Friday, December 16, 2005

Airline security a waste of money

Bruce Schneier has a terrific piece on airline security in his latest crypto-gram.

"Since 9/11, our nation has been obsessed with air-travel security. Terrorist attacks from the air have been the threat that looms largest in Americans' minds. As a result, we've wasted millions on misguided programs to separate the regular travelers from the suspected terrorists -- money that could have been spent to actually make us safer.

Consider CAPPS and its replacement, Secure Flight. These are programs to check travelers against the 30,000 to 40,000 names on the government's No-Fly list, and another 30,000 to 40,000 on its Selectee list.

They're bizarre lists: people -- names and aliases -- who are too dangerous to be allowed to fly under any circumstance, yet so innocent that they cannot be arrested, even under the draconian provisions of the Patriot Act. The Selectee list contains an equal number of travelers who must be searched extensively before they're allowed to fly. Who are these people, anyway?

The truth is, nobody knows. The lists come from the Terrorist Screening Database, a hodgepodge compiled in haste from a variety of sources, with no clear rules about who should be on it or how to get off it. The government is trying to clean up the lists, but -- garbage in, garbage out -- it's not having much success.

The program has been a complete failure...

I know quite a lot about this. I was a member of the government's Secure Flight Working Group on Privacy and Security. We looked at the TSA's program for matching airplane passengers with the terrorist watch list, and found a complete mess: poorly defined goals, incoherent design criteria, no clear system architecture, inadequate testing. (Our report was on the TSA website, but has recently been removed -- "refreshed" is the word the organization used -- and replaced with an "executive summary" (.doc) that contains none of the report's findings. The TSA did retain two (.doc) rebuttals (.doc), which read like products of the same outline and dismiss our findings by saying that we didn't have access to the requisite information.) Our conclusions match those in two (.pdf) reports (.pdf) by the Government Accountability Office and one (.pdf) by the DHS inspector general...

These programs are based on the dangerous myth that terrorists match a particular profile and that we can somehow pick terrorists out of a crowd if we only can identify everyone. That's simply not true."

If we take the billions we're spending on crazy programs like ID cards, children's databases, passenger screening programs like Secure Flight, passenger data disclosure between the EU and US, and spent them on more better trained police, child support professionals and intelligence officers and the resources they need to carry out effective intelligence gathering, investigation and action to prevent and respond to criminal acts, we'd be a lot better off. Even when governments are told by their own experts that these big technology schemes are worse than useless, they still press ahead not only ignoring reality but actively covering up. What you have here is what Diane Vaughan would call the "normalisation of deviance." Government evolves to a state where the process of ignoring or covering up inconvenient evidence is normalised, everyone must stay "on message" no matter how warped that message might be and we end up with vast unwieldy messes like the UK's coming ID card system or the EU database directive.

Thursday, December 15, 2005

New Consumer Digital Rights campaign

A new European Consumers Digital Rights campaign has been launched. They have a list of six generic rights,
Right to choice, knowledge and cultural diversity
Right to the principle of “technical neutrality” – defend and maintain consumer rights in the digital environment
Right to benefit from technological innovations without abusive restrictions
Right to interoperability of content and devices
Right to the protection of privacy
Right not to be criminalised
which they urge policymakers to respect.

WIkipedia close to Brittanica for reliability

A study by Nature suggests that Wikipedia comes very close to Encyclopedia Britanica in accuracy.

Kazaa owners may face jail in Australia

In the spirit of the season that's in it, the music industry in Australia have made an application to a federal court to have Kazaa owners declared in contempt of that court's order to implement software filters. Representatives of Sharman Networks, which owns Kazaa, say they have implemented the filters and succeeded in preventing most Australians from downloading copyrighted music using their software. The music companies are annoyed that the filters do not apparently apply outside Australia.

The judge said "Contempt proceedings are fairly rare in this court and I've never yet sent anyone to jail. I've threatened to a few times, but there's always a first I suppose."

Ireland to contest data retention directive

It looks as though Ireland is going to challenge the the EU parliament's passing of the data retention directive. It will apparently be done on procedural grounds and to defend the principle of Ireland's autonomy on justice matters.

The Commission's lawyers have already pointed out that the process has no legal basis so there is a good chance that such action on the part of the Irish government will be successful, if it is pursued to a natural conclusion in the European Court of Justice (ECJ). This all takes time, though.

The data retention vote seems, thus far, to have bypassed the attention of most of the mainstream media outlets in the UK, apart from the Guardian.

Wednesday, December 14, 2005

News outlets pick up data retention decision

The news outlets are now picking up the data retention decision.

Nearly 60000 people have signed a petition against this proposal. Member government parliaments have refused to ratify similar proposals at national level. The EU parliament has rejected an almost identical proposal in the past. European data protection commissioners have severely criticised the proposal. Commission lawyers have declared it to be illegal. The telecommunications and internet services industries have severely criticised the proposal. Civil liberties groups have been apoplectic about it.

Yet a small group of politicians and officials can do a deal behind closed doors and a majority of MEPs vote it through on the nod. Ralf Bendrath of the European Digital Right Initiative has this to day about it:

"Very bad news from Europe.

The European Parliament this morning voted in favour of a backroom deal
that had been made between the two big parties in Brussels and the Council
of Ministers, currently chaired by the UK. The deal completely ignored the
amendmends proposed by the Parliament's Rapporteur and by the Justice and
Civil Liberties Committee that was (well - officialy) in charge of the
process. After a hot debate and a number of signs of cracks in the party
blocks, a majority of 378 parliamentarians voted in favour of mandatory
retention of telecommunications data, 197 against, 30 abstained.

This is in short what we will get now:

- retention of telephone and internet connection data (including email
addresses) and location data for mobile phone calls
- no harmonisation of the retention period (6 to 24 months but longer is
allowed: Poland wants 15 years)
- no harmonisation of cost reimbursement for the needed investments on the
providers' side
- no limitation to certain types of crimes for which access is allowed
- retention of unsuccessful call attempts
- no independent evaluation
- no extra privacy safeguards
- follow-up committee without representation from civil rights organisations

Civil liberties organizations, consumers organizations and all the telco
industry associations as well as journalists associations had been
fighting like hell against this major and unprecedented surveillance plan
until the last minute. We did not win (the outcome is in fact the worst
possible, exactly what the UK home affairs minister Clarke wanted), but we
at least raised a lot of awareness and disturbed the conservative and
social-democrat party lines. But the UK council presidency had pushed so
hard after the London bombings that this directive will enter the EU
history as the one which took the shortest time ever from the first
Commission draft to the final vote (less than three months - normally they
need years).

The next steps will be the adoption by the Council of Ministers (before
christmas) and then the implementation process into national laws. There
will be challenges to this plan before the constitutional courts. I am
pretty sure that the German constitutional court will not like it, as it
recently had ruled unconstitutional a major eavesdropping plan on phone
calls - and that one was only directed at suspicious persons, whereas the
EU directive applies to every single communication of all 450 Million
inhabitants of the EU.

More information, including recordings of the EP debate, is available at
http://wiki.dataretentionisnosolution.com/."

EU parliament vote for data retention

The EU parliament have voted for the data retention directive.

"Results of votes at plenary session on Wednesday 14 December
A list of the reports put to the vote in the European Parliament on Wednesday 14 December. More detailed analyses of votes will soon be available from Parliament's Press Service website

Results of votes on Wednesday 14 December
Data retention
Directive of the European Parliament and of the Council on the retention of data processed in connection with the provision of public electronic communication services and amending Directive 2002/58/EC
(A6-0365/2005)
Rapporteur: Alexander Nuno Alvaro (ALDE, DE)
Parliament adopted a package of compromise amendments after agreement had been reached with the Council. The amendments were approved by 387 votes in favour to 204 against with 29. The final resolution was adopted by 378 votes in favour to 197 against with 30 abstentions."

I haven't noticed any of the major news sites picking this up yet.

Lyrics Browsers, iTunes and Copyright Law

From the EFF: Lyrics Browsers, iTunes and Copyright Law

"When I buy a CD, I look forward to having the lyrics printed in the liner notes. That's part of what I expect in exchange for my money. If the record label omits the lyrics, I feel I'm entirely within my fair use rights to listen closely to the recording and copy down the lyrics. Similarly, I'm within my fair use rights when I use a search engine to find the lyrics of the music I've legitimately purchased. And thanks to Apple's iTunes software, I now can add those lyrics to the digital copies of the music I've purchased and have them appear when the song plays on my iPod.

Apparently, at least one music publisher thinks that makes me a music pirate. Yes, annotating music I've legitimately purchased with lyrics makes me a pirate, according to music publishing giant Warner/Chappell.

Warner/Chappell sent a cease & desist letter last week to the developer of pearLyrics, a piece of software that automates the process of adding lyrics to iTunes tracks. (For more details, see the MacWorld review.)"

The best science that money can buy

David Bollier recounts the lack of trust of medical friends and acquaintances in medical journals which they believe have been compromised by the financial support of the large pharmaceutical companies; and draws on a Wall Street Journal article for support.

"Reporter Anna Wilde Mathews writes:
Many of the articles that appear in scientific journals under the bylines of prominent academics are actually written by ghostwriters in the pay of drug companies. These seemingly objective articles, which doctors around the world use to guide their care of patients, are often part of a marketing campaign by companies to promote a product or play up the condition it treats.
The article goes on to describe how ghostwriters are frequently hired to write articles that academics are invited to publish under their own names. It’s a sweet scam. Academics get to pad their publishing resumes. Medical journals get well-written articles by big-name scientists. And the drug companies get to exploit the credibility and independence of academic science for a relative pittance."

Monday, December 12, 2005

Digital Rights Ireland

A new digital rights group is about to be launched in Ireland.

Latest excuse... er reason for ID cards

The government's latest excuse for the ID cards scheme is that it wil cure online fraud, says John Lettice.

Canada may develop Patriot act shield

The federal government in Canada have, if this report is to be believed, have developed a plan that "would allow government departments to immediately cancel a contract with an American firm if it hands personal information about Canadians to U.S. anti-terrorism investigators" under the requirements of the PATRIOT Act. That's a fairly bold step on the part of the Canadians to take a stand against the PATRIOT act but where does it leave the companies that get stuck in the middle? As soon as they get served with a request for data by US authorities they break the law whichever way they turn.

Thanks to Michael Geist for the link.

ID cards for children by the back door

The Children Act of 2004 is back in the news with the announcement that the database to log the details of every child in the UK will cost £224 million plus another £41 million a year to operate. The Conservative party spokesman on the issue said:

"The government's nanny-state approach will do nothing to safeguard the children most at risk. We should be concentrating on the most vulnerable children who are on child protection registers, in care or in homes with a record of domestic violence.

We opposed this clause when it was proposed in the Children's Act 2004. It is bureaucratic nonsense and ID cards for children by the back door."

What's somewhat remarkable is that this law sailed through without the opposition that the ID card proposal has been facing. It suffers many of the same problems as the ID card system but just acts as another indicator of how difficult it is to politically oppose a plan with the stated aim of improving child protection, no matter how badly the actual details of the plan might, in practice, undermine that aim. The time that already stretched child care workers, police, NHS and others will have to put into bureaucratic processing of details of the vast majority of children who are not at risk, will take away from the already limited time and resources they have to work with the really vulnerable.

Remember Schneier's questions:

What problem are you trying to solve?
Protecting children.

How well does your solution solve the problem?
If there is joined up information and communications in the case of victims and tracking those who have abused children it may make a contribution to filling the holes that might have prevented some of the tragic cases we've seen in recent years. I'm not exactly sure that a central database of the type planned will necessarily do this, given the vast array of computing systems the various branches of public services engaged in child protection actually have.

How can the system fail naturally and how can it be made to fail by someone with malign intent?
Big databases have errors. People working with the system will make mistakes. A large number of people need access to the database so it will not be secure - it only takes a small number of malign actors internal or external to compromise a large database of this sort.

What other problems does it cause?
Scarce time and resources are lost in processing details and cases of children who are not at risk. False positive and false negative errors could have serious consequences.

How much does it cost?
£224 million plus £41 million per annum apparently.

Is it worth it?
Well could these resources be more effectively invested and targetted at frontline child protection services?

Setting up a system to assume every child is a victim is similar to setting up a system to assume every citizen is a terrorist. Neither will actively tackle the serious problems to which they are allegedly addressed and may very well end up compounding them.

Friday, December 09, 2005

IP geek

There's a new IP blog, IP Geek, in the blogosphere which looks promising.

Online journalism flourishing because it's trusted

David Bollier says the real reason that online journalism is flourishing is that it is trusted.

Felten on why drm inevitably becomes spyware

Ed Felten has a wonderful explanation of why drm vendors and spyware vendors are actually facing the same problems and so converge on the same solutions, so that drm inevitably becomes spyware.
"Here’s the key issue: Active protection only works if the DRM software is running on the user’s computer. But the user doesn’t want the software on his computer. The software provides no value to him at all. Its only effects are to stop him from doing things he wants to do (such as listening to the music with iTunes), and to expose him to possible security attacks if the software is buggy.

So if you’re designing a CD DRM system based on active protection, you face two main technical problems:
You have to get your software installed, even though the user doesn’t want it.
Once your software is installed, you have to keep it from being uninstalled, even though the user wants it gone.

These are the same two technical problems that spyware designers face.

People who face the same technical problems tends to find the same technical solutions. How do you get software installed against the user’s wishes? You mislead the user about what is being installed, or about the consequences of installation. Or you install without getting permission at all. How do you keep software from being uninstalled? You don’t provide an uninstaller. Or you provide an uninstaller that doesn’t really uninstall the whole program. Or you try to cloak the software so the user doesn’t even know it’s there.

Of course, you don’t have to resort to these tactics. But if you don’t, your software will have trouble getting onto users’ computers and staying there. If your whole business model depends on installing unwanted software and preventing its uninstallation, you’ll do what’s necessary to make that model work. You’ll resort to spyware tactics. (Or you’ll quit and go into another business.)

Having set off down the road of CD copy protection, the music industry shouldn’t be surprised to have arrived at spyware. Because that’s where the road leads."

iPod insurance

There's a nice article in The Big Issue this week about insurance companies attitudes to digital music. If you get your iPod or other MP3 player stolen, then don't expect your insurance company to replace the vast digital music collection you've built up on it. Basically, most people will "never have thought about how they would prove the financial value of their digital music collection if it became necessary."

Norwich Union replaced 36 iPods between January and September 2004. For the same period this year it was 1721. An insurance company manager offers the sound advice that people should keep a record of their online music purchases. But I doubt many people will be bothered enough to do so, particularly if their practice is to buy single tracks at 70p each.

John Gilmore in court

John Gilmore has finally had his appeal court hearing on his challenge to the secret US government regulations apparently making it compulsory for airlines to demand identification or subject a prospective passenger to a pat down search before boarding a flight.

There's some symmetry to the appearance of this hearing in the immediate wake of the UK House of Lords decision a couple of days ago ruling that evidence obtained under torture in foreign jurisdiction was not admissable in cases against terror suspects. The Court of Appeal had created quite a stir last year when they decided that such evidence could be used as long as the UK hadn't been involved in or condoned the torture.

Lord Bingham, said: "The issue is one of constitutional principle, whether evidence obtained by torturing another human being may lawfully be admitted against a party to proceedings in a British court, irrespective of where, or by whom, or on whose authority the torture was inflicted. To that question I would give a very clear negative answer."

MI5 chief, Eliza Manningham-Buller, told the law lords that she needed to rely on foreign intelligence to save lives, which is undoubtedly true. But the government lawyer's translation of that into the notion that they should not check the integrity or source of the intelligence, just in case it might upset the countries that do endorse and carry out torture, has got no basis in any kind of principle.

Thursday, December 08, 2005

Sony knocking the glass over

Ed Felten has more sound thoughts on the latest Sony drm security patch hole.

"Security is all about risk management. If you’re careful to avoid unnecessary risks, to manage the risks you must accept, and to have a recovery plan for when things go wrong, you can keep your security under control. If you plunge ahead, heedless of the risks, you’ll be sorry.

If you’re a parent, you’ll surely remember the time your kid left an overfull glass of juice on the corner of a table and, after the inevitable spill, said, “It was an accident. It’s not my fault.” And so the kid had to learn why we don’t set glasses at the very edges of tables, or balance paintbrushes on the top of the easel, or leave roller skates on the stairs. The accident won’t happen every time, or even most of the time, but it will happen eventually.

If you’re a software vendor, your software creates risks for its users, and you have a responsibility to your customers to help them manage those risks. You should help your customers make informed choices about when and how to use your software, and you should design your software to avoid exposing customers to unnecessary risks."

Felten's DRM, Incompatibility, and Market Power: A Visit to the Sausage Factory is also a must read on this sorry saga.

France to get the worst copyright law?

Cory wonders if France are about to adopt the worst copyright law in Europe.

Publishers should stop worrying about Google

Susan Crawford thinks publishers should stop worrying about Google and start thinking about the opportunities an evolving Web present them.

"What Google does is respond to search queries by providing snippets -- thumbnail pictures and a line of text here, a line from a page there, a headline -- and helping people get to where those things were posted. That's pointing, not copying, and it's a key element of Web 2.0.

The publishers, and the news agencies, are having trouble with this evolution -- heck, they had enough trouble with Web 1.0, much less the groupness we're seeing now-- and are relying on incumbent laws (like copyright law) to protect their ability to charge for content.

But there's a great opportunity here that shouldn't be missed: news companies can become not only providers of great stories (well-researched, well-written, unlike blog posts) but also sources of order. There is so much information now -- we need help! We need priority, and sense of impact, and sense of global connections. We need visualizations, and links, and commentary. All of these things are valuable. We'll pay -- with our attention, our loyalty to the brand, and maybe even with money if the reporters' own personalities are allowed out to play.

A search engine, alone, can't provide this kind of judgment. Not even Google can say which story is likely to have an important impact on our collective future. There is a Web 2.0 model for publishers, and they can only get there by letting go."

Major copyright reform in EU - uh oh.

IPKat has learnt from the Patent Office we're facing

"of an EU programme with potentially major implications for European copyright law. In, Implementing the Community Lisbon programme: A strategy for the simplification of the regulatory environment the European Commission explains the need for EU regulatory laws to be simplified so that a balance is struck between necessary regulation and the need to avoid overcomplicated legislation that entails “costs, hamper business, channel resources away from more efficient uses and in some cases act as a constraint to innovation, productivity and growth” .



The EU wants to save IP lawyers from confusion...
To this end, the EU is embarking on a programme designs to simplify the acquis of various of EU areas of influence. Included in the list of priorities is copyright. The following instruments are identified for “Recast[ing] with a view to improve[ing] the coherence and operation of the legal framework and adapt it to the new digital challenges:

* Council Directive 91/250/EEC of 14 May 1991 on the legal protection of computer programs
* Council Directive 92/100/EEC of 19 November 1992 on rental right and lending right and on certain rights related to copyright in the field of intellectual property
* Council Directive 93/83/EEC of 27 September 1993 on the coordination of certain rules concerning copyright and rights related to copyright applicable to satellite broadcasting and cable retransmission
* Council Directive 93/98/EEC of 29 October 1993 harmonising the term of protection of copyright and certain related rights
* Directive 96/9/EC of the European Parliament and of the Council of 11 March 1996 on the legal protection of databases
* Directive 2001/29/EC of the European Parliament and of the Council of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society"

The idea of simplifying IP regulations is laudable but the devil, as usual, will be in the detail. It is arguable, for example, that the IPR enforcement directive sinmplifies the IP regulatory environment by theoretically harmonising across all the member states but you certainly won't get me signing up to such an argument. The real damage from that particular directive still remains to play itself out over the coming years but that it will certainly do.

US reject generic drugs even for emergencies

David Bollier and James Love have an important story about trade negotiations over generic drugs at the World Trade Organisation a couple of days ago.

Love says:

"Although not reported in the US mainstream media, and barely noted in the European, Australian or Canadian press, the decision will contain a provision that is intended to prevent the United States, the members of the European Community, and a few other countries from getting access to generic medicines, even in cases involving national emergencies, such as an avian flu pandemic.

Our trade officials will tell the WTO our countries will “opt-out” of a WTO agreement, as potential importers of generic medicines, no matter what the circumstances are. The push for the “opt-out” was engineered by the CEOs of large pharmaceutical companies, such as Pfzier CEO Hank, McKinnell, and GSK’s Jean-Pierre Garnier.

In the United States, the “opt-out” was backed by President Bush’s
advisor, Karl Rove, and top US trade official Bob Portman. Portman
refused to meet with public health groups to defend the decision.

News reporters for the New York Times, the Washington Post, the Wall Street Journal, Reuters and other major news outlets have not reported on the opt-out issue, claiming “it’s too complex for readers to understand.”"

The pharmaceutical companies are acting to protect their interests via the WTO, as you expect them to do. They exist to make money not for public health reasons. Intellectual property is a complex subject, so the press say it is too hard for ordinary people to understand. That is a defensable position. Say "intellectual property" to most people and their eyes will glaze over.

However, the fact that business is in the business of making money and that IP is complicated, is not an excuse for saying that what is going on is right or even acceptable. When commerce operates to exploit complex regulations in such a way as to undermine the public interest, the media, public officials and ordinary citizens who do grasp the complexities have a duty to shine a light on the activity, explain it in such a way that it is comprehensible (especially if it's reprehensible) and bring that activity to a grinding halt.

Bollier puts it like this:

"Is it really so hard to understand the implications of these developments at the WTO? People will die because medicines are artificially expensive. Big Pharma wants to protect its patents and revenues at all costs, the public health and poor countries be damned. Compliant governments and a lapdog press are happy to let Big Pharma have its way.

That wasn’t so complicated now, was it?

The WTO decision represents a decisive repudiation of the WTO’s 2001 Doha Declaration on TRIPS and Public Health, which called for policies to make it easier to export generic medicines under compulsory licenses."

FOI request on ID cards rejected

The Home Office has rejected a Freedom of Information request by Computer Weekly to publish the risk register relating to the ID card scheme.

Ordinary people turned war criminals

On the front page of today's Independent, a story entitles War Criminals describes three court cases.

" * Maya Evans, 25, convicted for reading out names of 97 British soldiers killed in Iraq at unauthorised protest.
* Douglas Barker, 72, threatened with jail for withholding part of his tax payment in protest at the Iraq conflict.
* Malcolm Kendall-Smith, a 37-year-old RAF medical officer, facing court-martial for refusing to serve in Iraq"

Evans apparently told magistrates "I didn't want to be arrested but, as far as I was concerned, I didn't think I was doing anything wrong standing there on a drizzly Tuesday morning with a colleague reading names of people who had died in a war. I don't think it's a criminal offence and I don't think I should have been arrested for it."

She was convicted under Section 132 of the Serious Organised Crime and Police Act 2005.

Barker told magistrates that he'd estimated that 10% of his taxes were going on military spending and he had therefore witheld that amount and intended to send it to a charity caring for children in Iraq. He wanted a guarantee that if he did pay the money it would not be used for military purposes.

Kendall-Smith refused to serve in Iraq because having reviewed the legal advice on the war, including that of the Attorney General, he came to believe the war was illegal. His court martial is due to take place in the Spring.

Heise liable for reader comments

The first-instance district court of Hamburg has ruled that the online news site Heise can be held liable for readers comments and "has had issued a temporary restraining order preventing heise online from publishing reader comments calling on others to overload a company's server by massively downloading a program."

The court said Heise should be liable for reader comments inciting destructive attacks online, whether they were aware of the specific comments or not. Heise had deleted the comments which has originally prompted the lawsuit but originally believed they only had to removed comments that they were aware of or had been notified of.

Heise apparently get about 200000 comments per month and software filters just aren't good enough to catch all the relevant subtleties (not to mention the false positive irritations they cause). Manual checking of that number of comments is not an option, so do Heise have to close down the commenting option? Well the German Supreme court ruled last year that sites like Heise could only be held liable if there were reasonable ways of reviewing the content third party contributors, so maybe not. The EU ecommerce directive of 2000 also says service providers don't have to comprehensively monitor comments they just transmit or store. So where does that leave Heise? Probably paying lawyers to test the limits of what the contradictions really mean.

Tuesday, December 06, 2005

IPR battle at Cambridge University resumes

The battle over the intellectual property rights of academics at Cambridge University has started up again, according to Patent Baristas.

You'll probably find Ross Anderson has one or two things to say about that.

The $100 laptop

John is a little skeptical of the real utility of Nicholas Negroponte's $100 laptops for children in the developing world.

" the pedagogical philosophy implicit in OLPC is clearly inspired by Negroponte's MIT colleague, Seymour Papert.

Papert is a visionary whose entire career has been driven by the idea of the digital computer as a revolutionary machine...

Papert is an engaging thinker and writer, but is essentially a techno-evangelist...

He is thus rather grandly contemptuous of mundane questions such as whether there is any evidence that giving kids computers is educationally better than giving them books..."

As I've said before, you can't get someone to understand the principles of drawing graphs by getting them to show you how many colours the graphics package on their computer can deploy in producing something that looks like a graph on screen. By all means exploit technology (including the humble pencil) in education where it is useful and let people play with technology in education in order to find out how it can be useful. But spending vast sums on technology in the blind faith belief that it will automatically improve things regardless of the context, is a mug's game.

EDRI

The latest and possibly the last EDRI newsletter has been published.

Contents:

Urgent call for pledges of support for EDRI-gram
1. Final push for single EP vote on data retention
2. EDRI and PI call on EP to reject data retention
3. Polish plans for 15 years mandatory data retention
4. Urgency procedure for draft French anti-terrorism law
5. New anti-terrorism measures in Denmark
6. Launch of Digital Rights Ireland
7. Illegal video surveillance on Slovenian motorways
8. Post-WSIS civil society letter to Kofi Annan
9. NL supreme court ruling on internet anonymity
10. Results e-society conference in Macedonia
11. Advocate General European Court rejects PNR deal
12. Cryptography almost banned in the Czech Republic
13. Agenda
14. About

Ireland to challenge data retention deal

Irish justice minister, Michael McDowell, suggested in the wake of the agreement amongst most EU justice ministers about data retention, that Ireland would challenge the directive in the European Court of Justice, if it gets passed by the EU parliament next week.

Wikipedia integrity

I had the priviledge of meeting the founder of Wikipedia, Jimmy Wales, last week, at the inaugural gathering of the Open Rights Group. Wikipedia is a fantastic online encyclopedia, which, given the fact that anyone can alter an entry, is mostly remarkably reliable. Occasionally things go wrong, however, as this story in the New York Times illustrates. A Mr. Seigenthaler was shocked to find an entry on himself in Wikipedia, suggesting he might have been involved in serious crimes. The entry has since been corrected but the poster has not been identified. Mr. Seigenthaler has decided not to pursue the issue, though it would be possible for him to get a court order to ask the poster's ISP to identify the culprit and then pursue a defamation case. Sensibly he forgoes the opportunity to invest large sums in lawyers and the associated stresses of lawsuits, though he says he's learned a clear lesson:

"We live in a universe of new media with phenomenal opportunities for worldwide communications and research, but populated by volunteer vandals with poison-pen intellects."

The article also describes Jimmy Wales reaction

"Mr. Wales said in an interview that he was troubled by the Seigenthaler episode, and noted that Wikipedia was essentially in the same boat. "We have constant problems where we have people who are trying to repeatedly abuse our sites," he said.

Still, he said, he was trying to make Wikipedia less vulnerable to tampering. He said he was starting a review mechanism by which readers and experts could rate the value of various articles. The reviews, which he said he expected to start in January, would show the site's strengths and weaknesses and perhaps reveal patterns to help them address the problems.

In addition, he said, Wikipedia may start blocking unregistered users from creating new pages, though they would still be able to edit them.

The real problem, he said, was the volume of new material coming in; it is so overwhelming that screeners cannot keep up with it."

Monday, December 05, 2005

Court upholds random NY subway searches

Professor Dan Solove is annoyed at a recent court decision upholding the right to the police to engage in random searches on the New York subway.

"After making its general incantation of deference (which means that the government will automatically win), Judge Berman goes on to articulate the "persuasive" arguments of the government:
The Court is also persuaded by Commissioner Sheehan's opinion that the Program "reinforces the awareness of police officers, transit workers and the public of the need to be alert."
This is a silly argument. Essentially, the court says that providing the police with greater abilities to engage in searches without constitutional protections will make the police more "alert." Well, that's nice -- we should all be happy to sacrifice liberties so that the police become more alert. And the court notes that it will teach the public to be more alert too. So the argument is that we can make the people more alert by intruding upon their privacy. Let's try strip searches -- these will certainly make the cops more alert, and it will have great effects on public alertness too, and the cops can have a lot of fun at the same time.

The court also reasons:
[T]he Court is persuaded that the randomness of the searches rather than the actual number of searches conducted is (primarily) what makes the Container Inspection Proogram effective.
In other words, the court is saying that any small increase in terrorists believing they might get caught makes such a policy an effective. But if "effectiveness" is to have any meaning, the benefits of a policy that requires a sacrifice in liberty should be more than just trivial or speculative. There is no evidence that this policy will have any deterrent effect...

It is bad enough that so much money and resources must be wasted on a largely symbolic exercise to make public officials look like they're doing something to protect us when they're not. This cosmetic program for public officials which drains money from other more serious threats. It is even worse that people must sacrifice liberty and convenience too."

You have to admit he has a point.

Felten: DMCA should not protect spyware

Ed Felten thinks the DMCA should not protect spyware and he's submitted a request for an exemption along these lines to the US copyright office.

Exams

Open University exam results will be available soon. To those who don't do as well as you'd hoped, just remember that it's not the end of the world. Even the best of students can and sometimes do find things going wrong.

Getting through the process of distance learning whilst holding down a job and looking after a family and all the other real life committments that OU students typically have, is a major success in itself. So give yourself a pat on the back even before the results arrive - you deserve it.

Open letter on data retention

A whole plethora of digital rights groups have written an Open Letter to the European Parliament on Data Retention.

58000 people from all over Europe have signed a petition against data retention.

Will it make a difference to the European Parliament vote on the issue on 13 December? Only time will tell but it looks like the version of the proposal to go before the parliament will require two years data retention.

This process of repeatedly sending back lousy legislative proposals through the EU system, until opposition is chipped away though the lack of energy to be bothered with it again, seriously undermines the EU. But then representative democracy, which is what the parliament is supposed to be based on, only works if a sufficient number of dedicated people (albeit that sufficent number can range from 1 upwards) take an active interest. Nearly 60000 people have shown an interest here but in this case I'm not sure it's going to be enough.

Parliamentary drm enquiry

From the All Party Internet Group website: "(APIG)The All Party Parliamentary Internet Group (APIG) is to hold a public inquiry into the issues surrounding Digital Rights Management (DRM)...

The inquiry seeks written evidence particularly focusing upon the following:

Whether DRM distorts traditional tradeoffs in copyright law;
Whether new types of content sharing license (such as Creative Commons or Copyleft) need legislation changes to be effective;
How copyright deposit libraries should deal with DRM issues;
How consumers should be protected when DRM systems are discontinued;
To what extent DRM systems should be forced to make exceptions for the partially sighted and people with other disabilities;
What legal protections DRM systems should have from those who wish to circumvent them;
Whether DRM systems can have unintended consequences on computer functionality;
The role of the UK Parliament in influencing the global agenda for this type of technical issue.

APIG calls upon interested parties to present written evidence to the inquiry before 21st December 2005.

Written evidence should be submitted to admin@apig.org.uk. APIG may, at its discretion, ask for oral evidence from witnesses in January 2006 at the Houses of Parliament."

Transformational government

William Heath has posted his comments on the UK CIO Council IT strategy in four pieces. He thinks the main issues are:
- the fundamental premise that services should be personalised and directed at people, when I'd rather see simple, open and navigable government (which is less ambitious, cheaper and less intrusive)
- making identity government-controlled and tying it to the compulsory biometric scheme with audit trail
- grudging lip-service to privacy when human dignity is paramount
- whether or not the executive focus and energy is there to deliver changes like shared services.

Sunday, December 04, 2005

Diebold certified in spite of court order

It seems that the North Carolina Board of Elections has certified Diebold Election Systems to sell electronic voting equipment in the state, in spite of a federal judge's order that Diebold hand over their source code and list of programmers. Does this mean they have secretly handed over the required details (even though they claimed that they would rather withdraw from tendering) or that the Board officials were unaware of the judge's decision when they approved Diebold as an electronic voting machine vendor?

Saturday, December 03, 2005

UK intellectual property review

The UK Treasury has announced a review of intellectual property.

"At the Enterprise Conference on 2 December 2005, the Chancellor announced that, as part of the Pre-Budget Report 2005 package, he was asking Andrew Gowers to lead an Independent Review to examine the UK’s intellectual property framework, reporting to the Chancellor, the Secretary of State for Trade and Industry and the Secretary of State for Culture, Media and Sport in Autumn 2006."

Under "scope" the final bullet point says

"The review will provide an analysis of the performance of the UK IP system, including inter alia...

whether the current technical and legal IP infringement framework reflects the digital environment, and whether provisions for ‘fair use’ by citizens are reasonable."

Which is interesting because we don't have "fair use" in the UK. We have "fair dealing" which though similar is not the same. "Fair use" in the US, for example, allows the making of copies of CDs for personal use, whereas "fair dealing" in the UK does not.

Friday, December 02, 2005

Dutch e-citizen charter

William Heath thinks the Dutch 10 point e-Citizen Charter might be what we need for Europe. I'll have to come back to this as other things are pressing but it raises all kinds of interesting questions.

Turning the Net into cable TV

David Bollier advises:

"Beware the privateers! They whisper sweetly of fantastic new services they will provide – a faster Internet, better quality, even medical alerts for consumers….and blah-de-blah. Their unspoken agenda, however, is to convert the open Internet commons into a pay-for-performance marketplace. The companies who control the “pipes” of the Internet – i.e., the telephone and cable TV companies – are starting to make their move.

It’s imperative that we pay close attention to these plans – and register our objections to Congress and the companies themselves."

Thursday, December 01, 2005

Copyright dispute over book cover

Thomas Friedman and his publisher, Farrar, Straus and Giroux, have been sued over the cover on his latest book, The World is Flat. (Interestingly enough I see Amazon UK have "No Image Available" for the cover at the moment).

Freidman used an image from a poster he'd bought many years ago, of a painting done by artist Ed Miracle, showing boats sailing over the edge of the world, which featured the caption "I told you so." His publisher had duly licenced the right to use the image from the poster company. The poster company, unfortunately didn't hold the copyright in the image. They only had a licence to sell about a thousand posters and that licence expired in 1996.

The author said: "We didn't try to cheat anybody. We did it [purchased the rights] through normal channels. We thought this was all legal, kosher, and right. I feel bad that this happened, and I couldn't feel more bad for him [Miracle]."

The artist's agent, Rose von Perbandt, said "Is there no one in the press that sees the irony of a book on globalization—whose author stresses the need to protect against piracy and strengthen intellectual property protection—that is infringing the copyrights of the artist whose work was used on the cover?"

It's a fair point, which goes to show that even those with an interest in strong intellectual property rights, including Pulitzer Prize winning journalists/authors, can sometimes accidently get entangled in the complexity of the current IP landscape.

IPPR report

The Institute for Public Policy Research has just released a report "Markets in the Online Public Sphere." As the author of the report Will Davies puts it the report covers "the politics and economics of online information, and why policy-makers find it so hard to accertain the 'public interest' in this confusing terrain."

Tuesday, November 29, 2005

President Bush disaster

I don't think Rupert Murdoch really would have wanted this image to come across the way it does...

Diebold ordered to supply source code

A federal judge has ordered Diebold to hand over the source code on its electronic voting machines to North Carolina state officials. From the EFF:

"a North Carolina judge today told Diebold Election Systems that the e-voting company must comply with tough North Carolina election law and dismissed the company's case seeking broad exemptions from the law.

EFF intervened in the case earlier this month, after Diebold obtained a broad temporary restraining order that allowed it to evade key transparency requirements without criminal or civil liability. The law requires escrow of the source code for all voting systems to be certified in the state and identification of programmers. In today's hearing, the judge told Diebold if it wanted to continue in the bidding process for certified election systems in the state, it must follow the law and if it failed to do so, it would face liability...

Diebold could appeal the ruling, go forward with its bid, or withdraw from the process. However, Diebold told the court that it would likely withdraw the bid if the company did not have liability protection.

North Carolina experienced one of the most serious malfunctions of e-voting systems in the 2004 presidential election when over 4,500 ballots were lost in a voting system provided by Diebold competitor UniLect Corp. The new transparency and integrity provisions of the North Carolina election law were passed in response to this and other documented malfunctions that have occurred across the country."

It is very good news that a judge should enforce transparency requirements on a voting machine vendor. Given that Diebold have explicitly now threatened to withdraw from the bidding process rather than hand over theie source code, it will be interesting to watch to see if they follow through on that. Transparency is fundamental to the democratic process and no amount of technology or commerce should be allowed to undermine that.

New UK Biometric Centre

The Home Office are planning to set up a new "Biometric Centre of Expertise" (who comes up with these names?).

Their Science and Innovation Strategy 2005-08 includes the oft repeated, wildly ambitious and completely fallacious claim that "The National Identity Card scheme will be a powerful tool to tackle identity theft, illegal working, terrorism and organised crime." It follows up later in the same paragraph (p14, para on "Identification") with "In recognition of its importance the Home Office is creating a Biometric Centre of Expertise within HOSDB." HOSDB stands for "Home Office Scientific Development Branch."

Public services and ICT report

The Work Foundation has published its final report on Public Services and ICT.

Nothing earth shattering. Basically it says -

ICT could transform public services but only if objectives are clear and the right ICT is used,

Staff at all levels are struggling to make ICT effective,

Leaders must be responsible for realising potential and managing risks of ICT,

"Customers must be segmented" (sounds painful but this is just an attempt at marketing-speak),

The ICT with the most attractive bells and whistles is not necessarily the best for the job,

Improve supply chain management,

Listen to the users when building ICT systems,

ICT has an impact on privacy.

Monday, November 28, 2005

Kazaa get reprieve in Australia

P2P Net have the transcript of the hearing in an Australian court where Sharman Networks, owners of Kazaa, were given an extension to the deadline to implement filters. It seems the music industry's lawyers failed to attend a court ordered meeting about how the technicalities of the filtering were supposed to work but the judge does try not to let that cloud his judgement, even though he's angry about it.

The judge said:

"I thought it was discourteous in the extreme for your clients to notify that they wouldn't attend by an email sent at 8 minutes to 6 on the Friday night for an appointment that had been arranged for a long time which was due to start at 9 am on Monday. It is just not acceptable for solicitors to behave in that way to a Registrar of the court...

I just want to express as forcibly as I can, when I make directions for attendance before the Registrar I expect practitioners to treat the Registrar with the normal courtesies we would expect from each other."

The technical Registrar in a report to the court said

"Whilst the applicants had displayed co-operation in attending the first conclave and their technical representatives demonstrated good faith in contributing to the development of the protocol, it was unfortunate that this co-operation did not extend to their attendance at the resumed conclave."

So they engaged in the process to begin with but then pulled out because they reckoned the Kazaa folks were not taking it seriously, even though the court appointed officer felt that they were.

Kim Weatherall called the judge's decision on Kazaa "brave" when it was published primarily because of the huge amount of work she predicted would come the court's way in supervising this kind of process. This kind of spat was predictable though I'm not sure "brave" was the right descriptor. The transcript is quite entertaining in places with the judge suggesting to the music industry lawyer that they hadn't been too clever in their tactics - if they'd gone to the meeting and put it clearly on the record that Kazaa were not taking the filtering seriously and got the REgistrar to accept that, then Kazaa could have been in serious difficulties coming back before the court asking for a stay on the injunction. Instead they took their bat and walked away, insulting the court appointed registrar into the bargin. Interestingly enough the judge goes on to criticise both sides for their posturing.

It's well worth a read if you follow the politics and legalities of p2p file sharing.

PNR decision a shock?

EU law blog characterises the ECJ Advocate General's decision on the transfer of EU airline passenger data to the US authorites as a shock. I'm not sure it is a shock necessarily, given the amount of behind the scenes politicking that's gone on with this, but it's certainly worth noting that the specific reasons why he concludes as he does, that the European Court of Justice should annul the Council's and the Commission's decisions on the handover, are different to the reasons put forward by the European Parliament, which made the complaint.

"First, he considers that Commission Decision 2004/535/EC on the adequate protection of personal data contained in the Passenger Name Record of air passengers transferred to the United States Bureau of Customs and Border Protection was wrongly based on Directive 95/46/EC because the processing of the data put at the disposal of the United States concerned public security and the activities of the state in relation to criminal law and the fight against terrorism. Processing data for such purposes is outside the scope of the protection afforded by Directive 95/46/EC according to its Article 3 § 2. As the Commission could not lawfully adopt Decision 2004/535/EC on the basis of article 25 § 6 of Directive 95/46/EC, the Advocate General recommends that it should be annulled by the Court.

So, the reasons the Advocate General puts forward are very different from those submitted by the European Parliament which brought the action.

Second, the Advocate General considered that Article 95 EC was not the proper basis for adopting Council Decision 2004/496/EC of May 17th, 2004 on the conclusion of an Agreement between the European Community and the United States of America on the processing and transfer of PNR data by Air Carriers to the United States Department of Homeland Security, Bureau of Customs and Border Protection and it too should be annulled by the Court. The reasoning was the same. The processing of the data pursuant to the agreement between the EC and the USA concerned the fight against terrorism and serious crime whereas Article 95 EC concerned the functioning of the internal market of the EC."

Basically the decision says nothing about whether the Commission and Council should be allowed to mandate the passing of personal data to the US authorities, only that they used the wrong procedure. The Parliament were partly prompted to make the complaint in the first place because of anger over what they believed to have been assurances by the relevant EU commissioner, which they then felt he deliberately reneged on in confidential discussions and agreements with the US.

Essentially then, the EU Council of Governments and the EU Commission used the wrong procedure to mandate the handing over of large quantities of personal data to a foreign government. The EU Parliament then cited the wrong procedure in its complaint that a fundamental principle of European Union citizen data protection was being undermined. The mainstream press would probably paint this as another story of bureaucratic incompetence. As a great believer in the ubiquity of the cock of theory of history, I'd find it easy to be sold on that but there is another story here too. The making of reactive, superficial, high level political decisions about fundamental liberties and the pressurising of officials to "find a way" to get it done. The way is generally attaching it to some procedural process and with any luck it will slip through without getting subject to the kind of thorough judicial review the PNR decision attracted.

The Council and the Commission will now lean on officials to find another way...

Friday, November 25, 2005

Firefox Scholar

Firefox scholar.

"SmartFox will enable users, with a single click, to grab a citation to a book, journal article, archival document, or museum object and store it in their browser. Researchers will then be able to take notes on the reference, link that reference to others, and organize both the metadata and annotations in ways that will greatly enhance the usefulness of, and the great investment of time and money in, the electronic collections of museums and libraries. All of the information SmartFox gathers and the researcher creates will be stored on the client's computer, not the institution's server (unlike commercial products like Amazon's toolbar), and will be fully searchable. The Web browser, the premier platform for research now and in the future, will achieve the kind of functionality that the users of libraries and museums would expect in an age of exponentially increasing digitization of their holdings."

Good idea.

Data retention another step closer

From The Open Rights Group, Data retention another step closer.

The Patent Cold War

Quentin Stafford-Fraser on the Patent Cold War. Good stuff:

"The current patent system is something of a farce. Almost everybody involved in it knows this, but it's a game we all have to keep playing because nobody can afford to be the first one to stop...

And so we have the first major problem. The acquisition of patents, instead of being a means to an end, has become an end in itself...

And so this is problem number two: Lots of people have the ideas, but the wrong people are getting most of the patents...

And so we come to a very clichéd but nonetheless important problem number three: In the end, whether a patent is worth anything depends chiefly on how much you can afford to spend on lawyers. Even if you rightfully have the patent, you may not win...

And so we come to my last major concern, that a lot of the ideas for which patents are granted probably aren't very novel. So the system isn't really stimulating technological development by granting people 20-year monopolies on them..."

Verisign on Net CALEA compliance

Susan Crawford castigates Versign for their declaration that the FCC have not gone far enough in demanding that digital networks be architected for easy law enforcement interception.

"Within the last ten days or so, the key vendor of CALEA compliance services (VeriSign) has taken a very stern tone [pdf] with the FCC, saying that the Commission has read CALEA far too narrowly. VeriSign wants any SIP-using service to be part of the program, and suggests that interconnection with the traditional telephone network shouldn't necessarily be the standard for compliance. Translation: any possible multimedia application (whether connected to the phone network or not) and all connections to the internet should be designed in advance so as to be easily tappable by law enforcement.

(What's a SIP-based service? It's any service using the Session Initiation Protocol, an IETF signaling protocol that can be used in connection with any multimedia or voice or gaming application. GoogleTalk will use SIP; MSN Messenger already does; a host of VoIP applications already do. It's a very broadly used peer-to-peer protocol.)

VeriSign is also arguing that the rest of the world is moving smoothly along the vendor-assisted interception path, and that "the only impediment to implementation domestically principally lies in the Commission's actions" in the CALEA proceeding. We are ready, sayeth VeriSign (describing itself as a member of the "entrepreneurial and innovative global lawful interception industry") to provide these compliance services at minimal cost, but the Commission is getting in the way...

What's extraordinary about all this firmness on the part of the sole listener (DOJ) and the key vendor (VeriSign) is that the FCC has reached very far indeed to do their bidding already. By virtue of a less-than-weak reading of CALEA (which doesn't apply to "information services"), the Commission has gotten up the nerve to act like Congress and proclaim that a huge range of actors have to be CALEA compliant within 18 months, without saying what compliance means. Non-compliant firms will be subject to fines of $10,000 a day. So entities have to start complying without knowing what to do, and they won't even know whether they're covered -- because the FCC is sometimes flip about whether they are. Enormous, arbitrary, capricious, and aggressive confusion is in the air.

It's all pretty astonishing and pretty abusive...

But if you listen to VeriSign, we're all being silly, the world has moved on, and we should just shape up and get with the program. I feel sorry for the well-meaning professional staff at the Commission. They're under tremendous pressure."

WIPO meeting on copyright in education

IPKat also has a note about a WIPO meeting on copyright in education in the knowledge society.

"The digital environment presents enormous opportunities and challenges in terms of delivering educational materials in a sustainable manner, said Mrs. Rita Hayes, WIPO Deputy Director General in charge of copyright issues. "Today’s meeting was an excellent opportunity to look at the dissemination of teaching materials through balanced and effective copyright systems that meet the needs of all stakeholders; authors, publishers, libraries and educational services"

All stakeholders? Hmmm let's look at that list again - "authors, publishers, libraries and educational services." Nope I didn't miss them. Where were the readers or students?

But "delivering educational materials in a sustainable manner" is a nice idea, since sustainability, by definition, means protecting and cultivating and rich open-system (and I mean that in the purest thermodynamic sense, of course) source of open and renewable raw materials. Are WIPO promoting open access?

Laws of physics muck up a patent application

I learn from IPKat that there's a novel decision from the Patent appeal court, where the judge threw out an appeal against the dismissal of a patent application. He reckoned that it was reasonable for the patent examiner to hold that the proposed invention was not only obvious but it broke the laws of physics, or more specifically the law of conservation of energy (also widely known by engineers as the first law of thermodynamics).

So the invention was obvious despite the fact that it breached a fundamental law of nature, which presumably means that that fundamental law is not obvious? Being the scientific stick in the mud that I am, I'd say that is more of a reflection of the basic lack of scientific understanding rather than that the first law of thermodynamics is something less than obvious. Which in turn leads to the question of what actually is obvious? But that strays into the realm of philosophy which goes beyond the boundaries of my scientific, technical, commercial and legal training...

No that's not good enough. Even young children know you can't generate energy out of nothing, so if it is obvious to them why isn't it obvious to the legal system and society more generally? Just another example of our ability to believe in things which are simple, obvious and wrong, I guess.

ID cards in historical perspective

Jon Agar of Cambridge University has produced a paper on Identity cards in Britain: past experience and policy implications. I've just had time to scan the executive summary but it looks well worth a read. The paper looks briefly at the two previous ID card systems in the UK in the 20th century and idenitfies some features which could inform the debate on the government's planned system. Extract from the executive summary:

"The first national register (1915-1919), and accompanying identity card, was a failure, and the second (1939-1952) a partial success. The success of the second system was secured by analysing the causes of the failure of the first.

Universal registration systems have repeatedly been proposed as solutions to short-lived moral panics. But there is little evidence that national registers effectively resolve such panics.

Public indifference or hostility to identity cards was managed by building 'parasitic vitality' into the second experience. In particular, the system of national registration was intimately connected to the system of food rationing. Without similar 'parasitic vitality', contemporary proposals can be expected to struggle to win acceptance.

However, such interconnection encourages the phenomenon of 'function creep': eventually the pattern of disclosure and use of personal information is markedly different from that originally declared."

He goes on to say in the body of the report:

" the administrative operation of - and public response to - the historical card systems reveal features that should make all parties in the contemporary debate pause for thought. For example, the relative technological simplicity of the old card systems made a considerable contribution to their effectiveness: the simplistic equation of technological sophistication with effectiveness should be resisted."

As I say to my students, we should look to use the best available technology, including pencils and paper.

Thursday, November 24, 2005

LSE Prof on Government misrepresentation on ID cards

Professor Ian Angell of the London School of Economics Information Systems department is clearly getting irritated at the government's misrepresentation of the LSE research into the proposed ID cards scheme. In a letter to the Telegraph he says,

"Sir - What is going on with this so-called "debate" on ID cards? While appearing on the BBC's Hardtalk last week, immigration minister Tony McNulty claimed that, at a recent meeting in the House of Lords, the LSE had "admitted" that its estimate of the cost of ID cards was "hopelessly wrong". We made no such statement, and no one who attended that meeting could possibly make that inference.

This is typical of how debate over ID cards has degenerated into grand-standing and misrepresentation. With some minor adjustments, we stand by the figures we published in our June report. The reason our calculations differ from those of the Home Office is that we focused on the cost of implementing the scheme across government, while the Home Office estimated merely its own departmental costs.

It is the mission of the department of information systems at the LSE to be at the centre of academic research into any technological initiative that will have a major effect on the population. Having our position misrepresented by ministers will not deflect us from that position. So please, no more nonsense over figures. Let's get on with the real debate about the impact of this proposal on the nation, its effect on the lives of its citizens, and whether the systems stand any chance of functioning at an acceptable level."

Entertainment industry opportunism

It seems as though the entertainment industry in the EU have taken a leaf out of their US brethen's handbook. Just as the industry in the US attempted (though fortunately failed) to have a provision slipped into the PATRIOT Act in the emotional aftermath of 9/11, to enable them to hack into people's computers, the Creative and Media Business Alliance (CMBA), (i.e. Sony BMG, Disney, EMI, IFPI, Motion Picture Association, Reed Elsevier, Universal and many others) want the EU data retention proposals to be tweaked to enable the trawling of personal communications data to detect and pursue copyright infringement.

Now there is an argument to be made that the security services require access to the best available technology and people in the pursuit of serious crime and a data retention and access process, in some form, may well be a part of that. (I happen to believe the that EU data retention proposals present more problems for the police, the security services, the communications service providers and their customers than they do for the instigators of serious crime but that is another story). But as Suw Charman says here,

"Whether or not you agree with the need to retain traffic data for fighting terrorism and serious crime, there can be no benefit to national security from allowing the creative industries to use this information for prosecuting simple “infringement” cases.

Copyright Criminals

Now tie this in with IPRED2, another nasty bit of legislation which criminalises all “intellectual property” infringement on a commercial scale and “aiding and abetting such infringement”, with very thin definitions of what “commercial scale” or “intellectual property” means. The two directives together become even more alarming.

IPRED2 mandates that the police work with rightsholders to pursue suspected cases of IP infringement - including patent infringements - or merely vocal encouragement of infringement. And the Data Retention directive provides them with reams of data they can mine for evidence against these suspected infringers.

At the latest IPRED2 hearing, that’s exactly what the CBMA’s parent organisation, the International Federation of the Phonographic Industry (IFPI), demanded.

This opens up a very ugly can of worms where entire industries can get unparalleled powers of investigation, provided at the taxpayer’s expense.

Moreover, if the CMBA get their way, the number of data retention enquiries that the telcos and ISPs will have to process will be far higher than if restricted to terrorism and serious crime. This will put far more pressure on the telcos and ISPs who will not only have to bear the cost of storing the data, but also of providing access to the information to the authorities."

Remember what I was saying about the gaffer tape and Sony CDs yesterday? You could become a copyright criminal by sticking some tape round the edge of a Sony CD in order to stop it damaging your computer. So if Sony suspect you may have tried this trick (they'll have your personal details which you had to hand over to get the software to allegedly uninstall the damaging code, the same software which did no such thing and actually caused you further security headaches), under the tweaked data retention and the IPRED2 regulations they can demand a police investigation into your activities; an investigation which would include your communications data for the previous six months (phone calls, web sites visited, emails etc.)

The spectre of the systemic effect of the combination of technology, special interests, politics and ignorance looms again.

The IP parable of the cigarette fire

Ian Clarke has come up with a lovely parable on the extremes of intellectual property.

"I was in the pub last night, and a guy asked me for a light for his cigarette. I suddenly realised that there was a demand here and money to be made, and so I agreed to light his cigarette for 10 pence, but I didnt actually give him a light, I sold him a license to burn his cigarette. My fire license restricted him from giving the light to anybody else, after all, that fire was my property. He was drunk, and dismissing me as a loony, but accepted my fire (and by implication the licence which governed its use) anyway.

Of course in a matter of minutes I noticed a friend of his asking him for a light and to my outrage he gave his cigarette to his friend and pirated my fire! I was furious..."

Matches (if you'll excuse the pun) nicely Thomas Jefferson's:

" It would be curious then, if an idea, the fugitive fermentation of an individual brain, could, of natural right, be claimed in exclusive and stable property. If nature has made any one thing less susceptible than all others of exclusive property, it is the action of the thinking power called an idea, which an individual may exclusively possess as long as he keeps it to himself; but the moment it is divulged, it forces itself into the possession of every one, and the receiver cannot dispossess himself of it. Its peculiar character, too, is that no one possesses the less, because every other possesses the whole of it. He who receives an idea from me, receives instruction himself without lessening mine; as he who lights his taper at mine, receives light without darkening me. That ideas should freely spread from one to another over the globe, for the moral and mutual instruction of man, and improvement of his condition, seems to have been peculiarly and benevolently designed by nature, when she made them, like fire, expansible over all space, without lessening their density in any point, and like the air in which we breathe, move, and have our physical being, incapable of confinement or exclusive appropriation."

Wednesday, November 23, 2005

ECJ blocks handover of EU passenger data to US

This is an important decision. The advocate general of the European Court of Justice has said that the handing over of airline passenger to the US security services should has no adequate legal basis.

In referring to the EU Commission and the Council of ministers decisions to approve the disclosure of passenger data to US security agencies, AG Phillipe Léger says

“Neither the council decision approving the agreement nor the commission decision holding that information to be sufficiently protected by the US have an adequate legal basis”

He goes on to explicitly advice the ECJ to annul both decisions.

Opaque tape beats Sony drm rootkit

John Leyden in the Register reports that gaffer tape can be used to defeat the offending rootkit installing drm on Sony CDs (though I wouldn't recommend putting gaffer tape on CDs as the resulting loss of balance will probably lead to the CD getting scratched).

But since gaffer tape can be used for this purpose does that make it a technological protection measure (tpm) circumvention device. In which case does it breach the US Digital Millenium Copyright Act and the EU copyright directive?

So could someone be engaging in a criminal act by sticking a bit of tape on a CD to prevent that CD installing destructive code on their computer?

Given the precedent of the Hacker 2600 case (Corley v Universal), where a journalist was banned from linking to websites with DeCSS DVD security circumvention codes, could Leyden be in breach of the DMCA?

What about turning off of the autorun feature on Windows to prevent the Sony CD from automatically installing the destructive drm code? Could adjusting the default options on your own computer be a tpm circumvention mechanism?

Do I think the absurdities of music (and other copyrighted materials) protected by digital fences (drm), which in turn are protected by law with the threat of criminal sanctions, will now magically become clear?

Is that a flying pig I see over there?

ID card costs

From the Register:

"The London School of Economics (LSE) has issued a statement clarifying its position on its National ID card research. The announcement follows press reports that project costs could go as high as £40bn. The LSE says that its original estimate of a £19.2bn high watermark stands and no other figure should be attributed to them."

Schneier on the real story in the Sony drm fiasco

Bruce Schneier thinks the real story in the Sony drm disaster is

not Sony's rogue drm rootkit,
not that the drm acts as spyware,
not that attempts to get rid of it damage your Windows operating system
not that Sony stopped production on the destructive CDs
not that Sony recalled the destructive CDs
not that Sony secretly rolled out destructive drm
not that Sony after a lot of hassle and further privacy invasion offered a "fix" that not only didn't work appropriately but created more security problems
not that Sony lied about the privacy invading features of the drm
not that Sony said "Most people don't even know what a rootkit is, so why should they care about it?"
not that Sony's rootkit may have infringed on others' copyrights
not that Sony may have breached UK, US, Italian and other criminal codes
not that Sony probably won't be prosecuted in the US or the UK

but

"the collusion between big media companies who try to control what we do on our computers and computer-security companies who are supposed to be protecting us...

That all the big security companies, with over a year's lead time, would fail to notice or do anything about this Sony rootkit demonstrates incompetence at best, and lousy ethics at worst...

Who are the security companies really working for? It's unlikely that this Sony rootkit is the only example of a media company using this technology. Which security company has engineers looking for the others who might be doing it? And what will they do if they find one? What will they do the next time some multinational company decides that owning your computers is a good idea?

These questions are the real story, and we all deserve answers."

Tuesday, November 22, 2005

Did Sony's drm infringe copyrights?

Ed Felten is also asking if Sony's disastrous drm infringed copyright.

"The Sony copy protection debacle has so many angles that the mainstream press is having trouble keeping track of them all. The rootkit. The spyware. The other spyware. The big security hole. The other big security hole. It’s not surprising, then, that at least one important angle has gone nearly undiscussed in the mainstream press: the likelihood that the Sony/First4Internet XCP copy protection software itself infringes several copyrights. (Note to geeks: Slashdot doesn’t qualify as the mainstream press.)

Matti Nikki (a.k.a. Muzzy) and Sebastian Porst have done great work unearthing evidence pointing to infringement. They claim that the code file ECDPlayerControl.ocx, which ships as part of XCP, contains code from several copyrighted programs, including LAME, id3lib, mpglib, mpg123, FAAC, and most amusingly, DVD-Jon’s DRMS.

These are all open source programs. And of course open source is not the same as public domain. Open source programs are distributed with license agreements. If you copy and redistribute such a program, you’re a copyright infringer, unless you’re complying with the terms of the program’s license."

Felten on EFF v Sony

Ed Felten approves of the EFF's emphasis of the problems with Sony's MediaMax drm as spyware, in their lawsuit against the company.

"One interesting aspect of the EFF suit is its emphasis on MediaMax. Most of the other lawsuits have focused on Sony’s other copy protection technology, XCP. The EFF suit does talk about XCP, but only after getting through with MediaMax. Emphasizing MediaMax seems like a smart move — while Sony has issued an apology of sorts for XCP and has recalled XCP discs, the company is still stonewalling on MediaMax, even though MediaMax raises issues almost as serious as XCP...

It’s important to recognize that these problems are caused not by any flaws in SunnComm and Sony’s execution of their copy protection plan, but from the nature of the plan itself. If you want to try to stop music copying on a PC, you’re going to have to resort to these kinds of methods. You’re going to have to force users to use extra software that they don’t want. You’re going to have to invoke administrator privileges more often. You’re going to have to keep more software loaded and running. You’re going to have to erode users’ ability to monitor, control, and secure their systems. Once you set off down the road of copy protection, this is where you’re going to end up."

Which is why we should be avoiding the drm road completely.

People's willingness to give up other people's rights

There's a nice op ed in the San Francisco Chronicle from a last Monday, by a civil rights lawyer, Ben Rosenfeld, about why it is a bad idea to make common behaviour a criminal offence.

The origin of a police state in this country, I believe, is this: We gradually exchange a rights-based system, in which governmental power is limited by law, for a paternalistic one, in which we may all be arrested for one thing or another, but authorities forebear from doing so, or intruding in our lives, until they subjectively brand us "bad guys."...

Perhaps we will have to keep throwing away rights that matter more to other people for a time, until we realize that we are throwing away our own rights in the process. Only then will we start to create a society truly founded on principles of equal protection and mutual support."

Rent a mum

David Bollier has been brooding on what it might be unhinkable to buy or sell.

Jonathan Rowe has been doing likewise.

EFF take class action lawsuit against Sony BMG

The EFF has filed a class action lawsuit against Sony BMG over the CD drm fiasco.
"Music fans shouldn't have to install potentially dangerous, privacy intrusive software on their computers just to listen to the music they've legitimately purchased," said EFF Legal Director Cindy Cohn. "Regular CDs have a proven track record -- no one has been exposed to viruses or spyware by playing a regular audio CD on a computer. Why should legitimate customers be guinea pigs for Sony BMG's experiments?"

Unintended consequences

The story of how NASA missed the detecting the hole in the earth's ozone layer is one of unintended consequences arising from the failure of an information system. NASA had a deployed a sophisticated ozone mapping spectrometer in a satellite called Nimbus-7, which relayed hundreds of data measurements to base on a daily basis. NASA didn't have enough people to process the mass of data and relied on summary indicators.

Unfortunately the spectrometer had been originally programmed to ignore unusually low ozone levels because they had "never happened" previously. The raw data went unchecked until scientists from the British Antartic Survey published details of measurements they had made detecting the thinning of the ozone layer, using old tried and tested instruments.

The trust in the sophistication of the NASA technology combined with the lack of attention to the data generated led to a failure to detect major changes in the system being monitored and a defensive belief, at least initially until they went back and checked the raw data, that their sophisticated technology could not be wrong.

Blunkett, "impossible to fake" and biometric embedded ID cards come to mind, though Mr Blunkett is, of course, no longer in the driving seat on the scheme.

Just a thought

Have you ever noticed that blind faith in technology is often strongest amongst people who have no understanding of the technology?

I've been thinking about the ID card system again and repeatedly come back to US journalist John Lawton's observation: "the irony of the information age is that it gives new respectability to uninformed opinion."

Doc Searls on saving the Net

Doc Searls recently posted an amazing essay on saving the Net.

"The carriers have been lobbying Congress for control of the Net since Bush the Elder was in office. Once they get what they want, they'll put up the toll booths, the truck scales, the customs checkpoints--all in a fresh new regulatory environment that formalizes the container cargo business we call packet transport. This new environment will be built to benefit the carriers and nobody else. The "consumers"? Oh ya, sure: they'll benefit too, by having "access" to all the good things that carriers ship them from content providers. Is there anything else? No.

Crocodile grins began to grow on the faces of carriers as soon as it became clear that everything we call "media" eventually would flow through their pipes. All that stuff we used to call TV, radio, newspapers and magazines will just be "content" moving through the transport layer of the pipe system they own and control. Think it's a cool thing that TV channels are going away? So do the carriers. The future à lá carte business of media will depend on one medium alone: the Net. And the Net is going to be theirs.

The Net's genie, which granted all those e-commerce wishes over the past ten years, won't just get shoved back in the bottle. No, that genie will be piped and priced by the packet. The owners of those pipes have a duty to their stockholders to make the most of the privileged position they've been waiting to claim ever since they got blind-sided, back in the 80s and 90s...

Does it matter that countless markets flourish in the wide spaces opened by agreements and protocols that thrive at the grace of carriage? Or that those markets are threatened by new limits, protections and costs imposed at the pipe level?

No.

Thus, the Era of Net Facilitation will end. The choke points are in the pipes, the permission is coming from the lawmakers and regulators, and the choking will be done. No more free rides, folks. Time to pay. It's called creating scarcity and charging for it. The Information Age may be here, but the Industrial Age is hardly over. In fact, there is no sign it will ever end...

The new carrier-based Net will work in the same asymmetrical few-to-many, top-down pyramidal way made familiar by TV, radio, newspapers, books, magazines and other Industrial Age media now being sucked into Information Age pipes. Movement still will go from producers to consumers, just like it always did. Meet the new boss, same as the old boss. Literally...

what matters most is Saving the Net--keeping it a free and open marketplace for everybody--while also making sure that carriers of all kinds can compete and succeed while providing much of the infrastructure on which that marketplace resides. That means we need to understand the Net as more than a bunch of pipes and business on the Net as more than transporting and selling "content".

This isn't a trivial issue. It's a matter of life and death for the Net itself. How are we going to fight?

Read on.

Scenario II: The Public Workaround

The deathblow comes from the muni Wi-Fi efforts. It doesn't matter whether they are viable or not--all they need do is give local connectivity the moral high ground and represent a grass roots effort that the legislature not only can't ignore but can embrace. --Bob Frankston

In ancient telco lingo, "bypass" is anything that works around the phone system itself. Susan Crawford wisely encourages bypassing not only the system but the whole notion of fixing it with "Network Neutrality" agreements or legislation. In response to the questions, "What, if any, version of common carriage rules should govern Internet communications platforms? More specifically, can some concept of Network Neutrality be defined and enforced proactively in the form of prescriptive regulations?", she answers,

I think this is the wrong question. It assumes the limited world of online access providers we've got, makes them into "communications platforms," and then suggests we need to make rules about them. Not very imaginative. I have lost faith in our ability to write about code in words, and I'm confident that any attempt at writing down network neutrality will be so qualified, gutted, eviscerated, and emptied that it will end up being worse than useless...

The only way around this issue is to avoid it by encouraging the development of alternative online access methods, and being careful not to let the incumbents call them illegal. Let the dinosaurs huddle together in the snow, controlling and commoditizing to their hearts' content. We're made of better stuff. It should be no more illegal to have an open wireless network in your house than to practice the piano with the windows open. And having an open wireless network can lead to a community mesh network and a host of devices that open immediately to others, connecting us to the world.

If that's not possible, then the second best solution is structural separation, paying off the carriers for their stranded costs and moving to open utility platforms. BT seems to think that's a fine idea; why couldn't it work here?

Muni Wi-Fi is a form of bypass. So are other government-sponsored or assisted workarounds.

So are the private ones." (Like Google which is building its own network).

He quotes Susan Crawford again later in the piece asking a key question:

What happened to our leadership on internet policy? When did we lose the ability to walk and slide back into the sea? We experimented and tugged and pulled and came up with the idea of linking machines together with a common language, making it possible for humans to interact in unprecedented ways. Now we're turning those machines back into the machines we thought we were escaping--telephones, cable systems, and televisions--using insiders' language so that we can hide what's going on from the general public. What happened?

And goes on to supply an answer with his "Scenario III: Fight with Words and Not Just Deeds", where he goes on to describe the importance of the language of the debate. She who controls the language with the better metaphors will control the debate. "Stop piracy" beats "protect the commons" every time. Protect the what? "Piracy" in the intellectual property context used to be about illegal commercial enterprises copying an selling large numbers of counterfeit goods. Now it is about anyone copying anything on the Net.

"Advocating and saving the Net is not a partisan issue. Lawmakers and regulators aren't screwing up the Net because they're "Friends of Bush" or "Friends of Hollywood" or liberals or conservatives. They're doing it because one way of framing the Net--as a transport system for content--is winning over another way of framing the Net--as a place where markets and business and culture and governance can all thrive."

Read it all at Linux Journal. It's a long essay but well worth your time.

Monday, November 21, 2005

Geist on Sony drm disaster

Michael Geist has some sensible things to say about Sony's recent drm disaster.

New blog

Lilian Edwards of the AHRB Centre for the Study of Intellectual Property
and Technology Law at Edinburgh University has a new blog, BlogScript: Innovation, Technology and the Law.

Update: I should have said, Lilian's co-director of the AHRB, Andres Guadamuz, is a co contributor to the blog.

Portillo thinks Brown will kill ID cards

Michael Portillo, a former candidate for the leadership of the main opposition Conservative party in the UK, thinks Gordon Brown will eventually kill the ID card plans will a simple cost benefit analysis.