of financial settlements with companies Microsoft has trampled over the years, the payout for wrongdoing is roughly $3 billion to date. That represents about three months of profit for a company that literally can't spend its cash fast enough, and is giving shareholders a one-time bonus of $3 a share early next month. That payout will put only a temporary dent in the cash hoard.
What does all this mean? Simple. When governments fail to enforce the rules of capitalism, monopoly profits can buy one's way out of almost any kind of trouble...
...n a report last week about Microsoft's new search technology, for example, the Wall Street Journal observed: ``Microsoft brings a big wallet and a track record of coming from behind in areas that it deems critical. The company belatedly recognized the importance of the Internet and ultimately steamrolled Netscape Communications in Web browser software.''
You'll note there's not even a hint here that one of Microsoft's most essential tactics in achieving that browser dominance was breaking the law. Even the best and most important business newspaper in the world can't be bothered to remember history."
Not Microsoft's biggest fan.
Also from Sunday, Dan Gillmor laments Microsoft's ability to buy its way out of trouble.
"Microsoft's $536 million settlement with Novell, which had sued on antitrust claims, was big money for Novell. It was less than pocket change for Microsoft, which at last count had nearly $65 billion in cash and short-term investments -- and not a dime of debt.
In a slew of financial settlements with companies Microsoft has trampled over the years, the payout for wrongdoing is roughly $3 billion to date. That represents about three months of profit for a company that literally can't spend its cash fast enough, and is giving shareholders a one-time bonus of $3 a share early next month. That payout will put only a temporary dent in the cash hoard.
What does all this mean? Simple. When governments fail to enforce the rules of capitalism, monopoly profits can buy one's way out of almost any kind of trouble...
...n a report last week about Microsoft's new search technology, for example, the Wall Street Journal observed: ``Microsoft brings a big wallet and a track record of coming from behind in areas that it deems critical. The company belatedly recognized the importance of the Internet and ultimately steamrolled Netscape Communications in Web browser software.''
You'll note there's not even a hint here that one of Microsoft's most essential tactics in achieving that browser dominance was breaking the law. Even the best and most important business newspaper in the world can't be bothered to remember history."
Not Microsoft's biggest fan.
According to the Washington Post, the US Transportation Security Administration has ordered 72 airlines to hand over passenger data to test their new screening program Secure Flight.
The reporter worries that "Any U.S. carrier that shared information with the TSA about European passengers on flights overseas could be placed in a legal bind between the two continents", so presumably is not aware of EU Commissioner Bolkestein's agreement with the US on airline pasenger data sharing. OF course that agreement is currently being challenged by the EU parliament in the European Court of Justice, so her cocerns may well become substantive if the Court does eventually outlaw the agreement.
The reporter worries that "Any U.S. carrier that shared information with the TSA about European passengers on flights overseas could be placed in a legal bind between the two continents", so presumably is not aware of EU Commissioner Bolkestein's agreement with the US on airline pasenger data sharing. OF course that agreement is currently being challenged by the EU parliament in the European Court of Justice, so her cocerns may well become substantive if the Court does eventually outlaw the agreement.
Subscribe to:
Posts (Atom)