Saturday, December 15, 2007

Mark Thomas wants Gordon Brown jailed for demonstrating in Parliament Square

Mark Thomas wants help to put Gordon Brown in jail, for breaking his own law against demonstrating in Partliament Square. In fairness, though, I guess it was his predecessor who insisted on rushing the Serious Organised Crime and Police Act through parliament in 2005 because he was fed up with Brian Haw shouting at him through a megaphone from Parliament Square (See Taking Liberties Since 1997, starting at page 36 for a nice description of the story).

"If MPs pass ridiculous laws to limit our freedom, they should be forced to abide by them too

Mark Thomas
Thursday December 13, 2007
The Guardian


Rarely do first lines have the potential to cost thousands of pounds (outside of libel), and rarely do I get to write words quite like those that follow; so forgive me an over-dramatic opening sentence, but yesterday lawyers acting for me started an attempt to get Gordon Brown into the dock.

With lawyers and police working on the ongoing Donorgate inquiries, Downing Street can be quite crowded if you are trying to bring a legal action. Nonetheless, my lawyers delivered a letter to the director of public prosecutions yesterday afternoon calling for an urgent investigation into allegations that the prime minister broke the law by demonstrating unlawfully in Parliament Square last summer. If found guilty he could face 50 weeks in prison - though, after serving 10 years at No 11, he should do his bird with ease."



I do like his brand of serious humour.

Friday, December 14, 2007

Breaking the secrecy of the voting booth

Thanks to Glyn via the ORG list for the pointer to this YouTube video by Ron Gongrijp and co.:



After nearly 20 years of using computing machines, a TV programme just before the elections last year finally brought home the problems with evoting to the masses. The Dutch have now abandoned computer based voting, at least for the time being.

"On September 27, 2007 the Election Process Advisory Commission issued its 'Voting with confidence' report. The State Secretary for the Interior immediately announced that the 'Regulation for approval of voting machines 1997' will be withdrawn. On October 1, 2007 the District Court of Amsterdam decertified all Nedap voting computers currently in use in The Netherlands. The court order is a result of an administrative law procedure started by 'We do not trust voting computers' in March 2007. On October 21, 2007 the 'Regulation for approval of voting machines 1997' was finally withdrawn.

Elections in the Netherlands will be held using paper ballots and red pencil for a while. After that, we will likely be using 'vote printers' and separate counting machines."

Pity Bertie Ahern won't take the hint.

Data on 160,000 children lost by London hospital

I'm fairly sure these kinds of data losses are not new but in the wake of the HMRC debacle they have become temporarily newsworthy. The latest, via Ideal Government. I hope Ruth Kennedy won't mind me quoting her in full:

"That-paper-which-now-looks-really-heavyweight-in-comparison-to-all -the-freebie-showbiz-gossip-rags reports tonight that the personal details of 160,000 children have been lost at a London hospital in a fresh blunder over confidential information.

A computer disc containing the data was sent to St Leonard’s Hospital in Hackney but failed to reach the right department - even though it was signed for by hospital staff. The disc contained the names, dates of birth and addresses of 160,000 children and there were fears the information could be enough for criminals to create fake identities. The blunder occurred when the disc was sent by courier to the Hackney hospital by BT, which operates the NHS’s IT system, on 14 November. It is believed the courier company used by BT did not check that it was signed for by the correct person and the disc never reached its intended destination in the IT department.

A spokeswoman for City and Hackney Primary Care Trust, which runs St Leonard’s Hospital, said “BT couriered a fully encrypted disc containing patient information to City and Hackney PCT. “It was not received by the named recipient, and attempts by the PCT to find the disc have so far failed. All deliveries of personal information have been suspended in light of the breach.” BT today called for parents to remain calm over the latest incident. A spokesman said: “Patients should not be concerned because BT uses the highest levels of security to safeguard the data in its care.

[Er… short of making sure that it or its representatives only hands over the data to the person who is supposed to receive it?]

“All NHS data sent by disc is fully encrypted to industry standards. We apply stringent controls in managing the complex encryption pass phrases necessary for unlocking the data. In this instance the encryption pass phrase would only have been released after one of two named individuals confirmed receipt. This was not confirmed so the encryption pass phrase has not been issued.

Ah… we can relax then. (Though the Standard worries that even 256-bit encryption has recently been shown by researchers to be crackable in two weeks...)

All this attention on missing data is not unhelpful in drawing ordinary people’s attention to a) the volume and frequency of personal data transfers and b) the potential value of their personal data. That’s not a bad thing - probably more effective than a fancy public service advertising campaign. Ruth Carnall, chief executive of NHS London, has asked for an independent review of all NHS data transfer in London. WIBBI all these emergency reviews encompassed a really citizen-centric cost-benefit analysis of centralised data systems. "

Thursday, December 13, 2007

When you don't like the decision, sack the decision maker

From the Independent today: You're fired! Councillor loses his job after voting against Donald Trump's golf course

MercExchange win another round v eBay

MercExchange has won the latest round in the long running, electronic button patent, dispute with eBay.

"A federal judge has approved a roughly $30 million judgment against eBay Inc. more than four years after a jury concluded the online auctioneer had infringed on the patent of a small Virginia company.

U.S. District Court Judge Jerome Friedman's certification, issued late Tuesday in Virginia, edges Great Falls, Va.-based MercExchange LLC a step closer to cashing in on its long-running battle against one of the Internet's powerhouses.

But eBay still hopes to avoid writing a check."

Much though we may like to sympathise with the underdog, and in this case MercExchange has apparently reduced its workforce from 40 to 3, it is frankly ludicrous that a patent for a "buy it now" electronic button on a website should have been awarded in the first place, let alone kept expensive lawyers and the full gamut of the US court system (including the US Supreme Court last year, where at the hearing Chief Justice Roberts confessed himself somewhat perplexed that something so obvious could be the subject of a patent dispute) gainfully employed for over four years.

Wednesday, December 12, 2007

3 strikes and you're terminated

From Michael at ORG:

"Last week’s Social Market Foundation event - ‘Intellectual Property Rights and Consumer Rights’ - despite the title’s implied concern for balance, showed disregard for consumers and promoted rights holders’ interests. The minister responsible for UK-IPO spoke of the need for balance in reforming Britain intellectual property regulation but Government’s actions do not yet evidence this commitment. The BPI’s trail for a UK version of France’s ‘3 strikes’ approach to p2p infringement also gave cause for concern.

The Parliamentary Under-Secretary for the Department for Innovation, Universities and Skills’, Lord Triesman, broad-ranging speech (link to PDF download) took in the usual policy concerns of technological developments, new business models, traffic in infringing content and consumer awareness of IPR. However, a year on from the Gowers Review recommendations for flexible copyright regulation, including a ‘format-shifting’ exception to legalise the near-universal practice of transferring CD recordings to mp3 players, seem no closer despite the rapid allocation of funding to ‘anti-piracy’ enforcement. Ian Brown, billed as the event’s agent provocateur, slammed the speech for its anti-competition and anti-consumer stance. For a more balanced approach to these issues, Ian’s slides are available for download.

In the panel discussion that followed, Richard Mollett flagged moves towards a voluntary agreement between the BPI and ISPs to reduce copyright-infringing traffic, similar to France’s ‘3 strikes’ model. He expects an initial warning from the ISP that infringing traffic is associated with a particular account will halt 75% of infringers. If suspicious activity continues then account suspension is the next step, before the final sanction of account termination. Even assuming there will be adequate appeal procedures, although no assurances were given, this mechanism will harm consumer interests unless systems for identifying protected content operate perfectly. Regardless, and fortunately this point was recognised by all parties to the discussion, cutting off internet access is very much the ‘nuclear option’. The proportionality of this approach still requires broader public discussion given internet access may soon become a basic need, comparable to utilities like water and electricity."

Yale's open courses

Yale now have an open content project, Open Yale Courses. Yaaay(l). (Sorry - couldn't resist it). At the moment they cover astronomy, english, philosophy, physics, political science (I wish they wouldn't call it that - politics is not science), psychology and religious studies.

Patent Troll Tracker stats for 2007

The Patent Troll Tracker has been adding up the number of patent troll cases seen in the US between January and November 2007.

"Here are the cumulative statistics for the first 11 months of 2007, comparing the various districts. Note that I got an email from someone who had numbers run independently, and I am told I have undercounted the number of cases by X and the number of defendants in EDTX by Y. As I said above, this is really a judgment call. I may not have counted all of the bifurcated Judge Clark cases while someone else may have. Either way, even if my numbers are low, they are astoundingly high compared to history:

ED Texas: 343 patent cases, 1,320 defendants sued (140 troll cases)
CD California: 251 patent cases, 647 defendants sued (17 troll cases)
D New Jersey: 176 patent cases, 329 defendants sued (13 troll cases)
D Delaware: 128 patent cases, 310 defendants sued (16 troll cases)
ND California: 127 patent cases, 240 defendants sued (19 troll cases)
ND Illinois: 125 patent cases, 231 defendants sued (23 troll cases)
SD New York: 95 patent cases, 244 defendants sued (13 troll cases)

Peter Zura has an interesting post here, where he notes that Justia's stats show 2,577 cases for 2007 through the end of November - probably trending to be flat for the year, in terms of number of cases (ECF has 2,741 cases, 248 in November -- which has to have you wondering whether to trust Justia on this). But Zura wonders whether, if you track by the number of defendants, 2007 is in fact busier than previous years.

I think the answer is a resounding yes. The numbers I have collected and the ones others have sent me indicate that even though the number of cases filed nationwide is trending to be flat from 2006 to 2007, or perhaps up slightly - like 5% - the number of defendants sued is way way up. In EDTX alone, there were around 1,000 defendants sued in 2006, give or take. Well, already through the end of November, there are over 1,300 sued, a 30% increase. I am projecting around a 30% increase nationwide from 2006 to 2007, and perhaps even higher. That's about 1,800-2,000 more defendants sued for patent infringement in 2007 vs. 2006."

The obsession with improving voter turnout is dangerous

Councillor's Commission, has decided that councils be allowed to offer people a material incentive, like a free lottery ticket, to encourage people to vote, thereby improving voter turnout in local elections.

" All this stuff about turnout would hardly be worth going on about if it was just a matter of preventing some councillors luring people to the polling station with the offer of a free tombola. Unfortunately the drive to increase turnout has a serious consequence. It leads politicians (particularly, at the moment, Labour ones, who fear it is their voters staying at home) to feel that it is more important to make voting easier than it is to ensure that the voting system is secure...

The Electoral Commission, the body policing the system, has been working hard to ensure voting and politics has integrity. And it has repeatedly argued that we need individual-signed voter registration. Tomorrow it will press its case again. But it is being resisted by MPs. Why? Because it is feared that such registration will reduce turnout.

This obsession with turnout isn't simply pointless. It's dangerous."

'Digital Decision Making: Back to the Future' a "must read"

In a bout of shameless self promotion, I just wanted to say many thanks to Kim Cameron for describing my book, Digital Decision Making: Back to the Future, as "a must read". Coming from one of the smartest digital identity architects of our time, I consider that a huge compliment.

The Canadian Facebook Copyright Activists

Michael Geist set up a Facebook page at the beginning of December to protest against the Canadian government's plans to introduce their own version of the DMCA and EUCD. As of today it has 17,732 members (5 of whom have signed up in time it took me to write this post). Michael has been articulating the problems with the proposed legislation on his blog for some time. Other highly respected bloggers like Cory Doctorow and Howard Knopf have also been railing against the proposals and there have been various real world protests, all of which, superficially at least, seem to have led the minister driving the proposals to stop (scroll to top to see Geist's commentary) and consider whether he is doing the right thing.

The Facebook page is labelled 'Fair copyright for Canada.'
"The Canadian government is about to introduce new copyright legislation that will be a complete sell-out to U.S. government and lobbyist demands. The new Canadian legislation will likely mirror the U.S. Digital Millennium Copyright Act with strong anti-circumvention legislation that goes far beyond what is needed to comply with the World Intellectual Property Organization's Internet treaties. Moreover, it will not address the issues that concern millions of Canadians. For example, the Conservatives' promise to eliminate the private copying levy will likely be abandoned. There will be no flexible fair dealing. No parody exception. No time shifting exception. No device shifting exception. No expanded backup provision. Nothing that focuses on the issues of the ordinary Canadian.

Instead, the government will choose locks over learning, property over privacy, enforcement over education, (law)suits over security, lobbyists over librarians, and U.S. policy over a "Canadian-made" solution.

This group will help ensure that the government hears from concerned Canadians. It will feature news about the bill, tips on making the public voice heard, and updates on local events. With regular postings and links to other content, it will also provide a central spot for people to learn more about Canadian copyright reform."

Tuesday, December 11, 2007

Craig Venter and the synthetic genomes patents

The ETC Group have been getting exorcised over Craig Venter's latest genome patent land grab.

"Six months ago ETC Group exposed the Venter Institute’s controversial patent applications on the world’s first human-made living organism built entirely from synthetic DNA (dubbed “Synthia” by ETC Group). Newly published patent claims reveal an even bigger grab for ownership of synthetic life.

A suite of patent applications lodged by J. Craig Venter and his colleagues claims exclusive monopoly on a wide swath of synthetic biology and demonstrate a not-so-subtle move to position Venter’s company, Synthetic Genomics, Inc., as the ‘microbesoft’ of synthetic life. Find out about “The Men & Money Behind Synthia.”

This time, Venter’s shop isn’t claiming a single microbe (Synthia) made from synthetic DNA – the new claims are broadly framed to seek exclusive monopoly on ALL synthetic genomes. Venter’s latest bid for extreme monopoly has drawn strong condemnation – but not much surprise – from civil society and from scientists in the field of synthetic biology."

EU Online Copyright Bill Coming

IPWatch worry the publishing industry have got too cosy with EU information Society Commissioner, Viviane Reding.

"European publishers and copyright holders have a friend in European Information Society Commissioner Viviane Reding, which she reinforced last week in describing efforts to push through a new bill on digital publishing copyrights. At the same event, publishers and cutting-edge US technology company SecondLife debated IP issues such as the problems of digital rights management for protecting copyrights.

“Copyright is a cornerstone of the information and knowledge-based society,” Reding told the 6 December European Publishers’ Forum. “This is why I introduced in the new framework an appropriate balance between ownership and access.”

“This is a concrete legal endorsement of the role of copyright and I hope it will send a signal across the whole industry at a critical time,” she said."

A watched society leads to active conformity

Lynne Duke at the Washington Post has been thinking about our growing surveillance society and the degree to which awareness of that surveillance leads people to actively conform to expected behaviour norms.

Thanks to Suw via ORG for the link.

Race.Net Neutrality

Jerry Kang has a fascinating paper on net neutrality pending publication in a forthcoming Journal on Telecommunications and High Technology Law. It's available at SSRN: http://ssrn.com/abstract=1000042 He essentially uses the history of race discrimination to shine a light on net discrimination. This kind of cross disciplinary analysis has long been advocated by my colleagues in the systems department at the Open University.

Abstract:

"The “net neutrality” debate is undergoing a theoretical transition. Since the late 1990s, we have moved from “open access,” to “end to end,” to “net neutrality,” and by 2007, the question seems to have transformed into “anti‐discrimination.” To the extent that net discrimination frames the question, our history and experience with race discrimination should be cognitively salient. Although patently different subjects, these two forms of discrimination share some similarities which have been noted by various commentators but never systematically explored. This Essay begins that study, with the goal of gleaning lessons for telecommunications policy.

A comparison and contrast between race discrimination and net discrimination teaches us, first, to particularize the discrimination at issue, and to be wary of what I call normative carve‐outs in defining discrimination. Second, the comparison sensitizes us to the clash between welfarist and deontological concerns that have not been adequately distinguished within the net neutrality debate. Third, it urges us to be cautious about facile assurances that individual, firm, or market rationality will ensure the public interest. I conclude with a provocative question: do the arguments against net neutrality regulation apply equally well against common carriage obligations for traditional telephony?"

Thanks to various Cyberprofs for the pointer.

Saturday, December 08, 2007

Free speech QED

Ruthie at Ruthie's Law has been giving her very own paint by numbers lesson on the value of free speech.

"It is clear that free speech is a requirement in any society which aspires to democracy - a system described by Winnie as the worst form of government, except for all the others. Thus, free speech must be defended. If that means anything at all, it means that free speech must be granted to those whose views are despicable, disgraceful and disgusting (dear Diary, Tucker says that alliteration is admirable).

But what is this free speech? I suggest that it is a right to speak. It is not a right to be heard. It is not a right to speak anywhere one likes. It is a right not to be locked up or persecuted by the State for expressing an unpopular (as opposed to a criminal) point of view. But it is not a right to be given an audience. For some reason it is a matter of principle for some that David “Auschwitz is a lie an exaggeration” Irvine should be able to peddle his turd-speak wherever he likes, on the basis that he describes himself as an historian: so that’s alright then.

If Irwhinge wanted to say that black people were intrinsically inferior to white people it is difficult to see the same approach being adopted. Thus, I conclude that this debate is not really about free speech at all. It is about what people are comfortable hearing. Part of the reason that this country is comfortable about holocaust denial or minimisation is that (unlike Germany) it still congratulates itself for not being on the wrong side. Dear Diary, it is entitled to such congratulation. Yet, alas, it has learned the wrong lesson. The lesson is not that traditional British tolerance will ensure that it does not happen here - even though that may be true. The lesson is that people like Irwhinge and Grithick mean what they say. We tend to find that thought so incomprehensible that we shy away from it, and thus fail to learn the lesson of history.

Once one grants that the people who speak freely mean what they say, the debate sharpens up considerably. If we entirely prevent them speaking then, apart from driving their views underground (a tactical debate which I do not address here), we must trust the state to get it absolutely right when determining who can and cannot speak out. Most of us do not have that level of trust in the state and, in a democracy, most politicians do not have that level of trust in themselves. Good...

As dear old Voltaire should have said: “I do not agree with what you say, but I will defend to the death your right to mumble it to the other addle-pates whilst not being prosecuted for doing it. However, the minute you begin not to mumble you are liable to arrest if your words result in actions against those about whom you speak, of which there is a clear risk to an objective observer.” That dear Diary, is the issue of criminalising hate-based conduct. Whether we have the balance right is another question. That there is a balance should be plain. Ultimately we all have a choice about what we hear. How we exercise that choice is something that impacts on everyone and is thus a moral decision. Our fear of that decision must not prevent us denying the essential reality that we are responsible for what we do and that millions of individual decisions matter. If one feels too insignificant to make a difference that is sad. But it is not an excuse for denying the obvious in a self-indulgent attempt to stay in the nursery."

Read it in full and the comments. Great stuff.

Here we go again...

Data of 60,000 on stolen computer

"A laptop computer containing personal details of up to 60,000 people has been stolen from the Citizens Advice Bureau in Belfast."

Friday, December 07, 2007

Wikipedia in the Nazi speech firing line

From News.com: Politician files charge over Nazi symbols on Wikipedia

"A left-wing German politician has filed charges against online encyclopedia Wikipedia for promoting the use of banned Nazi symbols in Germany.

Katina Schubert, a deputy leader of the Left party, said she had filed the charge with Berlin police on the grounds that Wikipedia's German language site contained too much Nazi symbolism, particularly an article on the Hitler Youth movement."

ContactPoint Early Day Motion

Via Terri Dowty:

" You might want to ask your MP to sign up to this Early Day Motion

CONTACTPOINT
29.11.2007

Brooke, Annette

That this House notes the announcement by the Parliamentary Under-Secretary of State for Children, Schools and Families of the deferral of the implementation of ContactPoint to allow for an independent assessment of its security procedures by Deloitte and to address the changes to ContactPoint that potential system users have suggested, but regrets that this review will not extend to the design and content of ContactPoint; expresses concern over the safety implications of such a vast database containing potentially sensitive information in the light of security breaches at HM Revenue and Customs; further expresses concerns about the projected costs of ContactPoint; notes the conclusion of the House of Lords Select Committee on Merits of Statutory Instruments that the Government has not conclusively demonstrated that a universal database is a proportionate response to the problem being addressed; and therefore calls upon the Government to reconsider its decision to proceed."

Good for her. Meanwhile some people have been writing to the Guardian on the same subject.

"The planned database containing the details of all 11 million children in England should be suspended because it is insecure and will put children's safety at risk, an alliance of independent school heads and privacy campaigners warns today.

In a letter to the Guardian, influential groups representing private schools, together with the human rights campaign Liberty, say it is "ludicrous" that the government intends to push on with the controversial ContactPoint database project while awaiting the outcome of a new security analysis of the system."

Demos report: the new politics of personal information

I heard on the BBC radio news this morning that Demos has published a new report today: We no longer control what others know about us, but we don’t yet understand the consequences... The new politics of personal information compiled by Peter Bradwell and Niamh Gallagher.

"Aims of the study

This report has three aims:

1 to connect the value people gain from an information rich society with the challenges that arise from giving away personal information

2 to raise awareness of the consequences of the increasing reliance on personal information by institutions in the public and private sector

3 to provide a framework within which policy-makers, businesses and individuals can address these challenges in the long term.

This report is intended to push the debate on personal information
beyond the legal and technical language associated with data
protection and identity management. The debate must move towards
something that people – through day-to-day experiences in their own
lives – have a stake in. New trends of communication, customer
services, personalisation, and issues of social inclusion and privacy
are helping to create a new framework for the discussion of personal
information.

Our argument

Personal information has become central to how we live – from
banking online and supermarket shopping, to travelling, social
networking and accessing public services. The visible result of this is a
trend towards personal, tailored services, and with this comes a
society dominated by different forms of information gathering. This
is not just something people are subjected to. They are more and
more willing to give away information in exchange for the
conveniences and benefits they get in return, and are often keen for
the recognition and sense of self it affords.

But there is a tension here. By sharing personal information we
surrender control in the longer term by leaving ourselves open to
judgement by different groups in different ways. The drive to
personalise or tailor services, which is shaped by those judgements,
can lead to differences between what people experience and have
access to. This can mean a narrowing of experience, can lead to social
exclusion, and has significant implications for how we live together as
a society. We argue that these problems can only be resolved by a
more open understanding of and better democratic debate about the
boundaries, rights and responsibilities that regulate the use of
personal information. That debate should focus on developing the
collective rules that determine individuals’ ability to negotiate how
personal information is used...

Recommendations

People themselves must be put at the centre of information flows.
Our findings suggested a number of measures that government, the
private sector and individuals could follow to improve the relationship
between people, personal information and the institutions that
use that information.

For individuals, we recommend:

 The first step is for individuals to take measures to protect
their personal information – for example, by securing
wireless networks. Second, they must recognise the
connections between the benefits of sharing information,
and the often less tangible costs and dangers that can
result. A better understanding of this relationship is the
necessary step towards bottom-up policy driven by
collectively negotiated norms and rules, rather than policy
driven by the narrower needs and interests of government
or business. However, this does need considerable support
from government and the private sector to start the
process.

For government, we recommend:

 The government should develop a more coherent strategy
around personal information use. This strategy should
clarify the links between how government will use
personal information, in specific contexts, and what the
potential benefits or costs might be for individuals. Each
government department using personal information must
say how they are accessing personal information, for what
purpose, and how it affects people. They should also
employ ‘cash-handling’ disciplines for dealing with
people’s personal information.

 The government should begin long-term research and
thinking into increasing levels of information about
individuals, coupled with personalising services and
experiences. Segmentation and increasing knowledge of
individuals will create markets that exclude in ways that
current uses of information do not. That will have a
significant impact on what is meant by equality. For
example, will a new frontier of the welfare state be
providing life insurance for certain types of people who
are deemed bad investments by private insurance
providers?
 The Information Commissioner’s Office (ICO) needs
greater capacity to cope with the range of demands of an
information society, which continue to extend away from
just security of data towards data use and the nature of
information sharing. For example, that could include the
ability for the ICO to audit organisations’ use of personal
information without needing their consent.
 ‘Privacy impact assessments’ should be used for major
projects across public and private sectors to assess the use
of personal information early in development, led by the
ICO.

 There needs to be a serious, renewed debate about the
identity card scheme, with the kind of engagement that
should have happened at the start of the process.
Otherwise, the scheme should be dropped. There needs to
be more open consideration of what kind of information
the cards would hold, why, and in what circumstances
they will be used.Meaningful engagement with the
public about how the technology should work must be
foremost in shaping what the cards do, if they are to go
ahead.

For business and the private sector, we recommend:

 The rights of access individuals have to information held
about them in the private sector should be extended,
including the right to know what groups people have been
‘segmented’ into, and allow greater ability for individuals
to challenge and change existing information about themselves
that they believe to be invalid, incorrect or unfair.

 Information holders should engage in an open debate
about where responsibility for personal information lies,
with a view to clarifying the rights and responsibilities of
businesses and individuals.

 There should be a common sense test for privacy
statements and personal information policy. The private
sector must provide simple, accessible explanations of
why personal information is gathered. It is too easy
currently to adapt and rely on established legalistic
policies. A move away from jargon is needed. This means,
for example, requiring businesses to follow the legal
concept of the ‘reasonable person’ when drawing up
policy statements on personal information.
 Banks should consider a ‘no claims bonus’ for customers
who successfully protect their personal information.
 Technical distinctions used by business – between
authenticators and identifiers, for example – should be
binned. As for government, private sector involvement in
digital identity should be grounded in the ways that
people use and value their digital identities. That should
imply a move away from using information people are
likely to divulge – such as family maiden names, dates of
birth – as ‘authenticators’ instead.

 As a bridge between people, policy-makers and
technologists, a body such as the ICO should be given the
remit and resources to lead open discussions and debate
to help build more secure, effective and appropriate
technology for personal information."

Whose secret diary was Facebook so keen for you not to read?

Also from the Indie on Tuesday: Whose secret diary was Facebook so keen for you not to read?

"In the Facebook era, where everyone is spilling their secret thoughts for all to read on a social networking site, it is as if nothing is private any more.

So it might seem highly ironic that Facebook's founder Mark Zuckerberg has been pleading with a Boston court to censure a Harvard magazine that has ferreted out and published a personal journal from his university days and his 2001 application to study at the illustrious college. The judge, Douglas Woodlock, turned him down and ruled that the documents will stay in the public domain."

David Holtzman will no doubt have had a wry grin over the proceedings.

ELQ funding consulatation

Just a reminder to all OU and other part time students that the government "consultation" on their decision to cut a massive chunk out of the funding for part time students ends today. Yvonne Cook had an excellent article in Tuesday's Independent (4 Dec.) this week on the issue, 'The threat to lifelong learning'.

Good old Arsenal

With the Usmanov affair, the recent loss in the Champions league, draw to Newcastle and various injuries to key players like Fabregas, there are some concerns around the Emirates Stadium at the moment. But it's nice to hear that the Arsenal players, directors and many other staff are donating a day's pay to Treehouse, the national charity for autism education.

"Be a Gooner. Be a Giver

This season, TreeHouse is over the moon to be working with Arsenal to raise £250,000 to build the sports facilities in our new National Centre for Autism Education in Noth London.

We have launched "Be a Gooner. Be a Giver" to encourage everyone in the Arsenal family to give whatever they can afford to help us reach our target. We are delighted that Arsenal's amazing players and directors have already generously donated a day's wages - please join them in supporting us, so that we can help many more children with autism through our new National Centre. You really will be making a difference.

If you would like to find out more about TreeHouse and Arsenal, and for a chance to win tickets to the Chelsea game on 16th December, download the free TreeHouse epac at www.epacstore.com/treehouse

Thank you from the bottoms of our hearts....and go Arsenal!

From the Children, Staff and Parents of TreeHouse"

Thursday, December 06, 2007

Congratulations Fernando

The highly entertaining Fernando Barrio, who I met at Gikii 2 earlier this year has been nominated and shortlisted for the law teacher of the year award. Congratulations to him.

There is no tech bubble

Thanks to Ian Yorston, Head of Digital Strategy at Radley College, and aka the Unreasonable Man for alerting me to this:

Facebook not too hot on privacy

David Holtzman, author of the excellent Privacy Lost, is fairly fuming over Facebook's most recent privacy invading shenanigans.

"I was actually hoping this would blow over, but sigh. Another arrogant, young, venture-funded social networking company has done something counter-consumer, caused a furor and backed down, apologizing with a hearty "my bad." Yes, it's Facebook and their notorious Beacon program, which monitors things that members buy on 3rd party affiliated sites and broadcasts these purchases to the member's network, regardless of whether he/she wants them to or not. Originally Beacon was a compulsory "feature"--now it is kinda opt-out. It should have been opt-in all along, but I guess Facebook doesn't see it that way.

Facebook's CEO, Mark Zuckerberg (who is by the way, younger than most of my dental work), has apologized to the user community. In an interview, he said: "I'm not proud of the way we've handled this situation and I know we can do better." I believe Mr. Zuckerberg has completely missed the point--it's not a problem of how he reacted, it's the fact that they rolled out an evil f**king system to begin with.

Even now, the opt-out is transactional, you have to say no each time. The fact these bastards are tracking people at all on 3rd party sites is highly creepy and invasive anyway.

However as most of the critics have said, you don't have to use Facebook.

Good idea. Let's not."

Ian did a forensic examination of Facebook's privacy settings for Gikii 2 this year and came to the conclusion that they didn't measure up too well. He was slightly more polite about their failings.

Canadia Songwriters want to tap commercial potentional of P2P

Via Michael Holloway on the ORG list, the Songwriters Association of Canada are proposing to put in place a system to enable them to be compensated for the distribution of their works on peer to peer networks.

"We propose an amendment to the Copyright Act which would establish a new right: The Right to Equitable Remuneration for Music File Sharing.

4. We define Music File Sharing as the sharing of a copy of a copyrighted musical work without motive of financial gain.

Since the new right is limited to activities that take place without motive of financial gain, parties who receive compensation for file sharing would not be covered by this right. Therefore, this new right is distinct from rights licensed by legal music sites like iTunes and PureTracks.

5. The new right would make it legal to share music between two or more parties, whether over Peer to Peer networks, wireless networks, email, CD, DVD, hard drives etc. Distinct from private copying, this new right would authorize the sharing of music with other individuals.

6. In exchange for this sharing of their work, Creators and rights holders would be entitled to receive a monthly license fee from each internet and wireless account in Canada.

7. We propose a licence fee of $5.00 per internet subscription, per month. Payment of this fee would remove the stigma of illegality from file sharing. In addition, it would represent excellent value to the consumer, since this fee would grant access to the majority of the world’s repertoire of music. Existing download subscription services generally charge considerably more than $5.00 per month, while offering a mere fraction of the file-sharing repertoire."

Interestingly they go on to say that although they are not opposed to TPM/DRM and laws against circumvention (Canada are just about to pass their very own version of the the DMCA and EUCD), they believe their proposal makes DRM obsolete. In addition

"Given the consumer aversion to TPM’s, we believe their use will inhibit the success of recordings in which they are embedded, and they will simply fall out of use."

Nice to see them thinking about using rather than banning p2ps but the sticking point might well be the $5 per month on every account. All the usual economic arguments about levies supporting special commercial interests come into play but it is progress. As with the webcasting levies the devil would be in the detail, though the proposal is probably too late to have any effect on the Canadian government's deployment of their very own DMCA.

EDRI-gram newsletter - Number 5.23

EDRI-gram - Number 5.23, 5 December 2007 has just been issued and as usual is essential reading for digital rights folks. Contents:

Wednesday, December 05, 2007

Microsoft disables remote disabling

It seems that the good guys in Microsoft (and there are a quite a few of them btw) have got the message through that it is not a good idea to remotely disable customers's computers if it suspects piracy.

"Microsoft Corp. is pulling back from a system that disables programs on users' computers if it suspects the software is pirated, opting instead for a gentler approach based on nagging alerts.

Microsoft said late Monday it will roll out the new version of Windows Genuine Advantage with the first "service pack" for Windows Vista, due in the first quarter of 2008.

When computer users activate a copy of Windows Vista or try to download certain software from Microsoft's Web site, the Windows Genuine Advantage system scans their PCs for signs of pirated software. Today, if the tool finds an unauthorized copy of Vista, the glassy Vista user experience disappears and other features are suspended."

I suspect the nagging alerts are going to create major problems as innocents get targetted (identifying copyright infringement is an inexact science not best turned over to software) but it is a little better than having your brand new machine disabled.

German court says iPhone network tie-in ok

From SiliconValley.com: German court upholds T-Mobile's exclusive iPhone contract

"T-Mobile can sell Apple's sought-after iPhone exclusively locked to its own service, a German court ruled Tuesday, reversing an injunction last month requiring the company to sell an unlocked version in Europe's biggest economy.

The Hamburg District Court said Tuesday that T-Mobile, part of Deutsche Telekom AG, could indeed sell the phone, coupled with a two-year contract, that could not be used on networks provided by rival wireless companies.

The arrangement is similar to those Apple Inc. has with other carriers around the world. In the United States, AT&T Inc. is Apple's exclusive partner."

Tuesday, December 04, 2007

Judge Dismisses LimeWire Antitrust Suit

Also via Michael: Judge Dismisses LimeWire Antitrust Suit

"A federal judge on Monday threw out an antitrust lawsuit that the operator of the LimeWire online file-sharing service filed against a coalition of major record labels.

U.S. District Judge Gerard E. Lynch in New York ruled that Lime Group LLC failed to make its case that it has been harmed by the recording companies' business practices, and he granted the companies' motion to dismiss the claims.

Lynch also dismissed several claims brought under state laws "without prejudice," which gives New York-based Lime Group the option to pursue the claims in state court."

Passport applicant finds massive privacy breach

Via Michael Geist: Passport applicant finds massive privacy breach

"A security flaw in Passport Canada's website has allowed easy access to the personal information - including social insurance numbers, dates of birth and driver's licence numbers - of people applying for new passports.

The breach was discovered last week by an Ontario man completing his own passport application. He found he could easily view the applications of others by altering one character in the Internet address displayed by his Web browser."

Monday, December 03, 2007

Websites sell secret bank data and PINs

On the front page of this morning's Times: Websites sell secret bank data and PINs.

Nothing particularly new here but the Times have reported the specific sites to Richard Thomas, the Information Commissioner, and he has agreed to investigate.

"Mr Thomas will address the Commons Justice Committee tomorrow on the addional powers that he says are needed to prevent breaches of data protection. He believes that reckless failure to protect information should result in prosecution and that his staff should have powers to raid government and business premises.

Hacking sites act as online bazaars for stolen personal information. They are well run, hierarchical groups structured like businesses. Some even have review sections where buyers can recommend a particular fraudster...

Senior police officers are concerned that current methods of dealing with large-scale data protection breaches are unworkable. Detective Chief Inspector Charlie McMurdie, of the Metropolitan Police e-crime unit, said: “At the moment people report internet crimes to a local police station but no one locally has the resources to investigate properly.”

Since April customers have been told to report card crimes to their banks rather than to the police. Mr McMurdie, backed by the main banks, has asked the Home Office for £1.3 million to fund a central e-crime unit."

All I would say is that the government has already rejected overtures to get serious about technology-complemented crime and I suspect Chief Inspector McMurdie is asking for a small sum in the expectation of not getting much. But £1.3 million is nowhere near enough to fund the technically literate police force we need to deal with these kinds of crimes not to mention the technical infrastructure required.

Saturday, December 01, 2007

Copyright’s Heart of Darkness

Matthew Sag & Mark Schultz have offered a comment on John Tehranian’s “Infringement Nation”.

"John Tehranian’s recent Utah Law Review Essay, Infringement Nation, tells a riveting story about copyright law and the widening gap between law and norms. Like Charles Marlow’s journey into the Congo River, Tehranian has given us a transporting narrative of copyright’s potential despotic application to the life of an “ordinary law professor” named John. At the end of John’s journey down the copyright river, Tehranian asks us to “imagine a world where every act currently deemed infringing under the law were actually prosecuted.”

One can almost hear Kurtz’ whispered cry, “The horror! The horror!”

Tehranian argues that “on any given day, … even the most law-abiding American engages in thousands of actions that likely constitute copyright infringement.” Tehranian makes his case with an imaginative list of seeming benign “infringing” acts and concludes that “if copyright holders were inclined to enforce their rights to the maximum extent allowed by law, [John] would be indisputably liable for a mind-boggling $4.544 billion in potential damages each year.” (emphasis added)

Without any disrespect to Tehranian, we take issue with his argument and almost all of his analysis. To begin with, many of his examples clearly do not qualify as copyright infringement, others are marginal cases at best...

The real problem with copyright law today is not so much the tyranny of the law as eventually applied, but rather the tyranny of uncertainty as to how the law will be applied. This uncertainty is the product of factors including, the opaque structure of the Copyright Act, the complicated and fact specific nature of the fair use doctrine and defenses such as implied licensing. It is easy and rhetorically expedient to construct a dystopian scenario of copyright gone wild, but this kind of exaggeration does little to address public confusion about the law and only emboldens copyright maximalists by lending credence to their most grandiose claims.

What kind of copyright debate do we want to have? The “Orange Alert” strategy employed by too many copyright commentators simply produces a clash between irreconcilable extremes: “information wants to be free” versus “sole and despotic dominion.”

We continue to hope for something more."

A worthy response which should be read in full.

Chinese Computer Scientist Jailed for Copyright Infringement

William Stepp at Against Monopoly reports that a Chinese computer scientist has been jailed for copyright infringement.

"Chen Shoufu, an innovative Chinese computer scientist, was jailed August 16 in Beijing for violating the copyright of China's leading instant-messenging service, Tencent Holdings Ltd., owner of the popular QQ program. Mr. Chen's program Coral QQ made QQ more user friendly by blocking ads, resolving internet addresses, and identifying the computer from which a message is sent at no charge. (Tencent charges for the ID service.) He had previously paid a 100,000 yuan fine, about $13,600. Here is the article in the Wall Street Journal.

He has become a hero in China, the second largest internet market. One blogger decried Tencent for "bullying Chinese users by monopolizing the market."

This is yet another chilling example in a long list of violations of the liberty of people to use their property in non-invasive and very often innovative ways that ironically could improve the lives of their prosecutors, as well as countless other people. "

NYT interactive debate transcript analyzer

Now this is really neat from the NYT - an interactive analyzer of the transcript of the recent Republican presidential candidates' debate.

The Nerd Handbook

Michael Lopp has compiled The Nerd Handbook. Recommended, especially for families and friends of nerds.

I thought I subscribed to them...

Google Reader now makes recommendations of feeds that are related to those you already subscribe to. The top four were ones I thought I already subscribed to, so I guess they've got me pegged.

Friday, November 30, 2007

The Untold Story of the ENIAC Programmers.

Via Mary Hodder: The Untold Story of the ENIAC Programmers.

"Did you know that sixty years ago, six young women programmed the ENIAC, the first all-electronic programmable computer?

And when LIFE magazine published a post-ww2 story about the ENIAC, the women were not mentioned. The article only featured information on the machine, not the engineers who made it work."

A Financial Perspective on DRM

At Kuro5hin: A Financial Perspective on DRM

" I noted yesterday that there seems to be some media fanfare surrounding Amazon's launch of a digital book tablet. It occurred to me that the markets surrounding media such as books, music and movies bear more than a passing resemblance to financial markets, and as such, perhaps they were amenable to a similar method of analysis. Being the owner of a sizable collection of paper books, this led me to consider the drawbacks one faces when Digital Rights Management restrictions are put in place...

when one purchases media encumbered by ... DRM schemes, one is taking on undiversified credit risk with an indefinitely long time horizon -- that is, you're counting on Microsoft or Apple not going out of business any time in your life and making all of your media instantly unreadable. Worse yet, unlike in the credit market, there are no such strong and well-defined legal protections to offer you recourse in the event that the company defaults -- they may choose to end (or more likely, "upgrade") the service at any time and render your library of purchases useless...

While books and music are almost never bought as investments with the expectation of making a profit, in the financial markets, investors rationally demand a high return premium for taking on such extreme risk. Asking consumers to take on such risks with no prospect of them materially benefiting in return is an incredibly unreasonable proposition and, to me, is the chief mechanism standing in the way of widespread adoption. While DRM schemes of this nature may flourish for now, it is only a matter of time before consumers wise up, the markets become more efficient, and people demand a fairer deal from large media companies. Publishers may not like it, but attaining the same characteristics for their digital products as they have for their physical products is the best hope they have for slimming down their distribution costs and stemming the tide of digital piracy."

Interesting perspective.

How Can Government Improve Cyber-Security?

Also from Ed Felten: How Can Government Improve Cyber-Security?

"One of the biggest challenges comes from the broad and porous border between government systems and private systems. Not only are government computers networked pervasively to privately-owner computers; but government relies heavily on off-the-shelf technologies whose characteristics are shaped by the market choices of private parties. While it’s important to better protect the more isolated, high-security government systems, real progress elsewhere will depend on ordinary technologies getting more secure.

Ordinary technologies are designed by the market, and the market is big and very hard to budge. I’ve written before about the market failures that cause security to be under-provided. The market, subject to these failures, controls what happens in private systems, and in practice also in ordinary government systems.

To put it another way, although our national cybersecurity strategy might be announced in Washington, our national cybersecurity practice will be defined in the average Silicon Valley cubicle. It’s hard to see what government can do to affect what happens in that cubicle. Indeed, I’d judge our policy as a success if we have any positive impact, no matter how small, in the cubicle.

I see three basic strategies for doing this. First, government can be a cheerleader, exhorting people to improve security, convening meetings to discuss and publicize best practices, and so on. This is cheap and easy, won’t do any harm, and might help a bit at the margin. Second, government can use its purchasing power. In practice this means deliberately overpaying for security, to boost demand for higher-security products. This might be expensive, and its effects will be limited because the majority of buyers will still be happy to pay less for less secure systems. Third, government can invest in human capital, trying to improve education in computer technology generally and computer security specifically, and supporting programs that train researchers and practitioners. This last strategy is slow but I’m convinced it can be effective."

Slysoft Commercializes Next-Gen DVD Circumvention

From Ed Felten: Slysoft Commercializes Next-Gen DVD Circumvention

"We’ve been following, off and on, the steady meltdown of AACS, the encryption scheme used in HD-DVD and Blu-ray, the next-generation DVD systems. By this point, Hollywood has released four generations of AACS-encoded discs, each encrypted with different secret keys; and the popular circumvention tools can still decrypt them all. The industry is stuck on a treadmill: they change keys every ninety days, and attackers promptly reverse-engineer the new keys and carry on decrypting discs.

One thing that has changed is the nature of the attackers. In the early days, the most effective reverse engineers were individuals, communicating by email and pseudonymous form posts. Their efforts resulted in rough but workable circumvention tools. In recent months, though, circumvention has gone commercial, with Slysoft, an Antigua-based maker of DVD-reader software, taking the lead and offering more polished tools for reading and ripping AACS discs. "

The Cape Town declaration

Martin Weller and Stephen Downes have some thoughtful responses to the Cape Town Open Education Declarion.

Martin's quite positive:

"I would have foregrounded it more, something along the lines of

New technologies, open content and an opening up of opportunities to participate means that radically new models of learning are now possible. These can be based around rich content discovery, social networks, informal learning, commons based peer production, loosely coupled systems, democratic communities and a long tail of interests. Addressing these challenges will require new models of pedagogy, accreditation, guidance, support, licensing and content production.

So will I sign up for it? Yes, there are more people aligned against open education than behind it, so the last thing we need to do is factionalise within our own camp. But, next time, let's eat our own dog food eh? "

Stephen is critical mainly due to the process through which it came about and the demographics of the participants:

"Normally I would expect to enthusiastically add my name to a document supporting free access to open learning resources. This is certainly a cause I have worked toward all my life, one that is expressed in the statement of principle on my home page, one that characterizes the papers I write, the software I code, the speeches I give.

I find myself at odds with the declaration written by a group of mostly American academics and advocates invited by a foundation to a private meeting in South Africa to author a "fixed and final" declaration on open educational resources...

I do not believe that a panel of hand-picked representatives representating overwhelmingly a certain commercial perspective is qualified or able to speak on behalf of the rest of us. The very people they name - "learners, educators, trainers, authors, schools, colleges, universities, publishers, unions, professional societies, policymakers, governments, foundations and others" - are mostly nowhere present in these deliberations."

He also suggests the document should be opened up to us latter folks (I guess I'm a learner, educator, author and other) and I would recommend all in the ed tech community read his critique but like Martin would sign up on the proviso, as he says, that we pay more attention to eating our own dog food.

PlayStations not to blame for UK reading difficulties

Martin Samuels at the Times thinks education secretary Ed Balls is wrong to blame the poor reading performance of Uk children on computer games.

Whilst I agree to the extent that it is not down to gaming, the thought that teachers in classrooms of thirty plus kids, each with a variety of developmental and educational needs (er... 30+ or so) can cure the nation's reading problems, is a little naive, especially when those teachers and the schools they work in are so constrained by government targets.

Publican appeals over right to pick her football satellite

From the Times: Publican appeals over right to pick her football satellite

A publican in Southsea who decided to buy a satellite dish, decoder and card and then subscribe to Greek TV station, Nova, for £800 rather than BSkyB for £6000, is appealing a conviction for criminal copyright infringement. She's already lost one appeal.

Now we all know copyright based companies aspire to be different but this is an EU citizen buying a service from a business in another EU country, rather than buying the equivalent, significantly more costly service from the local EU branch of a multinational organisation. So it must at least raise some interesting legal questions.

I wonder if the excellent Jeremy Phillips and co. have any more informed views on the subject.

Everything is Miscellaneous - The Video

Michael Wesch of Kansas State University has summed up David Weinberger's book Everything is Miscellaneous in a brilliant 5 minute video. Weinberger basically says information is no longer confined to the shelf as it was pre-Web/Net and we shouldn't confine ourselves to thinking about or organising it in that way when we have such fantastic tools at our disposal now to do it better. Prior to the advent of the Web and associated technologies information was kept in a file or on a shelf and managing it involved managing categories. This required experts and was still hard to do. Now it's not confined to experts or categories and assumptions about paper based information don't apply to digital information, the latter for example not necessarily having a fixed material form i.e. it can be molded or adapted to context and we can "rethink information beyond material constraints". We have links and tags etc. We're going through an information {explosion} revolution and the responsibility to
  • harness
  • create
  • critique
  • organise
  • and understand
is ours (all of us); are we ready? It's essentially the up side of the Benker worldview provided we choose to make the best of it.

Have a look at the video. It really is terrific and it will be 5 minutes 28 seconds well spent:

News sites want more control of search engines access

AP via Findlaw:

"The desire for greater control over how search engines index and display Web sites is driving an effort launched Thursday by leading news organizations and other publishers to revise a 13-year-old technology for restricting access.

Currently, Google Inc., Yahoo Inc. and other top search companies voluntarily respect a Web site's wishes as declared in a text file known as "robots.txt," which a search engine's indexing software, called a crawler, knows to look for on a site.

The formal rules allow a site to block indexing of individual Web pages, specific directories or the entire site, though some search engines have added their own commands.

The proposal, unveiled by a consortium of publishers at the global headquarters of The Associated Press, seeks to have those extra commands - and more - apply across the board. Sites, for instance, could try to limit how long search engines may retain copies in their indexes, or tell the crawler not to follow any of the links that appear within a Web page."

The proposed controls are known as Automated Content Access Protocol (ACAP). Google, Yahoo et al are never going to go along with this and sure enough -

"Google spokeswoman Jessica Powell said the company supports all efforts to bring Web sites and search engines together but needed to evaluate ACAP to ensure it can meet the needs of millions of Web sites - not just those of a single community." As Nicholas Carr and David Weinberger and others have said, the more 'free' content there is, the happier Google will be.

Thursday, November 29, 2007

Plan to Review ContactPoint Child Database preceded HMRC data loss

William Heath informs us that despite impressions to the contrary, the plan to review the children's database ContactPoint preceded the HMRC data loss debacle, rather than coming about as a reaction to it.

YouTube suspends account of Egyptian anti-torture activist

Via Citizen Media Project: YouTube Suspends Account of Prominent Egyptian Blogger and Anti-Torture Activist

"According to Reuters Africa, YouTube has recently suspended Abbas's account due to complaints about the content of his postings:
Wael Abbas said close to 100 images he had sent to YouTube were no longer accessible, including clips depicting purported police brutality, voting irregularities and anti-government demonstrations. YouTube, owned by search engine giant Google Inc., did not respond to a written request for comment. A message on Abbas's YouTube user page, http://youtube.com/user/waelabbas, read: "This account is suspended."

"They closed it (the account) and they sent me an e-mail saying that it will be suspended because there were lots of complaints about the content, especially the content of torture," Abbas told Reuters in a telephone interview. Abbas, who won an international journalism award for his work this year, said that of the images he had posted to YouTube, 12 or 13 depicted violence in Egyptian police stations.

Elijah Zarwan, a human rights activist and blogger living in Egypt (and a personal friend), told Reuters that he found it unlikely that YouTube had come under official Egyptian pressure, and was more likely reacting to the graphic nature of the videos."

Privacy International to pursue data breach legal action against UK government

Privacy International, in response to an unprecedented number of complaints about the HMRC data loss have decided to take legal action against the UK government.

The legal experts they have consulted so far say there "most likely a case that can be asserted" but not all of them are optimistic about the potential outcome of such a case.

Wednesday, November 28, 2007

Harry Potter and the (Re)Order of the Artists: Are We Muggles or Goblins?

Thanks to Mike Madison for pointing out that Gary Pulsinelli has written the article probably quite a few IP scholars have been thinking of writing a version of, ever since the last Harry Potter book was published. Abstract:
In Harry Potter and the Deathly Hallows, author J.K. Rowling attributes to goblins a very interesting view of ownership rights in artistic works. According to Rowling, goblins believe that the maker of an artistic object maintain an ongoing ownership interest in that object even after it is sold, and is entitled to get it back when the purchaser dies. While this view may strike some as rather odd when it is applied to tangible property in the ?muggle? world, it actually has some very interesting parallels to the legal treatment of intangible property, particularly in the areas of intellectual property and moral rights. Because of the way these parallels have been developing and growing, we seem to be becoming more goblinish in our willingness to recognize ongoing rights in artistic objects, including allowing the artist to collect a commission on subsequent resale of the work. Practical and social considerations suggest that we are unlikely to go as far as recognizing a permanent personal right in the creator that lets him or her reclaim such an object after a sale or other transfer is made. However, we are moving closer to recognizing some forms of the collective right that the goblins actually seem to demand, a cultural moral right in important cultural objects that enables the descendants of that culture as a group to demand the return of the object. Thus, we muggles may not be as far from the goblins as we may have at first believed.


Must make a point of reading it properly.

Grimmelmann's Library of Babel

Now that we're on the subject of Google I should recommend James Grimmelmann's excellent essay Information Policy for the Library of Babel to be published in the forthcoming edition of the Maryland Journal of Business and Technology Law.
"Borges’s 1941 short story The Library of Babel describes an unbelievably large library containing all possible books. Within the the “total” and “endless” reaches of the Library,”[t]here [is] no personal problem, no world problem, whose eloquent solution [does] not exist—somewhere …” but also “[f]or every rational line or forthright statement there are leagues of senseless cacophony, verbal nonsense, and incoherency.” As Borges describes it, the Library is the greatest imaginable source of information: it contains “The Vindications—books of apologiae and prophecies that would vindicate for all time the actions of every person in the universe and that held wondrous arcana for men’s futures.”

But the Library’s vastness and disorganization also make it almost completely useless: “[T]he chance of a man’s finding his own Vindication … can be calculated to be zero.” The image of the Library is haunting and suggestive. What would we do if we took it at face value? In this bagatelle of an essay, I propose to do just that: set out a few principles of sensible information policy for the Library of Babel."

[James Grimmelmann. 2007. "Information Policy for the Library of Babel" Maryland Journal of Business and Technology Law
Available at: http://works.bepress.com/james_grimmelmann/16]

The Google Complement - Free Content

Nicholas Carr might suggest that Google is on Martin's side in the future of content debate. Essentially he says Google wants content to be free because this complements its core business thereby making that business stronger.
Because the sales of complementary products rise in tandem, a company has a strong strategic interest in reducing the cost and expanding the availability of the complements to its core product. It’s not too much of an exaggeration to say that a company would like all complements to be given away. If hot dogs became freebies, mustard sales would skyrocket. It’s this natural drive to reduce the cost of complements that, more than anything else, explains Google’s strategy. Nearly everything the company does, including building big data centers, buying optical fiber, promoting free Wi-Fi access, fighting copyright restrictions, supporting open source software, and giving away Web services and data, is aimed at reducing the cost and expanding the scope of Internet use. To borrow a well-worn phrase, Google wants information to be free - and that is why Google strikes fear into so many different kinds of companies.

That actually also goes to the heart of why I (the poor man's Lessig remember) am no longer as pessimistic as I used to be about future limited access to content through tollbooths concentrated in few hands, even though drm is not going away. Large commercial entities are lined up on both sides of the divide and Google is likely to have more weight than all the most rational, evidence-based arguments academics, other experts and activists can muster. As Lessig says of his next ten year project, tackling corruption in US politics, it's all about the money.

The value of play

The Old Bridge Public library in New Jersey held a Wii tournament for senior citizens a few weeks ago, as part of a project to help pensioners become more technically literate. The library assistant director, Allan Kleiman, explained that it was a lot less intimidating and significantly more sociable to learn to use the Wii than to learn to use a computer. He's got a point. The social side of gaming is often overlooked by critics and it's pretty difficult for anyone to have an informed discussion about teh educational and social potential of gaming without having direct experience of using computer games in a variety of contexts.

Making the technology available also draws the younger folks into the library and ironically seems in turn to lead to more books getting loaned out, in contrast to the widely toted notion that computer games take kids away, to the detriment of their development, from the much more cerebral, engaging, but humble book.

It gets back to the Charles Nesson/Yochai Benkler assertion that we will become intelligent and creative 'readers'/users of new technology through being intelligent creators/users of and through new technology i.e. the try it out and see what works model of life. Keep playing and tinkering and find out for yourself rather than waiting for others to dictate to you.

RIAA ordered to detail expenses per song lost in P2P case

In UMG v Lindor, yet another RIAA v individual case the judge has ordered the RIAA to disclose the actual expenses incurred for each of the songs at issue in the case.

The defendant is arguing that the statutory damages of between $750 and $150,000 per song is excessive and they need to have an idea of the real cost to the record companies before damages can be assessed. That seems like a reasonable request.

The RIAA say they can't provide those figures without going to enormous expense. The temptation here is to omit a hollow laugh but actually we could look at this as the record labels finally admitting that no one knows or can possibly know the real extent of the impact of P2P file sharing, infringing and non infringing, on their market, despite the perennial estimates that it amounts to billions of dollars.

U.S. withdraws subpoena seeking identity of 24,000 Amazon customers

Via SiliconValley.com: U.S. withdraws subpoena seeking identity of 24,000 Amazon customers

Super Mario comes out fighting for patent

Earlier this year the UK Patent Office refused to award patent protection to a software technique Nintendo use in the Super Mario Kart game to get crashed cars quickly back on the track. Now another similar decision on software patents has been appealed to the High Court, according to IPKat, who says:

"The appellants allege that the UK-IPO’s practice undermines the ability of British industry to protect inventions reliant upon the development of new software. Each applicant has developed novel software, the control and distribution of which they say is critical to the success of their business. Nicholas Fox of Beresford & Co. said in the lead-up to the appeal,

Copyright protection only protects code against copying. In contrast, patent protection enables a company to monopolise an invention even if competitors independently come up with the same idea. In order to protect their commercial interests companies need patent claims directed towards the products and processes that are sold in the market place. In the case of computer based inventions this means that claims to disks and downloads embodying an invention are required.

In Court, the appellants argued that software on a disk represented a "dormant technical effect in waiting", analogous to a medical pill that just sat there doing nothing until the patient took it. Using the same principle, the software would produce a technical effect when run on the computer. [IPKat comment: this seems a new argument, and an interesting approach, but arguing by analogy is rarely helpful; after all, medicines themselves are not excluded under section 1(2)]

They argued that, following the landmark IBM decision T 1173/97 at the EPO, a computer program product is not excluded from patentability under Article 52(2) and (3) EPC if, when it is run on a computer, it produces a "further technical effect" which goes beyond the normal physical interactions between program and computer, i.e. between software and hardware. The EPO approach has been broadly consistent in its decisions since then."

Thanks to David Gerard via ORG for the link.

The Future of Reading

In the spirit of the debate Martin Weller and I, Will Woods and Patrick McAndrew had several weeks ago, on the future of content, Steven Levy has a terrific article in Newsweek this week on the future of the book, featuring Amazon's new ebook reader, the Kindle.

Tuesday, November 27, 2007

The Biometrics Cure

Ben Goldacre has a nice article on the government's cure-all-security-ills answer - biometrics - to last week's HMRC-NAO data loss.

Essentially ministers who think biometrics will make data misuse impossible are misinformed at best or lying at the other end of the spectrum.

As Ben points out, the thing about biometrics is that they may be unique (though they won't be for long when forged) but they are not secret. We leave fingerprints and bits of dna in the forms of loose hairs or bits of skin lying around all over the place, so our biometrics are most definitely not secret. And biometric technologies are not particularly good, in spite of government ministers' apparent belief to the contrary. So the notion that the HMRC-NAO data leak would not have been a problem if we'd been using biometrics or that we are going to tackle data security through biometrics is naive and stupid.

If you'd like some of succinct but serious and robust outlines of why this is so check out Ross Anderson's book, (chapter 13 current edition, chapter 15 new edition due in the new year), this Jerry Fishenden essay, and the brilliant letter below (which I hope Ian, Ross and co don't mind me re-producing in full) to the UK Parliament's Joint Committee on Human Rights.
Mr Andrew Dismore MP
Chair, Joint Committee on Human Rights
Committee Office
House of Commons
7 Millbank
London SW1P 3JA

cc: Committee members; David Smith, Deputy Information Commissioner

26 November 2007

Dear Mr Dismore,

The government, in response to the recent HMRC Child Benefit data breach, has asserted that personal information on the proposed National Identity Register (NIR) will be 'biometrically secured':

"The key thing about identity cards is, of course, that information is protected by personal biometric information. The problem at present is that, because we do not have that protection, information is much more vulnerable than it should be." - The Chancellor, Hansard Column 1106, 20/11/07

"What we must ensure is that identity fraud is avoided, and the way to avoid identity fraud is to say that for passport information we will have the biometric support that is necessary, so that people can feel confident that their identity is protected." - The Prime Minister, Hansard Column 1181, 21/11/07


These assertions are based on a fairy-tale view of the capabilities of the technology, and in addition, only deal with one aspect of the problems that this type of data breach causes.

Ministers assert that people's information will be 'protected' because it will be much harder for someone to pass themselves off as another individual if a biometric check is made. This presupposes that:

(a) the entire population can be successfully biometrically enrolled onto the National Identity Register, and successfully matched on every occasion thereafter - which is highly unlikely, given the performance of biometrics across mass populations generally and especially their poor performance in the only, relatively small-scale, trial to date (UKPS enrolment trial, 2004). Groups found to have particular problems with biometric checks include the elderly, the disabled and some ethnic groups such as Asian women;

(b) biometrics are 'unforgeable' - which is demonstrably untrue. Biometric systems have been compromised by 'spoofing' and other means on numerous occasions and, as the technology develops, techniques for subverting the systems evolve too;

(c) every ID check will be authenticated by a live biometric check against the biometric stored on the NIR or at the very least against the biometric stored on the chip on the ID card which is itself verified against the NIR. [N.B. This would represent a huge leap in the cost of the scheme which at present proposes only to check biometrics for 'high value' transactions. The network of secure biometric readers alone (each far more complex and expensive than, e.g. a Chip & PIN card reader) would add billions to the cost of rollout and maintenance.]

Even if, in this fairy-tale land, it came to pass that (a) (b) and (c) were true after all (which we consider most unlikely), the proposed roll-out of the National Identity Scheme would mean that this level of 'protection' would not - on the Home Office's own highly optimistic projections - be extended to the entire population before the end of the next decade (i.e. 2020) at the earliest.

Furthermore, biometric checks at the time of usage do not of themselves make any difference whatsoever to the possibility of the type of disaster that has just occurred at HMRC. This type of data leakage, which occurs regularly across Government, will continue to occur until there is a radical change in the culture both of system designer and system users. The safety, security and privacy of personal data has to become the primary requirement in the design, implementation, operation and auditing of systems of this kind.

The inclusion of biometric data in one's NIR record would make such a record even more valuable to fraudsters and thieves as it would - if leaked or stolen - provide the 'key' to all uses of that individual's biometrics (e.g. accessing personal or business information on a laptop, biometric access to bank accounts, etc.) for the rest of his or her life. Once lost, it would be impossible to issue a person with new fingerprints. One cannot change one's fingers as one can a bank account.

However, this concentration on citizens 'verifying' their identity when making transactions is only one issue amongst many when considering the leakage of personal data. Large-scale losses of personal data can have consequences well beyond an increase in identity fraud. For example, they could be potentially fatal to individuals such as the directors of Huntingdon Life Sciences, victims of domestic violence or former Northern Ireland ministers.

It is therefore our strongest recommendation that further development of a National Identity Register or National Identity Scheme (including biometric visas and ePassports) should be suspended until such time that research and development work has established beyond reasonable doubt that these are capable of operating securely, effectively and economically on the scale envisaged.

Government systems have so far paid little attention to privacy. Last week's events have very significant implications indeed for future government information systems development.

We would be pleased to clarify any of these points or provide further information if useful to the Committee.

Yours sincerely,

Professor Ross Anderson
Dr Richard Clayton
University of Cambridge Computer Laboratory

Dr Ian Brown
Oxford Internet Institute, University of Oxford

Dr Brian Gladman
Ministry of Defence and NATO (retired)

Professor Angela Sasse
University College London Department of Computer Science

Martyn Thomas CBE FREng

Child database plan under attack

From the Independent: Child database plan under attack following missing discs debacle

It seems the schools secretary Ed Balls has ordered a review of the Children Act database(s) in the wake of the HMRC-NAO data loss debacle. Good news on the surface but it has little or no prospect of it having any effect other than window dressing, in a transparent attempt to be seen to be doing something. If he was really serious he'd start by getting Terri Dowty, Ross Anderson, Ian Brown and the other folks who produced the report for the Information Commissioner last year, highlighting the risks to children’s safety of the government’s policy of creating large, centralised databases on children, in a room and listening seriously to them and acting on their advice, rather than treating them as outcasts with agendas to be ignored.

Sunday, November 25, 2007

An analysis of the latest Harry Potter case

C.E. Petit believes that the latest Harry Potter case against the Harry Potter Lexicon folks has more to do with Warner Bros than J.K. Rowling. Couldn't agree more.

BSA make money from threatening small businesses

The BSA are reportedly making a lot of money out of threatening small businesses with expensive court proceedings.

"An analysis by The Associated Press reveals that targeting small businesses is a lucrative strategy for the Business Software Alliance, the main global copyright-enforcement watchdog for such companies as Microsoft Corp., Adobe Systems Inc. and Symantec Corp.

Of the $13 million that the BSA reaped in software violation settlements with North American companies last year, almost 90 percent came from small businesses, the AP found."

ICO launch young people privacy awareness site

The Information Commissioner's Office has launched a web site to encourage young people to take privacy seriously on social networking sites.