Thursday, September 27, 2007

The Future of Content Pt 2 follow up

Martin has now responded to my earlier piece and Patrick McAndrew has followed through also with part 3 (beta).

I just wanted to add a few comments initially relating to Martin's piece. He says
But equally they [governments like China and Saudia Arabia] have really struggled to control information. Sure they’ve tried and had some success but this has had more to do with the immaturity of communication technologies, not the increasing ability of governments to censor information. The general trend is towards more freedom of information and as mobile devices and broadcasting/networking equipment become more powerful this will only increase.
I'm tempted to get into a long note here about civil rights and the Net but I'll restrict it to a three points. Totalitarian regimes rule through fear - brutalise a sufficient proportion of the population and the rest fall into line. They don't require total control, just enough. If the great firewall of China is 80% effective (and regular readers of this blog will know how much I detest filter software) it is effective enough.

The second point is that we basically have "zero privacy" (as Scott MacNealy said) on the Net. The way to tackle totalitarian regimes is to not be afraid (as is the way to tackle terrorism but now I'm getting even more side-tracked) but this is a risky business in these places, involving threat to life and liberty. Dissident bloggers are relatively easy to find - ISPs and tech cos are the choke points with the necessary information to hand over to the authorities - and as Cardinal Richelieu said, he only needed "six lines written by the most honest man" to present sufficient evidence to hang him. I wrote on this blog last year
Yahoo! chief, Jerry Yang, "feels horrible" that Yahoo! helped the Chinese authorities to jail journalists. When asked about the arrests he said they "are never things you go home and feel good about. We feel horrible about that...We have no way of preventing that beforehand....If you want to do business there you have to comply."

Badly damaging someone's life is merely the price of doing business. The heart of the business process is amoral hence the key rule is caveat emptor, where the 'emptor' encompasses everyone who comes into contact with that business in any way. It's kind of ironic that doing business fundamentally depends simultaneously on trust and lack of trust.

I doubt Mr Yang will get much sympathy over his horrible feelings but my question would be at what point does he believe the price of compliance becomes too high?

Thirdly, remember a few years ago when a handful of fuel protesters with mobile phones blockaded fuel depots and brought the UK to a grinding halt? Well the law has been changed and if they try it again they could very well get picked up by the police and disappear for 28 days (or longer if the government follow through with intentions to extend the term of detention without charge).

Moving on to the commerce end of things, Martin says
Sure the respective industries want to control it, but the point is they can’t anymore. This is because technologically they’ll always be beaten, and also because the online world allows new market players who will offer an alternative, often a free one. They have to adapt or die – look at photography: Kodak might have wanted to control the print process but ultimately digital cameras and Flickr meant they couldn’t.

Absolutely spot on - commerce has to adapt to the new technological context. Google didn't exist a little over a decade ago and it's almost hard to believe Microsoft is a young a company as it is. And sure, the established commercial landscape and players in any market changes over time but that amoral focus on the bottom line doesn't change and the commercial pressures to stick up barriers to a new technological contexts, just long enough to underpin, nurture, grow profit margins and leverage power in the new reality, never goes away.

Martin also points out that just because governments and commerce want to control the Net doesn't mean they can.
I heard Robert Cailliau, a colleague of Tim Berners-Lee, once argue that we were reaching the edges of our understanding of the complexity in the net. He joked that maybe it was using us to get built.
Since I've just published a book, one of the underlying themes of which is that we are pretty poor as a species at deploying, securing, controlling and regulating large information systems, I can only agree wholeheartedly with Martin and Robert Cailliau on this one.

But again what you've got to understand here - and it is difficult to emphasise this sometimes without sounding like a raving loonatic - is that the people (and their lawyers and the politicians they hold undue influence over) who run the content companies and other IP based industries, live in a completely different universe to the rest of us, with regard to their perspective on what the law ought to be. And they have the commercial, financial and political clout to ensure it is shaped in their favour. (Take a look at Jessica Litman's and Peter Drahos's terrific books Digital Copyright and Information Feudalism for engaging narratives on how these processes unfold in the US and international arenas)

The late Jack Valenti of the MPAA said the VCR relationship to the US movie industry was like that of the Boston strangler to a woman home alone. Jamie Kellner head of Turner Broadcasting believes TV viewers have a contract with the network to "watch the spots [adverts]" and that recording programmes for later viewing and then fast forwarding through the ads is theft. Why you you think the fast forward button on my DVD player is disabled when I want to skip those copyright notices at the beginning of a DVD? The US Movie industry run the DVD Content Control Association (DVDCCA) which licences tech companies to manufacture approved DVD machines with approved DRM mechanisms to play their DVDs.

I don't see how digital content shrinkwrap and clickwrap boilerplate licences, whether for software or any other product, which effectively say (and I paraphrase)-

"We cannot ever, under any circumstances, be held liable, even if proven beyond any reasonable doubt to be totally negligent when our product destroyed your life."

- could withstand appropriate scrutiny under the Unfair Contract Terms Act of 1977 or of the whole branch of civil liability tort law, which applies to normal products. But they do and courts repeatedly uphold them and we continue to buy generation after generation of substandardly secured software, for example, under purchasing conditions totally stacked in favour of the vendors.

The regulatory instruments and frameworks surrounding modern digital technologies are quite surreal. Technologists and educators need to be a lot more tuned into them than we are, if we are firstly to begin to understand them and secondly start to do something about imposing some semblance of reality on them in order to at least give Martin's vision of an accessible, sustainable, open content future a small glint of a fighting chance.

Tuesday, September 25, 2007

The Future of Content Pt 2

A few weeks ago I rashly agreed with Martin Weller to try an experiment in constructing an academic article on the future of digital content via a blog debate. Martin explains the idea here.

Well Part 1 is up and it's now my turn.

Next time I do this I'll try and make sure I'm better prepared in order to avoid what follows coming across as a stream of consciousness but Martin's post did trigger a whole series of ideas and possible responses in my mind. I'm tempted to launch into addressing the specifics of his essay and will do some of that but in an attempt to give the following some semblance of structure I'll try and address his primary points about digital content becoming free and widely available due to the pressures of economics and quality.

The idealist in me would like to believe that he's got it right that content will become widely and easily accessible but like Larry Lessig, I'm a bit of a pessimist and I fear a large chunk of this response may well end up parroting the message of several of Lessig's writings, with a dose of James Boyle and Yochai Benkler thrown in for good measure. Essentially I don't believe that the economics of information has changed, though networked digital technologies have re-shaped the distribution channels, the markets and business opportunities. Neither do I think that the technologies alone will lead to a kind of ecological emergence of widely accessible high quality content, especially since the market forces that Martin alludes to are distorted by an existing set information market dynamics dominated by small groups of established powerful interests, such as the entertainment, software and pharmaceutical giants.

A bit of recent history

In the early days of the general public's awakening consciousness of the World Wide Web, John Perry Barlow (another idealist) issued a Declaration of the Independence of Cyberspace.

"Governments of the Industrial World, you weary giants of flesh and steel, I come from Cyberspace, the new home of Mind. On behalf of the future, I ask you of the past to leave us alone. You are not welcome among us. You have no sovereignty where we gather.

We have no elected government, nor are we likely to have one, so I address you with no greater authority than that with which liberty itself always speaks. I declare the global social space we are building to be naturally independent of the tyrannies you seek to impose on us. You have no moral right to rule us nor do you possess any methods of enforcement we have true reason to fear... Cyberspace does not lie within your borders...

We will create a civilization of the Mind in Cyberspace. May it be more humane and fair than the world your governments have made before."

The Web and the Net were to become a self-organising free libertarian utopia where people could escape from the tyrannies of the real world - the anarchic emergence of freedom and democracy through technology. Needless to say it didn't happen because the people that use the technologies come under the jurisdiction of the real world governments. Actually round that time the notion that the Net would spontaneously lead to the inexorable spread of freedom around the world, something that democratic governments had spectacularly failed to achieve, became something of a mantra amongst technogeeks. Barlow was saying that geography didn't matter on the Net - someone in the UK or China could access a document in the US, where free speech was nominally protected by the First amendment to the Constitution. The comparatively low cost of access to speakers and listeners alike "guarantees" that speech in the most liberal regimes is available everywhere, even in the most restrictive regimes. Local laws and borders can be bypassed by the technology and the norms of cyberspace would converge towards the norms of the most liberal places connected to it.

Barlow's meme has often been taken to mean that we should rely on technology and geography and NOT laws, judges or politicians, to protect freedom of speech. Well government censorship of the Net in places like Saudi Arabia and large tech organisation's responsibility for fingering journalists for arrest in China have provided stark indications of totalitarian governments' ability to incorporate the existence of such technologies into their operations.

The idea that the technologies could not be regulated was distilled into the folklore of the Net partly in the form of three well known aphorisms that James Boyle labelled "a kind of Internet Holy Trinity." (Faith in the trinity is a condition of acceptance to the community. The sayings were (and indeed are still repeated and believed today in spite of the contrary developments of the past decade):

1/ In cyberspace the First Amendment is local ordinance (John Perry Barlow again)

2/ The Net interprets censorship as damage and routes around it (John Gilmore)

3/ Information wants to be free (Stewart Brand)

I guess I've already tackled Barlow but John Gilmore's "The net interprets censorship as damage and routes around it" was both a terrific sound-bite and, initially at least, it was technologically accurate. The Internet's original distributed architecture and packet switching were built around the problem of getting information packets delivered regardless of blockages, holes and malfunctions.

The Network was designed from the outlet to be neutral and operate in a way that would transcend its own inherent unreliability. The intelligence in the network would be kept at the ends or the nodes and the network itself would be relatively simple. Arguably, this end to end principle of network architecture is the most important factor underlying the explosion of innovation facilitated by the Internet. But remember end to end is a design principle and it doesn't hold in modern broadband networks. Increasing generations of network technology incorporate more and more 'intelligence' into the heart of the network facilitating network control by network owners.

The Net neutrality debate has been rumbling in the US for a few years now and if recent statements opposing net neutrality by the Department of Justice are anything to go by, it looks as though regulators on that side of the pond are leaning heavily towards favoring Network owners perspective in their approach to regulation.

John Naughton tells a wonderful story in his book, A Brief History of the Future, about when Paul Baran wanted to build a packet switching network in the 1960s. Jack Osterman, a senior executive at AT&T, the telecommunications monopolist in the US at the time, said "First, it can’t possibly work, and if it did, damned if we are going to allow the creation of a competitor to ourselves." Look at that word "allow". If the network owners control the networks, who uses them and how they get to use them then the network owners have a veto on innovation, which is the story told by Larry Lessig in the Future of Ideas.

Lessig also argues persuasively that the reason for the explosion in innovation facilitated by the Net was an accident of legal regulation - the telecommunications act of 1996 working together with the end to end architecture of the Net preventing discrimination by network owners - largely the telecoms companies - against innovators. The law and the technology disabled control. With broadband networks avoiding the end to end principle and the regulators facilitating network owner-operator control this has worrying implications for the future of freely accessible content postulated by Martin.

Now let's get back to Stewart Brand's declaration that "information wants to be free" - the implication being that free is it's natural state. It is an attractive notion and supported by weighty historical figures like Thomas Babbington Macaulay in his two speeches on copyright to the House of Commons in the 1840s and Thomas Jefferson widely quoted by cyberlibertarians:

"If nature has made any one thing less susceptible than all others of exclusive property, it is the action of the thinking power called an idea, which an individual may exclusively possess as long as he keeps it to himself; but the moment it is divulged, it forces itself into the possession of everyone, and the receiver cannot dispossess himself of it. Its peculiar character too is that no one possess the less, because every other possess the whole of it. He who receives an idea from me receives instruction himself without lessening mine; as he who lights his taper at mine receives light without darkening me. That ideas should spread from one to another over the globe, for the moral and mutual instruction of man and improvement of his condition, seems to have been peculiarly and benevolently designed by nature, when she made them like fire expansible over all space, without lessening their density at any point."

Sterling stuff and there's light at the end of the tunnel for Martin's accessible content future again. But people conveniently forget that when Brand first said information wants to be free the complete quote from that hackers conference in 1984 was:

"On the one hand information wants to be expensive, because it's so valuable. The right information in the right place just changes your life. On the other hand, information wants to be free, because the cost of getting it out is getting lower and lower all the time. So you have these two fighting against each other."

And unfortunately for those who would like content to be free the most powerful actors in the decision making process surrounding the deployment and regulation of the networks that will distribute the content are those who want it to support their profit margins.

Arhitecture

With apologies to Larry and those immersed in Lessigisms, I'm going to start parroting Lessig closely here. In Code he offers and simple but powerful model explaining the four regulators of behaviour - social norms, market forces, law and technology architecture. In the Future of Ideas and Free Culture he goes on to tell the tale of how established vested interests in the content industries reacted to the innovations of the Internet age - MP3, the Rio, Napster and peer to peer networking - by launching a counter-revolution through law and architecture to protect their interests. Copyright laws now cover more things for longer and with hugely more severe penalties for infringement than ever before. DRM digital locks were introduced on content and it became illegal to bypass these locks, or build tools to bypass them or tell someone where they might possibly find a tool to bypass them. You could get jailed in the US, like Dimitri Sklyarov, for writing a program in Russia (where it was legal and in fact required in order to facilitate the backing up of digital content) to bypass the digital locks on an Adobe eBook.

And remember digital content comes with a licence written by a lawyer in lawyerland - so the Adobe ebook first edition of Alice's Adventures in Wonderland came with a licence which proclaimed "This book may not be read aloud". Bill Gates won't sign a Windows CD because the user doesn't own the software, she is just licensed to use it.

Established interests with established well paid lobbyists and politicians can influence the development of regulations in their favour as the story of intellectual property laws has demonstrated in the internet age. And content companies have had a surprisingly disproportionate influence (amazing considering the relative sizes of the industries - with the tech folk dwarfing the entertainment folk by a factor of ten economically) on the technology industry's outputs, convincing the Microsofts, Apples and Sonys (of course Sony is slightly schizophrenic having a foot in both camps) of the world to build disabling drm and surveillance technologies into their products.

As Lessig says, the content industries, wielding law and technology, have fought a bitter counterrevolution against Napster, DeCSS, CPHack, My.MP3, Grokster, Eldred et al and won, at least in the courts, every time. Though millions of copyrighted works are still circulating online it is an increasingly risky business to engage in such infringement with industrial scale operations the content companies now have in place monitoring this activity and targetting [tens of thousands] of people for legal action.

At the same time the broad-reaching effects of these changes in the intellectual property arena have been completely off the cognitive radar of interest of people they are likely to affect like educators (at least until the panic over the Blackboard patent last summer).

Lessig Again

The Internet provides a particularly stark example of the interraction of Lessig's four regulating forces - law, norms, architecture and markets. Depending upon its design, its architecture - it can support or undermine law, social norms, and market forces.

The Internet is an entirely artificially created entity

The architecture of the Internet or cyberspace is programmed in the code, the logical layer and protocols that determine how it operates

That code and architecture

- Embeds certain values
- Supports/allows certain behaviours (how many times have you been on the line to a service e.g. bank or utility only when you do get a real person to be faced with the line "the computer won't let me!")
- Sets the terms according to which life in cyberspace will be lived

- Just like the laws of nature set the terms on which life is lived in the real world.

The Net - an entirely artificially created entity

The architecture programmed in the code and protocols that determine how it operates

It had an end to end DESIGN and complementary regulations which made control of activity on that network difficult

IT is an entirely artificially created entity. The design changed - the architecture was re-programmed (or at least the architecture of the broadband networks the Net has migrated to is substantially different to the TCP/IP protocols piggybacking on the phone networks) - as did the laws.

The Original Net Made Control Difficult

Geeks and wannabe geeks like me who try to bridge the geek-realworld divide liked to think about the architecture of the Net as a given - the distributed architecture of packet switching, TCP/IP, end to end. And that it couldn't be changed, just like the laws of nature. Our experience, our values our perception of the way the Internet was was fixed and we could not see beyond that.

So as Lessig said, we recited slogans -

the net treats censorship as damage,

the 1st is local ordinance,

information wants to be free

you can't regulate the Net

But this was not a view about nature - it was just a report about a particular design, a design cyberspace had about the time it was coming to the public's attention

This initial design did disable control and it did make regulation difficult.

It disabled control by governments - which, according to libertarians, theoretically increases liberty

Supported by law, it also disabled control by commerce e.g. network owners (phone companies) and content companies (entertainment, publishing and software )- thereby facilitating innovation and competition.

The architecture protected free speech - you could easily say what you wanted without that speech being controlled by others. China could not censor news about China. News of terror in Bosnia could flow freely outside state borders.

The architecture protected privacy - it supported relaying technologies and made it relatively easy to hide whom you were. Life could be lived anonymously.

The architecture protected free flow of information - text, music and pictures could be copied perfectly and for free and distributed anywhere on the Net, theoretically anywhere in the world.

It also protected an individual against local state regulation - A state that banned gambling within its borders couldn't prevent people from gambling on the Net. Geography didn't matter.

Each of these "liberties" depended on a certain design and features of the early Net

1.Users were not always identifiable
2.Data could not always be classified

Hence data access could not always be controlled. It was a nuisance for regulators and content owners. It changed.

1. It became easier to ID someone - who they are and where they are
2. Content could be identifiable and traceable and more easily classified

The controlling technologies are private (Cisco's new generation intelligent routers deployed by network owners) - tools commerce has built to

• Know who the customer is
• Control more easily what the customer does
• - where she goes (AOL would like you to stick with AOL content)
• - what she does with the content she gets

and laws commerce has bought like the DMCA of 1998 and the intellectual property rights enforcement directive of 2004, which do likewise.

Speech became less free - Chinese bloggers identified by Yahoo got jailed.

Privacy/anonymity became less secure - ISPs are the chokepoints. They are obliged to retain your traffic data and identify alleged transgressors to the content industries and government authorities.

Content could begin to flow less freely.

ICraveTV, Lessig and Code

Lessig tells the story of ICraveTV in Code.

A place of liberty and explosive innovation becomes something else.

For example ICraveTV a Canadian company, were allowed, under Canadian law to capture broadcast signals and re-broadcast them in any medium. The used the Net. Free TV is not allowed in the US though. Under US law ICraveTV should have negotiated with the original broadcaster. They used filters to try and keep Americans away from their free TV. But the Net made this difficult - it sees filters as damage and routes around them.

Hollywood didn't like Americans having free TV and sued asking a US court to shut down this Canadian company.

What if a German court said Mein Kampf could not be sold by Amazon.com anywhere because a German might get hold of it and its illegal in Germany?

OR a French court said a US auction site could not sell Nazi memorabilia because this was illegal in France

OR a Chinese court said a US ISP should be shut down because it broadcast information illegal in China

The US would be up in arms waving the HOLY of HOLIES - The First Amendment - such things violate free speech

Free speech did not register in the Pittsburgh court decision in the ICraveTV case. The judge ordered the site closed until they could prove free TV from Canada could not be seen by even one American.

ICraveTV promised to try and developed filters to zone cyberspace based on geography. ID technologies make zoning possible.

Incidentally, the French judge, in the Yahoo v France nazi memorabilia case, so vilified by the US media for interfering with American rights to free speech, only wanted the filters to be 80-90% effective.

The ICraveTV judge wanted 100% effectiveness and to hell with Canadian rights to free speech.

The US is very vocal about championing the cause of free speech on the Net and in the real world.

When it comes to issues of national security, though, which of course copyright is in the US, the values of the free flow of information fall away.

The lessons of the ICraveTV and Yahoo cases are that there is a push to zone the Net to allow local rules to be imposed.

We can see this with DVD players as well. A DVD movie bought in the US will probably not play on a DVD player bought in the UK. A Norwegian teenager, Jon Johansen, faced a possible jail sentence in a case that took five years to resolve in Norway, due to pressure on Norwegian authorities from the US movie industry. What was his crime? He bought a DVD in France and got frustrated and not being able to watch it on his linux computer. So he and two others wrote a little utility programme to bypass the copy protection system on the DVD he owned so that he could watch it on his computer. He then made this utility available on the Net; which is a criminal offence under a US copyright law called the DMCA. And incidentally it irritates the hell out of me that my DVD player disables the fast forward button when draconian copyright notices come up at the start of my DVD movies.

The DMCA, the EU's copyright directive, the intellectual property rights enforcement directive, Napster and P2P, MP3, CPHack, DeCSS, Apple v Realnetworks, Sklyarov, Felten and SDMI, Apple's iPhone drm are all fascinating stories in their own right(which I've ranted about here over the years), even without the wider impact they have on Internet regulation.

As BigCos increasingly take charge of the network, download speeds are typically 8 times upload speeds and the ratio will get worse. It may be that individuals and small independent content cos will find it more and more difficult to get through and just to show that AT&T has evolved in forty years, when asked about open access to their network, Daniel Somes, head of AT&T's cable division said, they didn't spend $56 billion on a cable network "just to have the blood sucked out of our veins."

But I've already got waaaaaaay too sidetracked on what was supposed to be the set up/ background for my paper so I'm just going to briefly address Martin's two points about economics and quality.

Economics and Quality


The economics of information flows really haven't changed though the move from atoms to bits in distribution technologies means that the markets have fundamentally changed. As Benkler says

"Social production is reshaping markets while at the same time offering new opportunities to enhance individual freedom, cultural diversity, political discourse and justice."

But these outcomes are not necessarily going to automatically emerge from Web 2.0 any more than they emerged from the end to end Internet 1.0 since there is a powerful campaign by established commercial interests in the industrial information game - big content pharma and software - to protect themselves. And democratic consumerism will no more be an inevitable emergent property of web 2.0 than democracy and freedom.

Martin points to Weinberger's arguments about our changing relationship with content - ie that iTunes has led us to realise that the natural unit of musical interest in the single track but I'm not sure I buy that specific argument. The dynamics are a lot more complex and varied. Communities of shared interest have begun to create their own playlists by mixing tracks together. Personally I like the album package and find significant value in the job the music labels did in aggregating songs or artists together in one package. I also find it irritating that my son's MP3 player runs on a different piece of software to my own player and it is a tedious fiddly technical and aggregating administrative exercise collecting the songs together in the way I like.

Which brings me to Tim O'Reilly's Piracy is Progressive Taxation, and Other Thoughts on the Evolution of Online Distribution which offers seven lessons for the media revolution which though outlined in the relative ancient history of 2002 still, I think, hold true today:

Lesson 1: Obscurity is a far greater threat to authors and creative artists than piracy.

Lesson 2: Piracy is progressive taxation

Lesson 3: Customers want to do the right thing, if they can.

Lesson 4: Shoplifting is a bigger threat than piracy.

Lesson 5: File sharing networks don't threaten book, music, or film publishing. They threaten existing publishers.

Lesson 6: "Free" is eventually replaced by a higher-quality paid service

Lesson 7: There's more than one way to do it.

The key ones in the current context being lesson 5, 6 and 7. Yes the markets change. Yes the distribution channels have changed and yes the technologies have augmented the activities of the traditional content industries in ways they would never have dreamed of a mere ten years ago. As O'Reilly says:

"As Jared Diamond points out in his book Guns, Germs, and Steel, mathematics is behind the rise of all complex social organization.

There is nothing in technology that changes the fundamental dynamic by which millions of potentially fungible products reach millions of potential consumers. The means by which aggregation and selection are made may change with technology, but the need for aggregation and selection will not. Google's use of implicit peer recommendation in its page rankings plays much the same role as the large retailers' use of detailed sell-through data to help them select their offerings.

The question before us is not whether technologies such as peer-to-peer file sharing will undermine the role of the creative artist or the publisher, but how creative artists can leverage new technologies to increase the visibility of their work. For publishers, the question is whether they will understand how to perform their role in the new medium before someone else does. Publishing is an ecological niche; new publishers will rush in to fill it if the old ones fail to do so...

New media have historically not replaced but rather augmented and expanded existing media marketplaces, at least in the short term. Opportunities exist to arbitrage between the new distribution medium and the old, as, for instance, the rise of file sharing networks has helped to fuel the trading of records and CDs (unavailable through normal recording industry channels) on eBay.

Over time, it may be that online music publishing services will replace CDs and other physical distribution media, much as recorded music relegated sheet music publishers to a niche and, for many, made household pianos a nostalgic affectation rather than the home entertainment center. But the role of the artist and the music publisher will remain. The question then, is not the death of book publishing, music publishing, or film production, but rather one of who will be the publishers."

Open source works with software production. I would be delighted if sustainable business models for open content were to emerge from Web 2.0 in the face of the power dynamics at the heart of the established industrial information economy. I suspect we are a long way from the future that Martin is hoping for though as I have said before I think he is partly right in his thesis about some of the forces pressing for an accessible information future. (Though Adam Smith and Garrett Hardin [Tragedy of the Commons] might dispute the notion that individual participants in Web 2.0 activities, unlike Dawkin's selfish gene, would behave in the best interests of the system as a whole thereby speeding the evolutionary process) But O'Reilly's publishers, whatever shape or form they take, will need resources, resources which folk like Lessig, Boyle, Drahos and Benkler lead me to conclude will come via pay per view rather than free content augmented by parallel revenue flows.

Monday, September 24, 2007

Get your retaliation in first against the terrorists strategy a failure

David Cole and Jules Lobel argue in a new book that the Bush/Blair 'get your retaliation in first against the terrorist' strategy is a failure. Not only does it lead to the breakdown of the rule of law but it makes us all less safe.

"President George W. Bush is fond of reminding us that no terrorist attacks have occurred on domestic soil since 9/11. But has the Administration's "war on terror" actually made us safer? According to the July 2007 National Intelligence Estimate, Al Qaeda has fully reconstituted itself in Pakistan's northern border region. Terrorist attacks worldwide have grown dramatically in frequency and lethality since 2001. New terrorist groups, from Al Qaeda in Mesopotamia to the small groups of young men who bombed subways and buses in London and Madrid, have multiplied since 9/11. Meanwhile, despite the Bush Administration's boasts, the total number of people it has convicted of engaging in a terrorist act since 9/11 is one (Richard Reid, the shoe bomber).

Nonetheless, leading Democratic presidential candidate Hillary Clinton claims that we are safer. Republican candidate Rudy Giuliani warns that "the next election is about whether we go back on defense against terrorism...or are we going to go on offense." And Democrats largely respond by insisting that they, too, would "go on offense." Few have asked whether "going on offense" actually works as a counterterrorism strategy. It doesn't. The Bush strategy has been a colossal failure, not only in terms of constitutional principle but in terms of national security. It turns out that in fighting terrorism, the best defense is not a good offense but a smarter defense...

In isolation, neither the goal of preventing future attacks nor the tactic of using coercive measures is novel or troubling. All law enforcement seeks to prevent crime, and coercion is a necessary element of state power. However, when the end of prevention and the means of coercion are combined in the Administration's preventive paradigm, they produce a troubling form of anticipatory state violence--undertaken before wrongdoing has actually occurred and often without good evidence for believing that wrongdoing will ever occur.

The Bush strategy turns the law's traditional approach to state coercion on its head. With narrow exceptions, the rule of law reserves invasions of privacy, detention, punishment and use of military force for those who have been shown--on the basis of sound evidence and fair procedures--to have committed or to be plotting some wrong. The police can tap phones or search homes, but only when there is probable cause to believe that a crime has been committed and that the search is likely to find evidence of the crime. People can be preventively detained pending trial, but only when there is both probable cause of past wrongdoing and concrete evidence that they pose a danger to the community or are likely to abscond if left at large. And under international law, nations may use military force unilaterally only in response to an objectively verifiable attack or threat of imminent attack...

The preventive paradigm has compromised our spirit, strengthened our enemies and left us less free and less safe. If we are ready to learn from our mistakes, however, there is a better way to defend ourselves--through, rather than despite, a recommitment to the rule of law."

Sunday, September 23, 2007

Craig Murray, Boris Johnson and Arsenal's Uzbek billionaire

Apparently lawyers for billionaire Arsenal shareholder, Alisher Usmanov, have had the site of former British ambassador to Uzbekistan, Craig Murray, shut down by his webhost. Boris Johnson's and others' blogs have also been caught in the shutdown, a splendid illustration of how crude the process can be. Boris is not impressed. He's quoted by the Guardian thus:

"This is London, not Uzbekistan. It is unbelievable that a website can be wiped out on the say-so of some tycoon.

We live in a world where internet communication is increasingly vital, and this is a serious erosion of free speech."

Sadly I don't have the capacity to look into this with any degree of depth currently but the blogosphere, listservs and usual geek and cyberrights sites (and, unusually, Arsenal fan sites) are buzzing with details and speculation. Given the story dovetails my lifelong obsession with Arsenal football club with current professional interests, though, I'll be returning to it when I get the chance.

Friday, September 21, 2007

GIKII 2

Gikii 2 was a big success on Wednesday. Thanks to all who made it such an interesting day. The presentations are available online. I didn't use PowerPoint slides this time (I rarely do any more, partly for reasons explained much better by Edward Tufte, though some of the presenters showed how it can be a great aid to communication when used effectively) but the paper of my short talk is here.

Update: The entertaining Fernando Barrio has posted his thoughts on the conference.

RIAA Sends Another Wave Of Settlement Letters

RIAA Sends Another Wave Of Settlement Letters Not a lot more to say about that really that hasn't already been said many times before.

Family sues Virgin Mobile over use of Texas teen's photo in advertisement

Here's an interesting case. It seems Virgin Mobile in Australia used a photo from Flickr in their adverts. The photographer had posted the photo with a creative commons license. But the family of the girl, Alison Chang, in the photo are suing Virgin for causing her grief and humiliation.

"The picture of 16-year-old Chang flashing a peace sign was taken at an April church car wash by Alison's youth counselor, who posted it that day on his Flickr page, according to Alison's brother, Damon. In the ad, Virgin Mobile printed one of its campaign slogans, "Dump your pen friend," over Alison's picture.

The ad also says "Free text virgin to virgin" at the bottom.

The experience damaged Alison's reputation and exposed her to ridicule from her peers and scrutiny from people who can now Google her, the family charged in the lawsuit."

The case raise some quite tricky questions about intellectual property, attribution, damage to reputation and privacy. I suspect it is one of those that will be settled out of court but worth watching.

Fashion and the piracy paradox

James Surowiecki has been applying his wisdom of crowds mind to intellectual property in the fashion industry.

"In 1932, a group of American fashion manufacturers found themselves beset by a proliferation of cheap knockoffs. Designs, then as now, were not protected by patents or copyrights, so the manufacturers decided to take direct action to stop the copying. They set up the Fashion Originators Guild of America to monitor retailers and keep track of original designs; if you look at vintage dresses from the thirties, you can find labels reading “A registered original design with Fashion Originators Guild.” Retailers selling knockoffs were “red-carded,” and guild members wouldn’t sell their merchandise to red-carded stores. This was unpopular with the retailers, but it seems to have put a damper on the copying. The only hitch in the plan was that it was illegal: in 1941, the Supreme Court ruled that the manufacturers’ arrangement violated antitrust law, and the knockoff artists stayed in business."

He (or at least two law professor's whose paper he's been reading) reckons that obsolescence in the industry only comes about through widespread copying which then provides an incentive for designers to produce the next big thing.

"More striking, a recent paper by the law professors Kal Raustiala and Christopher Sprigman suggests that weak intellectual-property rules, far from hurting the fashion industry, have instead been integral to its success. The professors call this effect “the piracy paradox.”

The paradox stems from the basic dilemma that underpins the economics of fashion: for the industry to keep growing, customers must like this year’s designs, but they must also become dissatisfied with them, so that they’ll buy next year’s."

Spy czar urges extension of warrantless-wiretap law

From News.com: Spy czar urges extension of warrantless-wiretap law

NYT drop subscription fees

The NYT are going to drop their subscription fees. It seems their bean counters have been doing some sums and figured out ad revenues from increased traffic to a 'free' site would be worth more than subscription fees.

Tuesday, September 18, 2007

WSJ on Microsoft's EU Waterloo

The Wall Street Journal folk are less than impressed that the EU court of first instance rejected Microsoft's appeal against the EU's antitrust ruling. (Full article only available to subscribers)

"The ruling by the European Union's second most powerful court was a judicial slam dunk for Brussels. The court upheld the European Commission's 2004 judgment that Microsoft had abused the dominance of its Windows operating system... and affirmed the record €497 million fine that Brussels levied on the company.

The decision was clear and emphatic... We can't think of anything else good to say about this outcome...

Microsoft's general counsel, Brad Smith, points out that Apple's iPod dominates the MP3 player market, in which Microsoft's Zune is the underdog, and that Google's search engine has whipped Microsoft's MSN and all other comers... Mr. Smith seems to be implying that two can play at this game of making "strategic complaints."

Firms that do so risk little of their own time, energy or money. Once it takes up a case, the Commission does the heavy lifting. The targeted companies incur huge costs to defend themselves. European regulators, and now judges, apparently believe that the proper venue for competition among technology companies is in the courtrooms rather than research labs. Everyone will be worse off, except, of course, lawyers."

Update: The EU Commissioner is not very happy with the DOJ for criticised the Microsoft decision in the EU Court of First Instance.

"A U.S. official's criticism of a European Union court ruling dismissing Microsoft's monopoly abuse appeal was "totally unacceptable," EU antitrust chief Neelie Kroes said Wednesday.

Kroes said it was wrong for a representative of the U.S. administration to criticize "an independent court of law outside its jurisdiction."

"The European Commission does not pass judgment on rulings by U.S. courts and we expect the same degree of respect from U.S. authorities on rulings by EU courts," she said. "It is absolutely not done.""

Volkswagen and the Nazi YouTube parody

According to Wired magazine, Volkswagen are having a legal dispute with YouTube.

"A legal spat between YouTube and Volkswagen is throwing light on the increasing copyright surveillance of social networking sites.

Volkswagen has filed a subpoena seeking the identity of a YouTube user who posted a Nazi-themed parody of a recent VW Golf commercial. Volkswagen's move underscores the privacy risks to a blossoming community of users on sites like YouTube and Yahoo Video, and social-networking sites like Facebook and MySpace."

Monday, September 17, 2007

Neglected diseases, differential pricing and drug patents

Nature had some interesting articles on incentives for development and distribution of and access to drugs for neglected diseases in a recent edition. See in particular:

Neglected Diseases: At what price? by Patricia M. Danzon

Neglected Diseases: The road to recovery by Carlos M. Morel et al

and

Neglected Diseases: Patent sense by Paul Herrling

Thanks to Thiru Balasubramaniam via the A2K list for the pointer.

Microsoft lose the latest round in EU

Microsoft has lost its appeal against the EU's antitrust ruling in the EU's court of first instance, right off the back of numerous US states requesting that the overseer of the company's US antitrust agreement extend her supervision of the company due to its approach to compliance on that side of the pond. Don't expect this to be the end of the story. Microsoft's lawyers are very smart.

Update: The FFII agree that Microsoft's lawyers are very smart:
The Foundation for a Free Information Infrastructure (FFII) says that Microsoft was expecting the 17 September verdict of the EU's anti-trust case, and will exploit software patents to keep its monopoly grip on the global IT market.

FFII president Pieter Hintjens explains, "The decision seems positive but it is five years out of date. During that time, Microsoft has lobbied for software patents in Europe and bought patents on many trivial concepts. It has claimed patent violations against Linux, put patent timebombs into its formats and interfaces, and turned fear of patents into a core part of its business strategy. It will now open its formats, because that lets it extend its software patent franchise even further."

EU Commission: UK failed to implement a third of the Data Protection Directive

Following the EU's investigation the UK's implementation of the data protection directive, the Commission has surprisingly expressed dissatisfaction with the UK approach to about a third of the Directive.

"The articles of the Directive which the Commission claims have not been implemented properly are articles 2, 3, 8, 10, 11, 12, 13, 22, 23, 25 and 28 – just under a third of the 34 articles in the Directive.

These Articles relate to: the definitions used in the Directive (e.g. the meaning of personal data); the scope of the Directive's application to manual files; the conditions when sensitive personal data can be processed; the fair processing notices give to individuals; the rights granted to data subjects; the application of exemptions from these rights; the ability of individuals to seek a remedy when there is a breach; the liability of organisations for breaches of data protection law; the transfer of personal data outside European Union; and the powers of the Information Commissioner.

Data Protection expert Dr Chris Pounder of Pinsent Masons, the law firm behind OUT-LAW.COM, said that the extent of the objections reflects official attitude towards data protection policy. "All UK Governments involved in implementing the Directive have had a policy of minimising the Data Protection Directive's effect," he said. "The number of problems raised by the Commission seem to indicate that the UK Government may have misjudged the situation and minimised the effect of too many obligations"."

Thanks to Glyn via ORG for the pointer. The UK government had until recently been keeping the details of the EU's complaints under wraps but it seems Out-Law got the information via a freedom of information request. It's a coincidence that the details should begin to emerge now since I had just posted a note about loopholes in privacy legislation to the ORG list in recent days :

"The idea that regulation is a cure for privacy problems is widely held but I don't subscribe to it.

The EU and its member states have mountains of privacy regulations. Frequently when these regulations come under pressure, such as with the EU-US safe harbour provisions for transfer of personal data or the PNR agreement with the US, they buckle. In addition there are numerous loopholes that dedicated privacy regulation evaders can drive a coach and horses through. Even where the loopholes don't apply and in the face of the efforts of people like the Information Commissioner to explain the dangers and sound legal opinions to the effect that they will breach existing privacy regulations, the government still push through ID cards, the Children's Index database ContactPoint, data retention and an unending stream of terror, crime, immigration and other laws and regulations that undermine current protections (at best, though some would argue they destroy the existing protections completely).

Privacy is a complex issue and can't be addressed through regulation alone any more than complex systemic messes like terrorism or immigration can be solved by regulation (and imagined magical computer systems that keep everyone under surveillance then point out the
baddies) alone. Privacy levels and awareness are an emergent property of a whole series of complicated interracting and dynamic factors, relating to social, psychological, market, environmental, technological (in the Lessig architectural sense or possibly more accurately in the Kim Cameron/ Stefan Brands/ Caspar Bowden/ Ben Laurie/ etc. architectural sense) prevailing winds (and I'm sure members of the list can think of many more).


Apologies for the rant."

MediaDefender Internal Emails leaked on BitTorrent

From TorrentFreak:

"When we reported in July that an Anti-Piracy Gang Launches their own Video Download Site to Trap People and that the company was called Media Defender and, as anyone who aims to be a credible news resource would, we checked and double checked our sources. We said, with some confidence:

Media Defender, a notorious anti piracy gang working for the MPAA, RIAA and several independent media production companies, just launched their very own video upload service called “miivi.com”. The sole purpose of the site is to trap people into uploading copyrighted material, and bust them for doing so.

However, in comments made to Ars technica, Media Defender’s Randy Saaf chose to rubbish our claims, calling it an ‘accidentally un-secured internal project’.

From the emails we cannot be sure that it’s an entrapment site or that it is related to the MPAA (perhaps it’s a legit a P2P video client?), but it does look suspicious.

Unfortunately for Media Defender - a company dedicated to mitigating the effects of internet leaks - they can do nothing about being the subject of the biggest BitTorrent leak of all time. Over 700mb of their own internal emails, dating back over 6 months have been leaked to the internet in what will be a devastating blow to the company. Many are very recent, having September 2007 dates and the majority involve the most senior people in the company. Apparently this is not the first time that a MediaDefender email leaked onto the Internet."

Interesting insight into the kind of tactics being used by the entertainment industry to combat online copying and distribution of their wares. It also raises loads of interesting legal questions. If this one is genuine, for example:

"Dylan,

Another thing we can do to increase Google and other search engine traffic is to get more link-ins. At the next MiiVi meeting, I’m going to ask Randy for permission to incentivize people to link-in a MiiVi video on their MySpace. Colin is already doing this and it helps the word-of-mouth spread, even if the link-ins are nominal. I’m not sure what we could do in the link-in regard early on, but getting the cumulative ~1000+ MySpace friends of MediaDefender employees to see MiiVi link-ins can’t hurt….

Colin — start coming up with a list the list of keywords and descriptors for hidden metadata entries, per Dylan’s e-mail below.

Thanks,
Ben"

Wouldn't it amount to entrapment? It certainly suggests a honeypot at least, which MediaDefender has apparently denied. The very Mr Randy Saaf who made the denials though has apparently been actively trying to hide teh company's connection with the honeypot site.

"From: Randy Saaf
Sent: Wed 6/13/2007 12:54 AM
To: Colin Keller
Cc: Ben Grodsky; Steve Lyons; Jay Mairs
Subject: miivi emails

Colin:

Set up your email so that you always reply with a ckeller@miivi.com, dmca@miivi.com, or an info@miivi.com address respectively. I don’t want MediaDefender anywhere in your email replies to people contacting Miivi. Steve and Ben can help you set up your email for this. Make sure MediaDefender can not be seen in any of the hidden email data crap that smart people can look in.

I am setting up ckeller@miivi.com to forward to ckeller@mediadefender.com.

R"

This one could run for a while.

Thursday, September 13, 2007

Jack Goldsmith on 'The Terror Presidency'

NPR has a remarkable interview (accessible here) with Jack Goldsmith on some controversial events and processes in the Bush administration during his tenure as the Department of Justice's Office of Legal Counsel.

No checks and balances in the US in time of war

Jack Balkan says:

"The sad lesson of the past year is that the modern Presidency-- armed with control over military intelligence and a large standing army-- can have its way in matters of war even if the President's policies are very unpopular, and there is very little Congress can do to stop it.

This lesson should be abstracted from one's feelings about the current occupant of the White House. George W. Bush is a failure-- I won't mince words-- but even a failed President can do pretty much what he wants in war given the way our constitutional system has developed following the Second World War and the rise of the National Security State. The ascendant National Surveillance State, if anything, makes the President's hand even stronger.

We are moving, or more correctly, we have already moved, toward a system of one person rule on matters of war and peace. It is a very dangerous tendency in American constitutionalism. If you think that the Iraq episode has been a disaster, imagine an even more foolhardy and reckless President taking even greater and more dangerous risks. The Iraq war demonstrates that, in the context of modern politics and contemporary security threats, the framers' original system of checks and balances has utterly failed us."

Educators are on the wrong side of the copyright wars

In my nose-to-the-grindstone-administrative-box-ticking frenzy of recent weeks I failed to notice this piece in Reason magazine putting forward the theory that Educators are on the wrong side of the copyright wars

"Last month, the U.S. Senate passed legislation enlisting colleges in the effort to police peer-to-peer networks and file-sharing, in order to prevent "piracy" by students of music, movies, and for that matter, books.

One might wonder exactly why Senate Majority Leader Harry Reid—who introduced the amendment to the Higher Education Reauthorization Act, then tempered it when there was an outcry from college administrators—is concerned about campus file sharing, other than a general commitment to fight crime. A cynic might suggest the entertainment industry's considerable patronage of the Democratic Party.

According to The Chronicle of Higher Education, Reid's measure "called on the Recording Industry Association of America and the Motion Picture Association of America to draft annual lists of the 25 colleges receiving the most notices of copyright infringement. Those colleges would face a choice: Either use technological tools to block peer-to-peer file sharing, or risk forfeiting federal student aid.In other words, colleges would be put under the supervision of the RIAA and MPAA...

But this is a particularly egregious case because it enforces rules that are specifically inimical to education, and that run contrary the fundamental mission of a college or university—the sharing of information...the very essence of a university ought to place it in fierce opposition to demands that it police its students for the excessive sharing of information. On the contrary, colleges and universities ought to be working toward an environment in which information can be shared with more freedom."

Safe harbours for Internet intermediaries

Mark Lemley has written a fascinating paper on the patchwork of safety nets available to Internet intermediaries like telcos and ISPs to avoid liablity for the dodgy behaviour of their subscribers or remotely linked, with or without knowledge and aforethought, associates.

Abstract:

"Internet intermediaries - service providers, Web hosting companies, Internet backbone providers, online marketplaces, and search engines - process hundreds of millions of data transfers every day, and host or link to literally tens of billions of items of third party content.

Some of this content is illegal. In the last 12 years, both Congress and the courts have concluded that Internet intermediaries should not be liable for a wide range of content posted or sent through their systems by another. The reasoning behind these immunities is impeccable: if Internet intermediaries were liable every time someone posted problematic content on the Internet, the resulting threat of liability and effort at rights clearance would debilitate the Internet.

While the logic of some sort of safe harbor for Internet intermediaries is clear, the actual content of those safe harbors is not. Rather, the safe harbors actually in place are a confusing and illogical patchwork. For some claims, the safe harbors are absolute. For others, they preclude damages liability but not injunctive relief. For still others they are dependent on the implementation of a �notice and takedown� system. And for at least a few types of claims, there is no safe harbor at all. This patchwork makes no sense. In this article, I suggest that it be replaced with a uniform safe harbor rule. A single, rationally designed safe harbor based on the trademark model would not only permit plaintiffs the relief they need while protecting Internet intermediaries from unreasonable liability, but would also serve as a much needed model for the rest of the world, which has yet to understand the importance of intermediaries to a vibrant Internet."

Thanks to Derek Slater for the link.

Where are the UK's public intellectuals?

The Vice Chancellor of Buckingham University, Terence Keakey, has been lamenting the negative and distorted incentives generated by the 'Research Assessment Exercise' (which most people outside the higher education sector will be blissfully oblivious to) and its impact on the funding of universities.

"The Research Assessment Exercise is killing British universities as centres of public thought. Once, British universities fostered some of the most important public intellectuals in the world, but today British academics are rarely known outside their disciplines.The most influential living intellectual in the world is Noam Chomsky; in 2005, the readers of the British magazine Prospect voted him precisely that...

He made the leap from brilliant researcher to public intellectual exactly 40 years ago, in 1967, when he published his essay "The Responsibility of Intellectuals" in the New York Review of Books. That responsibility, Chomsky wrote, is to "expose the lies of government". Chomsky places that responsibility on his fellow academics...

Over the past 40 years, Chomsky has campaigned against American foreign policy, but it has been primarily as an academic that he has made his impact, showing by careful scholarship that American foreign policy is institutionally dishonest...

...today most people know that everything George Bush says is untrue...

MIT's support for Chomsky has been solid: even when it was receiving 80 per cent of its research income from the Department of Defense, Chomsky could launch his jeremiads without internal criticism.

But MIT is an independent university, and there is no RAE in America. Consequently, MIT's physics department can process as many defence grants as it wants, but the linguistics department, where Chomsky works, is free from governmental pressure...

The President of MIT answers solely to the trustees, who are alumni, donors, and proud of MIT's academic independence. But the real master – and paymaster – of a British vice-chancellor is the Government. Of course a troublesome Chomsky in Britain would be discouraged...

If our universities are to reassume their proper role of speaking truth unto power, they will have to value scholarship and public engagement as strongly as they now value research. We should, as a first step, ditch the RAE and identify proper funds and proper incentives for leisure and thought at work."

On the positive side he has a point about the paymaster dictating the agenda, which doesn't fit too comfortably with he role of the academic to explore truths (rather than expose lies). Though a campaign to facilitate leisure time (by which he really means scholarship and thinking time) for academics is unlikely to win too many advocates in modern media circles; and I suspect his satirical claim that everything George Bush says is false may well be taken out of context should anyone in Whitehall or Washington come across this call for a change to university funding structures.

Latest EDRI-Gram

The latests EDRI-Gram is available. Some highlights (see original for links):

The European Court of Human Rights could influence the UK DNA database
12 September, 2007 » Privacy | Biometrics


Sir Stephen Sedley has recently proposed the enlargement of the DNA database in UK to cover the entire population and visitors that stay in UK even for a week, under the argument of creating a fairer system and eliminating the ethnical unbalance in the present database. But a case brought by 2 English people to the European Court of Human Rights (ECHR) could change a lot in how the database will operate.

The UK DNA database is one of the largest in the world covering data from everybody having had anything to do with any crime, minor or major, guilty or not. According to Sadley, the database is biased against ethnic minorities. "It means where there is ethnic profiling going on disproportionate numbers of ethnic minorities get onto the database. It also means that a great many people who are walking the streets and whose DNA would show them guilty of crimes, go free."

The proposal met opposition from the Prime Minister who believes that would raise civil liberties concerns but also complicated logistical issues.

Shami Chakrabarti, director of human rights organization Liberty, also said that a database for everybody in the country was "a chilling proposal, ripe for indignity, error and abuse".

The present UK DNA database is already raising issues related to the way people's data are included in it. Shadow home secretary David Davis considers the system is arbitrary and erratic. The highest concern is related to the fact that the data of people proven innocent cannot be removed from the database. And this is exactly what has triggered a case at the ECHR, that could change the whole situation.

The case was brought in front of ECHR by Michael Marper and a teenager, known as S, both arrested in 2001, the former on harassment charges and the latter with attempted robbery. They were both cleared and with no criminal records. In 2002 they required their data to be removed from the Home Office database but the Court of Appeal ruled against it. Among the appeal judges that heard the case was Sir Stephen Sedley that proposed a "universal DNA database" even in that judgment.

Mr Marper and the juvenile argued that keeping their fingerprints and DNA samples was an infringement of their private life rights as per Article 8 of the European Convention on Human Rights. Their concern is related mostly to the possible future misuse of their data.

The situation seems to be now in the hands of ECHR. A ruling by ECHR against the British Government could not only stop Lord Justice's proposal to enlarge the DNA database but also lead to the destruction of the DNA and fingerprint evidence of people that have been found innocent. The case is considered important by the judges in Strasbourg as they have sent the case before the grand chamber, because it raises a serious problem affecting the interpretation of the European Convention on Human Rights.

"This decision by the European Court of Human Rights gives us significant hope that these cases will finally result in a massive change in the law - providing protection for those acquitted of crimes against their fingerprints and DNA samples being kept, putting them on a level footing with those not previously accused of any crimes (...) We think this will be one of the most important human rights challenges the court has grappled with in recent years" stated Peter Mahy, a civil liberties specialist at Sheffield-based Howells who represent Marper and "S".

All UK 'must be on DNA database' (5.09.2007)
http://news.bbc.co.uk/1/hi/uk/6979138.stm

Plan to put everyone in DNA database hinges on human rights case (7.09.2007)
http://www.out-law.com//default.aspx?page=8455

Europe to rule on whether police can keep DNA of innocent people (8.09.2007)
http://news.independent.co.uk/uk/legal/article2941849.ece

EDRI-gram : UK Home Office plans to fingerprint children starting 11 (14.03.2007)
http://www.edri.org/edrigram/number5.5/uk-fingerprint-children
previous

US gains new advantages in the EU-USA PNR agreement
12 September, 2007 » Airline Passenger Data

In some recently published documents, Statewatch revealed that very soon after the EU-USA agreement on PNR (passenger name record) was signed on 28 June 2007, the US government announced some changes in its Privacy Act that give exemptions from responding to request for personal information held to DHS (Department of Homeland Security) and ATS (Automated Targeting System). US Government also sent a written request to the Council of EU to agree on keeping secret all the documents on the negotiations for at least 10 years.

The declared purpose of the above-mentioned exemptions is for "national security, law enforcement, immigration and intelligence activities. These exemptions are needed to protect information relating to DHS investigatory and enforcement activities from disclosure to subjects or others related to these activities (....) Disclosure of information to the subject of an inquiry could also permit the subject to avoid detection or apprehension."

The exemptions are related to the new "Arrival and Departure System" (ADIS) that the USA is to introduce and which is meant to authorise people to travel only after PNR and API (Advance Passenger Information) data has been checked and cleared by US agency watchlists: "ADIS consists of centralized computerized records for and will be used by DHS and its components. .. The information is collected by, on behalf of, in support of, or in cooperation with DHS and its components and may contain personally identifiable information collected by other Federal, state, local, tribal, foreign, or international government agencies."

The Automated Targeting System, that is to be exempted as well, is a system of 6 modules of dealing with Passenger Name Record (PNR) data.

The exemptions seem to be meant to counterbalance "the set backs" for the US government in the EU-US PNR agreement signed in June. In the text of the agreement it is stated that DHS has taken the decision "to extend administrative Privacy Act protections to PNR data stored in the ATS regardless of the nationality or country of residence of the data subject, including data that relates to European citizens. Consistent with U.S. law, DHS also maintains a system accessible by individuals, regardless of their nationality or country of residence, for providing redress to persons seeking information about or correction of PNR."

The exemptions introduced now contradict this statement, as also notice Tony Bunyan, Statewatch editor : "The adoption of these two exemptions will seriously diminish any rights EU citizens have to find out what data is held on them and who it is held by. Did the Council and the Commission, who negotiated the agreement, know the US was planning to introduce them, and if not why not?"

Another measure taken by the US Government related to the agreement signed in June is one regarding the confidentiality of the negotiations that led to signing the act. On 30 July 2007, Mr Paul Rosenzweig, Acting Assistant Secretary for Policy at the US Department for Homeland Security sent a written request to the Council of European Union to agree on keeping secret all the documents on the negotiations for at least 10 years after the entering into force of the agreement.

EU's Article 29 Data Protection Working Party issued on 17 August an opinion on the new EU-USA PNR agreement concluding that it sensibly weakened the safeguards provided by the previous agreement and that "the new agreement leaves open serious questions and shortcomings, and contains too many emergency exceptions."

"Yet again we see the USA telling the EU what to do. In this case how it should operate the EU Regulation on access to documents. How can any request for PNR documents be fairly considered under EU law when it has already agreed to exercise a US veto? Are we going to see documents for all future EU-US agreements kept secret too? US access to PNR data and its further processing is an issue of substantial public interest which directly effects the rights and privacy of EU citizens and therefore all the documentation should be in the public domain for parliaments and people to see and discuss. It is a quite outrageous request and it is even more outrageous that the EU is going to agree to it" commented Tony Bunyan, Statewatch editor.

US changes the privacy rules to exemption access to personal data (4.09.2007)
http://www.statewatch.org/news/2007/sep/04eu-usa-pnr-exemptions.htm

US demands 10 year ban on access to PNR documents (2.09.2007)
http://www.statewatch.org/news/2007/sep/02eu-usa-pnr-secret.htm

Proposed Rules, Federal Register - DHS, 6 CFR Part 5, Privacy Act of 1974: Implementation of Exemptions (22.08.2007)
http://www.statewatch.org/news/2007/aug/usa-adis-privacy-act-exemption...
http://www.statewatch.org/news/2007/aug/usa-ats-exemptions-privacy-act...

Article 29 Data Protection Working Part - Opinion 5/2007 on the follow-up agreement between the European Union and the United States of America on the processing and transfer of passenger name record (PNR) data by air carriers to the United States Department of Homeland Security concluded in July 2007 (17.08.2007)
http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2007/wp138_en...

EDRI-gram: Final agreements between EU and USA on PNR and SWIFT (4.07.2007)
http://www.edri.org/edrigram/number5.13/eu-us-pnr-swift

Wednesday, September 12, 2007

NTP roll out the patent lawyers again

From Reuters:

"NTP Inc, which last year won a $612.5 million settlement from the maker of Blackberry, has sued four of the top U.S. mobile service providers for infringing eight patents related to wireless e-mail.

The lawsuits, against Verizon Wireless, Sprint Nextel Corp (S.N: Quote, Profile , Research), T-Mobile USA and the mobile unit of AT&T Inc (T.N: Quote, Profile , Research) were filed September 7 in the U.S. District Court for the Eastern District of Virginia, according to court documents."

A rare courtroom win for the tinkerers

The EFF have succeeded in blocking DirecTV's broadsweep legal tactics at least in the case of a couple of security researchers.

"In an important ruling today, the 9th U.S. Circuit Court of Appeals blocked satellite television provider DirecTV's heavy-handed legal tactics and protected security and computer science research into satellite and smart card technology after hearing argument from the Electronic Frontier Foundation (EFF).

The cases, DirecTV v. Huynh and DirecTV v. Oliver, involved a provision of federal law prohibiting the "assembly" or "modification" of equipment designed to intercept satellite signals. DirecTV maintained that the provision should cover anyone who works with equipment designed for interception of their signals, regardless of their motivation or whether any interception occurs. But in a hearing earlier this year, EFF argued that the provision should apply only to entities that facilitate illegal interception by other people and not to those who simply tinker or use the equipment, such as researchers and others working to further scientific knowledge of the devices at issue.

"Congress never meant this law to be used as a hammer on those who use or tinker with new technologies," said EFF Senior Staff Attorney Jason Schultz. "We're pleased the court recognized that researchers need to be protected."

These cases were part of DirecTV's nationwide legal campaign against hundreds of thousands of individuals, claiming that they were illegally intercepting its satellite TV signal simply because they had purchased smart card technology. Because DirecTV made little effort to distinguish legal uses of smart card technology from illegal ones, EFF has worked to limit the lawsuits to only those cases where DirecTV has proof that their signals were illegally received."

Tuesday, September 11, 2007

PETs so last century

From the ever thoughtful blogging on the identity trail comes an interesting essay on privacy enhancing technologies (PETs) from a privacy advocate.

"In May the European Commission endorsed the development and deployment of PETs(1), in order to help “ensure that certain breaches of data protection rules, resulting in invasions of fundamental rights including privacy, could be avoided because they would become technologically more difficult to carry out.” The UK Information Commissioner issued similar guidance on PETs in November 2006(2)...

Are PETs the answer to information privacy concerns? A closer look at the European and UK communiqués suggests otherwise - for all their timeliness and prominence, they reflect thinking about PETs that is becoming outdated. The reports cite, as examples of PETs, technologies such personal encryption tools for files and communications, cookie cutters, anonymous proxies and P3P (a privacy negotiation protocol). Not a single new privacy-enhancing technology category here in seven years...

Unfortunately, few of the privacy-enhancing tools cited by advocates have enjoyed widespread public adoption or viability (unless installed and activated by default on users’ computers, e.g. SSL and Windows firewalls). The reasons are several and varied: PETs are too complicated, too unreliable, untrusted, expensive or simply not feasible to use. The threat model they respond to, and benefits they offer, are not always clear or measurable to users. PETs may interfere with normal operation of computer applications and communications, for example, they can render web pages non-functional...

Perhaps the underlying difficulty may be a conceptualization of PETs as a technology, tool or application exclusively for use by individuals, complete in itself, expressed perhaps in its purest form by David Chaum’s digital cash Stefan Brands' private credentials. As brilliant as those ideas are, they have had limited deployment and viability to date. It seems that, to be viable, PETs must be also meet specific, recognizable needs of organizations...

A more comprehensive approach to defining and using PETs is required - one that clearly accommodates the interests and rights of individuals in a substantial way, yet which can be adopted or at least accommodated by organizations with whom individuals must inevitably deal. This requires a more systemic, process-oriented, life-cycle, and architectural approach to engineering privacy into information technologies and systems.

PETs as we know them are effectively dead, reduced to a niche market for paranoids and criminals, claimed by some security products (e.g., two-factor authentication dongles) or else deployed by organizations as a public relations exercise to assuage specific customer fears and to build brand confidence (e.g. banks' anti-phishing tools, web seals)."

Domain name outlaw faces 20 years

From NetworkWorld: "A Las Vegas man faces about 20 years in prison today after he agreed to plead guilty to wire fraud for impersonating an intellectual property lawyer and threatening lawsuits against the owners of Internet domain names."

US travellor data to be kept for 15 years not 40

From the AP:

"Rejecting a wave of criticisms, the U.S. government has agreed to only modest changes in the computerized system that assesses whether each American who travels abroad poses a terrorist threat.

The Homeland Security Department decided to keep the risk assessments for 15 years instead of 40 years and no longer will share them with federal, state and local officials who are deciding whether a person gets a job, a security clearance, a license to do business or a government contract.

Nevertheless, travelers still will not be allowed to see their actual assessments or the reasons for them. Federal agents still will be looking at an array of information about international travelers - Americans and foreigners; this includes even meal choices, the names of traveling companions and the number of hotel beds requested."

Monday, September 10, 2007

OpenID

Simon Willison gave an interesting keynote presentation on OpenID at Pycon UK 2007 in recent days. His slides are available at SlideShare.

In addition Kim Cameron and Ben Laurie had a really interesting debate about open ID and CardSpace over the summer, which I must have another look at.

Entertaining physics

I highly recommend Professor Walter Lewin's lectures on physics available at MIT's opencourseware.

The work of a wonderful teacher available at the click of a mouse.

ECHR to look at keeping DNA of innocents

The Independent reports this morning that judges in the European Court of Human Rights are to consider the retention by police of the DNA of suspects who subsequently acquitted or not charged of a crime.

"Police could lose the power to keep DNA samples taken from suspects who have been cleared of any wrongdoing, in a landmark case which is to be decided by the highest court in Europe.

A ruling against the British Government could lead to the destruction of tens of thousands of DNA and fingerprint materials as well as deal a severe blow to any plans to create a universal genetic database.

The challenge at the European Court of Human Rights is being brought by a teenager, known as S, who was arrested and charged with attempted robbery aged 11 in 2001, and Michael Marper, from Sheffield, who was arrested on harassment charges, aged 38, in the same year. Both were cleared and have no criminal records...

European judges in Strasbourg believe the issue is so important that they have decided to fast-track the case to go before the grand chamber, where all the Strasbourg justices will sit to determine the matter.

The decision has been taken because the court decided that the case raises a serious question affecting the interpretation of the European Convention on Human Rights or because its resolution might have a result inconsistent with a previous judgment of the court."

In the light of previous calls by Tony Blair, Gordon Brown and other members of the Nu Labour government and just last week a similar call from a respected law lord for the expansion of the DNA database, it is good to see the ECHR stepping in to assess the substantive issues. It's a case to be watched very closely, though whatever the outcome it will, sadly, be hyped up as a massive defeat or victory for the government.

More Apple digital locks

One of the reasons I've never been a big Apple fan is their heavy-handed proprietary approach to their technologies. I tell the story in my book about Apple's spat in 2004 with RealNetworks, when the Real folks made it possible for iPod owners to buy music from the Real music store in addition to the sole existing prior source, iTunes. Apple went nuts accusing Real of hacking into the iPod and threatening all kinds of lawsuits. Then they upgraded their software so that iPod owners couldn't buy songs from Real. Real upgraded theirs and so the tit for tat went on.

Fast forward three years and the same story is being played out on iPhone ringtones. Fred von Lohmann has a lovely succinct description of the latest idiocy.

"Apple's new product announcements this week may have laid the foundation for the next round of DMCA lawsuits. It sure looks like Apple is using the DMCA to block competition, rather than stop "piracy."

First suspect: ringtones on the iPhone. Just before the Apple announcement of its new ringtone offerings (that'll be 99 extra cents, please), Ambrosia had announced iToner, a new piece of software that allows iPhone owners to use any MP3 or AAC file as a ringtone. In other words, no more need to pay Apple for the privilege.

Apple's response? Well, apparently the latest "upgrade" to Apple's iTunes software (v. 7.4) auto-magically erases any unapproved ringtones that iToner installs...

Second suspect: locking the iPod video output. iLounge reports that the latest generation of iPods refuses to output video to cables, docks, and accessories that lack an Apple "authentication chip." If this is true, then it may represent an attempt by Apple to use the DMCA to limit competition and interoperability, in a manner reminiscent of Lexmark's printer toner cartridge lock-out chip or the infamous DMCA garage-door opener case...

Notice that neither of these Apple "lock-in" measures has any obvious relationship with preventing "piracy." As we've been saying for years, this appears to be the real legacy of the DMCA -- even as the music industry abandons DRM as an anti-piracy measure, Apple deploys it as an anti-competition measure."

Update: Derek Slater's thoughts on same are worth reading. As are those at the ipodminusitunes blog

Federal Judge in blistering critique of Congress over Patriot Act

From the AP via Findlaw: Federal judge strikes down part of Patriot Act in blistering criticism of Congress

"A federal judge struck down a key part of America's top anti-terror laws in a ruling that defended judicial oversight and bashed Congress for passing a law that makes possible "far-reaching invasions of liberty."...

He said Congress, in the original USA Patriot Act and less so in a 2005 revision, had essentially tried to legislate how the judiciary must review challenges to the law. If done to other bills, they ultimately could all "be styled to make the validation of the law foolproof."...

Regarding the national security letters, he said, Congress crossed its boundaries so dramatically that to let the law stand might turn an innocent legislative step into "the legislative equivalent of breaking and entering, with an ominous free pass to the hijacking of constitutional values."

He said the ruling does not mean the FBI must obtain the approval of a court prior to ordering records be turned over, but rather must justify to a court the need for secrecy if the orders will last longer than a reasonable and brief period of time."

Update: Jack Balkan's thoughts on the decision as ever are well worth perusing.

Little Britain, Catherine Tate, the lawyers and the evangelicals

Apparently an evangelical church publishing group has been using catchphrases from popular BBC shows on it's recruitment posters and m'learned friends are not amused. The church group has withdrawn the posters. Naturally the Sun headlines the story: Little Brit catchphrases stolen The Star goes with How Very Dare You. And the rest of the pack don't seem to have picked up on it.

Wednesday, September 05, 2007

ISO panel reject proposed Microsoft standard

Here's the NYT report on the ISO panel rejecting Microsoft's efforts to have its open document format adopted as an international standard.

BMA call to halt e-record roll out

From William Heath: BMA call to halt e-record roll out

"An open letter to government from the doctor's association wants a stop to the roll out of summary care records until a review has taken place

The British Medical Association's (BMA) chair, Dr Hamish Meldrum, has called for a halt to further implementation of the NHS summary care record, beyond six early adopter sites, until an independent review has been completed.

In a letter to Ben Bradshaw, the minister responsible for the National Programme for IT (NPfIT), Dr Meldrum says that at a recent BMA meeting, doctors from primary and secondary care expressed their frustration with the programme and want a public enquiry to address problems."

Good for them.

Law Lord wants everyone on the DNA database

One of the Law Lords, Lord Justice Sedley, has called for everyone's DNA to be put on the national DNA database because the current collection of data is discriminatory.

"The present database in England and Wales holds details of 4m people who are guilty or cleared of a crime.

Lord Justice Sedley said this was indefensible and biased against ethnic minorities, and it would be fairer to include everyone, guilty or innocent."

This is the standard 'treat everyone the equally by treating them all badly' argument and it is disappointing to hear it from someone who should know better. The usual Schneier needles in data haystacks warnings naturally apply.

Monday, September 03, 2007

The Biometric Dilemma

From Kim Cameron:

"Vision researcher Terrence E. Boult has identified what he calls the “Biometric dilemma” - the more we use biometrics the more likely they will be compromised and hence become useless for security.

This is a hugely important observation - the necessary starting point for all thinking about biometrics. I’d even call it a law.

Terrence was responding to a piece by Sean Convery that picked up on my post about reversing biometric templates. Terrence went on to call our attention to more recent work, including some that details the reversibility of fingerprint templates."

Friday, August 31, 2007

Legal or Not, IPhone Hacks Might Spur Revolution

Jennifer Granick writing in Wired has offered her perpective on the iPhone "hacking" controversy i.e. techies breaking through the proprietary digital locks to enable iPhone owners to use their expensive gadgets with providers other than AT&T.

"The iPhone's fantastic user interface is inspiring another consumer-electronics revolution: making people care about cell-phone unlocking. After my clients' long, successful battle before the U.S. Copyright Office to exempt phone unlocking from the anti-circumvention provisions of the Digital Millennium Copyright Act, have iPhone customers won the freedom to tinker with their cool new handsets? The answer, unfortunately, is that we still don't know.

In the past week, New Jersey teenager George Hotz published instructions for unlocking the iPhone. Meanwhile an anonymous group called iPhoneSimFree plans to sell its software-only solution, and a company called UniquePhones is set to sell a remote unlocking service. These offers generated buzz from iPhone owners, who are restricted -- by technological locks built into the GSM-based handset -- to using the AT&T wireless network. On Monday, some buzz circulated from AT&T lawyers trying to shut down the distribution of unlocking software. Does AT&T have a leg to stand on?...

We won an exemption in November of 2006 that allows you to circumvent digital locks (.pdf) in order to access "computer programs in the form of firmware that enable wireless telephone handsets to connect to a wireless telephone communication network, when circumvention is accomplished for the sole purpose of lawfully connecting to a wireless telephone communication network."

Despite this success, the exemption does not offer blanket protection for phone unlocking, though the practice might be legal for other reasons. The problem is that the exemption protects unlockers, but it doesn't apply to those entities that distribute unlocking tools or provide unlocking services to others."

Ed Felten has some thoughts on the controversy too.

"Can AT&T cook up a legal theory justifying a ban on iPhone unlocking? I’ll leave that question to the lawyers. It seems to me, though, that regardless of what the law does say, it ought to say that iPhone unlocking is fine. For starters, the law should hesitate to micromanage what people do with the devices they own. If you want to run different software on your phone, or if you want to use one cell provider rather than another, why should the government interfere?

I’ll grant that AT&T would prefer that you buy their service. Exxon would prefer that you be required to buy gasoline from them, but the government (rightly) doesn’t try to stop you from filling up elsewhere. The question is not what benefits AT&T or Exxon, but what benefits society as a whole. And the strong presumption is that letting the free market operate — letting customers decide which product to buy — is the best and most efficient policy."

With Gonzales gone is it time to probe the war on terror policies

Edward Lazarus thinks that, now that Attorney General Alberto Gonzales has resigned, it is time for the US to have a wide public debate about the Bush administration's policies relating to the 'war on terror'.

"It's been inevitable for quite a while, and now it has finally happened: Attorney General Alberto Gonzales has abandoned his bedraggled rear-guard action and resigned his post. It is not hard to sum up Gonzales's legacy at the Department of Justice: He leaves behind a shattered agency - a corps of loyal career public servants who were forced to choose between opting out of their life's work, and watching helplessly as Gonzales (and other top officials) consistently chose loyalty to the President and partisan advantage over professionalism and even-handed enforcement of the law...

Now that Gonzales has joined the merry ranks of Bushies abruptly deciding to attend more closely to family concerns... There are three obvious items on the agenda: the pending investigations, the goal of re-invigorating DOJ, and the debate over the questionable legal theories underlying the Bush Administration's approach to the war on terror (policies that DOJ, under both Ashcroft and Gonzales, rationalized and implemented). All of these issues are important, but none, in my view, is as important at this particular moment than the last."

Wednesday, August 29, 2007

Polaris sues Amazon, Google and others

From the NYT:

"Maybe they haven’t sued the whole Internet, just a good chunk of it. Polaris IP, a patent firm, has filed a patent infringement suit against Google, Yahoo, Amazon.com, A9.com, Borders, AOL and IAC/InterActiveCorp, which owns Ask.com.

Polaris is the owner of United States Patent No. 6,411,947, for an “Automatic Message Interpretation and Routing System.” It is not entirely clear what the patent covers or how Google, Yahoo, et. al. infringed on it. "

Tuesday, August 28, 2007

Microsoft, Yahoo! deal with Chinese

Microsoft and Yahoo have signed a deal with the Chinese government to encourage "the big name web players to record the identities of bloggers and censor content. So says Reporters Without Borders, an organization that fights for journalistic rights across the globe."

Dan Rather on evoting

Dan Rather recently broadcast a programme on evoting. Worth watching - a nice accessible introduction to the problems with electronic voting. He opens with the Sarsota county debacle in Florida in 2006, the results of which are still being challenged by the losing candidate, Christine Jennings.

Sunday, August 26, 2007

Convicted Bittorrent admin must use Windows

A linux user convicted and jailed for criminal copyright offences via BitTorrent is, following his release from jail, obliged to install Windows so that the probation department can monitor his computer use. The probation depatment's monitoring software is incompatible with linux. Thanks to Becky Hogge at ORG for the pointer.