Tuesday, December 06, 2005

EDRI

The latest and possibly the last EDRI newsletter has been published.

Contents:

Urgent call for pledges of support for EDRI-gram
1. Final push for single EP vote on data retention
2. EDRI and PI call on EP to reject data retention
3. Polish plans for 15 years mandatory data retention
4. Urgency procedure for draft French anti-terrorism law
5. New anti-terrorism measures in Denmark
6. Launch of Digital Rights Ireland
7. Illegal video surveillance on Slovenian motorways
8. Post-WSIS civil society letter to Kofi Annan
9. NL supreme court ruling on internet anonymity
10. Results e-society conference in Macedonia
11. Advocate General European Court rejects PNR deal
12. Cryptography almost banned in the Czech Republic
13. Agenda
14. About

Ireland to challenge data retention deal

Irish justice minister, Michael McDowell, suggested in the wake of the agreement amongst most EU justice ministers about data retention, that Ireland would challenge the directive in the European Court of Justice, if it gets passed by the EU parliament next week.

Wikipedia integrity

I had the priviledge of meeting the founder of Wikipedia, Jimmy Wales, last week, at the inaugural gathering of the Open Rights Group. Wikipedia is a fantastic online encyclopedia, which, given the fact that anyone can alter an entry, is mostly remarkably reliable. Occasionally things go wrong, however, as this story in the New York Times illustrates. A Mr. Seigenthaler was shocked to find an entry on himself in Wikipedia, suggesting he might have been involved in serious crimes. The entry has since been corrected but the poster has not been identified. Mr. Seigenthaler has decided not to pursue the issue, though it would be possible for him to get a court order to ask the poster's ISP to identify the culprit and then pursue a defamation case. Sensibly he forgoes the opportunity to invest large sums in lawyers and the associated stresses of lawsuits, though he says he's learned a clear lesson:

"We live in a universe of new media with phenomenal opportunities for worldwide communications and research, but populated by volunteer vandals with poison-pen intellects."

The article also describes Jimmy Wales reaction

"Mr. Wales said in an interview that he was troubled by the Seigenthaler episode, and noted that Wikipedia was essentially in the same boat. "We have constant problems where we have people who are trying to repeatedly abuse our sites," he said.

Still, he said, he was trying to make Wikipedia less vulnerable to tampering. He said he was starting a review mechanism by which readers and experts could rate the value of various articles. The reviews, which he said he expected to start in January, would show the site's strengths and weaknesses and perhaps reveal patterns to help them address the problems.

In addition, he said, Wikipedia may start blocking unregistered users from creating new pages, though they would still be able to edit them.

The real problem, he said, was the volume of new material coming in; it is so overwhelming that screeners cannot keep up with it."

Monday, December 05, 2005

Court upholds random NY subway searches

Professor Dan Solove is annoyed at a recent court decision upholding the right to the police to engage in random searches on the New York subway.

"After making its general incantation of deference (which means that the government will automatically win), Judge Berman goes on to articulate the "persuasive" arguments of the government:
The Court is also persuaded by Commissioner Sheehan's opinion that the Program "reinforces the awareness of police officers, transit workers and the public of the need to be alert."
This is a silly argument. Essentially, the court says that providing the police with greater abilities to engage in searches without constitutional protections will make the police more "alert." Well, that's nice -- we should all be happy to sacrifice liberties so that the police become more alert. And the court notes that it will teach the public to be more alert too. So the argument is that we can make the people more alert by intruding upon their privacy. Let's try strip searches -- these will certainly make the cops more alert, and it will have great effects on public alertness too, and the cops can have a lot of fun at the same time.

The court also reasons:
[T]he Court is persuaded that the randomness of the searches rather than the actual number of searches conducted is (primarily) what makes the Container Inspection Proogram effective.
In other words, the court is saying that any small increase in terrorists believing they might get caught makes such a policy an effective. But if "effectiveness" is to have any meaning, the benefits of a policy that requires a sacrifice in liberty should be more than just trivial or speculative. There is no evidence that this policy will have any deterrent effect...

It is bad enough that so much money and resources must be wasted on a largely symbolic exercise to make public officials look like they're doing something to protect us when they're not. This cosmetic program for public officials which drains money from other more serious threats. It is even worse that people must sacrifice liberty and convenience too."

You have to admit he has a point.

Felten: DMCA should not protect spyware

Ed Felten thinks the DMCA should not protect spyware and he's submitted a request for an exemption along these lines to the US copyright office.

Exams

Open University exam results will be available soon. To those who don't do as well as you'd hoped, just remember that it's not the end of the world. Even the best of students can and sometimes do find things going wrong.

Getting through the process of distance learning whilst holding down a job and looking after a family and all the other real life committments that OU students typically have, is a major success in itself. So give yourself a pat on the back even before the results arrive - you deserve it.

Open letter on data retention

A whole plethora of digital rights groups have written an Open Letter to the European Parliament on Data Retention.

58000 people from all over Europe have signed a petition against data retention.

Will it make a difference to the European Parliament vote on the issue on 13 December? Only time will tell but it looks like the version of the proposal to go before the parliament will require two years data retention.

This process of repeatedly sending back lousy legislative proposals through the EU system, until opposition is chipped away though the lack of energy to be bothered with it again, seriously undermines the EU. But then representative democracy, which is what the parliament is supposed to be based on, only works if a sufficient number of dedicated people (albeit that sufficent number can range from 1 upwards) take an active interest. Nearly 60000 people have shown an interest here but in this case I'm not sure it's going to be enough.

Parliamentary drm enquiry

From the All Party Internet Group website: "(APIG)The All Party Parliamentary Internet Group (APIG) is to hold a public inquiry into the issues surrounding Digital Rights Management (DRM)...

The inquiry seeks written evidence particularly focusing upon the following:

Whether DRM distorts traditional tradeoffs in copyright law;
Whether new types of content sharing license (such as Creative Commons or Copyleft) need legislation changes to be effective;
How copyright deposit libraries should deal with DRM issues;
How consumers should be protected when DRM systems are discontinued;
To what extent DRM systems should be forced to make exceptions for the partially sighted and people with other disabilities;
What legal protections DRM systems should have from those who wish to circumvent them;
Whether DRM systems can have unintended consequences on computer functionality;
The role of the UK Parliament in influencing the global agenda for this type of technical issue.

APIG calls upon interested parties to present written evidence to the inquiry before 21st December 2005.

Written evidence should be submitted to admin@apig.org.uk. APIG may, at its discretion, ask for oral evidence from witnesses in January 2006 at the Houses of Parliament."

Transformational government

William Heath has posted his comments on the UK CIO Council IT strategy in four pieces. He thinks the main issues are:
- the fundamental premise that services should be personalised and directed at people, when I'd rather see simple, open and navigable government (which is less ambitious, cheaper and less intrusive)
- making identity government-controlled and tying it to the compulsory biometric scheme with audit trail
- grudging lip-service to privacy when human dignity is paramount
- whether or not the executive focus and energy is there to deliver changes like shared services.

Sunday, December 04, 2005

Diebold certified in spite of court order

It seems that the North Carolina Board of Elections has certified Diebold Election Systems to sell electronic voting equipment in the state, in spite of a federal judge's order that Diebold hand over their source code and list of programmers. Does this mean they have secretly handed over the required details (even though they claimed that they would rather withdraw from tendering) or that the Board officials were unaware of the judge's decision when they approved Diebold as an electronic voting machine vendor?

Saturday, December 03, 2005

UK intellectual property review

The UK Treasury has announced a review of intellectual property.

"At the Enterprise Conference on 2 December 2005, the Chancellor announced that, as part of the Pre-Budget Report 2005 package, he was asking Andrew Gowers to lead an Independent Review to examine the UK’s intellectual property framework, reporting to the Chancellor, the Secretary of State for Trade and Industry and the Secretary of State for Culture, Media and Sport in Autumn 2006."

Under "scope" the final bullet point says

"The review will provide an analysis of the performance of the UK IP system, including inter alia...

whether the current technical and legal IP infringement framework reflects the digital environment, and whether provisions for ‘fair use’ by citizens are reasonable."

Which is interesting because we don't have "fair use" in the UK. We have "fair dealing" which though similar is not the same. "Fair use" in the US, for example, allows the making of copies of CDs for personal use, whereas "fair dealing" in the UK does not.

Friday, December 02, 2005

Dutch e-citizen charter

William Heath thinks the Dutch 10 point e-Citizen Charter might be what we need for Europe. I'll have to come back to this as other things are pressing but it raises all kinds of interesting questions.

Turning the Net into cable TV

David Bollier advises:

"Beware the privateers! They whisper sweetly of fantastic new services they will provide – a faster Internet, better quality, even medical alerts for consumers….and blah-de-blah. Their unspoken agenda, however, is to convert the open Internet commons into a pay-for-performance marketplace. The companies who control the “pipes” of the Internet – i.e., the telephone and cable TV companies – are starting to make their move.

It’s imperative that we pay close attention to these plans – and register our objections to Congress and the companies themselves."

Thursday, December 01, 2005

Copyright dispute over book cover

Thomas Friedman and his publisher, Farrar, Straus and Giroux, have been sued over the cover on his latest book, The World is Flat. (Interestingly enough I see Amazon UK have "No Image Available" for the cover at the moment).

Freidman used an image from a poster he'd bought many years ago, of a painting done by artist Ed Miracle, showing boats sailing over the edge of the world, which featured the caption "I told you so." His publisher had duly licenced the right to use the image from the poster company. The poster company, unfortunately didn't hold the copyright in the image. They only had a licence to sell about a thousand posters and that licence expired in 1996.

The author said: "We didn't try to cheat anybody. We did it [purchased the rights] through normal channels. We thought this was all legal, kosher, and right. I feel bad that this happened, and I couldn't feel more bad for him [Miracle]."

The artist's agent, Rose von Perbandt, said "Is there no one in the press that sees the irony of a book on globalization—whose author stresses the need to protect against piracy and strengthen intellectual property protection—that is infringing the copyrights of the artist whose work was used on the cover?"

It's a fair point, which goes to show that even those with an interest in strong intellectual property rights, including Pulitzer Prize winning journalists/authors, can sometimes accidently get entangled in the complexity of the current IP landscape.

IPPR report

The Institute for Public Policy Research has just released a report "Markets in the Online Public Sphere." As the author of the report Will Davies puts it the report covers "the politics and economics of online information, and why policy-makers find it so hard to accertain the 'public interest' in this confusing terrain."

Tuesday, November 29, 2005

President Bush disaster

I don't think Rupert Murdoch really would have wanted this image to come across the way it does...

Diebold ordered to supply source code

A federal judge has ordered Diebold to hand over the source code on its electronic voting machines to North Carolina state officials. From the EFF:

"a North Carolina judge today told Diebold Election Systems that the e-voting company must comply with tough North Carolina election law and dismissed the company's case seeking broad exemptions from the law.

EFF intervened in the case earlier this month, after Diebold obtained a broad temporary restraining order that allowed it to evade key transparency requirements without criminal or civil liability. The law requires escrow of the source code for all voting systems to be certified in the state and identification of programmers. In today's hearing, the judge told Diebold if it wanted to continue in the bidding process for certified election systems in the state, it must follow the law and if it failed to do so, it would face liability...

Diebold could appeal the ruling, go forward with its bid, or withdraw from the process. However, Diebold told the court that it would likely withdraw the bid if the company did not have liability protection.

North Carolina experienced one of the most serious malfunctions of e-voting systems in the 2004 presidential election when over 4,500 ballots were lost in a voting system provided by Diebold competitor UniLect Corp. The new transparency and integrity provisions of the North Carolina election law were passed in response to this and other documented malfunctions that have occurred across the country."

It is very good news that a judge should enforce transparency requirements on a voting machine vendor. Given that Diebold have explicitly now threatened to withdraw from the bidding process rather than hand over theie source code, it will be interesting to watch to see if they follow through on that. Transparency is fundamental to the democratic process and no amount of technology or commerce should be allowed to undermine that.

New UK Biometric Centre

The Home Office are planning to set up a new "Biometric Centre of Expertise" (who comes up with these names?).

Their Science and Innovation Strategy 2005-08 includes the oft repeated, wildly ambitious and completely fallacious claim that "The National Identity Card scheme will be a powerful tool to tackle identity theft, illegal working, terrorism and organised crime." It follows up later in the same paragraph (p14, para on "Identification") with "In recognition of its importance the Home Office is creating a Biometric Centre of Expertise within HOSDB." HOSDB stands for "Home Office Scientific Development Branch."

Public services and ICT report

The Work Foundation has published its final report on Public Services and ICT.

Nothing earth shattering. Basically it says -

ICT could transform public services but only if objectives are clear and the right ICT is used,

Staff at all levels are struggling to make ICT effective,

Leaders must be responsible for realising potential and managing risks of ICT,

"Customers must be segmented" (sounds painful but this is just an attempt at marketing-speak),

The ICT with the most attractive bells and whistles is not necessarily the best for the job,

Improve supply chain management,

Listen to the users when building ICT systems,

ICT has an impact on privacy.

Monday, November 28, 2005

Kazaa get reprieve in Australia

P2P Net have the transcript of the hearing in an Australian court where Sharman Networks, owners of Kazaa, were given an extension to the deadline to implement filters. It seems the music industry's lawyers failed to attend a court ordered meeting about how the technicalities of the filtering were supposed to work but the judge does try not to let that cloud his judgement, even though he's angry about it.

The judge said:

"I thought it was discourteous in the extreme for your clients to notify that they wouldn't attend by an email sent at 8 minutes to 6 on the Friday night for an appointment that had been arranged for a long time which was due to start at 9 am on Monday. It is just not acceptable for solicitors to behave in that way to a Registrar of the court...

I just want to express as forcibly as I can, when I make directions for attendance before the Registrar I expect practitioners to treat the Registrar with the normal courtesies we would expect from each other."

The technical Registrar in a report to the court said

"Whilst the applicants had displayed co-operation in attending the first conclave and their technical representatives demonstrated good faith in contributing to the development of the protocol, it was unfortunate that this co-operation did not extend to their attendance at the resumed conclave."

So they engaged in the process to begin with but then pulled out because they reckoned the Kazaa folks were not taking it seriously, even though the court appointed officer felt that they were.

Kim Weatherall called the judge's decision on Kazaa "brave" when it was published primarily because of the huge amount of work she predicted would come the court's way in supervising this kind of process. This kind of spat was predictable though I'm not sure "brave" was the right descriptor. The transcript is quite entertaining in places with the judge suggesting to the music industry lawyer that they hadn't been too clever in their tactics - if they'd gone to the meeting and put it clearly on the record that Kazaa were not taking the filtering seriously and got the REgistrar to accept that, then Kazaa could have been in serious difficulties coming back before the court asking for a stay on the injunction. Instead they took their bat and walked away, insulting the court appointed registrar into the bargin. Interestingly enough the judge goes on to criticise both sides for their posturing.

It's well worth a read if you follow the politics and legalities of p2p file sharing.

PNR decision a shock?

EU law blog characterises the ECJ Advocate General's decision on the transfer of EU airline passenger data to the US authorites as a shock. I'm not sure it is a shock necessarily, given the amount of behind the scenes politicking that's gone on with this, but it's certainly worth noting that the specific reasons why he concludes as he does, that the European Court of Justice should annul the Council's and the Commission's decisions on the handover, are different to the reasons put forward by the European Parliament, which made the complaint.

"First, he considers that Commission Decision 2004/535/EC on the adequate protection of personal data contained in the Passenger Name Record of air passengers transferred to the United States Bureau of Customs and Border Protection was wrongly based on Directive 95/46/EC because the processing of the data put at the disposal of the United States concerned public security and the activities of the state in relation to criminal law and the fight against terrorism. Processing data for such purposes is outside the scope of the protection afforded by Directive 95/46/EC according to its Article 3 § 2. As the Commission could not lawfully adopt Decision 2004/535/EC on the basis of article 25 § 6 of Directive 95/46/EC, the Advocate General recommends that it should be annulled by the Court.

So, the reasons the Advocate General puts forward are very different from those submitted by the European Parliament which brought the action.

Second, the Advocate General considered that Article 95 EC was not the proper basis for adopting Council Decision 2004/496/EC of May 17th, 2004 on the conclusion of an Agreement between the European Community and the United States of America on the processing and transfer of PNR data by Air Carriers to the United States Department of Homeland Security, Bureau of Customs and Border Protection and it too should be annulled by the Court. The reasoning was the same. The processing of the data pursuant to the agreement between the EC and the USA concerned the fight against terrorism and serious crime whereas Article 95 EC concerned the functioning of the internal market of the EC."

Basically the decision says nothing about whether the Commission and Council should be allowed to mandate the passing of personal data to the US authorities, only that they used the wrong procedure. The Parliament were partly prompted to make the complaint in the first place because of anger over what they believed to have been assurances by the relevant EU commissioner, which they then felt he deliberately reneged on in confidential discussions and agreements with the US.

Essentially then, the EU Council of Governments and the EU Commission used the wrong procedure to mandate the handing over of large quantities of personal data to a foreign government. The EU Parliament then cited the wrong procedure in its complaint that a fundamental principle of European Union citizen data protection was being undermined. The mainstream press would probably paint this as another story of bureaucratic incompetence. As a great believer in the ubiquity of the cock of theory of history, I'd find it easy to be sold on that but there is another story here too. The making of reactive, superficial, high level political decisions about fundamental liberties and the pressurising of officials to "find a way" to get it done. The way is generally attaching it to some procedural process and with any luck it will slip through without getting subject to the kind of thorough judicial review the PNR decision attracted.

The Council and the Commission will now lean on officials to find another way...

Friday, November 25, 2005

Firefox Scholar

Firefox scholar.

"SmartFox will enable users, with a single click, to grab a citation to a book, journal article, archival document, or museum object and store it in their browser. Researchers will then be able to take notes on the reference, link that reference to others, and organize both the metadata and annotations in ways that will greatly enhance the usefulness of, and the great investment of time and money in, the electronic collections of museums and libraries. All of the information SmartFox gathers and the researcher creates will be stored on the client's computer, not the institution's server (unlike commercial products like Amazon's toolbar), and will be fully searchable. The Web browser, the premier platform for research now and in the future, will achieve the kind of functionality that the users of libraries and museums would expect in an age of exponentially increasing digitization of their holdings."

Good idea.

Data retention another step closer

From The Open Rights Group, Data retention another step closer.

The Patent Cold War

Quentin Stafford-Fraser on the Patent Cold War. Good stuff:

"The current patent system is something of a farce. Almost everybody involved in it knows this, but it's a game we all have to keep playing because nobody can afford to be the first one to stop...

And so we have the first major problem. The acquisition of patents, instead of being a means to an end, has become an end in itself...

And so this is problem number two: Lots of people have the ideas, but the wrong people are getting most of the patents...

And so we come to a very clichéd but nonetheless important problem number three: In the end, whether a patent is worth anything depends chiefly on how much you can afford to spend on lawyers. Even if you rightfully have the patent, you may not win...

And so we come to my last major concern, that a lot of the ideas for which patents are granted probably aren't very novel. So the system isn't really stimulating technological development by granting people 20-year monopolies on them..."

Verisign on Net CALEA compliance

Susan Crawford castigates Versign for their declaration that the FCC have not gone far enough in demanding that digital networks be architected for easy law enforcement interception.

"Within the last ten days or so, the key vendor of CALEA compliance services (VeriSign) has taken a very stern tone [pdf] with the FCC, saying that the Commission has read CALEA far too narrowly. VeriSign wants any SIP-using service to be part of the program, and suggests that interconnection with the traditional telephone network shouldn't necessarily be the standard for compliance. Translation: any possible multimedia application (whether connected to the phone network or not) and all connections to the internet should be designed in advance so as to be easily tappable by law enforcement.

(What's a SIP-based service? It's any service using the Session Initiation Protocol, an IETF signaling protocol that can be used in connection with any multimedia or voice or gaming application. GoogleTalk will use SIP; MSN Messenger already does; a host of VoIP applications already do. It's a very broadly used peer-to-peer protocol.)

VeriSign is also arguing that the rest of the world is moving smoothly along the vendor-assisted interception path, and that "the only impediment to implementation domestically principally lies in the Commission's actions" in the CALEA proceeding. We are ready, sayeth VeriSign (describing itself as a member of the "entrepreneurial and innovative global lawful interception industry") to provide these compliance services at minimal cost, but the Commission is getting in the way...

What's extraordinary about all this firmness on the part of the sole listener (DOJ) and the key vendor (VeriSign) is that the FCC has reached very far indeed to do their bidding already. By virtue of a less-than-weak reading of CALEA (which doesn't apply to "information services"), the Commission has gotten up the nerve to act like Congress and proclaim that a huge range of actors have to be CALEA compliant within 18 months, without saying what compliance means. Non-compliant firms will be subject to fines of $10,000 a day. So entities have to start complying without knowing what to do, and they won't even know whether they're covered -- because the FCC is sometimes flip about whether they are. Enormous, arbitrary, capricious, and aggressive confusion is in the air.

It's all pretty astonishing and pretty abusive...

But if you listen to VeriSign, we're all being silly, the world has moved on, and we should just shape up and get with the program. I feel sorry for the well-meaning professional staff at the Commission. They're under tremendous pressure."

WIPO meeting on copyright in education

IPKat also has a note about a WIPO meeting on copyright in education in the knowledge society.

"The digital environment presents enormous opportunities and challenges in terms of delivering educational materials in a sustainable manner, said Mrs. Rita Hayes, WIPO Deputy Director General in charge of copyright issues. "Today’s meeting was an excellent opportunity to look at the dissemination of teaching materials through balanced and effective copyright systems that meet the needs of all stakeholders; authors, publishers, libraries and educational services"

All stakeholders? Hmmm let's look at that list again - "authors, publishers, libraries and educational services." Nope I didn't miss them. Where were the readers or students?

But "delivering educational materials in a sustainable manner" is a nice idea, since sustainability, by definition, means protecting and cultivating and rich open-system (and I mean that in the purest thermodynamic sense, of course) source of open and renewable raw materials. Are WIPO promoting open access?

Laws of physics muck up a patent application

I learn from IPKat that there's a novel decision from the Patent appeal court, where the judge threw out an appeal against the dismissal of a patent application. He reckoned that it was reasonable for the patent examiner to hold that the proposed invention was not only obvious but it broke the laws of physics, or more specifically the law of conservation of energy (also widely known by engineers as the first law of thermodynamics).

So the invention was obvious despite the fact that it breached a fundamental law of nature, which presumably means that that fundamental law is not obvious? Being the scientific stick in the mud that I am, I'd say that is more of a reflection of the basic lack of scientific understanding rather than that the first law of thermodynamics is something less than obvious. Which in turn leads to the question of what actually is obvious? But that strays into the realm of philosophy which goes beyond the boundaries of my scientific, technical, commercial and legal training...

No that's not good enough. Even young children know you can't generate energy out of nothing, so if it is obvious to them why isn't it obvious to the legal system and society more generally? Just another example of our ability to believe in things which are simple, obvious and wrong, I guess.

ID cards in historical perspective

Jon Agar of Cambridge University has produced a paper on Identity cards in Britain: past experience and policy implications. I've just had time to scan the executive summary but it looks well worth a read. The paper looks briefly at the two previous ID card systems in the UK in the 20th century and idenitfies some features which could inform the debate on the government's planned system. Extract from the executive summary:

"The first national register (1915-1919), and accompanying identity card, was a failure, and the second (1939-1952) a partial success. The success of the second system was secured by analysing the causes of the failure of the first.

Universal registration systems have repeatedly been proposed as solutions to short-lived moral panics. But there is little evidence that national registers effectively resolve such panics.

Public indifference or hostility to identity cards was managed by building 'parasitic vitality' into the second experience. In particular, the system of national registration was intimately connected to the system of food rationing. Without similar 'parasitic vitality', contemporary proposals can be expected to struggle to win acceptance.

However, such interconnection encourages the phenomenon of 'function creep': eventually the pattern of disclosure and use of personal information is markedly different from that originally declared."

He goes on to say in the body of the report:

" the administrative operation of - and public response to - the historical card systems reveal features that should make all parties in the contemporary debate pause for thought. For example, the relative technological simplicity of the old card systems made a considerable contribution to their effectiveness: the simplistic equation of technological sophistication with effectiveness should be resisted."

As I say to my students, we should look to use the best available technology, including pencils and paper.

Thursday, November 24, 2005

LSE Prof on Government misrepresentation on ID cards

Professor Ian Angell of the London School of Economics Information Systems department is clearly getting irritated at the government's misrepresentation of the LSE research into the proposed ID cards scheme. In a letter to the Telegraph he says,

"Sir - What is going on with this so-called "debate" on ID cards? While appearing on the BBC's Hardtalk last week, immigration minister Tony McNulty claimed that, at a recent meeting in the House of Lords, the LSE had "admitted" that its estimate of the cost of ID cards was "hopelessly wrong". We made no such statement, and no one who attended that meeting could possibly make that inference.

This is typical of how debate over ID cards has degenerated into grand-standing and misrepresentation. With some minor adjustments, we stand by the figures we published in our June report. The reason our calculations differ from those of the Home Office is that we focused on the cost of implementing the scheme across government, while the Home Office estimated merely its own departmental costs.

It is the mission of the department of information systems at the LSE to be at the centre of academic research into any technological initiative that will have a major effect on the population. Having our position misrepresented by ministers will not deflect us from that position. So please, no more nonsense over figures. Let's get on with the real debate about the impact of this proposal on the nation, its effect on the lives of its citizens, and whether the systems stand any chance of functioning at an acceptable level."

Entertainment industry opportunism

It seems as though the entertainment industry in the EU have taken a leaf out of their US brethen's handbook. Just as the industry in the US attempted (though fortunately failed) to have a provision slipped into the PATRIOT Act in the emotional aftermath of 9/11, to enable them to hack into people's computers, the Creative and Media Business Alliance (CMBA), (i.e. Sony BMG, Disney, EMI, IFPI, Motion Picture Association, Reed Elsevier, Universal and many others) want the EU data retention proposals to be tweaked to enable the trawling of personal communications data to detect and pursue copyright infringement.

Now there is an argument to be made that the security services require access to the best available technology and people in the pursuit of serious crime and a data retention and access process, in some form, may well be a part of that. (I happen to believe the that EU data retention proposals present more problems for the police, the security services, the communications service providers and their customers than they do for the instigators of serious crime but that is another story). But as Suw Charman says here,

"Whether or not you agree with the need to retain traffic data for fighting terrorism and serious crime, there can be no benefit to national security from allowing the creative industries to use this information for prosecuting simple “infringement” cases.

Copyright Criminals

Now tie this in with IPRED2, another nasty bit of legislation which criminalises all “intellectual property” infringement on a commercial scale and “aiding and abetting such infringement”, with very thin definitions of what “commercial scale” or “intellectual property” means. The two directives together become even more alarming.

IPRED2 mandates that the police work with rightsholders to pursue suspected cases of IP infringement - including patent infringements - or merely vocal encouragement of infringement. And the Data Retention directive provides them with reams of data they can mine for evidence against these suspected infringers.

At the latest IPRED2 hearing, that’s exactly what the CBMA’s parent organisation, the International Federation of the Phonographic Industry (IFPI), demanded.

This opens up a very ugly can of worms where entire industries can get unparalleled powers of investigation, provided at the taxpayer’s expense.

Moreover, if the CMBA get their way, the number of data retention enquiries that the telcos and ISPs will have to process will be far higher than if restricted to terrorism and serious crime. This will put far more pressure on the telcos and ISPs who will not only have to bear the cost of storing the data, but also of providing access to the information to the authorities."

Remember what I was saying about the gaffer tape and Sony CDs yesterday? You could become a copyright criminal by sticking some tape round the edge of a Sony CD in order to stop it damaging your computer. So if Sony suspect you may have tried this trick (they'll have your personal details which you had to hand over to get the software to allegedly uninstall the damaging code, the same software which did no such thing and actually caused you further security headaches), under the tweaked data retention and the IPRED2 regulations they can demand a police investigation into your activities; an investigation which would include your communications data for the previous six months (phone calls, web sites visited, emails etc.)

The spectre of the systemic effect of the combination of technology, special interests, politics and ignorance looms again.

The IP parable of the cigarette fire

Ian Clarke has come up with a lovely parable on the extremes of intellectual property.

"I was in the pub last night, and a guy asked me for a light for his cigarette. I suddenly realised that there was a demand here and money to be made, and so I agreed to light his cigarette for 10 pence, but I didnt actually give him a light, I sold him a license to burn his cigarette. My fire license restricted him from giving the light to anybody else, after all, that fire was my property. He was drunk, and dismissing me as a loony, but accepted my fire (and by implication the licence which governed its use) anyway.

Of course in a matter of minutes I noticed a friend of his asking him for a light and to my outrage he gave his cigarette to his friend and pirated my fire! I was furious..."

Matches (if you'll excuse the pun) nicely Thomas Jefferson's:

" It would be curious then, if an idea, the fugitive fermentation of an individual brain, could, of natural right, be claimed in exclusive and stable property. If nature has made any one thing less susceptible than all others of exclusive property, it is the action of the thinking power called an idea, which an individual may exclusively possess as long as he keeps it to himself; but the moment it is divulged, it forces itself into the possession of every one, and the receiver cannot dispossess himself of it. Its peculiar character, too, is that no one possesses the less, because every other possesses the whole of it. He who receives an idea from me, receives instruction himself without lessening mine; as he who lights his taper at mine, receives light without darkening me. That ideas should freely spread from one to another over the globe, for the moral and mutual instruction of man, and improvement of his condition, seems to have been peculiarly and benevolently designed by nature, when she made them, like fire, expansible over all space, without lessening their density in any point, and like the air in which we breathe, move, and have our physical being, incapable of confinement or exclusive appropriation."

Wednesday, November 23, 2005

ECJ blocks handover of EU passenger data to US

This is an important decision. The advocate general of the European Court of Justice has said that the handing over of airline passenger to the US security services should has no adequate legal basis.

In referring to the EU Commission and the Council of ministers decisions to approve the disclosure of passenger data to US security agencies, AG Phillipe Léger says

“Neither the council decision approving the agreement nor the commission decision holding that information to be sufficiently protected by the US have an adequate legal basis”

He goes on to explicitly advice the ECJ to annul both decisions.

Opaque tape beats Sony drm rootkit

John Leyden in the Register reports that gaffer tape can be used to defeat the offending rootkit installing drm on Sony CDs (though I wouldn't recommend putting gaffer tape on CDs as the resulting loss of balance will probably lead to the CD getting scratched).

But since gaffer tape can be used for this purpose does that make it a technological protection measure (tpm) circumvention device. In which case does it breach the US Digital Millenium Copyright Act and the EU copyright directive?

So could someone be engaging in a criminal act by sticking a bit of tape on a CD to prevent that CD installing destructive code on their computer?

Given the precedent of the Hacker 2600 case (Corley v Universal), where a journalist was banned from linking to websites with DeCSS DVD security circumvention codes, could Leyden be in breach of the DMCA?

What about turning off of the autorun feature on Windows to prevent the Sony CD from automatically installing the destructive drm code? Could adjusting the default options on your own computer be a tpm circumvention mechanism?

Do I think the absurdities of music (and other copyrighted materials) protected by digital fences (drm), which in turn are protected by law with the threat of criminal sanctions, will now magically become clear?

Is that a flying pig I see over there?

ID card costs

From the Register:

"The London School of Economics (LSE) has issued a statement clarifying its position on its National ID card research. The announcement follows press reports that project costs could go as high as £40bn. The LSE says that its original estimate of a £19.2bn high watermark stands and no other figure should be attributed to them."

Schneier on the real story in the Sony drm fiasco

Bruce Schneier thinks the real story in the Sony drm disaster is

not Sony's rogue drm rootkit,
not that the drm acts as spyware,
not that attempts to get rid of it damage your Windows operating system
not that Sony stopped production on the destructive CDs
not that Sony recalled the destructive CDs
not that Sony secretly rolled out destructive drm
not that Sony after a lot of hassle and further privacy invasion offered a "fix" that not only didn't work appropriately but created more security problems
not that Sony lied about the privacy invading features of the drm
not that Sony said "Most people don't even know what a rootkit is, so why should they care about it?"
not that Sony's rootkit may have infringed on others' copyrights
not that Sony may have breached UK, US, Italian and other criminal codes
not that Sony probably won't be prosecuted in the US or the UK

but

"the collusion between big media companies who try to control what we do on our computers and computer-security companies who are supposed to be protecting us...

That all the big security companies, with over a year's lead time, would fail to notice or do anything about this Sony rootkit demonstrates incompetence at best, and lousy ethics at worst...

Who are the security companies really working for? It's unlikely that this Sony rootkit is the only example of a media company using this technology. Which security company has engineers looking for the others who might be doing it? And what will they do if they find one? What will they do the next time some multinational company decides that owning your computers is a good idea?

These questions are the real story, and we all deserve answers."

Tuesday, November 22, 2005

Did Sony's drm infringe copyrights?

Ed Felten is also asking if Sony's disastrous drm infringed copyright.

"The Sony copy protection debacle has so many angles that the mainstream press is having trouble keeping track of them all. The rootkit. The spyware. The other spyware. The big security hole. The other big security hole. It’s not surprising, then, that at least one important angle has gone nearly undiscussed in the mainstream press: the likelihood that the Sony/First4Internet XCP copy protection software itself infringes several copyrights. (Note to geeks: Slashdot doesn’t qualify as the mainstream press.)

Matti Nikki (a.k.a. Muzzy) and Sebastian Porst have done great work unearthing evidence pointing to infringement. They claim that the code file ECDPlayerControl.ocx, which ships as part of XCP, contains code from several copyrighted programs, including LAME, id3lib, mpglib, mpg123, FAAC, and most amusingly, DVD-Jon’s DRMS.

These are all open source programs. And of course open source is not the same as public domain. Open source programs are distributed with license agreements. If you copy and redistribute such a program, you’re a copyright infringer, unless you’re complying with the terms of the program’s license."

Felten on EFF v Sony

Ed Felten approves of the EFF's emphasis of the problems with Sony's MediaMax drm as spyware, in their lawsuit against the company.

"One interesting aspect of the EFF suit is its emphasis on MediaMax. Most of the other lawsuits have focused on Sony’s other copy protection technology, XCP. The EFF suit does talk about XCP, but only after getting through with MediaMax. Emphasizing MediaMax seems like a smart move — while Sony has issued an apology of sorts for XCP and has recalled XCP discs, the company is still stonewalling on MediaMax, even though MediaMax raises issues almost as serious as XCP...

It’s important to recognize that these problems are caused not by any flaws in SunnComm and Sony’s execution of their copy protection plan, but from the nature of the plan itself. If you want to try to stop music copying on a PC, you’re going to have to resort to these kinds of methods. You’re going to have to force users to use extra software that they don’t want. You’re going to have to invoke administrator privileges more often. You’re going to have to keep more software loaded and running. You’re going to have to erode users’ ability to monitor, control, and secure their systems. Once you set off down the road of copy protection, this is where you’re going to end up."

Which is why we should be avoiding the drm road completely.

People's willingness to give up other people's rights

There's a nice op ed in the San Francisco Chronicle from a last Monday, by a civil rights lawyer, Ben Rosenfeld, about why it is a bad idea to make common behaviour a criminal offence.

The origin of a police state in this country, I believe, is this: We gradually exchange a rights-based system, in which governmental power is limited by law, for a paternalistic one, in which we may all be arrested for one thing or another, but authorities forebear from doing so, or intruding in our lives, until they subjectively brand us "bad guys."...

Perhaps we will have to keep throwing away rights that matter more to other people for a time, until we realize that we are throwing away our own rights in the process. Only then will we start to create a society truly founded on principles of equal protection and mutual support."

Rent a mum

David Bollier has been brooding on what it might be unhinkable to buy or sell.

Jonathan Rowe has been doing likewise.

EFF take class action lawsuit against Sony BMG

The EFF has filed a class action lawsuit against Sony BMG over the CD drm fiasco.
"Music fans shouldn't have to install potentially dangerous, privacy intrusive software on their computers just to listen to the music they've legitimately purchased," said EFF Legal Director Cindy Cohn. "Regular CDs have a proven track record -- no one has been exposed to viruses or spyware by playing a regular audio CD on a computer. Why should legitimate customers be guinea pigs for Sony BMG's experiments?"

Unintended consequences

The story of how NASA missed the detecting the hole in the earth's ozone layer is one of unintended consequences arising from the failure of an information system. NASA had a deployed a sophisticated ozone mapping spectrometer in a satellite called Nimbus-7, which relayed hundreds of data measurements to base on a daily basis. NASA didn't have enough people to process the mass of data and relied on summary indicators.

Unfortunately the spectrometer had been originally programmed to ignore unusually low ozone levels because they had "never happened" previously. The raw data went unchecked until scientists from the British Antartic Survey published details of measurements they had made detecting the thinning of the ozone layer, using old tried and tested instruments.

The trust in the sophistication of the NASA technology combined with the lack of attention to the data generated led to a failure to detect major changes in the system being monitored and a defensive belief, at least initially until they went back and checked the raw data, that their sophisticated technology could not be wrong.

Blunkett, "impossible to fake" and biometric embedded ID cards come to mind, though Mr Blunkett is, of course, no longer in the driving seat on the scheme.

Just a thought

Have you ever noticed that blind faith in technology is often strongest amongst people who have no understanding of the technology?

I've been thinking about the ID card system again and repeatedly come back to US journalist John Lawton's observation: "the irony of the information age is that it gives new respectability to uninformed opinion."

Doc Searls on saving the Net

Doc Searls recently posted an amazing essay on saving the Net.

"The carriers have been lobbying Congress for control of the Net since Bush the Elder was in office. Once they get what they want, they'll put up the toll booths, the truck scales, the customs checkpoints--all in a fresh new regulatory environment that formalizes the container cargo business we call packet transport. This new environment will be built to benefit the carriers and nobody else. The "consumers"? Oh ya, sure: they'll benefit too, by having "access" to all the good things that carriers ship them from content providers. Is there anything else? No.

Crocodile grins began to grow on the faces of carriers as soon as it became clear that everything we call "media" eventually would flow through their pipes. All that stuff we used to call TV, radio, newspapers and magazines will just be "content" moving through the transport layer of the pipe system they own and control. Think it's a cool thing that TV channels are going away? So do the carriers. The future à lá carte business of media will depend on one medium alone: the Net. And the Net is going to be theirs.

The Net's genie, which granted all those e-commerce wishes over the past ten years, won't just get shoved back in the bottle. No, that genie will be piped and priced by the packet. The owners of those pipes have a duty to their stockholders to make the most of the privileged position they've been waiting to claim ever since they got blind-sided, back in the 80s and 90s...

Does it matter that countless markets flourish in the wide spaces opened by agreements and protocols that thrive at the grace of carriage? Or that those markets are threatened by new limits, protections and costs imposed at the pipe level?

No.

Thus, the Era of Net Facilitation will end. The choke points are in the pipes, the permission is coming from the lawmakers and regulators, and the choking will be done. No more free rides, folks. Time to pay. It's called creating scarcity and charging for it. The Information Age may be here, but the Industrial Age is hardly over. In fact, there is no sign it will ever end...

The new carrier-based Net will work in the same asymmetrical few-to-many, top-down pyramidal way made familiar by TV, radio, newspapers, books, magazines and other Industrial Age media now being sucked into Information Age pipes. Movement still will go from producers to consumers, just like it always did. Meet the new boss, same as the old boss. Literally...

what matters most is Saving the Net--keeping it a free and open marketplace for everybody--while also making sure that carriers of all kinds can compete and succeed while providing much of the infrastructure on which that marketplace resides. That means we need to understand the Net as more than a bunch of pipes and business on the Net as more than transporting and selling "content".

This isn't a trivial issue. It's a matter of life and death for the Net itself. How are we going to fight?

Read on.

Scenario II: The Public Workaround

The deathblow comes from the muni Wi-Fi efforts. It doesn't matter whether they are viable or not--all they need do is give local connectivity the moral high ground and represent a grass roots effort that the legislature not only can't ignore but can embrace. --Bob Frankston

In ancient telco lingo, "bypass" is anything that works around the phone system itself. Susan Crawford wisely encourages bypassing not only the system but the whole notion of fixing it with "Network Neutrality" agreements or legislation. In response to the questions, "What, if any, version of common carriage rules should govern Internet communications platforms? More specifically, can some concept of Network Neutrality be defined and enforced proactively in the form of prescriptive regulations?", she answers,

I think this is the wrong question. It assumes the limited world of online access providers we've got, makes them into "communications platforms," and then suggests we need to make rules about them. Not very imaginative. I have lost faith in our ability to write about code in words, and I'm confident that any attempt at writing down network neutrality will be so qualified, gutted, eviscerated, and emptied that it will end up being worse than useless...

The only way around this issue is to avoid it by encouraging the development of alternative online access methods, and being careful not to let the incumbents call them illegal. Let the dinosaurs huddle together in the snow, controlling and commoditizing to their hearts' content. We're made of better stuff. It should be no more illegal to have an open wireless network in your house than to practice the piano with the windows open. And having an open wireless network can lead to a community mesh network and a host of devices that open immediately to others, connecting us to the world.

If that's not possible, then the second best solution is structural separation, paying off the carriers for their stranded costs and moving to open utility platforms. BT seems to think that's a fine idea; why couldn't it work here?

Muni Wi-Fi is a form of bypass. So are other government-sponsored or assisted workarounds.

So are the private ones." (Like Google which is building its own network).

He quotes Susan Crawford again later in the piece asking a key question:

What happened to our leadership on internet policy? When did we lose the ability to walk and slide back into the sea? We experimented and tugged and pulled and came up with the idea of linking machines together with a common language, making it possible for humans to interact in unprecedented ways. Now we're turning those machines back into the machines we thought we were escaping--telephones, cable systems, and televisions--using insiders' language so that we can hide what's going on from the general public. What happened?

And goes on to supply an answer with his "Scenario III: Fight with Words and Not Just Deeds", where he goes on to describe the importance of the language of the debate. She who controls the language with the better metaphors will control the debate. "Stop piracy" beats "protect the commons" every time. Protect the what? "Piracy" in the intellectual property context used to be about illegal commercial enterprises copying an selling large numbers of counterfeit goods. Now it is about anyone copying anything on the Net.

"Advocating and saving the Net is not a partisan issue. Lawmakers and regulators aren't screwing up the Net because they're "Friends of Bush" or "Friends of Hollywood" or liberals or conservatives. They're doing it because one way of framing the Net--as a transport system for content--is winning over another way of framing the Net--as a place where markets and business and culture and governance can all thrive."

Read it all at Linux Journal. It's a long essay but well worth your time.

Monday, November 21, 2005

Geist on Sony drm disaster

Michael Geist has some sensible things to say about Sony's recent drm disaster.

New blog

Lilian Edwards of the AHRB Centre for the Study of Intellectual Property
and Technology Law at Edinburgh University has a new blog, BlogScript: Innovation, Technology and the Law.

Update: I should have said, Lilian's co-director of the AHRB, Andres Guadamuz, is a co contributor to the blog.

Portillo thinks Brown will kill ID cards

Michael Portillo, a former candidate for the leadership of the main opposition Conservative party in the UK, thinks Gordon Brown will eventually kill the ID card plans will a simple cost benefit analysis.

Friday, November 18, 2005

Keane leaves the auld enemy

Roy Keane's frustration with developments at Man Utd has finally led to an abrupt parting of the ways. I wonder if Arsene Wenger would have the cheek to sign him to fill the hole left by Patrick Veira until he could find a more permanent replacement?

Since Chelsea have been making a habit for a number of years of stepping in with more money for any player Wenger seems to be interested in and would be unlikely to covet an old Utd cast off, it's an idea...

UK Government attack academic over ID cards

In the course of the second day of the House of Lord's Committee stage debate on the Identity Cards Bill, Home Office Minister Baroness Scotland of Asthal, encouraged by Baroness Corston, attempted to undermine (scroll down to "16 Nov 2005 : Column 1092") the critical London School of Economics report on the scheme, by attacking one of the academics associated with the report, Simon Davies.

Just as a matter of interest, Jean Corston was created a life peer by the UK government in July this year and is is chair of the Parliamentary Labour Party. She is an ex Labour MP and Parliamentary Private Secretary (PPS). Call me cynical but it is really difficult to believe this little exchange wasn't worked out in advance of the debate:

"Baroness Corston: While my noble friend is finding the appropriate place, perhaps I may comment on something she said earlier. I have been very dismayed at the degree to which noble Lords have referred to a particular report as the "LSE report". It was actually written by a Mr Simon Davies, who works for Privacy International, which is an international organisation that is violently opposed to identity card Bills and has opposed them in many countries. Mr Davies came to a meeting in the other place chaired by me a couple of years ago when the Government first mentioned identity cards.

It is true that Mr Davies is a visiting fellow of the LSE, but that is a different matter. Indeed, the present director of the LSE, Howard Davies, has confirmed that the document itself is not an official corporate document of the LSE. Perhaps we should start calling it the "Davies report".

Baroness Scotland of Asthal: My noble friend is absolutely right: it is the Davies report. I am perhaps in error in calling it the London School of Economics report. That is how it has been referred to in the debate. It is an inaccurate reference. I do not want to cast any aspersions on the London School of Economics. I will certainly take my noble friend's stricture and from henceforth I will refer to it only as the "Davies report". So we have that clarity."

Baroness Anelay, the Conservatives's shadow home affairs minister in the House of Lords, then points out that given the range of LSE professors associated with the report it is reasonable to call it the "LSE report." But Jean Corston insists she will now continue to label it the "Davies report."

Now let's look at what the LSE Department for Information Systems website says about the LSE ID card research:

"The Identity Project

The Identity Project has published two reports on the Government's Identity card proposals. These reports have been widely discussed in the press and parliament and you can download the reports and link to the press coverage on these page.

The Identity Project has been organised and sponsored by the LSE Department of Information Systems. Two departtment members, Gus Hosein and Simon Davies have co-ordinated the production of the reports and have serviced the advisory committee of 14 LSE professors who guided the report. Dr Edgar Whitley co-ordinated the international team of 60 researchers who contributed to the report."

So the report was created by the LSE Department of Information Systems, 14 other LSE Professors and an international team of 60 researchers. And as for Jean Corston's suggestion that the director of the LSE, Howard Davies, had distanced the institution from the report, let's look at his letter to the Times on the subject in full:

From the Director of the LSE

Sir, Over the last six months a team of London School of Economics researchers has mounted a major research project to assess the Government’s Identity Cards Bill and its implications. Sixty people contributed to the work, overseen by a dozen LSE professors.

The report is long (305 pages) and detailed. One conclusion among many is that the Government’s scheme will be more costly than it claims (report, June 28).

Aware of the work, Home Office officials demanded to see advance copies. Before they had been provided, the Home Secretary condemned the cost estimates as “mad”. When it was published, he described the analysis as a “fabrication” and one of the project mentors as “highly partisan”.

Following the media coverage, LSE’s Governing Council reasserted the right of academic researchers to publish and be damned. The report is not, of course, a “corporate” LSE document. It does, however, represent the honest and considered views of a team of experts.

It is unfortunate that, on an issue where the civil liberties concerns are so serious, the Government should have chosen to adopt a bullying approach to critics whose prime motivation was to devise a scheme which might work, at an acceptable cost.

HOWARD DAVIES
Kingsway, London

Not much room for government comfort there then. I really don't know whether Simon Davies should be flattered or annoyed at the attention he's getting from the government but the LSE report is certainly a major thorn in their side in the ID card debate.

Sony drm fiasco good for digital music

Derek Slater has been adding his two cents worth to the fall out from the Sony drm problems.

"DRM proponents often argue that DRM's limitations will never be unacceptably invasive or strict, because consumer desires will never allow it. If one music supplier uses DRM in a way that is too restrictive, another supplier will exploit that opportunity, offering music with less restrictions and drawing consumers away. In sum, the competitive market solves all.

And what do you need to get a competitive, efficient market? Full information. Perfect information and perfectly competitive markets don't exist outside of textbooks, but we'd like to get as close as possible to those goals.

If consumers come away from the Sony debacle deciding to never buy another DRMed CD again, that's the market at work. To the extent this provokes consumers to be more critical when buying any DRMed product, and they reject DRMed products on that basis, that's the market at work...

Sony CD DRM certainly is an extreme example of the harm DRM can do as well as a situation in which people buying DRMed content without fully understanding the restrictions. However, all the major online music services are misleading in the way they advertise their services, obscuring how restrictive their DRM actually is. We should hope that consumers come away from this scandal more critical about DRM in general; if they decide to purchase music from the online music services, they should do so knowing what they're buying.

Property in the knowledge society

David Bollier thinks something's gotta give given the overreaching behaviour of some companies in the name of protecting their property. He picks out the Sony CD drm fiasco as an illustrative case.

"we have a case where a major company unleashed malicious software to secretly colonize millions of computers in an attempt to extend the reach of property-rights enforcement...

In its never-ending quest to lock up its music products, Sony BMG had installed an aggressive type of DRM, or digital rights management system, to prevent people from making more than three copies of their CDs on their computers. This particular piece of DRM included a “Trojan horse,” as it’s called in the trade. The code secretly embedded itself on a user’s Windows operating system and sent messages back to Sony servers. Not only could users not detect the virus, most could not uninstall it without professional help.

Sony BMG estimated that the code was present on 49 different music CDs and five million discs, two million of which had been sold. (Watch out if you bought Celine Dion, Neil Diamond or Van Zant. More at the Sony BMG site.)

Once they got wind of the problem, security experts estimated that at least 568,000 computers had been infected by the bad code, and probably many, many more...

So this is where the zealous defense of “property rights” has come: furtive infiltration of your personal computer with harmful code. Is it any wonder that the music industry and copyright law are facing a legitimacy crisis? They seem to think it’s more dangerous for you to make a few copies of your own, legally purchased CD than it is for them to implant rogue software on your computer without your knowledge."

It's worth repeating that: "They seem to think it’s more dangerous for you to make a few copies of your own, legally purchased CD than it is for them to implant rogue software on your computer without your knowledge."

Panic induces reactive and not necessarily sensible behaviour and ever since the advent of the world wide web, Karlheinz Brandenburg's invention of MP3, and Diamond Multimedia's release of the first digital music player, the Rio, the record labels have been in a state of almost constant panic. DRM is one of the primary results of that panic. It represents the illusory quick technical fix to a fundamental shift in the landscape of their business world.

Hopefully within the next ten years or so the shifting tectonic plates of the information and entertainment industries will settle down and gain some level of stability. If drm were to become one of the casualties of the process, then I'm sure the millions of Sony CD buyers, with virus infected computers, will not be lamenting the extinction of that particular digital species.

Ultimately, unusually for me as a pessimist, I reckon that drm will eventually die out because it's such a lousy idea. But it is one of those superfically attractive ideas to some, that we will probably find it getting resurrected periodically to the extent that future generations will have to suffer various infestations, until it can be beaten back to the edge of extinction again in another cycle.

Thursday, November 17, 2005

Scambusters on Sony drm hole

Scambusters have a useful article on the Sony CD drm problems, Sony's Rootkit CDs -- And What It Means for You

Sony's apology over drm security hole

Cory is distinctly unimpressed with Sony's non-apology apology after the security problems created by their drm CDs.

Ex MI5 chief critical of ID cards

Dame Stella Rimington, a previous MI5 chief, has said: "I don't think anybody in the intelligence services - not in my former service - will be pressing for ID cards" because they will not make the country any safer. It's not particularly surprising that she believes this. Any competent security professional will tell you the same thing. The government will not be pleased she's prepared to make her views public though.

Wednesday, November 16, 2005

Does the UK government IT strategy have teeth?

Does the UK government IT strategy have teeth? Mark Say, editor of Government Computing, thinks not.

Banks infiltrated by organised crime

From Ian Brown: FSA warns of bank insider fraud

tag cloud catalogue

Here's a neat marriage of tag clouds and library catalogues.

Thanks to Jenny Levine for the link.

Tony Blair abolishes elections

This is worryingly close enough to reality to almost not be funny but it still made me grin.

Unauthorised sequels

There was a copyright case in France recently, Pierre Hugo and others v SA Plon and another (Cour d'appel de Paris), on whether Victor Hugo's moral rights were breached by the publication of a couple of unauthorised sequels to Les Miserables.

Even though the specific legal issues were different it reminds me of the case over The Wind Done Gone, when Margaret Mitchell's estate sued Alice Randall and her publishers over the publication of her first novel, a parody of Gone with the Wind, written from the perspective of Scarlett O'Hara's half-sister Cynara, a slave on Scarlett's plantation. The estate managed to get an injunction preventing the publication initially but the case was eventually settled out of court and the book was published in 2002.

Open Rights Group open invite

The new UK Open Rights Group have issued an invitation "to an evening of digital rights discussion, networking and wine at 01Zero-One Hopkins Street on Tuesday 29 November at 6pm"

The guest speaker is Jonathan Zittrain.

IFPI sue 2100

The International Federation for the Phonographic Industry (IFPI) are suing another 2100 individuals (in civil and criminal cases) all over the world for alleged copyright infringement via p2p file sharing.

Tuesday, November 15, 2005

John Battelle's common sense advice

John Battelle has provided the MacArthur Foundation, at their request, with a sensible suggestion for a philanthropic investment.

"In an age where the knowledge of mankind is increasingly at our fingertips through the services of Internet search, we must teach our children critical thinking. One can never have all the answers, but if prepared, one can always ask the right question, and from that creative act, learn to find his or her own answer.

Instead, we have leaders that believe that questions have one answer, and they already know what it is. Their mission, then, is to evangelize that answer. That, to me, is a dangerous course. Reversing it by teaching our children to learn, rather than to answer, seems to me to be a noble cause.

I then later added:

Developing a framework in our schools for "search literacy" - how to use and think about using a search engine - might be just the kind of thing you could do with a modest investment...."

RFID chips in passports

Bruce Schneier offers praise, in his latest Crypto-Gram for State Department officials who have responded sensibly and responsibly to two specific criticisms of the proposal to put RFID chips in US passports. He still has serious concerns about the plan, however:

"RFID passports will now include a thin radio shield in their
covers, protecting the chips when the passports are closed. Although
some have derided this as a tinfoil hat for passports, the fact is the
measure will prevent the documents from being snooped when closed.

However, anyone who travels knows that passports are used for more than
border crossings. You often have to show your passport at hotels and
airports, and while changing money. More and more it's an identity
card; new Italian regulations require foreigners to show their
passports when using an Internet cafe.

Because of this, the State Department added a second, and
more-important, feature: access control. The data on the chip will be
encrypted, and the key is printed on the passport. A customs officer
swipes the passport through an optical reader to get the key, and then
the RFID reader uses the key to communicate with the RFID chip.

This means that the passport holder can control who gets access to the
information on the chip, and someone cannot skim information from the
passport without first opening it up and reading the information
inside. This also means that a third party can't eavesdrop on the
communication between the card and the reader, because it's encrypted.

By any measure, these features are exemplary, and should serve as a
role model for any RFID identity-document applications. Unfortunately,
there's still a problem.

RFID chips, including the ones specified for U.S. passports, can still be uniquely identified by their radio behavior...

To fix this, the State Department needs to require that the chips used in passports implement a collision-avoidance system not based on unique serial numbers...

The State Department has done a great job addressing specific security and privacy concerns, but its lack of technical skills is hurting it. The collision-avoidance ID issue is just one example of where, apparently, the State Department didn't have enough of the expertise it needed to do this right.

Of course it can fix the problem, but the real issue is how many other problems like this are lurking in the details of its design? We don't know, and I doubt the State Department knows, either. The only way to vet its design, and to convince us that RFID is necessary, would be to open it up to public scrutiny...

Right now the State Department has no intention of doing that; it's already committed to a scheme before knowing if it even works or if it protects privacy."

UK firm to test Irish e-voting system

I missed this when it was published in April in the Irish Times. The Irish Commission on Electronic Voting has commissioned QinetiQ, which was the national defence laboratory of the UK Ministry of Defence prior to being privatised, to review the country's electronic voting system.

The UK government continue to hold a 56% share of the company. The remainder of the shares are owned by company employees and the Carlyle Group. Why choose a company whose major shareholder is a foreign, albeit friendly, government to audit your voting system? It would be fascinating to review the decision processes involved. I wonder how many Irish consultancy companies bid for the contract?

Monday, November 14, 2005

Thinking traps

With ID cards and their data retention proposals and many others related to the information society, the UK government has been acting deliberately not only against the interests of the nation but against their own interests. As soon as the real life affects of these policies start hitting people (e.g. the £500 cost of an ID card) Tony Blair and co are going to be on the receiving end of general public disgruntlement, probably sufficient to vote them out of office. So why in the face of sensible, clear minded exposition of the real problems of these ideas, by folks like those at the LSE, do decision makers persist with wrong-headed and completely counter-productive policies?

John's right when he says prime ministers exist inside a bubble which insulates them from reality. But acting, demonstrably against reason and even enlightened self interest, according to an absolute, pre-conceived, unshakable belief in the rightness of some scheme like ID cards, has got to reflect more than sheer folly and the desire to "act" and be seen to be acting (in the absence of any serious diagnosis of the complex problems allegedly targetted)?

The thinking trap is certainly one contributory explanation. Geoffrey Vickers described it thus:

Lobster pots are designed to catch lobsters. A man entering a lobster pot would become suspicious of the narrowing tunnel, he would shrink from the drop at the end; and if he fell in he would recognise the entrance as a possible exit and climb out again – even if he were the shape of a lobster.

A trap is a trap only for creatures who cannot solve the problem it sets. Man traps are dangerous only in relation to the limitations of what men can see and value and do. The nature of the trap is a function of the nature of the trapped...

We the trapped tend to take our own state of mind for granted – which is partly why we are trapped.


He goes on to note that we can only start to climb out of our self made thinking traps when we recognise that we are in a trap and start questioning our own limitations and the assumptions that led us there.

The government trap in this instance is their focus on selling the rightness (or righteousness) of their solutions, whilst wholly avoiding addressing the complexity of the underlying problems.

And the solutions are neat, simple (or certainly sold as such, even though they are anything but simple) and wrong.

US Government Step into Blackberry dispute

The US Justice Department has filed a "statement of interest" in the NTL v RIM patent dispute, saying that if the judge decides to stop the sales of the Blackberry, "it is imperative that some mechanism be incorporated that permits continuity of the federal government's use of BlackBerry devices." A jury decided a couple of years ago that RIM's Blackberry did infringe on NTL's patents. The two companies were then reported as having agreed a settlement whereby RIM would pay NTL £450 million. They are now in dispute about whether there was an agreement or not. If the judge decides there was no agreement he could issue an injunction against the sales in the next few weeks.

NTL has rejected any notion that government personnel would be affected by such an injunction.

Dodgy Dossier mark II

Ian Brown points to a couple of interesting articles in the Times on Tony Blair's Dodgy Dossier mark II. Not Mr Blair's biggest fans. Simon Jenkins is particularly scathing:

"The Andy Hayman 90-day dossier was treated by Blair with the same biblical reverence that he once showered on Alastair Campbell’s notorious variations on a 45-minute theme.

By Wednesday the prime minister appeared to believe that only 90-day detention stood between Britain and the imminent arrival of Hitler’s storm troops. Charles Clarke, the home secretary, said it would be “obscene” not to go for 90 days in the immediate aftermath of the July 7 memorial service, lending weight to the suspicion that the St Paul’s event had been politically orchestrated. "

Spy Blog on ANPR cameras and data retention

From Spy Blog,

If the Sunday Times is to be believed , a newspaper which has proven itself to be entirely capable of misinterpreting any new technology, the latest NuLabour Police "total surveillance" fantasy involves even more spy cameras on our road network than the thousands of them which are already in place. The article (which like many of their dubvious technoligy feature articles is illustrated by an artist's impression) includes this alarming claim::

Details of any vehicle passing a camera will be stored in a database for at least two years — even if the owner has not committed an offence

This is so unacceptable as to beggar belief.

There is no, repeat, no justification for retaining the ANPR processed license plate, location, time and date records of millions of innocent motorists for two minutes, let alone 2 years !

The Sunday Times article referred to is here.

Not a consumer

Mary Hodder has emphasised again her distaste for the "consumer" label.

"We are not creating our own media, writing blogs (Intelliseek owns Blogpulse, a blog search product), in some cases creating our own products, as 'consumers.' We are *users* with a proactive capital U.

Users are people who go out, find stuff they like, publish, remix and create a new. They are smart, they are proactive. They don't take being marketed to, but would rather either discover or get more real information from people they trust. Users have been operating digitally since the advent of the internet.

Consumers are those whose mouths are wide open, pointed toward the sky, so they can't see what's going on, like baby birds, helpless and clueless and waiting to be marketed to, while information or products are spoon-fed to them by marketers. Consumers are so 1980's.

It's Users. Get your ticket now on the cluetrain. If you keep talking about consumers, the users will pass you by as they take control of their own media, product interests and activities."

Kevin Marks thinks it should be neither "consumers" nor "users" but "amateurs"

Lessig on bipolar debate on Google Print

Larry Lessig has been criticising one of his critics, James DeLong, who he accuses of mischaracterising what he (Lessig) has been saying about the copyfight in the context of the Google Print dispute.

James DeLong says:

"In a recent blog about Google Print, Stanford Law Professor Larry Lessig repeats a story that is also at the center of his book Free Culture. He cites the 1946 airplane noise case of U.S. v. Causby as clearing the way for the air age by overthrowing the old legal doctrine that a landowner’s property extends to the heavens, thus making the airspace into a commons. He then draws an analogy to Google Print, arguing that the old copyright regime must be similarly overthrown in the name of the new commons of the Internet Age. Unfortunately, his depiction misstates the issues in Causby, ignores the fact that the landowner actually won, and fails to mention that the case stands for close to the opposite of the principles for which he cites it."

Lessig responds:

My use of the story — in both contexts — is perfectly apt, and correct. Here’s the passage I quoted from the case in the book, and referred to in the blog post:
It is ancient doctrine that at common law ownership of the land extended to the periphery of the universe - Cujus est solum ejus est usque ad coelum. But that doctrine has no place in the modern world. The air is a public highway, as Congress has declared. Were that not true, every transcontinental flight would subject the operator to countless trespass suits. Common sense revolts at the idea. To recognize such private claims to the airspace would clog these highways, seriously interfere with their control and development in the public interest, and transfer into private ownership that to which only the public has a just claim. 328 U.S. at 261.

The use I’ve made of this paragraph is simply to remark an old property rule (that property extended to the “periphery of the universe”) that modern “common sense” changed (by making the “air a public highway”). What might have made sense with one technology (a world without airplanes) no longer makes sense with another technology (airplanes) and so society thus faces a choice: respect the ancient doctrines despite the consequence for progress (by which I mean the ordinary meaning of “progress” and not the very different meaning intended in the title, “Progress & Freedom Foundation”), or let “common sense” revolt against that regressive idea. The case recognized, and respected, the revolt. The law of property does not extend to the “periphery of the universe.”...

I think Google has a “fair use” right to build an index to books. (See a careful account of this by Bill Patry.) I don’t think Google has the right to scan copyrighted books from a library and serve full copies of those books to anyone in the world. That is, I distinguish between some rights, and all rights.

The Causby case matches that distinction precisely:

(1) The law gives copyright owners an exclusive right to “copy.” That’s the equivalent of the law giving land owners rights to the “periphery of the universe.”

(2) A new technology (digital networks; airplanes) now renders absurd respecting that exclusive right as it was before that technology.

(3) The proper response is for commons sense to “revolt” against the extreme claim (that the publishers get to control every copy, even one to simply produce an index; that the rights to land extend to the “periphery of the universe”)

(4) Revolting against the extreme claim does not entail abolishing all rights absolutely. The Causby’s can complain about planes flying within the “immediate reaches” of the ground. The authors and publishers should be able to complain about, e.g., someone who scanned and made full copies of a copyrighted book available online.

But there is one great and true part to DeLong’s email. As he writes,
Causby was entitled only to the decline in his property value, not to a share of the gains from the air age.

Truly, if there is a principle here, that should be it. The baseline is the value of the property BEFORE the new technology. Does the new technology reduce THAT value. Put differently, would authors and publishers be worse off with Google Print than they were before Google Print?"

They'll probably be better off, as long as Google doesn't tune the search engine to favour some authors/publishers over others, though there are other issues such as the hacking mentioned by Doug Lichtman in the comments; and the devil on the issues will, as usual, be in the detail. It seems fairly clear, however, that the lawsuits at the moment are primarily about derviving a share of Google's revenues from Google Print. Whether you would characterise this, as Larry does, as an attempt by the publishers and Authors Guild "to tax the value created by Google Print" is another question.

Microsoft to remove Sony BMG drm

Microsoft have labelled the controversial Sony BMG drm as spyware and will be releasing detection and removal tools to deal with it. Good for them.

Gartner tell business to delay on Vista

Gartner have encouraged the business community to avoid investing in Microsoft's coming Vista operating system until at least 2008, according to the Register.

Train commuters face security scans

Alistair Darling is planning to introduce airport style security checks at train stations. Passengers will apparently be chosen for random scanning checks. Mr Darling is quoted as saying "We are only as strong as our weakest link" as far as security is concerned but I'm not sure he really means it.

The 'treat everyone as a threat' approach to security will never come anywhere close to matching the effectiveness of targeting the real threats through sound intelligence and policing. Not to mention the waste of scarce security resources and time engaged in unproductive activities and processing of false positives, the damage spread through the meme of the fear that the guy sitting next to you could be a terrorist (despite the real chances of this being statistically negligible) etc...

Building an Online Library

From the WSJ, a nice article on the Internet Archive and how they are putting together an online library "one volume at a time."

Liquid mesh

Susan Crawford sees the goal of net neutrality facing many complex challenges.

"I am as committed to the ideal of the open internet as the next guy, and my dream is to have OneWebDay support that goal. But the mischief that can be done to our future (in so many unexpected ways) by insisting on statutory and regulatory definition of neutrality seems to outweigh the possible benefits of this path. There is so much nonsense, so much horse-trading, between where we stand now and the glorious goal of neutrality. The sad fact is that Americans don't mind vertical integration one bit, and the duopolists know that. Not only that, but price discrimination in a competitive market is actually a good thing. Now all we need is a competitive market."

Before regulating networked technologies with what amount to simplistic dictats, we really need to understand how little we understand about the knowledge society and its enabling tools. As H.L Mencken once said, for every problem there is a solution which is simple, obvious and wrong.

Sony shipping spyware from SunnComm too

Following Sony's recent PR nightmare over the security holes created by their CD drm, Ed Felton points out again that other Sony CDs user another drm program, SunnComm (the same SunnComm that turned the shift key on computers into an illegal circumvention device) Mediamax that is effectively spyware. Felten has a number of concerns about the spyware:

"1. MediaMax installs without meaningful consent or notification...

2. MediaMax discs include either no uninstaller or an uninstaller that fails to remove major components of the software...

3. MediaMax transmits information about you to SunnComm without notification or consent...

To summarize, MediaMax software:
Is installed onto the computer without meaningful notification or consent, and remains installed even if the license agreement is declined;
Includes either no uninstall mechanism or an uninstaller that fails to completely remove the program like it claims;
Sends information to SunnComm about the user’s activities contrary to SunnComm and Sony statements and without any option to disable the transmissions.

Does MediaMax also create security problems as serious as the Sony rootkit’s? Finding out for sure may be difficult, since the license agreement specifically prohibits disassembling the software. However, it certainly causes unnecessary risk. Playing a regular audio CD doesn’t require you to install any new software, so it involves minimal danger. Playing First4Internet or SunnComm discs means not only installing new software but trusting that software with full control of your computer. After last week’s revelations about the Sony rootkit, such trust does not seem well deserved.

Viewed together, the MediaMax and XCP copy protection schemes reveal a pattern of irresponsible behavior on the parts of Sony and its pals, SunnComm and First4Internet. Hopefully Sony’s promised re-examination of its copy protection initiatives will involve a hard look at both technologies."

The prime minister's bubble

John was waxing lyrical on Tony Blair's and John Major's reality distortion fields on Friday.