Monday, January 22, 2007
The case against secrecy in voting system testing
"The Election Assistance Commission has some explaining to do. The secrecy that pervades the EAC, which oversees testing and certification of voting systems, holds dire consequences for our electoral system. Both chambers of Congress need to work to dispel this culture of secrecy.
A recent case illustrates why secrecy is a fundamental problem at the EAC. Last summer the EAC prohibited a lab run by Ciber Inc. from testing new voting systems due to inadequate test plans and documentation. Nonetheless, the voting systems that Ciber previously has tested remained certified and were used in elections in November. The EAC has not disclosed which voting systems Ciber tested using faulty procedures, but according to our calculations, nearly 70 percent of registered voters in the 2006 general elections voted on equipment qualified by Ciber...
consider that the public and voting officials learned of the Ciber de-accreditation not from the EAC last summer, but from The New York Times two weeks ago...
Secrecy is pervasive in voting system development and testing. As one test lab representative testified before the EAC in October, their procedures must be kept secret because their clients — voting system vendors — require confidentiality and “own” the test results. Though this secrecy might protect some proprietary information, or prevent embarrassing information from coming to light, it is inimical to proper oversight of the election system.
Last month, when the EAC adopted its new testing and certification policy, it left the major elements of voting system testing secrecy in place. For example, the EAC’s new policy will continue to allow voting system manufacturers to select, pay and communicate confidentially with test labs, thus diminishing the labs’ independence. Under its new rules, the EAC will not receive manufacturers’ technical data packages, which are documents crucial to understanding a voting system...
In addition, the EAC failed to ensure that election officials, as well as the public, can assess the sufficiency of the test labs’ work. Under its new policy, the EAC will publish test labs’ reports about systems that gain certification. The EAC, however, will not publish the details about what a lab did to test a system, the so-called test plan. Keeping the test plan secret will make it difficult for anyone other than the EAC, the labs and the vendors to judge the conclusions presented in the report. As the experience with Ciber shows, knowing how a test lab evaluates a voting system is just as important as knowing what conclusions the lab reaches.
This secrecy works against voting integrity. Test labs, after all, are charged with determining whether voting systems satisfy standards, all of which are public. Test plans simply put the rubber to the road, and the system benefits by having a common understanding of what kinds of tests are sufficiently rigorous. Keeping this information secret only protects labs with lax procedures. Greater transparency, on the other hand, would encourage all test labs to develop more rigorous procedures."
Gutmann Vista and DRM: Microsoft Response
"Windows Vista includes content protection infrastructure specifically designed to help ensure that protected commercial audiovisual content, such as newly released HD-DVD or Blu-Ray discs, can be enjoyed on Windows Vista PCs. In many cases this content has policies associated with its use that must be enforced by playback devices. The policies associated with such content are applicable to all types of devices including Windows Vista PCs, computers running non-Windows operating systems, and standalone consumer electronics devices such as DVD players. If the policies required protections that Windows Vista couldn't support, then the content would not be able to play at all on Windows Vista PCs. Clearly that isn't a good scenario for consumers who are looking to enjoy great next generation content experiences on their PCs...
It's important to emphasize that while Windows Vista has the necessary infrastructure to support commercial content scenarios, this infrastructure is designed to minimize impact on other types of content and other activities on the same PC. For example, if a user were viewing medical imagery concurrently with playback of video which required image constraint, only the commercial video would be constrained -- not the medical image or other things on the user's desktop. Similarly, if someone was listening to commercial audio content while viewing medical imagery, none of the video protection mechanisms would be activated and the displayed images would again be unaffected...
The paper implies that Microsoft decides which protections should be active at any given time. This is not the case. The content protection infrastructure in Windows Vista provides a range of à la carte options that allows applications playing back protected content to properly enable the protections required by the policies established for such content by the content owner or service provider. In this way, the PC functions the same as any other consumer electronics device."
Another demonstration of the insanity of complex organisations and the restraints they place on the largely rational people who work for them. I'm sure Dave Marsh would much rather be focussing on delivering and loudly proclaiming fantastic new video functionality, than having to find explanations via carefully constructed language about third party contraints the company has accepted they need to build into the technology. I don't envy him that job in the slightest.
Update: Some of the comments at the end are really worth reading (though some are the usual Microsoft bashing for the sake of Microsoft bashing), like this one from a doctor pointing out the impact of lack of interoperability on patient care:
"Since when did you think that DRM would not apply to medical imaging. Speaking as a physician, we ALREADY have this problem. The medical image DICOM format has been split into various flavors by competing software vendors who do their best to make sure that you have to have THEIR viewer in order to see files saved in their version of the format.
Further competing hospitals are choosing not to install viewers that would allow MD's to look at films that were taken at their competition ( or perhaps their IT staff can't be bothered to install them -- either way the result is the same). This proprietary behavior is already hindering patient care."
Technically this isn't necessarily drm the doc is complaining about but lack of interoperability, (which drm will also impede).
Rob Glaser calls for end to DRM
"Glaser reportedly stated that he is "seeing some signs the industry is open to ... giving consumers a way to purchase music with the flexibility that you can only get if you take the DRM off.... For purchases, move away from DRM" (emphasis added). What common sense - when you buy music, you own it and should be able to make personal use of it however you want."
Btw, my own drm mini saga is still partly ongoing. The replacement DVD player got delivered and seems to work ok - it reads and plays my DVDs, or at least the three I've so far tried on it. But when City-Link delivered the new machine the van driver refused to collect the faulty one. It wasn't his job apparently. Coming up to 5pm on Friday I was getting kinda anxious that there were no further City-Link vans on the horizon - my refund on the faulty machine does not come through until Hughes-Direct get it back.
So I phoned City-Link. They had no notification of a collection from my address.
So I phoned Hughes-Direct. They assured me they had arranged for the collection and gave me a collection tracking number.
So I phoned City-Link with the number and was informed that Hughes-Direct had asked for the faulty machine to be picked up next Friday, 26th January between 10am and 5pm.
So I phoned Hughes-Direct and pointed out what I assumed to be the error. They told me they would arrange for the machine to be picked up today between 10am and 5pm Well so far no sign of the City-Link van and since my refund is dependent on the efficient expedition of the logistics between them I'm hoping I'm not going to be playing phone tag between the two firms again this evening.
Update: Well City-Link collected the faulty machine about 3.30pm and now I have to trust/make sure that the appropriate refund will be expeditiously forthcoming in the next few days.
Sunday, January 21, 2007
Judge allows music industry suit v XM radio to go ahead
"A lawsuit in which record companies allege XM Satellite Radio Holdings Inc. is cheating them by letting consumers store songs can proceed toward trial, a judge ruled Friday after finding merit to the companies' claims.
U.S. District Judge Deborah A. Batts made the finding in a case brought by Atlantic Recording Corp., BMG Music, Capitol Records Inc. and other music distribution companies against the licensed satellite radio broadcaster.
| |
Gonzales quized about domestic spying
Friday, January 19, 2007
A deadly certitude
"Richard Dawkins’s even-handedness is well-intentioned, but it is misplaced. I share his lack of respect for all religions, but in our times it is folly to disrespect them all equally."
NYT Pogue Blog Ode to the RIAA
"You’ve just been sued by the R.I.A.A.!
You’ve just been sued by the R.I.A.A.!
Their attorneys say, you committed a crime,
And there’d better not be a next time!
They’ve lost their minds at the R.I.A.A.!
Justice is blind at the R.I.A.A….
“You’re depriving the bands! You are learning to steal,
You can’t do whatever you feel!”"
Funny.
Superdatabase madness
"Joe Soap, clean, honest living man who wanted to find new work to pay the mortgage and his bills, never been in trouble in his life, now has a criminal record, his fingerprints and DNA will stay on file for 100 years, he now has an ASBO which makes it illegal for him to do everyday things that the rest of us can do legally, he is no longer allowed to travel to London, and travel anywhere else in the UK has to be approved by the police, he is on the V&S Offenders register, and his life is under constant supervision...
By passing laws and building Databases all your eggs are now in one basket and make everyone, absolutely everyone suspicious, be the target of suspicion, and allow the lowest rated civil servant access to your very soul.
I can hear Mr Blair protesting now that this is not what all these laws are for, but Mr Blair, please understand, THIS IS HOW THEY WILL BE APPLIED, if not in a dictatorial regime, certainly one in which it is very easy to hit all your targets when the laws are all on your side."
Thursday, January 18, 2007
Commission 1 Ireland 0
The Irish government's crime? IPKat explains:
"They had exempted all categories of public lending establishments from the obligation to remunerate authors for any lending carried out by them, that's what they did."
IPKat welcomes the judgement. Personally, this time, I'm on the side of the Irish government, given the nature of the potential impact on open access.
Minister McFadden and wibbies
Bush agrees to drop warrantless wiretapping
"The President has "determined not to reauthorize the Terrorist Surveillance Program when the current authorization expires," and the Department of Justice will now submit its surveillance applications to the FISA Court for approval. Indeed, this volte-face apparently is the result of the fact that DOJ has convinced a FISA judge to issue "innovative and complex" orders in one precedential case already. So says a new letter from the AG to Senators Leahy and Specter.
According to the letter, the FISA court seems to have approved orders finding that at least part of the FISA statutory standard was [would be?] satisfied -- that "one of the communicants is a member or agent of Al Qaeda or an associated terrorist organization." (That's not quite the statutory standard, which requires that the target of the intercept be such an agent, and also that "each of the facilities or places at which the electronic surveillance is directed is being used, or is about to be used, by a foreign power or an agent of a foreign power.") It apparently took "considerable time and work" for DOJ to persuade the FISA judge to go along with whatever this newfangled sort of approval is. (According to Tony Snow, the FISA Court has promulgated "guidelines" and "rules" to govern this new form of approval.)
The ACLU case challenging the legality of the TSP is, at least for now, scheduled to be argued before the U.S. Court of Appeals for the Sixth Circuit in two weeks...
The transcript of the background conference call with DOJ officials is here. The officials there claimed that the new procedures "will comply in all respects with the requirements of the FISA statute,"... One official did stress, however, that the orders "take advantage of . . . developments in the law before the FISA court." In other words, the FISA court apparently has been persuaded that in some respects the FISA statute is more forgiving than previously understood -- that it demands less proof or proof of a different kind than what the court once required. Orin Kerr provocatively surmises that perhaps what's going on here is a form of anticipatory warrant. It's unlikely that we'll know the details of this secret new internal law of FISA anytime soon.]...
Without knowing anything more about it, my sense is that this is probably a beneficial development, whatever its impetus might have been. I find it very difficult to imagine that the FISA court would roll over and approve an "innovative" legal theory if it were dubious -- especially not in this context, where DOJ has many incentives to get the FISA court on-board and where the congressional and public spotlight is shining so brightly. Without the New York Times, and Judge Taylor, and the 2006 election, this would never have happened. Sunshine is the best disinfectant, and all . . . . Even though the public might never find out exactly what's up here, presumably Congress and the FISA court are now acting as some not-insignificant checks. And if so -- if the extreme and unilateral positions of the Executive are a thing of the past here, the system has worked."
It looks, on the surface, like a significant reigning in of presumed Executive powers for Mr Bush to back down on something this politically sensitive. Of course Marty Lederman and others have been arguing for some time that the president has been acting outside the constitutional checks on balances of his office in relation to his actions in approving the mass warrantless surveillance at the centre of this dispute. Jack Balkan thinks the motives are political:
"in this case, the Administration insisted for months that the President did not need to follow the procedures in FISA, either because of the AUMF or because of inherent Presidential authority. Apparently, it has now retreated from that legally untenable position, hoping to moot, or at the very least disarm, federal litigation challenging the legality of the NSA program. Once again, the goal is to prevent a court from stating clearly that the President acted illegally and that his theories of executive power are self-serving hokum.
When we put these two stories together, a pattern emerges: the Administration repeatedly takes unreasonable positions about its powers. It insists that obedience to these views is necessary to the very survival of the Republic and that those who would dare to disagree are jeopardizing national security. It makes these aggressive claims repeatedly in every venue, hoping that others, cowed by its aggressive self-confidence and patriotic appeals, will be overawed and simply give in. It struts and boasts and threatens and exaggerates until its bluff is called, at which point its previous assertions simply become-- as they once put it in the Nixon Administration-- inoperative. Put another way, the Administration's stance on Presidential power has resembled nothing so much as an altogether familiar character, the neighborhood bully."
eIFL Statement at WIPO SCCR
Limitations and Exceptions for Libraries
Electronic Information for Libraries (eIFL) and the International Federation of Library Associations (IFLA) have argued in our previous statements that any draft treaty on the protection of broadcast organisations limits itself to its intent i.e. to prohibit signal piracy. We welcome the endeavours in the Chairs discussion non-paper that the focus should be set on the protection of the live signal and on signal theft.
Both our organisations support the Joint Statement of Certain Civil Society, Private Sector and Rightsholder Representatives. Point three of the statement argues that any treaty that allows for broader rights must be accompanied by an equally broad set of mandatory exceptions and limitations. We believe that this is a time consuming task for the purposes of this draft treaty and in the signal based approach, it is unnecessary.
The alternative rights based approach would involve crafting appropriate exceptions and limitations, an increasingly complex task for the digital age. Today we live in a global digital environment. But the exceptions and limitations with which we work were developed in an analogue world. They are paperbound. The basic format for most content has become digital. Librarians find themselves struggling with unsuitable exceptions and limitations to adequately deliver content and services in the digital age. Nowadays, libraries must adopt sometimes absurd practices in order to comply with copyright law. Libraries services are stymied when they should be expanding and developing in response to new technologies. Analysis and guidance on the issues is necessary.
The agreed statement to Article 10 of the WIPO Copyright Treaty, which states that Member States may extend existing exceptions and limitations to the digital environment and may devise new exceptions appropriate to the digital network environment, was an attempt to provide a remedy to such future issues. Ten years on, we believe that the problems faced by libraries have become too complex to be properly addressed by this general statement expressing an intention.
Exceptions and limitations are being undermined in substance because they are bound to an ageing technology. As a result of the change in format from print to digital, libraries have largely become subject to contract law instead of copyright law. Libraries experience on a daily basis how exceptions and limitations are being undermined in principle by contracts which seek to override statutory exceptions and limitations and are enforced by technological protection measures. We believe that this serves to undermine copyright law itself. Analysis and guidance on the issues is necessary.
This is why we welcome the initiative of the distinguished delegation of Chile and the support of GRULAC for this committee to consider exceptions and limitations for libraries, education and the disabled in its regular work. The proposal by Chile for a study on exceptions and limitations for libraries is therefore a welcome step.
Libraries are an essential component for education and research, the acquiring of knowledge and culture by citizens, and for the enlightenment of society. This role has traditionally been recognised through exceptions and limitations for libraries as expressed in international treaties and national copyright laws.
We would wish for the proposed study to identify the problems, illustrated by case studies from a range of real experiences, from the local public library to the worlds great research libraries. Different remedies would be analysed, followed by recommendations of practical benefit to libraries. In this way, we would hope that the role of exceptions and limitations for libraries in the digital environment would be reinvigorated.
eIFL and IFLA believe that WIPO is the natural organisation to host such a study and we would be pleased to be of any assistance in this regard.
WIPO attempt to finalise broadcasting treaty
"One faction in the negotiations wants to revamp provisions in a 1962 treaty (one that the United States and 80 other countries never signed), with new or expanded intellectual property rights for anyone who "broadcasts" third party content. Relying upon the current 108 page draft of the treaty, they propose that anyone who qualifies as a "broadcaster" or "cablecaster" would get a set of exclusive rights to prevent others from re-publishing or using the information, including on the Internet, without permission from the broadcaster or cablecaster. This right would be in addition to the rights and permissions (if any) associated with the copyright in the work, and would apply even to works that are in the public domain, or where the copyright owner was willing to freely distribute the work. It would create an entirely new set of liability problems for companies that aggregate third party content, a fact that lawyers for Yahoo and News Corp (treaty supporters) have apparently not explained to their CEOs...
Opposing this scenario are a growing group of countries that want the treaty to take a much narrower approach, only prohibiting the "theft" of programing signals, but not extending an intellectual property right in other people's copyrighted works. The problem is, no one can explain why such protection is needed, since it is already illegal to steal cable or satellite service under many existing laws, including existing copyright laws."
Privately, Hollywood admits DRM isn't about piracy
"For almost ten years now I have argued that digital rights management has little to do with piracy, but that is instead a carefully plotted ruse to undercut fair use and then create new revenue streams where there were previously none...
In a nutshell: DRM's sole purpose is to maximize revenues by minimizing your rights so that they can sell them back to you...
There is simply no evidence whatsoever that DRM slows piracy. In fact, all of the evidence suggests the opposite, and arguments that DRM "keeps honest people honest" are frankly insulting. If they're already honest, they don't need DRM.
If we believe Ronald Grover's sources in his BusinessWeek article of last week, the problem is liberal DRM and not piracy, and this is a startling admission. According to him, an unnamed studio executive said that a major reason why studios weren't jumping on board with the iTunes Store and other similar services is that their DRM is too lax. "[Apple's] user rules just scare the heck out of us." It's not piracy that's the concern, it's their ability to control how you use the content you purchase.
As it turns out, five devices authorized for playback is too many, and the studios apparently believe that this is "just as bad" as piracy. Hollywood believes that iTunes Store customers will add their buddies' devices to their authorization list, and like evil communists, they'll share what they have purchased. This makes little sense, because the way iTunes works, you can only issue so many device authorizations at a time. You could share with a friend, but then your friend would have to be authorized to play all of your purchased content, taking up an authorization. Inconvenient, huh? But is it a big problem?
I can walk in to Best Buy right now, buy a DVD, and lend it to every person I know. Who hasn't lent a DVD to a friend or colleague? This is perfectly legal behavior, but you can see that Hollywood hopes to stop this kind of thing via DRM. Thanks to the DMCA, once copyrighted contents have been encrypted, your rights fly right out the window."
Horse bolted on school fingerprinting
Wednesday, January 17, 2007
Petition for open access to scientific publications
In the wake of the publication of the report from the "EU Study on
the Economic and Technical Evolution of the Scientific Publication
Markets of Europe" a consortium of organisations working in the
scholarly communication arena is sponsoring a petition to the
European Commission to demonstrate support for Open Access and for
the recommendations in the report. Signatures may be added on behalf
of individuals or institutions.
Please register your support for Open Access in this way. To sign the
petition (shown below), please go to http://www.ec-petition.eu/ The sponsoring organisations are JISC (Joint Information Systems
Committee, UK), SURF (Netherlands), SPARC Europe, DFG (Deutsches
Forschungsgemeinschaft, Germany), DEFF (Danmarks Elektroniske Fag- og
Forskningsbibliotek, Denmark).
Dear Commissioner,
Our mission of disseminating knowledge is only half complete if the
information is not made widely and readily available to society. Berlin Declaration, October 2003
In January 2006 the European Commission published the Study on the
Economic and Technical Evolution of the Scientific Publication
Markets of Europe. The Study resulted from a detailed analysis of the
current scholarly journal publication market, together with extensive
consultation with all the major stakeholders within the scholarly
communication process (researchers, funders, publishers, librarians,
research policymakers, etc.). The Study noted that 'dissemination and
access to research results is a pillar in the development of the
European Research Area' and it made a number of balanced and
reasonable recommendations to improve the visibility and usefulness
of European research outputs.
Now, a year after publication of the Study, we urge the EC to endorse
the recommendations in full. In particular, we encourage you to adopt
the first recommendation as a matter of urgency:
RECOMMENDATION A1. GUARANTEE PUBLIC ACCESS TO PUBLICLY-FUNDED
RESEARCH RESULTS SHORTLY AFTER PUBLICATION
Research funding agencies have a central role in determining
researchers' publishing practices. Following the lead of the NIH and
other institutions, they should promote and support the archiving of
publications in open repositories, after a (possibly domain-specific)
time period to be discussed with publishers. This archiving could
become a condition for funding.
The following actions could be taken at the European level: (i)
Establish a European policy mandating published articles arising from
EC-funded research to be available after a given time period in open
access archives, and (ii) Explore with Member States and with
European research and academic associations whether and how such
policies and open repositories could be implemented.
We would recommend that, in accordance with the recent
recommendations from the European Research Advisory Board and the
statement of the European Research Council on Open Access, any
potential 'embargo' on free access should be set at no more than six
months following publication.
Research must be widely disseminated and read to be useful. Adopting
Recommendation A1 will immediately ensure the widest possible
readership for EC-funded research, increasing the potential benefits
resulting from the research, and promoting European scholarship both
within Europe and beyond. Evidence is accumulating to indicate that
research that is openly accessible is read more and used more and
that open access to research findings would bring economic advantage
across the European Research Area. The Commission has a unique
opportunity to place Europe at the forefront of the dissemination of
research outputs and we encourage you to adopt the Study
recommendations for the benefit of European research.
I've been DRM'd
I connected all the wires up and the machine went into its automatic set up routine. Again everything seemed fine and it picked up the channels etc. with no apparent difficulties. The digital signal was quite strong though it somehow picked the wrong aspect ratio, so we got an elongated picture until I adjusted it manually. We watched the end of a film on one of the digital channels and again everything was basically ok though the digital signal cut out once or twice when the wind got up later on. Then I put in one of the kids' DVDs.
We get "whirr, beep, whirr, whirr..." for about half a minute as the machine scans the disk, then the display reads “NoREAD” and a small window appears briefly on the TV screen saying “Cannot Read”. Attempting to press the “play” button on the machine or the remote control merely brings up a small red circle with a red diameter in the top right corner of the TV screen. Page 75 of the manual helpfully says this means: “The procedure is being prevented by the unit or the disc” but unhelpfully doesn't provide any remedy whatsoever.
Uh oh, I think, DRM? Well maybe I should try a different disk before jumping to conclusions. I tried six, all with the same result. Grr does this blooming machine think I'm trying to pass a US DVD off on it or something? All six were UK sourced disks though the machine is set up to play region 2 or all region encoded disks. The kids were disappointed not to be able to use the new toy right away
This morning I spoke to a very helpful and technically knowledgeable Hughes' customer service representative called Paul who immediately confirmed my suspicions about the DRM getting a bit confused. Occasionally in transit on some part of the manufacturing process or the supply chain the machine gets a bump which just knocks the drm out of synch and it "thinks" it is officiously carrying out its duty to protect the machine from playing DVDs from unapproved regions and actually it just can't read the code and recognise approved disks either. We both agreed I should send it back to them, so that is where it is going on Friday with Hughes providing a full refund. Since they didn't have any 85s left in stock I've ordered a lower spec and cheaper EX75 instead.
I await the DMR-EX75, due Friday, on which hopefully the DRM will be more cooperative. Well done to HughesDirect and particularly Paul for being so helpful. My visions of being kept waiting endlessly in an automated answering queue thankfully didn't come to fruition this time.
Tuesday, January 16, 2007
An Educational Prank
"In a groundbreaking marketing move, six corporations sponsored my undergraduate course during the fall of 2006. To be more accurate, I should say, with a wink and a nod, that they "sponsored" the course.
There was no contractual exchange of money or services in this faux patronage experiment and, to be honest, some of the businesses didn't want to be involved in my scheme. (One company representative, sensing the political motivations behind my endeavor, told me via an e-mail message: "You will not use the Disney logos or any connection to the Disney Co. in your class.")
I began referring to my syllabus as a McSyllabus, and for the duration of the semester my corporately sponsored name was Professor McKembrew McLeod...
My experiment was a provocation, a quiet protest that escalated near the end of the semester after a contentious move made by the University of Iowa's Board of Regents. That body had increasingly adopted a top-down management style and embraced a corporate model for the university, and demonstrated that last November by scuttling a 10-month presidential search because it didn't like the finalists.
The board's actions inspired me to push my prank even further, and so I personally contacted each regent, telling them about my plan. It came as no surprise when one regent -- unaware of my satirical motives -- happily endorsed the idea of a corporately sponsored classroom...The troubles faced by the University of Iowa (and our nation's universities, more generally) run deeper than a mere bureaucratic squabble. This episode highlights the systemic problems that emerge when we try to turn the university into "an economic engine for the state," a term our administrators are fond of using."
"Brain fingerprinting" admissable in court
"Apparently, your brain creates a very specific electrical brain response, known as P300, when one is presented with information that is already contained in one’s mind. If you recognize the information (i.e., it is familiar to you), you will have a P300 response. There is no way to avoid this; it is a biological/electrical stimulus response event. Sort of like a lie detector, only (reportedly) always accurate.
Think of this as Mind-Reading 1.0.
Question: "Did you murder John Doe?"
Answer: "No."
Question: "Have you ever been inside this house?" [While presenting a picture of the front of a house]
Answer: "No."
Question: "Did you commit this murder?" [While presenting a picture of the murder scene, which took place in the bedroom]
Answer "No."
"Sir, you are under arrest – you had a P300 response to the murder scene."
Maybe you are feeling some comfort knowing this is not being accepted in the courtroom. Think again. P300 is already being used in court as admissible evidence by both defense and prosecuting attorneys.
Now what happens when science improves and Mind-Reading 2.0 is available?...
Now juxtapose this emerging technology with how our courts have interpreted our rights against unreasonable searches and seizures guaranteed in the Fourth Amendment of our Constitution. For example, the Supreme Court long ago ruled (Smith vs. Maryland) that we have no "reasonable expectation of privacy" in telephone call header data (i.e., whom you called, on what day, and for how long).
Now that the technology exists to "read" P300 responses, I have to wonder where we are going to draw the line...
Is it possible the Supreme Court could someday rule that certain brain activity is not private? If this seems far-fetched, let me share one plausible journey that might just make this true. The Court has held (Katz vs. United States) that an expectation of privacy is not "reasonable" unless both: (1) a person can claim "a legitimate expectation of privacy" over a particular type of information; and (2) this expectation is one that society is prepared to recognize as "reasonable." And, of course, what society sees as "reasonable" changes over time..."
Scary but a nice illustration of how a series of apparently small and some moderate-impact technology and legal systems decisions, spread out over a period of time and taken without a systemic appreciation of their cummulative effect, can lead to a dangerous place.
MI6 and Blair at odds over Saudi deals
"Britain's secret intelligence service, MI6, has challenged the government's claim that a major corruption inquiry into Saudi Arabian arms deals was threatening national security.
The attorney general, Lord Goldsmith, told parliament before Christmas that the intelligence agencies "agreed with the assessment" of Tony Blair that national security was in jeopardy because the Saudis intended to pull out of intelligence cooperation with Britain. But John Scarlett, the head of MI6, has now refused to sign up to a government dossier which says MI6 endorses this view."
US Law School Deans united on Guantanamo detainees
"We, the undersigned law deans, are appalled by the January 11, 2007 statement of Deputy Assistant Secretary of Defense Charles 'Cully' Stimson, criticizing law firms for their pro bono representation of suspected terrorist detainees and encouraging corporate executives to force these law firms to choose between their pro bono and paying clients.
As law deans and professors, we find Secretary Stimson's statement to be contrary to basic tenets of American law. We teach our students that lawyers have a professional obligation to ensure that even the most despised and unpopular individuals and groups receive zealous and effective legal representation. Our American legal tradition has honored lawyers who, despite their personal beliefs, have zealously represented mass murderers, suspected terrorists, and Nazi marchers. At this moment in time, when our courts have endorsed the right of the Guantanamo detainees to be heard in courts of law, it is critical that qualified lawyers provide effective representation to these individuals. By doing so, these lawyers protect not only the rights of the detainees, but also our shared constitutional principles. In a free and democratic society, government officials should not encourage intimidation of or retaliation against lawyers who are fulfilling their pro bono obligations.
We urge the Administration promptly and unequivocally to repudiate Secretary Stimson?s remarks."
This blunt Chicago Tribune article spells out exactly why the people incarcerated in Guantanamo Bay need high quality legal representation.
"Sometime before the terror attacks of Sept. 11, a man named Abdul Aliza was taken from his home and his family in Afghanistan and was forced at gunpoint to work for the Taliban as a cook's assistant.
Interrogated years later by U.S. officers at the military prison at the Guantanamo Bay Naval Station in Cuba, Aliza insisted that he had never joined with the fighting against America or its allies.
"Did you fight against the Northern Alliance . . . or any United States forces?" Aliza was asked, according to a transcript the Pentagon released.
"I have never fought," Aliza answered. "I was forcefully taken."
"What did you do while in captivity or while you were with the Taliban?"
"I served them food."
Officers told Aliza that having been kidnapped by the Taliban and forced to serve as a cook or a waiter was irrelevant to whether Aliza was an enemy combatant. Aliza found this impossible to comprehend...
Bush administration officials have assured the American people that Guantanamo keeps us safe because it keeps dangerous Al Qaeda terrorists off the street.
But the Pentagon's data show that only 8 percent of the prisoners at the base are even alleged to have been Al Qaeda fighters--assuming the allegations against them are true...
Much of the problem has to do with the words and definitions the administration uses.
Being an enemy combatant does not mean a prisoner did anything wrong, the administration said in documents written by the Department of Defense in 2004.
The term does not require evidence that a prisoner knowingly took any action against the United States, or even that he was a willing participant in the conflict. As a result, many prisoners at the base are, by any reasonable standard, completely innocent.
...in the past, we sensibly distinguished enemy soldiers from unwilling servants. Today, we conjure up combatants from the Taliban's cooks. Some of the men identified in this article spent years at Guantanamo before their eventual release without any charges; the rest, along with nearly 400 others, linger there still."
Energy debate
Monday, January 15, 2007
Sofware patents yes or no?
"Section 60 of the UK Patents Act 1977 sets out what does and doesn't constitute an infringement of a patent. In subsection (5) there is quite an extensive list of exceptions to the standard ways of infringing a patent (eg making, using, disposing of). These are meant to be equitable ways of limiting the power of a patent holder against those who should not be pursued for infringement. These include farmers, private non-commercial users, medical researchers and others.
Perhaps this is the place to look for a solution. Why should the development, use, distribution etc. of computer software itself be classed as infringing? If it wasn't an infringement, wouldn't this solve the problems of those who only want to make new software or modify existing software and don't want to risk infringement? Wouldn't making an exception of this kind help the development of new and innovative software solutions?
Here is a proposal then that might just achieve this. In Section 60(5), insert this subclause:
(j) it consists of the making, use, disposal, offering, keeping or importation of computer software.This little change would exempt software itself from patent infringement. It would not prevent computer implemented inventions from being patented, nor would it prevent companies from suing others for infringement based on real embodiments requiring patentable software solutions, for example the sale of music players or telephones incorporating patented software-implemented inventions. It would, however, prevent software developers from being sued under a patent for merely developing and distributing software they have developed themselves.
Of course, big companies like Microsoft and IBM would doubtless complain that their rights would be severely restricted by such exceptions. However, a large part of the protection afforded to software such as Microsoft's operating systems is due to the combination of copyright protection together with the almost impossible task of reverse engineering publically available object code into source code that can be made sense of. So, copyright protection (which, to remind readers, lasts for 70 years after the last author's death - a very very long time) together with the law of confidential information, seems quite adequate to protect the investment needed to develop software. After all, a return on investment is what the IP game is all about, is it not?"
US Defence Official Calls for Business pressure on Guantanamo lawyers
"Now comes before you Mr. Cully Stimson, deputy assistant secretary of defense for detainee affairs. In an interview with conservative radio broadcasters on a local A.M. station, Mr. Stimson remarks that an interesting, breaking story is the list of blue-chip law firms representing Guantanamo detainees – a list that he says was unearthed by a FOIA request (although, as Stimson knows quite well, the information was never a secret). (The audio is here. Scroll down to Guantanamo Bay: Five Years Later.) Stimson finds it “shocking, really” that prominent law firms would do any such thing. As he rattles off the list of law firms, it becomes clear that he has it on paper in front of him: it’s too lengthy to come off the top of his head. Asked who is paying the law firms, Stimson magnanimously admits that some of these lawyers are working pro bono, but then he hints darkly that others may have nefarious, secret funding sources. Enemies within! More terrorist lawfare!
He adds, “I think, quite honestly, when corporate CEOs see that those firms are representing the very terrorists who hit their bottom line back in 2001, those CEOs are going to make those law firms choose between representing terrorists or representing reputable firms, and I think that is going to have major play in the next few weeks. It will be fun to watch that play out.”...
The response was predictable, and gratifying. The ABA’s president, and defense-bar spokesman Neal Sonnett leaped to the law firms’ defense, as did Senator Leahy. After outraged editorials in both the New York Times and the Washington Post publicized Stimson’s obscurely-situated interview, the Defense Department disavowed his remarks in strong terms, and made all the right noises about how important it is for the legal process to have excellent counsel for detainees.
How’s that again? For five years, the government (not least Defense) has fought in every way possible to avoid access to legal process for the detainees, a campaign that culminated in the habeas-stripping provisions in the Military Commissions Act. Why would they want excellent representation for the detainees, given that they don’t want the detainees ever to find a forum to be represented in? The hypocrisy boggles the mind. I assume that what bothered Defense about Stimson’s remarks is not their content but their candor."
EU officials OK US ATS data sharing
"But in a letter to the chief privacy officials of 27 countries, the American Civil Liberties Union and London-based Privacy International said the Automated Targeting System violated the October data-sharing accord, U.S. law and European data-protection laws.
The system's creation of terrorist risk assessments on all passengers, the storing of profiles for as long as 40 years, and the fact that passengers have no right to see, modify or correct the information violates the agreement, the groups said."
Carbon trading and human rights
"...human rights abuses at Mount Elgon National Park in east
Uganda, where the Dutch FACE Foundation has been planting carbon
'offset' trees since 1994. The report exposes how villagers living along
the boundary of the park have been beaten and shot at, have been barred
from their land and have seen their livestock confiscated by armed park
rangers guarding the 'carbon trees' inside the National Park."
The table of contents of the 104 page report give you some idea of what to expect from its substance but chapters 1, 3 and 7 are well worth a read.
"CONTENTS
1. Ticking the right boxes or offsetting responsibility? .................... 7
Box: FACE: The facts .......................................................................................... 9
Box: The Uganda Wildlife Authority (UWA)...................................................... 12
2. Mount Elgon......................................................................................... 21
The peoples living in and around Mount Elgon ................................................ 23
The Bagisu ......................................................................................................... 23
The Sabiny ......................................................................................................... 24
3. A chronology of conflicts at Mount Elgon ....................................... 27
Box: The British in Uganda................................................................................. 28
Box: International support for evictions ............................................................. 33
Mount Elgon is declared a national park ............................................................ 37
Evictions from the Kapkwata Softwood Plantation ............................................ 40
Land rights, shootings, killings .......................................................................... 41
A new boundary and more evictions .................................................................. 42
Parliamentary committee on natural resources ................................................... 44
More conflict ...................................................................................................... 46
Boundary disputes, another survey and the Benet sue UWA ........................... 47
Illegal logging and yet more conflicts ................................................................ 49
4. The UWA-FACE project ..................................................................... 59
Is the FACE project additional? .......................................................................... 59
UWA’s version of events at Mount Elgon ......................................................... 62
The UWA-FACE project and the boundary of the national park ....................... 64
Benefits to local people from carbon sales? ....................................................... 67
Notes from a visit to Mount Elgon ..................................................................... 68
5. IUCN and NORAD.............................................................................. 73
IUCN and the Katoomba Group ......................................................................... 78
Box: Carbon forestry in Uganda ......................................................................... 79
6. Forest Stewardship Council Certification ........................................ 83
Does the project comply with FSC standards?................................................... 83
SGS’s visits to Mount Elgon .............................................................................. 93
Certifying the trees or certifying the park management? .................................... 94
7. “We just want our land back” ............................................................ 99"
Over 50 people have reportedly been killed in and around the boundaries of the disputed region. We cannot tackle pollution and climate change through carbon trading schemes designed to allow the affluent to go on polluting at increasing rates. It's smoke and mirrors. It may ease our conscience to think that we've paid to have some trees planted in Africa to aborb carbon emissions equivalent to those pumped into the atmosphere by our latest holiday flight. Yet any "solution" to this massive global systemic mess based on the assumption that we can continue to pollute at exponentially increasing rates is doomed to fail. And as this report points out, the immediate implications for indigenous peoples in and around the areas chosen for these carbon-offsetting plantations can be life threatening in ways that us comfortably off Westerners would prefer not to think about.
Thanks to my colleague, Ray Ison, for the link.
Crypto-Gram January 15, 2007
Friday, January 12, 2007
Government to review school fingerprinting
Digital records of 'disruptive behaviour'
"According to Children Now:
Leicestershire Council has signed a £1m contract for an IT system designed to help target truancy, behaviour and pupil attainment.
The five-year agreement with Capita Education Services will provide a system to manage pupil and school data. It will make it easier for children’s services teams to share information on attendance, exclusions, behaviour, pupil attainment and special educational needs.
Over on the Capita education site, online demonstrations of all their products are available. The ‘Detailed Pupil Record’ captures, well, everything - right down to ‘disruptive behaviour - throwing food’.
Schools need to start being very careful if they are logging and sharing information on what may be subjective or unfair decisions about behaviour. After all, who hasn’t at some point been unfairly accused of some misdemeanour or other at school?
Generally children shrug injustice off as yet another example of a particular teacher’s irascibility or unreasonableness, but if that information is going to be spread around and find its way on to the databases of other services in order to facilitate judgments about whether a child is showing signs of being ‘at risk’ of future offending, that’s another matter completely...
A child whose database record is peppered with incidents of ‘disruptive behaviour’ is a child heading for a label and a multi-agency intervention scheme. More, that record is persistent: unlike the punishment book, it doesn’t disappear down the back of the head teacher’s filing cabinet to accumulate dust once the pages have started to fall out. It can follow a child around every agency with which s/he has contact for years to come.
Teachers are going to have to start being very sure indeed about what goes on to a child’s behaviour record, because as soon as children’s information starts crossing the school fence, the implications of unjust accusations suddenly become extremely serious."
Secret war?
"Washington intelligence, military and foreign policy circles are abuzz today with speculation that the President, yesterday or in recent days, sent a secret Executive Order to the Secretary of Defense and to the Director of the CIA to launch military operations against Syria and Iran.
The President may have started a new secret, informal war against Syria and Iran without the consent of Congress or any broad discussion with the country.
Thursday, January 11, 2007
Kim Weatherhall's last post
"The last 12 months have been particularly insane. Just over a third of the 'words' I have written on the blog have happened in the last 12 months. So I'm tired. And I need to do other academic-y stuff. you know, like write journal articles and books. I've not done enough of that, because of the blog and the law reform involvement. I need to give myself a bit of time to think about things more broadly and deeply. It doesn't happen when you're desperately trying to keep up with things and have views on every development."
Good luck to Kim with the academic-y stuff and the thinking.
Becta warn schools to avoid Vista
"technical, financial and organizational challenges associated with early deployment currently make this (Vista) a high-risk strategy."
MI5 email alert sign up routed via US
"MI5, the Security Service, part of whose remit is supposed to be giving protection advice against electronic attacks over the internet, is sending all our personal details (forename, surname and email address) unencrypted to commercial third party e-mail marketing and tracking companies which are physically and legally in the jurisdiction of the United States of America, and is even not bothering to make use of the SSL / TLS encrypted web forms and processing scripts which are already available to them."
Super Mario Software Patent denied
"The decision related to refusal of Nintendo's application under section 1(2) of the UK Patents Act 1977. The examiner had maintained an objection regarding s1(2)(c), i.e. that the contribution lay solely in the field of computer programs, and consequently refused the application. Referring to Aerotel/Macrossan (previously reported in the IPKat here), the Hearing Officer applied the now approved four step test, noting that the decision must be treated as a definitive statement of how the law on patentable subject matter is now to be applied in the UK, and that it should not be necessary to refer back to previous UK or EPO case law regarding the issue.
After construing the claims, the Hearing Officer considered the contribution to be the process of setting a kart upright and facing in the same direction as it was prior to crashing. This was seen to be clearly wholly within the area of a computer program, but not itself a scheme, method or rule for playing a game. Since the third step question was answered in the affirmative, it was not seen to be necessary to consider the fourth step, i.e. whether the contribution was "technical" in nature. The application was therefore refused.
The IPKat sees much sense in this decision, but wonders how it can be squared with the previous decisions of Sun Microsystems and ARM, both of which also related to ways of getting computer programs to do clever things purely implemented in software, but which were related to much more serious-sounding issues of bytecodes and compilers rather than silly racing karts."If the EU Council of Ministers had succeeded with just one of their many attempts to sneak the proposed software patents directive through via fisheries and other unrelated Council meetings, (doumented in great detail by Florian Mueller in his book) then Nintendo would probably now be the proud owners of a UK software patent for uprighting cars/vehicles in computer games.
Beckham goes to the US for $1million a week
January 11 is the International Day to Shut Down Guantanamo
EU report rejects call for copyright term extension
"Chapter 3: Extending the term of protection for related (neighbouring) rights
Holders of neighbouring rights in performances and phonograms have expressed concern that the existing term of protection of 50 years puts them and the European creative industries, in particular the music industry, at a disadvantage, as compared to the longer protection provided for in the United States. Chapter 3 examines these concerns, first by describing and comparing the terms in the EU in the light of the existing international framework and existing terms in countries outside the EU, secondly by examining the rationales underlying related (neighbouring) rights protection and finally by applying economic analysis.
The authors of this study are not convinced by the arguments made in favour of a term extension. The term of protection currently laid down in the Term Directive (50 years from fixation or other triggering event) is already well above the minimum standard of the Rome Convention (20 years), and substantially longer than the terms that previously existed in many Member States. Stakeholders have based their claim mainly on a comparison with the law of the United States, where sound recordings are protected under copyright law for exceptionally long terms (life plus 70 years or, in case of works for hire, 95 years from publication or 120 years from creation). Perceived from an international perspective the American terms are anomalous and cannot serve as a legal justification for extending the terms of related rights in the EU.
An examination of the underpinnings of existing neighbouring rights regimes does not lend support to claims for term extension. Whereas copyright (author’s right) protects creative authorship, the rights of phonogram producers are meant to protect economic investment in producing sound recordings. The related rights of phonogram producers have thus more in common with rights of industrial property, such as design rights, semiconductor topography rights, plant variety rights and the sui generis database right. Whereas all these rights share the same ‘investment’ rationale, their terms are considerably shorter, while setting higher threshold requirements. For example, whereas the database right requires ‘substantial investment’ in a database, the phonographic right requires no more than the making of a sound recording, be it a complex studio production or simply a matter of ‘pushing a button’ on a recording device. Indeed, a good argument could be made for shortening the term of protection for phonogram producers.
Given that the legal protection of phonogram producers is based on an investment rationale, it is important to note that the costs of owning and operating professional recording equipment has substantially decreased in recent years due to digitalisation. On the other hand, the costs of marketing recordings has apparently gone up. These costs now make up the largest part of the total investment in producing a phonogram. However, it is doubtful whether these costs may be taken into account as investment justifying legal protection of phonogram producers. Insofar as marketing costs accrue in the goodwill of trademarks or trade names, phonogram producers or performing artists may already derive perpetual protection therefore under the law of trademarks.
For the large majority of sound recordings the producers are likely to either recoup their investment within the first years, if not months, following their release, or never...
As the rights expire, recordings falling into the public domain will become subject to competition and falling prices, which will lead to a loss of income for the former right holders. Stakeholders argue that this will negatively affect future investment in A&R. However, it appears that onlylimited shares of phonogram producers’ overall revenues are currently invested in A&R, so the predicted negative effect on investment in new talent is likely to be limited.
Another argument that stakeholders have advanced in favour of term extension refers to the so-called ‘long tail’ (i.e. the reduced costs of digital distribution has created new markets for lowselling content). A term extension might indeed inspire phonogram producers to revitalise their back catalogues recordings, and make them available to a variety of digital distribution channels. On the other hand, the immense market potential of digital business models should already today have provided ample incentive to phonogram producers to exploit their back catalogues in new media. The recent history of the internet, however, indicates that these opportunities have not always been seized by those stakeholders now asking for a term extension.
Stakeholders have also posited that not granting a term extension would distort competition between right holders based in the EU and their competitors in non-EU countries, where right holders may enjoy longer terms. It has been argued that foreign countries would apply a ‘comparison of terms’ to the detriment of EU right holders. This argument is wholly unconvincing...
Another argument advanced by stakeholders is that a failure to bring the term of protection in the EU in line with the US will negatively affect the competitiveness of the European music industry. However, the competitiveness of phonogram producers is based on a wide variety of factors, intellectual property protection in general and the term of protection in particular being just one of them. Moreover, the worldwide music market is dominated by only four multinational companies (the so-called ‘majors’), that can not be characterised as either ‘European’ or ‘American’. Juxtaposing the interests of the European and the American music industries, therefore, would be wholly artificial. Even so, the market dominance of the ‘majors’ is an economic factor to be taken into consideration. A term extension would in all likelihood strengthen and prolong this market dominance to the detriment of free competition.
A final argument sometimes advanced in favour of term extension comes from the world of accountancy. It assumes that a longer term of protection would increase the value of ‘intangible assets’ in the balance sheets of European record companies. Granting a shorter term of protection to record companies in the EU than their competitors in the US already receive, would arguably result in a comparatively lower valuation of assets of European companies. This argument, however, is largely without merit. The value of a record company’s own recordings is not regularly recognised as intangible assets by the record labels, and not capitalised in the balance sheets. Acquired catalogues of recordings are usually capitalised, but routinely written off well before the existing terms of related rights protection expire. A term extension will perhaps play a minor role only in the valuation of the goodwill of a record company in the context of a merger or acquisition. Even then, its effect will be minimal.
The fact that some recordings still have economic value as rights therein expire, cannot in itself provide a justification for extending the term of protection. Related rights were designed as incentives to invest, without unduly restricting competition, not as full-fledged property rights aimed at preserving ‘value’ in perpetuity. The term of related rights must reflect a balance between incentive and market freedom. This balance will be upset when terms are extended for the mere reason that content subject to expiration still has market value. The public domain is not merely a graveyard of recordings that have lost all value in the market place. It is also an essential source of inspiration to subsequent creators, innovators and distributors. Without
content that still triggers the public imagination a robust public domain cannot exist.
Admittedly, an argument could be made in favour of extending the term of protection of performing artists, since the reasons for protecting artists are comparable to those underlying author’s rights. However, in the light of existing contractual practices, it is unlikely that performers would actually fully benefit from a term extension, since record companies routinely require a broad assignment of the rights of the performing artists. Therefore, extending the term of protection of performing artists should be considered only in connection with the harmonisation of statutory measures that protect the artists against overbroad transfers of rights. Obviously, a term extension would benefit only those artists that are still popular after 50 years and continue to receive payments from collecting societies and phonogram producers. This however concerns only a small number of performing artists."
Thanks to Ian Brown for the pointer via the ORG list.
iPhone myphone Cisco sues Apple
Wednesday, January 10, 2007
MedImmune v Genentech US Supreme Court Drug patent decision
MedImmune were paying Genentech licence fees to work on their patented antibodies technologies and also technologies that had a patent pending. When the latter patent was granted Genetech asked for more money but MedImmune though the second patent was invalid. They decided to pay the royalties to avoid being sued by Genetech but they also challenged the patent. Genetech argued that there was no "case in controversy" because MedImmune were paying royalties. MedImmune argued they should not have to stop paying royalties, thereby opening themselves up to being sued by Genetech, before they were allowed to challenge the patent. The Supreme Court agreed with MedImmune.
IPKat says: "in US Constitutional law terms the case extends the scope of the "case in controversy" test significantly, but for patent lawyers its effect is quite simple. You can apply to the court for a patent to be revoked while continuing to pay the licence fee: keeping the farm and all the animals safe."
Digital decision making and transformational government
" 1. From today we involve customers right from the start in any major public-service project. They'll be involved in design, decision, development, monitoring and feedback stages. WeÂ?ll freeze any project that didnt involve customers from the start. They fail their Gateway reviews, and we'll review urgently what people actually wanted. Two quick and easy way's we'll do this are to routinely offer a moderated "forum" alongside any complex services so users can shareexperiencess and we can learn from that. Also we'll open a public discussion link for new projects so we test our our ideas and hear suggestions as clearly and early as possible.
2. If we stop pretending everything is perfect can we please have an end to mindless criticism of government IT. Informed constructive criticism we can accept. We'll be frank and truthful about our aims and intentions, the evidence base, what it costs (not just the IT, but the whole programme including training, restructuring), what works and what doesnt.
3. We intend to engage with, inform and learn from people about what we're undertaking here. This includes non-technical officials, political leaders, our suppliers, independent experts and sceptics. We're all in this together; we're all paying for this and we all share an interest in the outcome. We can't impose this change on everyone. To lead credibly we have to listen. We have to speak out on the big IT issues, and educate people about the use of IT including its dangers.
4. WeÂ?ll default to making any non-personal and tax-funded public information free and openly available using standard formats and APIs. This country is committed to Freedom of Information and we can make this happen. We want to be as trusted and competitive as the Scandinavian countries, and they have a 240 year headstart in FoI. We've got a lot of catching up to do, so it's fortunate that the web makes it cheap and easy.
5. We'll apply full openness and transparency about contracts and costs for public sector contracts in future, including Gateway reviews. Level playing field - same applies to all.
6. WeÂ?ll presume that any software paid from public funds will be placed in a public-sector SourceForge, reusable by any other public service under creative commons licence.
7. WeÂ?ll apply a principle of maximal anonymity to any transaction involving personal data, and invite the Information Comissioner to challenge any unnecessary disclosure of data.
8. Before we spend over £1m on any development we'll offer £20,000 to some talented developers to see if they can produce a substantially functional version of what we're after. We must find better ways of building our large-scale systems. We need innovation and accelerate dadoption of best practice.
9. With multi-agency work we'll make sure we've got multi-agency buy-in before we commit ourselves to a course of action.
10. The principle of subsidiarity will reign in government IT."
I make a somewhat similar argument in the concluding chapter of my book, though couched more generically in the context of a suggested 'digital decision making framework.' It's all about active, informed and critically constructive participation of all appropriate stakeholders, including the general public, in the decision making process.
Secure Flight Privacy Report
"The Department of Homeland Security (DHS) Privacy Office conducted a review of the Transportation Security Administration's (TSA) collection and use of commercial data during initial testing for the Secure Flight program that occurred in the fall 2004 through spring 2005. The Privacy Office review was undertaken following notice by the TSA Privacy Officer of preliminary concerns raised by the Government Accountability Office (GAO) that, contrary to published privacy notices and public statements, TSA may have accessed and stored personally identifying data from commercial sources as part of its efforts to fashion a passenger prescreening program.
These new concerns followed much earlier public complaints that TSA collected passenger name record data from airlines to test the developmental passenger prescreening program without giving adequate notice to the public.1 Thus, the Privacy Office’s review of the Secure Flight commercial data testing also sought to determine whether the data collection from air carriers and commercial data brokers about U.S. persons was consistent with published privacy documents.
The Privacy Office appreciates the cooperation in this review by TSA management, staff, and contractors involved in the commercial data testing. The Privacy Office wishes to recognize that, with the best intentions, TSA undertook considerable efforts to address information privacy and security in the development of the Secure Flight Program. Notwithstanding these efforts, we are concerned that shortcomings identified in this report reflect what appear to be largely unintentional, yet significant privacy missteps that merit the careful attention and privacy leadership that TSA Administrator Kip Hawley is giving to the development of the Secure Flight program and, in support of which, the DHS Acting Chief Privacy Officer has committed to provide Privacy Office staff resources and privacy guidance."
Findings:
"As ultimately implemented, the commercial data test conducted in connection with the Secure Flight program testing did not match TSA's public announcements. Part of the reason for this discrepancy is the fact that the Fall Privacy Notices were drafted before the testing program had been designed fully. However well-meaning, material changes in a federal program's design that have an impact on the collection, use, and maintenance of personally identifiable information of American citizens are required to be announced in Privacy Act system notices and privacy impact assessments. In addition, not meeting these requirements can significantly impair a program's credibility.
The creation of an effective program requires contributions from operational personnel as well as policy and legal advisors. To be most successful, all groups must have effective communications and coordination. Given the disparity between the published Fall Privacy Notices that explained the commercial data test for Secure Flight and the actual testing program that was conducted, it seems readily apparent that closer consultation and better coordination at key decision points between the Secure Flight program office and TSA legal, policy, and privacy offices was needed. While this may have been due to short deadlines and resource constraints, the end result was that TSA announced one testing program, but conducted an entirely different one.
To TSA’s credit, after being informed of this significant discrepancy, TSA revised and reissued the SORN and PIA to reflect more closely the testing program’s conduct. Additionally, throughout the commercial data test, TSA made the security of the commercial data a high priority. TSA expressly prohibited the commercial entities
involved in testing from maintaining or using the PNR for any purpose other than Secure Flight testing, and it instituted real-time auditing procedures and strict rules for TSA access to the data. This was certainly challenging given the complex and changing nature of the program.
Whatever the causes, however, the disparity between what TSA proposed to do and what it actually did in the testing program resulted in significant privacy concerns being raised about the information collected to support the commercial data test as well as about the Secure Flight program. Privacy missteps such as these undercut an agency's effort to implement a program effectively, even one that promises to improve security."
Recommendations:
"Based on its extensive review of the commercial data test, the Privacy Office offers the following recommendations for Secure Flight. These can also serve as guideposts for any Departmental initiative that involves the collection, use, and maintenance of personally identifiable information:
1. Privacy expertise should be embedded into a program from the beginning so that program design and implementation will reflect privacy-sensitive information handling practices.
2. Programs should create a detailed "data flow map" to capture every aspect of their data collection and information system life cycle. Such an exercise will help produce accurate public documents explaining program compliance with the fair information practices principles of the Privacy Act of 1974, which must guide collection and use of personally identifiable data in the government space.
3. Good communications and collaborative coordination between operational personnel and policy, privacy, and legal advisors are essential in order to ensure that key documents explaining an information collection program are accurate and fully descriptive.
4. Programs that use personal information succeed best if the public believes that information to be collected is for a necessary purpose, will be used appropriately, will be kept secure, and will be accessible for them to review. To obtain such public trust requires the transparency and accountability that can be reflected in careful drafting of publicly available SORNs and PIAs.
5. Privacy notices should be written and published only after the design of a program or a program phase has been fully described in writing and decided upon by authorized program officials;
6. Privacy notices should be revised and republished when program design plans change materially or a new program phase is going to be launched; and
7. Program use of commercial data must be made as transparent as possible and explained in as much detail as is feasible."
It's an important report especially given the recent formal agreement between the EU and US re-introding the transfer of EU airline passenger name records to the US security authorities, though sadly it will probably only register on the radar of PNR or civil liberties geeks.
Government attack information commissioner
The government, however, are complaining that if the general public were to see these reviews it might cause "substantial harm." So basically their smart internal people told them the ID scheme was a lousy idea and because they have been selling it to Jo Public as a wonderful panacea for a variety of ills, they don't want the reality of the advice they received to be made public. This is exactly the kind of thing that kills public confidence in government, politicians and the political process. They have been overselling the utility of their big ID card idea, in spite of clear internal and external advice and evidence that the scheme won't work. Now they don't want their internal frank advice published because it would cause "substantial harm" and might "damage public confidence" in the scheme.
Thanks to HJ Affleck at FIPR for the link.
Monday, January 08, 2007
Felten's predictions for 2007
"(1) DRM technology will still fail to prevent widespread infringement. In a related development, pigs will still fail to fly.
(2) An easy tool for cloning MySpace pages will show up, and young users will educate each other loudly about the evils of plagiarism...
(5) Major record companies will sell a significant number of MP3s, promoting them as compatible with everything. Movie studios won’t be ready to follow suit, persisting in their unsuccessful DRM strategy...
(7) Some mainstream TV shows will be built to facilitate YouTubing, for example by structuring a show as a series of separable nine-minute segments.
(8) AACS, the encryption system for next-gen DVDs, will melt down and become as ineffectual as the CSS system used on ordinary DVDs...
(10) A worm infection will spread on game consoles.
(11) There will be less attention to e-voting as the 2008 election seems far away and the public assumes progress is being made. The Holt e-voting bill will pass, ratifying the now-solid public consensus in favor of paper trails.
(12) Bogus airport security procedures will peak and start to decrease. "
The anti-torture memos
"We've previously compiled a running list of all posts related to civil liberties, the War on Terror, and presidential power, listed by author.
By popular demand, here is a list of the essays grouped by topic. We've eliminated postings that are very short or that mostly quote newspaper articles. What follows is a compendium of substantive analyses on some of the key issues of the War on Terror by the authors here at Balkinization."
I doubt there is a better single source of analyses anywhere. Most of the articles are from 2005 and 2006 and they are divided into eight sections:
"Part I-- Civil Liberties
Part II-- Presidential Power and Constitutional Structure
Part III-- Torture and the "Torture Memos"
Part IV? The NSA Controversy and Government Surveillance
Part V-- Hamdan
Part VI-- The Military Commissions Act of 2006
Miscellaneous Posts
Posts by Guest Bloggers"
US 2006 evoting failures report
"In all, we looked at 1022 reports of problems associated with electronic voting equipment from 314 counties in 36 states...
The mid-term election revealed that the promise of easier voting, more accurate tallies, and
faster results with electronic systems has not been fulfilled. Voters in some jurisdictions
waited in line for hours to cast their ballots. Others cast their ballots accidentally before
they were done because they pressed the wrong button or left without casting their ballots
because they didn’t press the right button. Many voters watched the machine highlight a
candidate they didn’t select or fail to indicate a vote for a candidate they did select and
were then blamed for not being able to use a computer correctly.
Many polling places couldn’t open on time because of machine failures, and complex
procedures often left pollworkers frustrated and reluctant to serve again. Election directors
were often forced to rely on voting equipment vendors to set up the election, administer it,
and tally the votes because it was too complicated for their personnel to handle. Others
blamed themselves for not following the poorly documented, non-intuitive procedures
required to collect and tally the votes.
After the polls closed, poll workers and election officials struggled with a myriad of
reporting problems. Many couldn’t retrieve data from memory cards or couldn’t get the
tally software to combine totals from different computerized systems, while others couldn’t
figure out why the software was subtracting votes instead of adding them, or adding them
two and three times instead of only once; couldn’t determine for sure whether the first set
of results was correct, or the second set, or the third; couldn’t explain why one out of every
six voters didn’t have an electronic vote recorded for a hotly contested race; or why the
machines recorded more ballots than the number of voters who signed in to vote.
Often hidden from public view, equipment malfunctions such as these have normally been
exposed only when they are severe enough to attract media coverage...
While our source material is neither a complete list of problems nor even a
representative sampling, the number of incidents and the broad range of problems reported
is indicative of the widespread failure of electronic voting systems across the country and
how this failure affected the experience of voters on November 7, 2006."
So we had:
- Voters unable to get the machines to register their vote for their preferred candidates
- vendor companies running the elections because officials can't understand the machines
- and pollworkers not being able to work out final tallys or which of several final tallys to use.
Update: Federal officials in the US have temporarily suspended testing of electronic voting systems at the lab that has certified most of the evoting systems in the US.