Monday, September 10, 2012

Regulation and trust in the digital economy: an uneasy relationship


A copy of the slides for and the transcript* of my talk at the Trust in the Digital Economy workshop at Aberdeen University last week.



Regulation and trust in the digital economy: an uneasy relationship

Good morning Aberdeen.

Abstract
What have terrorism, copyright infringement, spam, child protection and organised crime got in common?  They have all been cited by policymakers as reasons for introducing internet related laws. Unfortunately too many of these regulations are passed by legislatures lacking a rudimentary understanding of the technologies they are attempting to control. This has significant implications for innovators, economic agents and citizen consumers which go to the heart of what it means to engender trust in the digital economy.

Introduction
In the next 20 minutes I’m going to shoot through some basic behavioural economic theory and give a couple examples of regulations which I believe undermine trust in the digital economy. One of these is an existing law, the Digital Economy Act (DEA) 2010 and one is passing through parliament at the moment, the Communications Data Bill (CDB).

Whilst I’m outlining these ideas I’d like you to keep in mind that trust in the digital economy is one of the most fundamental issues of the 21st century.  We need to trust more people, more institutions and more complex systems than ever before. We need to trust them from further away and via the internet and technologies many of us don’t understand. So creating trust and engendering trust is more difficult than ever before.

The scale of it all also means that the bad guys can do more damage than ever and yet the traditional bad guys – the four horsemen of the infocalypse, drug dealers, child abusers, organized crime and terrorists – are not the key threats to trust, since they are few in number and operate at the fringes of society. The key threats arise from powerful governments and large organisations (including large criminal organisations) using their power to subvert trust. The global financial meltdown is the key case study of recent times. 

I’d also like you to remember that the number of people and institutions we trust every day is huge – the utility companies and their employees that provide my energy and water, the food I’ve consumed in the past 24 hours that I didn’t have to test chemically before eating it, the airports, airlines, pilots, ground staff, air crew, transport and security infrastructure that got me here today, [1] the websites I booked it all through, the police and public services that support order and stability.

3 Stakeholders’ model

Ok so getting back to the economics it’s useful to have a model through which to frame or attempt to understand some of these complex issues.  One way to think of it is through groups of stakeholders.  We can outline three generic groups of stakeholders in the digital economy –

  • the innovators/creators who come up with the ideas that form the basis of our products & services
  • the economic agents – by economic agents I mean commerce, public services and government – that get products and services to the public
  • the public – citizen consumers

I don’t like the word ‘citizen’ or ‘consumer’ but both together serve to separate this group from the other two.

For trust to thrive we need to look after the interests of all three sets of stakeholders.  All three need to thrive and that balance of interests is theoretically assumed to be delivered through Adam Smith’s invisible hand of the market working in harmony with enlightened governance.

Each of these three sets of stakeholders constitutes complex ecologies in themselves. Different innovators have different interests.  Different economic agents have often competing and/conflicting interests.  You only have to think about internet file sharing and the postulated damage it has done to the traditional large music labels, online news v newspapers, Amazon v ordinary bookshops.

There are fierce legal battles in the mobile and tablet computing space with  more than 50 Android patent cases being litigated globally. In the past couple of weeks a US jury had awarded Apple more than $1 billion in damages against Samsung.  The same week a Korean court issued injunctions against the sale of Apple and Samsung products for infringing each others’ patents. Last week Samsung won their latest court battle with Apple in Japan. These two companies alone are facing off against each other in courtrooms in ten different jurisdictions.  In the UK Samsung currently have the upper hand but only because the judge considered Apple’s products “much cooler”.

If you buy into some of the political rhetoric in the context of the US presidential race then the Government is against everybody.

So the reality is more complex than the model but for now let’s stick with the 3 stakeholder groups.

Behavioural forces model

What is it, then, that regulates the behaviour of these sets of stakeholders?  Yochai Benkler and Lawrence Lessig suggest there are four key forces:

  • social norms
  • the market
  • the environment or architecture
  • the law

Social norms dictate how we behave in social groups. When I first moved to the south of England to work, I didn't know I was not supposed to say hello to a stranger on a train. My attempts to engage someone in conversation were subject to suitably disdainful and horrified looks from my fellow passengers, who tried valiantly to ignore me. Having been normalised after 20 years, I can dish out the dirty looks with the best of them.

Social norms punish deviation after the event.

Market forces also regulate behaviour. Markets dictate that we don't get access to something unless we offer something of value in exchange. The price of cigarettes is potentially a constraint on a child's opportunity to smoke. Unlike social norms, market forces regulate at the time of the transaction. If children have no money, retailers will not sell them cigarettes.

Law and legal regulations provide the framework through which governments prescribe what is acceptable behaviour and what is not. Law acts as a threat. If we don't follow the law there is a risk that we will be found out and punished. I could cheerfully strangle several of the zombie bureaucrats I deal with on a daily basis but in addition to having some ethical concerns about murder, I’d prefer not to deal with the legal consequences of engaging in such activity.

Under the law, as with social norms, the punishment happens after the event.

‘Architecture’ or the built environment and the laws of physics – i.e. how the physical world is (and the limits of the laws of physics) – also regulate behaviour. Architecture is particularly important in the context of the digital economy, since digital technologies are entirely human constructs and designs.

Like market forces, constraints on behaviour imposed by architecture happen when we are trying to engage in that behaviour. For example, if a building has steep steps at the entrance and no other way in, it is difficult for a wheelchair user to enter the building unaided.

Prolific 20th-century New York City planner Robert Moses built highway bridges along roads to the parks and beaches in Long Island that were too low for buses to pass under. Hence the parks and beaches were accessible only to car owners – many of them white middle class or wealthy. Poor people without cars, mainly African Americans and other minorities, would be forced to use other parks and beaches accessible by bus. Thus social relations between black and white people were regulated, an example of discriminatory regulation through architecture.
It should be noted that Moses vehemently denied that there was any racist intent on his part. In one sense, his intent is irrelevant. The architecture regulated behaviour whether he intended to or not.

Architecture is also self-regulating – the steep steps get in the wheelchair user's way because they are steep and they are steps! Laws, norms and markets can only constrain when a ‘gatekeeper’ chooses to use the constraints they impose.

There were a couple of stark examples of architecture and technology regulating behaviour in an uncontrolled way in the past week.  On the evening of the 2nd of September roving network bots shut down the live streaming of the Hugo Awards ceremony just as Neil Gaiman was getting an award for his scripting of a Dr Who story, The Doctor’s Wife. The company policing the stream for copyright infringement, Ustream, could not stop the bots from censoring the live video streaming of one of the world’s most prestigious science fiction award ceremonies; a ceremony which could not be viewed live anywhere else other than by those physically present there.  Ustream could not shut down the bots once these automated stream killers decided to block the video because the bots were programmed and deployed by a third party company, Vobile, which was subcontracted by Ustream to do automated takedowns. The bots saw Dr Who clips and decided their broadcast wasn’t allowed regardless of rights clearances or fair use.

Ustream have reportedly discontinued their business relationship with Vobile.[2] Vobile’s CEO tells a different story to Ustream explaining that Vobile only notifies the main client when their bots find a match for material tagged copyrighted in their database.  They have no control over takedowns which were entirely the remit of Ustream as far as the Hugo Awards were concerned.[3]

Who is really responsible is irrelevant to the overriding point though that technological architecture inappropriately shut down a legitimate internet broadcast without due cause or justification.

In a postscript to the story overzealous drm bots hit the video of Michelle Obama’s speech to the Democratic National Convention a few days later. This time the bots didn’t shut down the live stream but blocked access to the video after the event.[4] What’s amusing about this is the Democratic Party’s long history of support for entertainment industry lobbying for more and more stringent copyright laws.

Architecture is a massively important regulator in the context of the digital economy.

Force of law

Here’s a pictorial representation of the four forces regulating an individual. It’s an over-simplified picture again because the different forces also interact with each other and have different powers of influence depending on the context and the stakeholder in question.
For the rest of this talk I’d like to focus mainly on the distorting power of one of the forces – ill-informed laws – in undermining trust in the digital economy.  I have chosen a couple of examples from recent times to illustrate the issue. Both are laws that attempt to enforce dangerous surveillance/controlling technological architectures.

  • The Digital Economy Act (DEA) 2010
  • The Communications Data Bill (CDB) currently under consideration

DEA

The Digital Economy Act was passed in the “wash up” of laws just before the last general election.  The process is supposed to be used only for uncontroversial measures that are agreed between the front benches of the main political parties.  The DEA was very controversial, however, and over 20,000 people and multiple big telcos and technology companies wrote to the MPs in an ultimately futile effort to get it blocked. BT and TalkTalk have subsequently unsuccessfully challenged it through the courts.

Sections 3-18 of the DEA essentially make ISPs responsible for policing the internet for copyright infringement.  Detailed provisions relate to:

  • notifying subscribers of reported infringements
  • providing infringement lists to copyright owners
  • obligations to limit internet access
  • obligations  to engage in website blocking (the current government have decided to abolish this since Ofcom said it was unworkable)

Ofcom and the government are working on the details of how this will all operate in practice.  The Hargreaves ‘Review of Intellectual Property and Growth’ cited the passage of the DEA as an example of the distortion of public policy by questionable evidence.

The reality of the Digital Economy Act's (DEA) online infringement of copyright provisions (sections 3 - 18) may finally begin to hit home next year (theoretically) when thousands of people start to get accusatory letters about copyright infringement from their ISPs. The UK courts have not fully tested evidence presented in such copyright infringement cases as the few that have been pursued were eventually settled out of court. So there is no authoritative legal guidance on standards of evidence or process.

In any case the systematic threatening of large numbers of people by ISPs on behalf of the copyright industries is unlikely to be conducive to engendering trust in the digital economy.

It was not even clear until very recently whether the process of identifying the accounts of suspected copyright infringers could be done with any degree of forensic integrity. Thanks to a report[5] by Dr Richard Clayton of Cambridge University for Consumer Focus it appears that as long as a careful detailed set of procedures which he outlines in the report are followed this may be possible.[6] But he emphasises that his blueprint is time limited and will be useless once peer to peer network technologies evolve to incorporate encryption routinely.

There is a lot of heated rhetoric exchanged through the mainstream media whenever new copyright regulations like the DEA come along (and there have been a lot of them over the past 15 or 20 years).  So it might be instructive to take some of the heat out of the debate by looking at the impact of copyright law on our three sets of stakeholders.

Take innovators/creators.  We can imagine that there is an optimum standard of copyright law that will encourage innovators to maximise their creative/inventive activity. As strength of copyright increases from nothing the economic incentive to create becomes greater.  But there will be a point at which the incentive decreases since it gets so strong that it prevents creators building on the work of earlier creators. Copyright in the UK and many other jurisdictions lasts now for the life of the author plus 70 years. So creative artists are theoretically precluded from using most of 20th century culture, as the basis or inspiration for their work.

We can also imagine that the public might prefer copyright to be weaker to enable them to access more creative work at cheaper prices.

Similarly the economic agents – agents, music, film, software, media companies and publishers – that get creative work from the creators to market might prefer stronger copyright laws.

In theory we could tweak copyright law to balance the interests of all three sets of stakeholders. We could measure the effects, feed that evidence back into the policymaking process and ultimately evolve an informed, evidence based set of copyright laws.  Choice of the optimum level won’t be ideal for all the stakeholders but it should be possible to agree a compromise to balance the interests of all three.

That’s not the way it worked with the DEA. There was no evidence just effective lobbying by the large entertainment industries.  The big winners with the DEA are some agents – a select few large music labels and movie companies who hold the copyright on commercially valuable works – and some creators – mostly the tiny percentage of global superstars who earn large sums from royalties.

The losers with the DEA was everybody else – the public, other creators and other economic agents, in particular the ISPs who have to engage in very costly technology investment and operational processes to police copyright on the Net.

The other big loser was trust.  It is not good business practice to threaten, throttle or block the internet connections of your customers.

CDB

The second regulatory vehicle I’d like to look at briefly is the Communications Data Bill. Section 1 of the Bill essentially gives the Secretary of State and her successors a blank cheque and they get to order anyone to do anything that can be related to facilitating access to communications data. Yes she gets carte blanche to order tracking, monitoring, surveillance, watching, interception, collection and use of any data she likes about everybody, however and whenever she feels like it with essentially no meaningful oversight or accountability. 

S9 of the Bill relates to the authorisations for obtaining data by police and other public authorities.

The government has the right to intercept and record information when someone is suspected of a serious crime. They have the right to engage targeted intelligence led surveillance on anybody. They should not have the right to engage in monitoring everyone.  But these proposals mean collection of data without suspicion or oversight: which is in effect uncontrolled mass surveillance. Due process requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To instigate the new set of legal norms envisaged in the Communications Data Bill which subsequently give the entire population less protection than a hitherto genuine suspected criminal is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is also unlawful.

There is a significant danger in measures like the CDB of stumbling by default into a police state, just because the technology of mass surveillance is now more readily available and nominally more sophisticated. We need to avoid deploying these technologies blindly in response to some perceived threat. Without sufficient reasoned analysis of the purpose and detailed requirements of the technical systems we propose to build to counter these threats, we could find ourselves building technological monsters. Building an infrastructure of surveillance makes our three sets of stakeholders – innovators/creators, economic agents and the public – more vulnerable not less so to attacks by criminal elements such as the four horsemen of the infocalypse and rogue states with malevolent intent.

ISPs will evolve from the copyright police of the DEA to surveillance agents of the state under the CDB and that kind of mass surveillance is no way to engender trust. It also doesn’t work as any of the economists in the room with an understanding of Bayes theorem and the base rate fallacy will tell you.[7]

Under the CDB the only winners are the suppliers of the technology of surveillance. All other stakeholders lose and the damage to trust is potentially irreparable, in spite of the public being hugely forgiving of mass data collection.

We get bad laws when governments don’t understand technology

It’s a caricature but governments generally have two simplistic perspectives on technology:

  1. It is a magic solution to ill defined political problems that can be easily presented to the rabid 24 hour news media
  2. It is a terrifying tool that is used by the four horsemen of the infocalypse for nefarious ends, therefore requiring blanket surveillance.

The internet they see as TV on steroids or an online shopping centre best controlled by the entertainment industry.

This ignorance is bad for our three sets of stakeholders

    • Innovators/creators
    • Agents
    • Public
The laws this ignorance fosters, such as the DEA and CDB, undermine trust. And they undermine it in ways that are at best difficult or almost impossible to remedy. Mandating and building technological architectures of surveillance is bad for everyone but the agents who monetise and control those technologies.

Conclusion

The innovators and the public are hugely forgiving of or blind to economic agents’ (both commerce and government) data gathering.

That gives the powerful agents – commercial and government – substantial responsibility. Data pollution is the environmental disaster of the digital age and it is going to play havoc with trust in the digital economy.

For commercial agents delivering secure convenient products and services at a reasonable price, not suing the competition based on dodgy law, is the key to success.

For governments, can I recommend Professor Chris Reed’s doctrine of creative inertia when it comes to making laws about the internet, especially in relation to mandating architecture of surveillance? Mainly, don’t. And if you must, take the time, the care and the considerable cognitive effort that is required to find out what it is you’re dealing with first.

In relation to trust in the digital economy where have we got to?

Firstly we should understand, as my friend John Naughton says, that the internet is a global machine for springing surprises.

So:
  • Innovators need to engage with it
  • Governments need to apply creative inertia principle to regulating, especially with respect to surveillance architectures. They also need make a better effort to understand it (and those subsets of stakeholders who do understand it need to get better at explaining it to them)
  • Commercial agents, particularly those making hay from bad regulations e.g. entertainment companies and surveillance technology companies, need to understand that unfettered data pollution will come back to bite all three sets of stakeholders
  • And citizen consumers need to get educated, engaged and active

That’s it and if you have been, thanks for listening.
 

*Transcript of the talk as written rather than as delivered.  I spent a little longer on the DEA than I intended and didn't cover the CDB other than in outline

[1] Following some interesting experiences at Heathrow airport yesterday I was tempted to change my talk to outline how lack of trust nearly led to me not making it here at all but that’s a story for another day.  See http://b2fxxx.blogspot.co.uk/2012/09/the-chief-immigration-officer-and-me-or.html for the details.
[2] How copyright enforcement robots killed the Hugo Awards http://io9.com/5940036/how-copyright-enforcement-robots-killed-the-hugo-awards.
[3]See Don’t blame the copyright bots, says CEO of copyright bot company http://www.slate.com/blogs/future_tense/2012/09/07/vobile_ceo_yangbin_wang_copyright_bots_didn_t_kill_ustream_s_hugo_awards.html
[7] See Rudmin, Floyd (2006) ‘The Politics of Paranoia and Intimidation: Why does the NSA engage in mass surveillance of Americans when it is statistically impossible for such spying to detect terrorists?’ http://www.counterpunch.org/rudmin05242006.html for a lovely succinct illustration of this.

Saturday, September 08, 2012

The chief immigration officer and me...

...or how I briefly became the Mehran Karimi Nasseri of Heathrow

I’ve been in Aberdeen for a conference on trust in the digital economy.

Funny enough I nearly didn’t make it and by the time I got there was very tempted to change my talk to outline why.

It all started with the booking of a BA/Bmi flight to Aberdeen via the internet.

Everything was fine with the booking. The confirmation email came through. I printed the itinerary and ignored the small print since I’ve done this so many times before. That was my first mistake.

Before logging off I did a quick check with the neat little “Which terminal” search gadget on the Heathrow website.

That was my second mistake.

You see I trusted the answer I got.

Heathrow flights to Aberdeen, it said, go from Terminal 1. (Though, interestingly enough I just did the search again and it says BA flights to Aberdeen go from terminals 1 and 5 and Bmi flights go from terminal 1). A glimpse at the final page of the confirmation email confirms the flight back from Aberdeen on the Thursday lands at terminal 1. My misplaced trust is re-inforced.

Ok off I go to the Heathrow parking site and book my parking for the 36 hours or so I’ll be away. Extortionate. But will I pay the extra £6 to park in the business class carpark and get back to my car 15 to 20 minutes earlier upon return. Hang it, it’s £6, so yes. Been working long hours and the extra 20 minutes at home won’t do me any harm. All done.

24 hours before departure I get the email that tells me I can now check in online. I click the link, go through the steps and print the boarding pass. No need to check that. I’ve seen too many of them. Mistake number 3.

Morning of departure I hear on the radio that there’s been a vehicular collision between junctions 4 and 3 of the M4. Balderdash that’s Heathrow. I’ll have to set out earlier than I intended. Luckily by the time I decided I have to set out the accident and the road have cleared so I get an extra hour’s grace.

Finding the car park at Heathrow is the usual exercise in multiple road junctions and signage overload but I make it without incident. And things are looking up – the bus driver is just on his way out of the car park when he spots me, stops at the exit and hails me over. What a decent chap. Fortunately I was to encounter a number of decent and caring people in the next few hours.

Off the bus and into terminal which has changed since I was last here and I head straight for security with my boarding card. Just as I reach security I realise I’ve left my passport at home. That was mistake number 4. Ridiculously it is a good idea to always have your passport with you even on domestic flights. Anyway I explain to the security guy I’m only going to Aberdeen and wonder if it will be ok if I don’t have my passport.

“Dinnaw may. We’s just sehcurihy. Check wi the BA desk”

No problem. Sensible suggestion. So I head for the nearest BA desk where a helpful chap assures me I don’t need a passport to fly from Heathrow to Aberdeen. Back I go to departures initial security check desks where my first encounter is busily checking someone’s boarding card so I go to his colleague. She scans my home printed boarding card and gets the ok from the system and waves me through.

Head for the x-ray machines. Laptop out. Jacket off. Belt and watch. They also want my kindle out of the bag, so out it comes. Hang onto trousers since I’ve lost a couple of inches round the waist with the help of the bike. No beep from the scanner as I walk through so I get away without a pat down.

Belt back on, I can stop hanging onto my trousers. Get all the gear back in the bag and I’m set for the waiting lounge. Check the screens for my flight. That’s strange. It’s not there. There is a BA flight at 14.30 but not 14.10. Need the gents then I’ll consult security.

Back to the vicinity of the x-ray machines and there is a group of security people here chatting. I explain my flight isn’t on the board and I’m puzzled. None of them are too concerned as they assure me Aberdeen flights go from terminal 1. Then star number 1 of the show appears. She’s called into the conversation and genuinely takes me under her wing. “Don’t worry. It’s really confusing. BA and Bmi have been changing the numbers of their flights and the same flight changes sometimes on the screens. Let’s go and look and I’ll show you.”

No one has any doubt but that I’m at the correct terminal. We get back to the screens, spot the 14.30 BA flight again and my guardian angel of terminal 1 explains I need to watch flight details they will change back and forth between the number on the screen and my flight number.

We wait. No change. She’s puzzled. Never mind it’s just a system problem. All the Aberdeen flights go from gate 8 so just head down there when the time comes. Thanks a lot for your help. I’m partly but not entirely re-assured. At this point I decide to check my flight itinerary. Sure enough in the small print near the end it says I’m flying out of terminal 5. Terminal 5! How the heck do I get there from here in time?

Back to x-ray machine area where guardian angel has not wandered too far and explain my itinerary and my boarding pass (which I now decided to glance at too) both say terminal 5. Uh oh. Guardian angel says don’t worry. Let’s go see the suited security guys and get a definitive answer off the system.

“Can you check this flight number for me? The gentleman is flying to Aberdeen but his boarding pass says terminal 5. Couple of phone calls. Check the system. Yup I’m going out from terminal 5. Now what? Can I make it on time?

Guardian angel: “ don’t worry you have plenty of time. Just head down towards the gates and follow the flight connections signs which will lead you to a bus that will take you straight to terminal 5. You’ll be there in 10 minutes.” From start to finish this lady was terrific. She saw a passenger with a non-standard problem and helpfully took it upon herself to sort it out. Kudos to her.

I make my way via the air side bus to terminal 5. Here’s where the problems really begin. I get directed through a BA desk but beyond that is Border Control. Now I know there are difficulties ahead.

I explain to the very kind BA desk staffer that I haven’t got my passport, erroneously started out at terminal 1 and got sent over here via the bus. The very agreeable woman scans my boarding pass, says she doesn’t need my passport and I should be ok as long as “they”, gesturing to Border Control let me though; but by the way they have changed my seat number from 32A to 22D. She doesn’t know why. Possibly because the Airbus 319 only has 22 rows of seats. So I’m a little unsure why I might have been put in row 32 in the first place. She prints me a new boarding pass, wishes me a pleasant flight and waves me through.

I know this isn’t going to work. The queues are long. The border staff are under pressure. I get to the head of the queue and explain to my border control guard that I haven’t got my passport for reasons outlined earlier.

“Sir how did you even get here? You shouldn’t be airside at all.” I explain again. He’s very courteous but explains he cannot let me through border control without a passport. He’s thinking on his feet though about how to help. “Sir what nationality are you?” Though I can tell he’s already pegged my accent, I explain I’m Irish. “I’m sorry sir. If you’d have been British and held a British passport I could have called your details up on the computer in a few minutes and checked you out.” He’ll have to consult his boss, the chief immigration officer. But for the moment I’ll have to wait until the queues clear.

Fair enough.

I wait. The queues are shortening. They clear. My border guard (there were 4 on duty) goes off to talk to management. He walks with the aid of a stick so I feel doubly guilty for making his life difficult.

I do get the opportunity while waiting to watch border control in action. They are efficient and courteous. I don’t like the quizzing of ethnic minority small children to check the woman they are with is their mother. Don’t get me wrong. It’s done in a friendly way. Big smile. “Hello what’s your name? Where’s your mum?” And checking to see if the chid indicates the woman. They are doing their job.

My guard gets back and says he cannot process me though border control without officially approved identification documents. I have credit cards but the only photo ID I have is an Oxford University library card. He might be able to do something with a driving licence but even that is not officially approved. “But the chief immigration officer will arrange to have a security person escort you to your flight though a different route. The chief immigration officer is arranging that for you now sir. “

Thanks. I really appreciate your help. I still don’t fully appreciate, yet, the Mehran Karimi Nasseri (or Tom Hanks in 'The Terminal') nature of my situation. But everyone is being as helpful as they can given the circumstances and even if I don’t get to fly (my flight time is creeping up fast) I’ll at least get a blog post on airport security out of this. How did a passenger get to border control for a domestic flight and what went wrong to get him there?

I tell the officer that ironically I’m going to Aberdeen to give a talk about trust. Not a flicker of amusement. Border control is a serious business.

Guardian angel number 2, a security lady called Kat, appears. She’s is just brilliant. The border control man who I’ve also got to like a lot by now explains my predicament to Kat. He also notes I’m a security, airline and port authority problem not a border control problem. Kat thinks and says no worries she has an idea of how to get me to the right gate for the flight. Off we go following thanks to my professional border man.

Cognisant of the imminent scheduled departure of my flight Kat moves quickly and talks to a colleague (boss?) on her walkie talkie. She explains my situation and how she is going to deal with it. She just needs his (it is a male, I can hear his responses) ok to pass through a security gate.

He says no. No way. Not a chance. I’m border control’s problem. Get them to let me through.

Right. We stop. U-turn.

Back to my friend at Border Control. Fortunately the queues aren’t too bad and we indicate we’ll wait to the lady who is free until my friend deals with his last current passenger. He gives us a weary glance. And explains again I’m not getting through there. But he’s not giving up on me.

He and my wonderful security Kat agree I’m a security failure in terminal 1. He also points out again that though he’s not letting me through I’m an airline and port authority problem and if both agree I can get on my flight then they should be able to get me physically there via a different route to border control. Let’s go consult the airline.

We go to the BA desks just ahead of border control. The woman who had printed my new boarding pass is no longer there. The one member of BA staff who is there is actively disinterested, glances repeatedly at me as though I might be something nasty she just stepped in and makes it abundantly clear she doesn’t want to get involved. The first unhelpful person I’ve encountered today. Remarkable how I could have achieved such pariah status in the eyes of someone I have barely met properly or even spoken to.

So Kat, Border man and I head for the BA desks behind which are offices in which the duty officer resides. We explain my story to the man at the desk and though he’s not sure what to do he’s helpful and quickly summons the duty officer, another star of the day.

My flight departure time has by now come and gone. The duty officer is great. Guardian Kat and Border man explain the situation and border man explains the rules. The duty officer grins cheerily and tells me I’m a first. Nice to know I’ve brightened someone’s day and regained membership of humanity after the unfortunate attitude of the previous BA woman. The duty officer has a think and meanwhile the border man explains (he has noted it a couple of times before) that I really am a Tom Hanks. No documents, so I can’t get through Border Control either to get on my flight or get out of the airport. An undocumented alien who should not be where I am right now.

“I really am Tom Hanks!” I’m still thinking this is going to make a great story. He also notes the titles of a couple of border control statutes which might be applied under one of which exists a power to search me for drugs. But since he’s getting to know me now, he almost smiles and says he’s not going to search me for drugs, as he has absolutely no reason to be suspicious on that account. I risk “I think I need a couple of paracetamol for a headache.”

Duty officer has a solution. Pretty much the solution that guardian Kat has previously come up with. Border man says cheerio and good luck and shakes my hand. I thank him sincerely and say goodbye to another star.

Luckily for me, though my flight has long since gone, I believe, duty manager discovers it’s been delayed and I still have a shot at making it. Though they’ll book me on a later flight if not. Guardian Kat, duty manager and I take off again. We get to a BA desk near – to the side of border control. The lady there wants to check my documents etc. Duty star sorts that out and waves me and Guardian Kat on our way. My final encounter with star number 3.

Kat and I are moving quickly again. Dodging crowds and queues we get to another set of security and X-ray machines. Kat gets me and my bag to the front of the queue and she and I traverse security again. She has to put her walkie talkie etc through the machine too. We take off again at an increased pace once I’m belted up and repacked again. Kat and duty manager have let the airline and port staff at the gate know I’m on the way and we learn that the flight is just boarding.

I make it in time to be the penultimate passenger on the plane. I thank Kat yet again for all her help. She’s been an absolute diamond and deserves a commendation for going above and beyond the call of duty.

And that’s the bottom line. When we make mistakes and there are system failures we need caring dedicated people to fix things.

If everyone had taken the attitude that they were just following the rules, or worse the attitude of the BA woman who apparently found me to be unforgivably distasteful, then I might still be stuck at Heathrow.  As it was I encountered 4 stars – security guardian at terminal 1, professional border man at terminal 5, my guardian security Kat and the BA duty officer, who all cared enough and actively made it their business to help out a traveler with problems.The decent car park bus driver must also get an honorary mention along with this band of heroes - he didn't have to stop for me on his way out of the car park but he did. He put me in a good mood and that undoubtedly helped with the perils ahead. It might have been him that made all the difference.

I realised in the final dash for the plane that I didn’t know any of their names and that’s when I asked and discovered my guardian angel was called Kat. So thank you again bus driver, security Kat, Ms Terminal 1, border man and BA duty officer. Apologies for not getting to know your names but thanks for your care, your energy and your unfailing courteousness in getting me to my planned destination and for making what could have been a difficult experience extraordinarily stress free.

I hadn’t planned, on getting up on that Wednesday morning to make anyone's lives difficult and certainly not the lives of such helpful people.

Postscript

The return leg from Aberdeen was a little smoother. Roll up to the airport on the bus. Check in at the self service check in. Print my boarding pass there. Through security to the departure lounge. The 54 seat Embraer aircraft I flew back on is a neat little machine and London is spectacular from the air at night.

I got a brief but beautiful bird's eye view of the Olympic stadium at just about the time Jonnie Peacock was winning the T43/T43 100m final at the Paralympics. The bonus was also that my flight landed at Terminal 1. No complicated Heathrow business this time. Straight out onto the car park bus and I'm on my way home. I had to do a 25 mile detour due to a road closure and an idiot in a BMW who tried to kill me, him and everyone around us on the M4. But that's a story for another day.

Wednesday, September 05, 2012

Stop opt-out “Adult” filtering

The Open Rights Group are encouraging people to respond to the consultation by the Department for Education on parental internet controls. Closing date tomorrow, 6 September.

I'm really busy this evening but sent off the note below.  It was done in a hurry as a stream of consciousness (including cut and pasting from earlier blog posts) and it has not been critically read. So if anyone spots anything silly let me know asap, please. I also neglected to put a defence of unwelcome speech section in e.g. if freedom of expression means anything, it must be granted to those whose views and creative work are considered by some people to be despicable, disgraceful, sacrilegious, uncomfortable and disgusting (e.g in the case of "adult material" church, political and other groups find pornography highly offensive).

A copy of this email is going to my MP. I am raising my concerns about the proposal for network filtering of adult content and default blocking.

I would like to submit the following evidence:

Blocks do plenty of harm, but little good. They always block the wrong sites. They are pretty much useless at determining what exactly constitutes "adult material" whilst always overblocking innocent sites. Filters have been blocking my academic blog at http://b2fxxx.blogspot.co.uk/ or as Yahoo! did labelling it a "dangerous download"  for years.  I couldn't access my own blog from my mobile because up until earlier this year Orange blocked all blogs.

Just this week bots have taken down the live streaming of the Hugo Awards, the world's most prestigious science fiction awards, and the Democratic National Convention!

Ofcom has pointed out in a report related to the Digital Economy Act that web blocking is unworkable. And government is committed to abolishing section 17 of the DEA on web blocking.  In 2011  far reaching decision the Advocate General of the European Court of Justice, Cruz Villalón, concluded that

    "a measure ordering an internet service provider to install a system for filtering and blocking electronic communications in order to protect intellectual property rights in principle infringes fundamental rights".

In the context of child protection web blocking is counter productive and dangerous. It's not even hard to see why blocking is dangerous and stupid in this context - it leaves the crime scenes online, the criminals at large and the abused kids in danger, whilst enabling governments to pretend that they are "doing something". If a fraction of the energy that went into trying to pass such blocking provision and collating lists of worst of the worst sites actually went into tracking these abhorent child abusers, taking their servers offline, rescuing the kids involved and successfully prosecuting the offenders, there might be some inroads made into tackling the problem. So viewed purely as a child protection measure alone, web blocking is fundamentally flawed, risky and irrational.

As COADEC say "Not only does this system of blocking sites have an effect on freedom of speech, but these kinds of blocks can be devastating to digital businesses who generate revenue through their sites. Default blocking inadvertently blocks perfectly legal and legitimate businesses and organisations, and a reporting and redress process that is complicated, and lengthy, could seriously inhibit a business who launches their site to discover it has incorrectly been blocked."

You cannot fix a social & political problem with technological filters.  It's irresponsible to try and do so and I'll just leave you with Scott Adams take on the likely success of such an approach: http://dilbert.com/strips/comic/1996-01-23/

Friday, August 24, 2012

Submission to consultation on Communications Data Bill

I've sent a response to the consulation of the Joint Committee on the draft Communications Data Bill. Having been buried in meetings and battles with bureaucracy it was done at the last minute so may read as something of a tired stream of consciousness. Nevertheless I reproduce it below in the hope that if I've made any errors in the analysis my sharp eyed reader will put me straight.  I incorporated the Open Rights Group's draft letter to parliament on the subject as part of the submission, so that bit at least should be fine!


I would like to register my objection to the Draft Communications Bill.

My key concerns include:

Home Office vague on justifications for the Bill and the Bill does not solve the complex problems it has been posited as addressing

In multiple media engagements the Home Secretary and other supporters of the Bill mention "protecting the public" from all four horsemen of the infocalypse - terrorists, drug dealers, child abusers and organised crime - and more, on several occasions quoting the Met police chief as insisting passing this legislation is a "matter of life and death".

Building multiple massive databases of intimate personal communications data makes the public more vulnerable to the four horsemen not less so. That such mass surveillance will not work can be demonstrated mathematically.

Floyd Rudmin, Professor of Social & Community Psychology at the University of Tromsø in Norway, analysed President Bush’s authorisation of the National Security Agency’s (NSA) secret monitoring of the email messages and phone calls of all Americans (The Politics of Paranoia and Intimidation Why does the NSA engage in mass surveillance of Americans when it's statistically impossible for such spying to detect terrorists? May 24, 2006 by Floyd Rudmin

“The US Census shows that there are about 300 million people living in the USA.
Suppose that there are 1,000 terrorists there as well, which is probably a high
estimate. The base-rate would be 1 terrorist per 300,000 people. In percentages,
that is .00033%, which is way less than 1%. Suppose that NSA surveillance has an
accuracy rate of .40, which means that 40% of real terrorists in the USA will be
identified by NSA's monitoring of everyone's email and phone calls. This is
probably a high estimate, considering that terrorists are doing their best to avoid
detection. There is no evidence thus far that NSA has been so successful at finding
terrorists. And suppose NSA's misidentification rate is .0001, which means that .01% 
of innocent people will be misidentified as terrorists, at least until they are
investigated, detained and interrogated. Note that .01% of the US population is
30,000 people. With these suppositions, then the probability that people are terrorists
given that NSA's system of surveillance identifies them as terrorists is only
p=0.0132, which is near zero, very far from one. Ergo, NSA's surveillance system
is useless for finding terrorists.”

Rudmin takes one basic statistic – 300 million people in the US – and takes a conservative guess at some others e.g. the proportion of terrorists in the population. He then does wonderfully simple analysis to prove mass surveillance is useless for finding terrorists. The kind of conditional probability calculation done here by Rudmin is based on Bayes’ Theorem, taught in most introductory college statistics classes and is mathematically very sound.

Mathematically the 4 horsemen are not problems that lend themselves to data mining. Even highly accurate data mining systems will swamp investigators with false positives when dealing with a large population. Law enforcement authorities end up investigating and alienating large numbers of innocent people. Finding the horsemen is a needle in a haystack problem and you can’t find the needle by throwing infinitely more hay on your stack and/or creating multiple giant and exponentially growing data haystacks.

That such mass databases are useless for finding terrorists is clear. That they also make the public less safe is associated with the impossibility of securing mass silos of valuable personal data. Computer scientists simply do not know how to keep databases of the magnitude of those envisaged in the Bill secure from external hackers or the multitude of insiders who have access to these databases as a routine part of their jobs.  Security experts like Ross Anderson, Peter Sommer, Bruce Schneier and Richard Clayton have written extensively about this.  To understand this you have to think about how such systems can fail - how they fail naturally, through technical problems and errors (a universal problem with computers), and how they can be made to fail by attackers (insiders and outsiders) with malign intentions e.g. the four horsemen. When the inevitable hacks, leaks, data contaminations happen, what then?

Part 1 of the draft bill is indefensible

Part 1 of the draft bill gives the Secretary of State unlimited powers to mould data access regulations in perpetuity without the need to consult parliament in any meaningful way:

(1) The Secretary of State may by order—
(a) ensure that communications data is available to be obtained from telecommunications operators by relevant public authorities in accordance with Part 2, or
(b) otherwise facilitate the availability of communications data to be so obtained from telecommunications operators.
(2) An order under this section may, in particular—
[...]
(b) impose requirements or restrictions on telecommunications operators or other persons or provide for the imposition of such requirements or restrictions by notice of the Secretary of State"

There is no mechanism for amending such Henry VIII orders and they usually get rubber-stamped by Parliament without material scrutiny.  The Secretary of State and her successors get to order anyone to do anything that can be related to facilitating access to communications data:

If you combine this with, as barrister Francis Davey points out (see ‘The Communications Data Bill (first look)’, Sunday, 17 June 2012 at http://www.francisdavey.co.uk/2012/06/communications-data-bill-first-look.html), with the broad definitions given in clause 28 of the bill, e.g.

"“person” includes an organisation and any association or combination of persons
[..]
“telecommunications operator” means a person who—
(a) controls or provides a telecommunication system, or
(b) provides a telecommunications service,
“telecommunication system” means a system (including the apparatus comprised in it) that exists (whether wholly or partly in the United Kingdom or elsewhere) for the purpose of facilitating the transmission of communications by any means involving the use of electrical or electro-magnetic energy,
“telecommunications service” means a service that consists in the provision of access to, and of facilities for making use of, a telecommunication system (whether or not one provided by the person providing the service)"

- this Bill could theoretically, as currently drafted mean that we might be obliged to keep "who, what, when and where" records of family and friends social gatherings which involve listening to music, TV watching, internet or mobile phone use, electronic gaming or just chatting. Unlikely though that might currently seem and far though it may be from the current government’s intentions, the wording of the bill must be viewed in the light of the inevitable progressive function creep (discussed below) and through the lens of a less benevolent future government.

Inversion of innocent until proven guilty principle

The notion that the day to day activity of every citizen should be recorded in the expectation that those records can, in future, be mined for nefarious activity is anathema to a healthy functioning liberal democracy.

Control of my data

I have no control over my data, once it is collected by third parties’ on behalf of the government. The government is placing me at risk without my consent. The risks include
1.         That police have access to a record of my political beliefs and social habits
2.         That these records could be shared with private investigators or journalists
3.         That these records could be unlawfully accessed by foreign governments or criminal gangs, and aid further identity fraud, blackmail or account hacking

This runs counter to everything governments including ours are trying to do through promotion of good privacy practice and data protection policies.

Suspicion should be the test for surveillance

The government of course has the right to intercept and record information when someone is suspected of a serious crime. But these proposals mean collection of data without suspicion: which is in effect mass surveillance. Due process requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To instigate the new set of legal norms envisaged in the Communications Data Bill which subsequently give the entire population less protection than a hitherto genuine suspected criminal, based on a standard of reasonable suspicion, is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is unlawful.

Accessing big data sets opens up new police surveillance powers

Being able to compare location data, contact histories, websites visited and so on will give the police the generalized ability to track any group, from sports fans to political protesters. This will create extreme risks for whistleblowers, journalists’ sources and legitimate but inconvenient forms of protest.

This is not “preservation” of capacity but a huge extension of policing powers, which deserves proper democratic debate, starting with a full public consultation.

Undermining of Fundamental Rights

The proposals fundamentally undermine the right to privacy guaranteed in the Human Rights Act and article 8 of the European Convention on Human Rights. The Bill also undermines fundamental rights relating to freedom of assembly, speech, religion and association.

Comms data and traffic data cannot be separated simply in the way that the Bill assumes


Function Creep

I can only echo the concerns on function creep expressed by Paul Bernal in his submission to the consultation:

"when a system is built for one purpose, that purpose will shift and grow, beyond the original intention of the designers and commissioners of the system. It is a familiar pattern, particularly in relation to legislation and technology intended to deal with serious crime, terrorism and so forth. CCTV cameras that are built to prevent crime are then used to deal with dog fouling or to check whether children live in the catchment area for a particular school. Legislation designed to counter terrorism has been used to deal with people such as anti-arms trade protestors – and even to stop train-spotters photographing trains.

In relation to the Communications Data Bill this is a very significant risk – if a universal surveillance infrastructure is put into place, the ways that it could be inappropriately used are vast and multi-faceted. What is built to deal with terrorism, child pornography and organised crime might creep towards less serious crimes, then anti-social behaviour, then the organisation of protests and so forth. Further to that, there are many commercial lobbies that might push for access to this surveillance data – those attempting to combat breaches of copyright, for example, would like to monitor for suspected examples of ‘piracy’. In each individual case, the use might seem reasonable – but the function of the original surveillance, and the justification for its initial imposition, can be lost."

The temptation for public and commercial services to use the data gathered for purposes not originally intended will be overwhelming. If it can be done it will be done regardless of original good intentions.

RIPA needs to be fixed first

Data retention is already excessive and creating risks. The access policies for police are too wide and lack judicial supervision. There is no notification policy for people who been placed under surveillance.

These problems should be fixed before the government suggests new surveillance powers.

We are in a recession

Spending billions of pounds surveilling innocent people while cutting back on policing seems wrongheaded. I would rather money is spent on front line intelligence, policing, detection  and emergency response work.

Bad examples to foreign governments

There are no democratic governments that force companies to aid surveillance through collection and creation of new data sets. How can the UK seriously stand up for human rights while abusing the privacy of millions of innocent citizens?

Conclusion

The government has failed to make the case for the need for the new powers proposed in the draft Bill. There is a significant danger in measures like the CDB of stumbling by default into a police state, just because the technology of mass surveillance is now more readily available and nominally more sophisticated. We need to avoid deploying these technologies blindly in response to some perceived threat. Without sufficient reasoned analysis of the purpose and detailed requirements of the technical systems we propose to build to counter these threats, we could find ourselves building technological monsters. Building an infrastructure of surveillance makes our citizens and our state more vulnerable not less so to attacks by criminal elements such as the four horsemen of the infocalypse and rogue states with malevolent intent.