Wednesday, June 18, 2014

Irish High Court refers Schrems Facebook privacy case to ECJ

The Irish High Court has this morning referred Max Schrems Facebook privacy case to the European Court of Justice. Judge Hogan (at p33) refers the following specific questions -
Whether in the course of determining a complaint which has been made to an independent office holder who has been vested by statute with the functions of administering and enforcing data protection legislation that personal data is being transferred to another third country (in this case, the United States of America) the laws and practices of which, it is claimed, do not contain adequate protections for the data subject, that office holder absolutely [sic] bound by the Community finding to the contrary contained in the Commission Decision of 26 July 2000 (2000/520/EC) having regard to Article 7 and Article 8 of the Charter of Fundamental Rights of the European Union (2000/C-364/01), the provisions of Article 25(6) of Directive 95/46/EC notwithstanding? Or, alternatively, may the office holder conduct his or her own investigation of the matter in the light of factual developments in the meantime since that Commission Decision was first published?
Judge Hogan's summary of overall conclusions runs from paragraphs 74 to 84.
"74... Mr Schrems' complaints are not "frivolous or vexatious"...
 75... Mr Schrems enjoys locus standi to bring this complaint and to bring these proceedings. It is irrelevant that Mr Schrems cannot show his own personal data was accessed in this fashion by the NSA, since what matters is the essential inviolability of the personal data itself. The essence of that right would be compromised if the data subject had reason to believe that it could be routinely accessed by security authorities on a mass and undifferentiated basis.
76... the evidence suggests that personal data of data subjects is routinely accessed on a mass and undifferentiated basis by the US security authorities.
77... as far as Irish law is concerned, s. 11(1)(a) of the 1988 Act forbids the transfer of personal data to a third country unless it is clear that that jurisdiction sufficiently respects and protects the privacy and fundamental freedoms of the data subjects. In this particular context of national law, the standards in question are contained in the Constitution.
78... the chief constitutional protections are those relating to personal privacy and the inviolability of the dwelling. The general protection for privacy, person and security which is embraced by the "inviolability"  of the dwelling in Article 40.5 of the Constitution would be entirely compromised by the mass and undifferentiated surveillance by State authorities of conversations and communications which take place within the home. For such interception of communications to be constitutionally valid, it would, accordingly, be necessary to demonstrate that this interception and surveillance of individuals or groups was objectively justified in the interests of suppression of crime and national security and, further, that any such interception was attended by appropriate and verifiable safeguards."
Just an aside on that last sentence in that paragraph - it could be interpreted as reading that surveillance would be justified "in the interests of suppression of ... national security". Let's just assume that's not what the good judge was attempting to convey.
"79... if the matter were to be measured solely by Irish law and Irish constitutional standards, then a serious issue would arise which the Commissioner would then have been required to investigate as to whether US law and practice in relation to data privacy, interception and surveillance matched those data standards."
(The "Commissioner" referred to is the Irish Data Protection Commissioner).

In paragraph 80 Judge Hogan explains, however, that Irish standards are effectively bypassed by the data protection directive and the European Commission's Safe Harbour agreement with the US; and the EC 2000/520/EC decision essentially declaring the US privacy-safe territory for EU personal data.
"81... it follows, therefore, that if [my emphasis] the Commissioner cannot look beyond the Commissions Safe Harbour decision of July 2000, then it is clear that the present application for judicial review must fail... because the Commission has already decided that the US provides an adequate level of data protection...
82... in holding that the complaint was unsustainable in law, the... Commissioner has ... demonstrated scrupulous steadfastness to the letter of the 1995 Directive and the 2000 Decision.
83... the applicant's objection is, in reality, to the terms of the Safe Harbour Regime itself rather than to the manner in which the Commissioner has applied the Safe Harbour Regime...
84... the critical issue which arises is whether the proper interpretation of the 1995 Directive and the 200 Commission decision should be re-evaluated in light of the subsequent entry into force of Article 8 of the Charter and whether, as a consequence, the Commissioner can look beyond or otherwise disregard this Community finding. It is for these reasons accordingly that I have decided to refer this question (and other linked questions) to the Court of Justice..."
My brief take -

The Irish High Court's decision amounts to a critique of mass and undifferentiated surveillance by state authorities, particularly the US. However, the much maligned Irish Data Protection Commissioner, Billy Hawkes, gets a pat on the back in rejecting Mr Schrems complaints, for "scrupulous steadfastness to the letter" of the data protection directive of 1995 and the EC Safe Harbour decision on the US in 2000. It appears, however, to constitute significant progress for Mr Schrems Europe v Facebook campaign and a small step in the right direction (nearly said "directive" there) for privacy in digital communications.

Note: Post above amended from earlier following access to full decision. 

Update: One other thought - Judge Hogan seems to think the Commissioner is boxed in by the data protection directive and the 2000 European Commission decision on Safe Harbour; but from my limited dealings with the Irish Data Protection Commissioner's office they seem to be more boxed in by a lack of resources and by their agreement with Facebook.

Thursday, June 05, 2014

Privacy cost of Cadbury's "Joy" promotion

Inside a chocolate bar wrapper:
"Joyful jubilations!
You've won a FREE
chocolate bar!"
Visit Cadbury.co.uk or Cadbury.ie and enter the code below..."
They've got to be kidding? Right? Nope.

Ok, I'll bite (sorry, couldn't resist).

Pull up the Cadbury site. Promotion front and centre. Click on the enter the code for FREE chocolate bar button. Click on the enter the code button again on the next page. Enter the code. Click through.

"Oh JOY! You've won a free
chocolate bar.
Enter your details to get your Cadbury coupon for one of the bars below."

Now they want a name and email address and here we have it - the links to the 2378 word terms and conditions and 3134 word privacy policy. I'll try the privacy policy first. Not sure I could stomach the terms and conditions. (That one I'm not apologising for).
"Mondelez Privacy Policy
All content on this website is owned and operated by Mondelez UK Ltd ("MDLZ" or "we")..."
Ok so I'm not even dealing with Cadbury any more? Oh yeah I forgot. Mondelez manages Cadburys for Kraft. Move along.
"Your access to and use of this Site and its contents (the “Site”) is subject to the terms and conditions of this Privacy Policy... By accessing and using this Site, you (the “User” or “you”) accept and agree to these terms and conditions without any limitation or qualification."
Absolutely. Accept urrg ur I agree... After all  my FREEE (sic - given the privacy policy has a number of typos I figured I was entitled to one and you can have that one for FREE) chocolate bar is in your hands.
"What type of data do we collect?
Personally-Identifiable Information On our Site, we may collect certain personally-identifiable information, such as name, gender, telephone number and e-mail address...
We may use cookies, web beacons/pixel tags, log files, and other technologies to collect certain information...
We may obtain information about you from other sources, including commercially available sources, such as data aggregators and public databases. This information may include name, demographic information, interests, and publicly-observed data, such as from social media and shopping behavior... "
All that data? "FREE" chocolate bar?

How do you process and use my information? For "promotional offers, materials, and other communications and information about MDLZ", to respond to me, to contact me...
" In addition we may use such personal information:
  • to respond to your questions and requests, to provide you with access to certain areas and features and to communicate with you about your activities on this Site;
  • to share it with our Related Parties as required to perform functions on our behalf in connection with the Site (such as delivery of merchandise, administration of the website or promotions or other features on it, marketing, data analysis or customer services). To do so, it may be necessary for us to transmit your personal information to outside the above Jurisdiction, and, where the site is based within the European Economic Area (EEA), to outside the EEA, and you agree to this transfer. Further use or disclosure of the information by them for other purposes is not permitted. To provide you with product information or promotional and other offers from us or our Related Parties;
  • if required by law, regulation or court order;
  • for the purpose of or in connection with legal proceedings or necessary for establishing, defending or exercising legal rights; or
  • in an emergency to protect the health or safety of website users or the general public or in the interests of national security."
So you are going to share my information with "Related Parties" including transmitting it outside the  European Economic Area (EEA) and I agree to this.

Dey don't know me vewy well do dey?

As if that extracting of the proverbial Michael Mouse wasn't enough, national security?!! I hereby put out a call to Bruce Schneier to include a special category in his 8th annual movie plot threat contest next year for plots centred on chocolate bars.
"How we share your information
    We do not sell or otherwise disclose personally identifiable information about our website visitors..."
Hang on, you've just said exactly the opposite.
"... except as described here."
So when you say you don't sell or disclose personally identifiable information, what you mean is you do. Gotcha.
"We may share personally identifiable information among MDLZ and MDLZ brands and subsidiaries... with service providers... [who may] disclose the information as necessary... In addition, we may disclose information where we think it’s necessary... in response to a request from... government officials
We may share with our promotional partners (and their service providers)... "
Ok so you're giving my information to all and sundry. What about security?
"The security of personally-identifiable information is important to us... To the fullest extent permitted by law, we disclaim all liability and responsibility for any Damages you may suffer due to any loss, unauthorized access, misuse or alteration of any information"
Ah yes. The old security is important but it's never, ever going to be our fault if we muck it up routine.

Well at least I know what I'm signing up to. It's all clear and fixed at the time I claim my FREE chocolate bar.
"We may change or update parts of this Data Privacy Statement at any time and without prior notice to you."
 Er. You and only you can change the deal at any time after it is concluded?

Right then I demand to know how long you are going to keep all the data you will gather on me, in exchange for this FREE chocolate bar you are offering.
"Your personal data will be kept by Mondelez Europe ... for as long as is reasonably necessary for the purposes for which they are processed"
That's clear, except you can change the deal whenever you feel like it. And despite it being a breach of a fundamental data protection principle, the purposes for which you are collecting this data appear already to be pretty fluid, even before you decide to change them at some unspecified point in the future.
"Children
    We take the protection of children’s privacy seriously. We operate this Site in compliance with all applicable law in the above Jurisdiction. Children under the age referred to below for the appropriate Jurisdiction for the Site should have a parent/guardian’s consent before providing any personal information to the website. We will not, as provided by applicable law, require or request children under this age to provide more personal information than is reasonably necessary to participate in the applicable activity on the Site. If we determine upon collection that a user is under this age, we will not use or maintain his/her personal information without the parent/guardian’s consent. Without such consent, though, the child may not be able to participate in certain activities. However, in certain circumstances, we may maintain and use such information (in accordance with the rest of this Policy and applicable law) in order to notify and obtain consent from the parent/guardian and for certain safety, security, liability and other purposes permitted under applicable law. A parent/ guardian can review, remove, change or refuse further collection or use of their child’s personal information by contacting us as provided above (include child’s name, address and e-mail address).
Site’s Jurisdiction/Applicable Age:
  • United States & Australia: Under 13 years of age.
  • Other Jurisdictions: Under 12 years of age."
In short you take children's privacy seriously. Parents or guardians should be involved if kids under 12 want to claim a FREE chocolate bar and they can chase you to alter or remove the child's details from your systems. But hey, if the the kid ticks the box to say s/he is 16 or over when claiming the FREE bar that's the parents/guardians' problem not yours.

Last question, what if a corporate raider comes a calling? Cadbury has been subject to hostile takeovers bids in the past after all.
"Transfer of assets
    During the course of our business, we may sell or purchase assets. If another entity acquires us or all or substantially all of our assets, personally and non-personally identifiable information we have collected about the users of the Site may be transferred to such entity. Also, if any bankruptcy or reorganization proceeding is brought by or against us, such information may be considered an asset of ours and may be sold or transferred to third parties."
Right so when the asset stripper moves in all bets are off and previous and loosely prevailing privacy "protections" are even more worthless than the prior electronic paper they were written on.

Fair enough. An hour down the road, even though I have not perused your terms and conditions yet, I now feel like I'm finally in a position to decide whether to indulge in joyful jubilations and claim my  FREE chocolate bar! My response Ms Rosenfeld, Chairman and CEO of Mondelez International is -
NO THANK YOU!
In fairness, Mondelez are just asking for a name and email address and engagement with their website, rather than anything more invasive in the first instance. They then email the coupon for the FREE chocolate (a certain Michael Mouse will be getting mine). But the overreaching "privacy" policy is all too typical and yet another indicator that the sugar industry is also now in the surveillance business.

Tuesday, June 03, 2014

John Oliver on FCC proposals to kill Net Neutrality

John Oliver, doing more in 13 minutes for the cause of net neutrality than years of campaigning by digital rights NGOs, academics and certain brands of big tech...



I particularly liked his point (at about 10m 20s) about corporate America understanding that "if you want to do something evil put it inside something boring. Apple could put the entire text of Mein Kampf inside the iTunes user agreement and you'd just go urrg ur I agree..."

His call to arms to internet trolls to explain, in the abusive way only they do, their disapproval, at fcc.gov/comments, however, may well land him in trouble, after the FCC site reportedly went under with the weight of the response elicited.

Saturday, May 31, 2014

Tuesday, May 20, 2014

Note to Chairman of JCSI on copyright exceptions

Given the recent decision of the Joint Committee on Statutory Instruments (JCSI) to spend more time considering the implementation of private copying and parody copyright exceptions statutory instruments, I've written to the Chairman of the Committee, George Mudie. Copy of my note below.
Dear Mr Mudie,
As Chairman of the Joint Committee on Statutory Instruments (JCSI), I’m writing to you in relation to your committee’s recent consideration of the proposed five copyright exceptions statutory instruments (SIs). I note the Committee has concluded its consideration of three of the five but has some questions about the private copying and parody exceptions.


In light of the decision of JCSI to hold up the implementation of copyright exceptions SIs for private copying and parody, could I ask that you draw the Committee's attention again to the Consumer Focus report, 'The economic impact of consumer copyright exceptions'. It was first published in 2010, republished last year and is available at:

http://www.consumerfocus.org.uk/publications/the-economic-impact-of-consumer-copyright-exceptions-a-literature-review

The report itself may be accessed directly at:

http://www.consumerfocus.org.uk/files/2010/11/The-economic-impact-of-consumer-copyright-exceptions-Rogers-Tomalin-Corrigan.pdf.

Full disclosure - I am an academic at the Open University and was involved in producing the report, along with colleagues from Oxford University, Mark Rogers and Josh Tomalin. Mark was terminally ill at the time and sadly died in July 2011.

An Oxford University economist of international renown, Mark was a passionate advocate for evidence based policy making in the intellectual property arena. Down to earth family man, friend, academic and practical economist, optimist, writer, basketball coach and player, runner, cyclist, all round handyman and an infinite well of sound personal and professional advice, Mark was one of those impossibly nice, exceptionally talented and generous individuals you’d like your children to emulate. The dignity and positive outlook with which he faced his illness were genuinely awe inspiring. The simple fact that someone of Mark’s ilk devoted considerable energy, over many years, to the importance of evidence based intellectual property policy making speaks for itself. What he had to say about copyright exceptions should be of particular interest to the JCSI.

In relation to JCSI’s recent deliberations, our Consumer Focus report focused solely on copyright exceptions as they relate to non-commercial, consumer activities. It dealt specifically with private copy format shifting and parody. We concluded -

Investigating potential economic damage to rights-holders requires an analysis of how consumer copyright exception could affect the demand for the original creative work. The processes via which consumer copyright exceptions influence the demand curve for original creative work can be complicated. This said, a standard analysis of the demand for creative works must assume that consumers incorporate the benefit of copyright exceptions into their demand. A consumer’s decision to purchase is based on the benefits of the product, including – in the case of creative work – the value of any copyright exception. In this sense, it can be argued that a creator automatically extracts value from copyright exceptions, since these directly influence the demand for the original creative work.

The economic evidence that format-shifting, parody and user-generated content cause any kind of economic damage to rights-holders simply does not exist. Arguments that support tighter copyright law, or support Private Copying Remuneration (PCR) systems, tend to confuse economic damage with consumer value. Any future analysis on this issue needs to investigate the conditions under which the proposed consumer copyright exceptions would have any impact on demand for creative work.

I hope that you and the JCSI find the report helpful. If you have any questions or I can provide any further input to the Committee’s deliberations on copyright exceptions do let me know.

Yours sincerely,

Ray Corrigan

Ray Corrigan, Senior Lecturer in Maths, Computing and Technology, Open University;

Sunday, May 18, 2014

The Clarkson crisis and mass surveillance

I will try and find some time to consider in detail and blog about the European Court of Justice decision imposing an obligation on Google to make an effort to respect what many are calling 'the right to be forgotten.'

Firstly though, on a parallel theme of our recorded digital pasts returning to haunt us, could I point you at an edited version of some thoughts I had on the recent crises Jeremy Clarkson found himself embroiled in, that the very good folks at The Conversation kindly published earlier this week. A more detailed edition of those thoughts resides below.

I see Jeremy Clarkson is in the soup again for saying the wrong thing. This time he's accused of using the reviled, offensive, racist N word, in a Top Gear out-take two years ago. The usual gang of anti-Clarksonites and more than a few others have lined up to demand the BBC fire him. Perhaps surprisingly members of the government and some in the media not otherwise known as Clarkson fans have offered him qualified support.

Elsewhere various sexists, racists, homophobes, hatemongers and other assorted flavours of humanity that dislike people not like them are attracting the attention of the news media and political opponents for being associated in some way with UKIP. The Prime Minister David Cameron has been condemned for saying recently Britain is a Christian country.

The thing is, respect for the principle of freedom of expression means letting people we disagree with speak. It means letting people who say offensive things speak. It means letting people who say nasty, unpleasant, unsavoury, distasteful, dreadful, objectionable, idiotic, mean, poisonous, hostile, malignant things speak.  It means letting people who mumble casual blokey racist comments, in ill-judged attempts at humour, speak.

Letting people speak doesn't mean we have to listen to them. It doesn't mean we have provide them with a platform to speak. It doesn't mean the media is obligated to draw attention to them. And it doesn't mean we have to laugh with them in a way that encourages casual blokey offensiveness.

I fully accept  Deborah Lipstadt's mantra that 'Reasoned dialogue has a limited ability to withstand an assault by the mythic power of falsehood' (p.25 Denying the Holocaust - a wonderful book btw). But when destructive speech does take hold we have to counteract it. We must be better at explaining, in widely accessible & persuasive ways, why hate speech is so harmful pernicious and noxious. And we must expose the falsehoods and malign intent and/or ignorance underlying it intelligently, accessibly, in a publicly appealing ways and preferably backed up with solid evidence.

The UK Human Rights Act makes the European  Convention on Human Rights part of UK law. Article 10 of the Convention says everyone has the right to freedom of expression. We have the legal right to freedom of expression in the UK. As a member of the EU, we also have the fundamental right to freedom of expression guaranteed by Article 11 of the Charter of Fundamental Rights of the EU.

To make life complicated, in the UK there are also criminal offences relating to offending or insulting someone, under a variety of statutes including s127 of the Communications Act 2003 and s4A and s5 of the Public Order Act 1986.

A number of social network users have found this out the hard way, most notably Paul Chambers of Twitter joke trial fame. Mr Chambers was convicted of sending, by a public electronic communication network, a message of a "menacing character" contrary to sections 127(1)(a) and (3) of the Communications Act 2003. He had joked on Twitter about blowing up Robin Hood airport after his flight to see his girlfriend got cancelled due to snow. He lost his job and another thereafter, subsequently found it difficult to get work and it took two and half years of legal wrangling and appeals before the High Court finally cleared his name.

The media, the public and public figures, we all love a good witch-hunt, as long as we are not the object of the hunt. Soundbite politics, the 24/7 news cycle and our world of short attention spans see words and phrases taken out of context and wielded as weapons to demonise and misrepresent opponents, shout insults past each other, blame and preferably punish someone. Public debate can't get past megaphone soundbites of the 'we're the goodies they're the baddies' variety.  This is an arena that is positively hostile to deep and informed engagement with any subject matter but a fertile place for mob rule.

Could any of us withstand the kind of scrutiny Mr Clarkson's misspoken offence, recognised at the time but resurrected two years later, or Mr Chamber's Twitter joke was subjected to? Well to be blunt we are going to have to.

Why?

Well for the best part of the past 25 years commercial entities have been recording, storing, processing and analysing everything we see and do on the world wide web, for how long, from where, with whom and with what equipment. Additionally telecommunications service providers, both fixed line and mobile, have been obliged for some time, under the 2006 EU data retention directive, to store details of and provide government access to everything everyone does on the telephone or internet; for a period of between 6 months and two years.

Invisible digital watchers follow and record everything we do on digital communications networks without our conscious knowledge or consent.

Article 5 of the 2006 directive specified the data that has been gathered by communications service providers throughout the EU. It covers names, addresses, who spoke to whom, where, when, for how long, on what device, how often, websites visited etc. etc. This all paints a very detailed picture and most people don’t know it has been going on. The who, where, why, how, what and when of individual lives is all there in this 'metadata.'

We've also discovered in the past year via the revelations of former NSA contractor, Edward Snowden, that governments, in particular the UK and US variety, have been going much further, watching and recording our networked lives in even more detail than previously realised. If we thought about it at all which most of us don't. Through clandestine programs like GCHQ's 'Tempora' and the NSA's 'PRISM' all telephone and internet traffic is being collected, processed and stored nominally for current or potential future use in the fight against terrorism or serious crime.

Anyone's complete online life history can be examined in forensic detail even though commerce and governments could not possibly examine everyone's life in detail. The UK intelligence services collect about 40 billion pieces of data per day, for example, and simply do not have the capacity to apply human intelligence to all of it.

Just one of the problems with these mass commercial and governmental silos of personal digital life histories is that small items taken out of context can constitute unexploded digital ordinance. Equivalent to the two year old misdemeanour of Jeremy Clarkson. Most of us don't have the public profile of Mr Clarkson or the interest of the public to anything like the same degree. But as Cardinal Richelieu is rumoured to have said about 500 years ago, "Give me six lines written by the most honest man and I'll show you the evidence to hang him."

Innocent ordinary people, not just celebrities of Mr Clarkson's ilk, have found themselves at the sharp end of media witch hunts.  And which of us knows what nefarious activities people connected to people connected to people connected to us via the internet might have engaged in at some time in that past or potentially in the future? I ask that particular question because the then deputy director of the NSA, Chris Inglis, testified before Congress, in July 2013, that you don't need to be a suspected bad guy to gain the attention of the intelligence services. The NSA track people "three hops" from their targets. If I had communicated with 200 people during my online lifetime I'd be three hops away from over 5 million people. Through my job at the Open University alone I've interacted directly with thousands of people over the past nineteen years. Three hops from thousands connects me to more than the entire population of the world.

I think it is fair to call this mass surreptitious collection of personal data mass surveillance.

Interestingly enough, in a historic decision, On 8 April 2014 the Grand Chamber of the Court of Justice of the European Union hinted at the same conclusion when they decided to invalidate the 2006 data retention directive discussed above. With what may be interpreted as half and eye on the Edward Snowden revelations, the Court, effectively condemned pre-emptive, suspicionless, warrantless mass surveillance and consequent "interference with the fundamental rights of practically the entire European population".

The case was the first major court decision on mass surveillance since the Snowden stories started to break in June 2013. Though high courts in Romania (2009), Germany (2010), Bulgaria (2010),  the Czech Republic (2011) and Cyprus (2011) had previously all declared the data retention directive unconstitutional and/or a disproportionate unjustified interference with the fundamental right to privacy, free speech and confidentiality of communications.

On 23 April 2014, the Slovak Constitutional Court, taking its lead from the Court of Justice, suspended of the Slovak implementation of the directive. The UK government, by contrast, has declared the UK data retention regulations remain in force despite the directive that requires them no longer being so. The Home Secretary, Theresa May, has stated elsewhere that the implications of the ECJ ruling were being assessed.  For the first time, on 9 May 2014, a UK parliamentary committee expressed concern at the oversight of the security and intelligence agencies in this context and asked for a prompt and clear resolution of the legal position on data retention.

The previous UK Labour government were one of the key driving forces behind the original implementation of the data retention directive. The current UK government is one of the biggest cheerleaders for and operators of mass surveillance standards and practices. Though the UK government was not involved directly in the case, (and are scrambling madly to find a way to circumvent the decision as, sadly, are the European Commission), both the current and the previous administrations' behaviour, in the data retention context, is considered so heinous in law that it should never have happened; and the laws facilitating that behaviour should never have existed.

Some commentators have also suggested the Court was firing a message not just to the UK but across the pond (2 min 40sec audio) to the effect that US mass surveillance standards are totally unacceptable in an EU context.

Now come full circle to the Clarkson furore. In their data retention decision, in passing (also known as 'obiter dicta'), the Court of Justice of the EU noted in paragraphs 27 and 28 of their decision the chilling effect of the knowledge that anything we say or do is being recorded and may be used against us -
"Those data, taken as a whole, may allow very precise conclusions to be drawn concerning the private lives of the persons whose data has been retained, such as the habits of everyday life, permanent or temporary places of residence, daily or other movements, the activities carried out, the social relationships of those persons and the social environments frequented by them.
In such circumstances... it is not inconceivable that the retention of the data in question might have an effect on the use, by subscribers or registered users, of the means of communication covered by that directive and, consequently, on their exercise of the freedom of expression"
I don't find casual laddish racist remarks at all funny. I find them offensive. Just as I find casual blokey demonisation/marginalisation/ but more particularly intentional-vicious-insult-dismissal and incitement of hatred, directed at [minority group of choice], offensive. It causes division, discrimination and tension and undermines equality, human rights, decency and collective care.

But Mr Clarkson misspoke, by accident, 2 years ago, when doing a recording for a popular TV programme. The trademark of said programme is three middle aged men, acting like big kids, mucking about with cars, playing pranks and laddishly insulting each other and other people and things for laughs.

Mr Clarkson has apologised for using a word he personally loathes. The motives of those who leaked the recording are not known.

I have no idea whether Mr Clarkson is racist though I suspect not. Intended or not, ill-used words do cause damage but it is the presence or absence of hateful intent behind such remarks rather than the words used that define the mindset of the speaker.  We can't read minds so interpret that intent, by proxy, from people's words.

Nevertheless, I would ask that s/he who wish to throw metaphorical stones at Mr Clarkson, to think also of their own many stored and detailed digital dossiers and how fragments thereof might well, one day, be held against you. Especially if, like a certain Open University academic, you might have a 3 hop connection to the population of the world.

Tuesday, May 13, 2014

General Hayden: "We kill people based on metadata"

The full video of the John Hopkins debate between David Cole and Michael Hayden is available on YouTube



For those interested in General Hayden's "We kill people based on metadata" quote -

Monday, May 12, 2014

Security Analysis of the Estonian E-Voting System

An international team of security experts, including Alex Halderman and Harri Hursti, have identified serious problems with Estonia's e-voting system and recommended its immediate withdrawal.
They've produced a neat short video explaining the issues -



And a couple of longer ones outlining the possible server malware attacks -



The team will be providing partial code for their proof-of-concept attacks after the conclusion of the May 2014 European Parliamentary elections.

Friday, May 09, 2014

Copyright exceptions for private copying and parody delayed

I've written to the intellectual property minister, Lord Younger of Leckie, regarding the decision, this week, to "delay" the implementation of copyright exceptions statutory instruments (SIs) for private copying and parody. These were scheduled for implementation on 1 June 2014.

I specifically draw his attention to the Consumer Focus report, 'The economic impact of consumer copyright exceptions'.

Dear Lord Younger of Leckie,

In light of the decision this week, of Joint Committee on Statutory Instruments (JCSI), to hold up the implementation of copyright exceptions statutory instruments for private copying and parody, could I ask that you draw the committee's attention to the Consumer Focus report, 'The economic impact of consumer copyright exceptions'. It was first published in 2010, republished last year and is available at:

http://www.consumerfocus.org.uk/publications/the-economic-impact-of-consumer-copyright-exceptions-a-literature-review

The report itself may be accessed directly at:

http://www.consumerfocus.org.uk/files/2010/11/The-economic-impact-of-consumer-copyright-exceptions-Rogers-Tomalin-Corrigan.pdf.

Full disclosure - I am an academic at the Open University and was involved in producing the report, along with colleagues from Oxford University, Mark Rogers and Josh Tomalin. Mark was terminally ill at the time and sadly died in July 2011. But he felt the absence of economic evidence informing copyright policy was hugely important, sufficiently so to merit a significant chunk of his considerable professional energy.

The report focused solely on copyright exceptions as they relate to non-commercial, consumer activities. It dealt specifically with private copy format shifting and parody. We concluded -

Investigating potential economic damage to rights-holders requires an analysis of how consumer copyright exception could affect the demand for the original creative work. The processes via which consumer copyright exceptions influence the demand curve for original creative work can be complicated. This said, a standard analysis of the demand for creative works must assume that consumers incorporate the benefit of copyright exceptions into their demand. A consumer’s decision to purchase is based on the benefits of the product, including – in the case of creative work – the value of any copyright exception. In this sense, it can be argued that a creator automatically extracts value from copyright exceptions, since these directly influence the demand for the original creative work.

The economic evidence that format-shifting, parody and user-generated content cause any kind of economic damage to rights-holders simply does not exist. Arguments that support tighter copyright law, or support Private Copying Remuneration (PCR) systems, tend to confuse economic damage with consumer value. Any future analysis on this issue needs to investigate the conditions under which the proposed consumer copyright exceptions would have any impact on demand for creative work.

I hope that you and the JCSI find the report informs your decision making in this area.

Yours sincerely,

Ray Corrigan

Wednesday, April 30, 2014

ECJ invalidate data retention directive

ECJ Invalidates data retention

On 8 April2014 the Grand Chamber of the European Court of Justice, (ECJ) in joined cases C-293/12 and C-594/12, issued a landmark decision declaring the 2006 data retention directive invalid.

The data retention directive was the instrument through which the EU required communications service providers, both fixed line and mobile, to store details of everything everyone does on the telephone or internet; for a period of between 6 months and two years. The details of what was required to be collected were laid out in article 5 of the directive and the only thing not permitted was recording of the content of calls or messages.

The ECJ decided that mass indiscriminate data retention interferes disproportionately and in a particularly serious manner with the fundamental rights to privacy and the protection of personal data.

The challengers

Digital Rights Ireland (DRI) and 11,130 Austrian citizens whose case was joined to that of DRI challenged the directive, ostensibly arguing it constituted an unlawful and unacceptable interference with fundamental rights to privacy and free speech. The Court focused on the effects of the data retention directive on articles 7 and 8 of the Charter of Fundamental Rights of the European Union - respect for private and family life and protection of personal data.

The Grand Chamber of the court proceeded to declare the directive invalid and effectively condemned pre-emptive, suspicionless, warrantless mass surveillance and consequent "interference with the fundamental rights of practically the entire European population".

Introduction and legal context

The Court opens by explaining Digital Rights Ireland challenged the implementation of the data retention directive into Irish law and the Austrian Constitutional Court, Verfassungsgerichtshof, was asked to consider the constitutionality of the Austrian implementation of the directive. They then set out the legal context.

The objective of the data protection directive, directive 95/46/EC, is to protect people's privacy. The aim of the directive on privacy and electronic communications, directive 2002/58/EC, is to harmonise privacy rights and allow sharing of data within and across the EU. Both these directives require appropriate technical and organisational measures to protect the security of personal data.  The 2002 directive prohibits surveillance without user consent, in theory. It has,however, the enormous loophole of article 15 which states any necessary, appropriate and proportionate measure can be used to bypass obligations to respect fundamental rights, when those measures are for national security or crime fighting reasons. Article 15 also specifically appears to approve of the retention of data.

The data retention directive itself obliged communications service providers to retain data. Under article 3, EU member state were required to adopt measures mandating data retention of categories of data specified in article 5. (Take a look at the list of information retained. It's almost unbelievable). Under article 4, access to this retained data would only be available to "competent national authorities" in specific cases and in accordance with national law. Article 6 specified the data should be retained for between 6 months and 2 years. Article 11 basically says when it comes to data retention the need to respect a basic level of fundamental rights theoretically noted in article 1 of the 2002 e-privacy directive could be ignored.

DRI and Austrian cases

The Court then outlines the Digital Rights Ireland and Austrian cases in paragraphs 17 to 22. DRI argued the directive constituted a disproportionate interference with fundamental rights to respect for privacy and family life, data protection and freedom of expression & information, guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Austrian citizens Mr Seitlinger, Mr Tschol et al sought the annulment of the Austrian law implementing data retention. The Austrian Court, took the view that data retention, because of the indiscriminate nature and scale of it, almost exclusively affects innocent people. The Verfassungsgerichtshof also felt data retention could not achieve its objectives and was disproportionate, so they also asked the European Court of Justice to review whether data retention constituted a disproportionate interference with fundamental rights guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Additionally the Verfassungsgerichtshof suggested the data protection directive and articles 52 and 53 of the Charter of Fundamental Rights presented barriers or at least limitations to data retention.

Next the ECJ considers the substance of the questions before them. They acknowledge (para 27) that the data mandated for retention taken as a whole provides a very rich picture of people's lives. Also that people might well adjust their behaviour and self censor due to the chilling effect of the knowledge of the mass data gathering (para 28). So there is a clear acceptance by the ECJ that freedom of expression protected by article 11 of the Charter could be on the line. They do not however pursue this to any solid conclusion and focus instead of matters of privacy and data protection, relating to articles 7 & 8 of the Charter.

Interference with privacy and data protection

The heavy lifting in the decision is then laid out from paragraph 32 to 71.
"32. ... Directive 2006/24... derogates from the system of protection of the right to privacy established by Directives 95/46 and 2002/58"
The data collected does not have to be sensitive or to inconvenience people in any way to establish the existence of an interference with the fundamental right to privacy. (Para 33). Data retention
"constitutes in itself an interference with the rights guaranteed by Article 7 of the Charter." (para 34). Access to the data retained by competent national authorities is an interference with the rights guaranteed by Article 7 of the Charter. (para 35). Likewise because the directive provides for the processing of personal data it is an interference with the fundamental right to data protection covered by article 8 of the Charter. (para 36). Paragraph 37 merits quotation in full:
"37.  It must be stated that the interference caused by Directive 2006/24 with the fundamental rights laid down in Articles 7 and 8 of the Charter is, as the Advocate General has also pointed out, in particular, in paragraphs 77 and 80 of his Opinion, wide-ranging, and it must be considered to be particularly serious. Furthermore, as the Advocate General has pointed out in paragraphs 52 and 72 of his Opinion, the fact that data are retained and subsequently used without the subscriber or registered user being informed is likely to generate in the minds of the persons concerned the feeling that their private lives are the subject of constant surveillance."
Justification for interference with fundamental rights

Having declared the interference with the fundamental rights to privacy and data protection particularly serious, the Court then must look at the justification for and proportionality of this interference. It finds the 2006 directive wanting on both counts.

Article 52(1) of the Charter of Fundamental Rights of the EU states that any circumvention of those rights must be proportionate, strictly limited and necessary to meet objectives of general interest or to protect the freedoms of others.

In paragraphs 39 and 40, the Court then makes a rather fuzzy attempt to step back from the absolutist stance it appears to have be shaping up to take against data retention.
"39... it must be held that, even though the retention of data required by Directive 2006/24 constitutes a particularly serious interference with those rights, it is not such as to adversely affect the essence of those rights given that, as follows from Article 1(2) of the directive, the directive does not permit the acquisition of knowledge of the content of the electronic communications as such."
This does not sit logically with the earlier acceptance in paragraphs 27 & 28 that metadata provides a very comprehensive picture of peoples' lives which could have a chilling affect on freedom of expression. It also seems something of a non sequitur - how must it be held that data retention constitutes a particularly serious interference with fundamental rights, yet not be such as to adversely affect the essence of those rights?

Paragraph 40 says the essence of article 8 data protection rights are not adversely affected because the text of data retention directive includes a note that says data protection must be respected. On that basis you could stick a token 'respect data protection' clause in every liberty bashing regulatory instrument and not "adversely affect" data protection.

The object of the the data retention is to fight serious crime and article 6 of the Charter of rights lays down the fundamental right to security. So fighting serious crime is a legitimate 'objective of general interest.' And communications technology is an important crime fighting tool. So
"44.  It must therefore be held that the retention of data for the purpose of allowing the competent national authorities to have possible access to those data, as required by Directive 2006/24, genuinely satisfies an objective of general interest."
Disproportionate nature of the data retention directive

The objective of data retention is acceptable. But is data retention a proportionate way to achieve that crime fighting objective? Proportionality requires acts of EU institutions to "not exceed the limits of what is appropriate and necessary in order to achieve" the objective in hand, in this case fighting serious crime.

The ECJ takes guidance from the European Court of Human Rights decision in 2008, S and Marper v UK, on the retention of DNA and fingerprints.
"47. ... the EU legislature’s discretion may prove to be limited, depending on a number of factors, including, in particular, the area concerned, the nature of the right at issue guaranteed by the Charter, the nature and seriousness of the interference and the object pursued by the interference (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., S. and Marper v. the United Kingdom [GC], nos. 30562/04 and 30566/04, § 102, ECHR 2008-V)."
Privacy and data protection are fundamental and so the discretion of EU legislature to interfere with them is reduced and any review of that discretion should be strict. (para 48). Data retention may be appropriate for crime fighting. (Para 49). The fight against serious crime requires modern techniques but that doesn't mean the kind of mass data retention required by the directive is necessary. (Para 51). Data protection is especially important for privacy.
"54. Consequently, the EU legislation in question must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards so that the persons whose data have been retained have sufficient guarantees to effectively protect their personal data against the risk of abuse and against any unlawful access and use of that data (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., Liberty and Others v. the United Kingdom, 1 July 2008, no. 58243/00, § 62 and 63; Rotaru v. Romania, § 57 to 59, and S. and Marper v. the United Kingdom, § 99)."
Data retention should have clear rule on scope and application and minimum safeguards against unlawful access. The unstated critique is that the directive fails on all counts.
"55.  The need for such safeguards is all the greater where, as laid down in Directive 2006/24, personal data are subjected to automatic processing and where there is a significant risk of unlawful access to those data (see, by analogy, as regards Article 8 of the ECHR, S. and Marper v. the United Kingdom, § 103, and M. K. v. France, 18 April 2013, no. 19522/09, § 35)."
Safeguards are particularly important with respect to the automatic large scale processing of data. Again the 2006 directive fails.
56. ... Directive 2006/24... entails an interference with the fundamental rights of practically the entire European population. [My emphasis]
"57.   In this respect, it must be noted, first, that Directive 2006/24 covers, in a generalised manner, all persons and all means of electronic communication as well as all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against serious crime.." [My emphasis]
Paragraph 58 goes on to criticise Directive 2006/24's mandate to engage in the mass surveillance of innocent people not remotely connected to serious crime. Additionally it circumvents rules protecting privileged communications.

Then in recognition of the need for targeted rather than mass surveillance they state:
"59.  Moreover, whilst seeking to contribute to the fight against serious crime, Directive 2006/24 does not require any relationship between the data whose retention is provided for and a threat to public security and, in particular, it is not restricted to a retention in relation (i) to data pertaining to a particular time period and/or a particular geographical zone and/or to a circle of particular persons likely to be involved, in one way or another, in a serious crime, or (ii) to persons who could, for other reasons, contribute, by the retention of their data, to the prevention, detection or prosecution of serious offences."
That paragraph alone could be interpreted as a serious judicial uppercut to the UK government's mass surveillance practices revealed by Edward Snowden. At the risk of being boring I'm going to repeat my old mantra here.  It is unnecessary and completely disproportionate, not to mention dangerously ineffective, to collect innocent communications in order to find serious criminals. Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services have to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance or facilitating the same through the legal architecture of directives like 2006/24 on data retention.

The ECJ follows up this mass surveillance critique with a clear declaration in paragraph 60 that the data retention directive has no limits on access to and use of retained data to the purpose of fighting serious crime and no criteria for determining such limits. In a way paragraphs 60 to 68 provide a blueprint for the Commission and particularly rabid surveillance addicted governments to re-write the data retention directive in a way that might be acceptable to the ECJ. Since these paragraphs spell out what is missing from the directive and might be read as suggesting 'make a token effort with these things next time and you'll be ok.'

Para 61 criticises Directive 2006/24's lack of procedures on determining access to data or its use or even limiting these to crime fighting. Para 62 notes the directive does not limit the number of people with access to the retained data to those strictly necessary. Nor does it subject access to the data to the prior review or oversight of a court, in order to limit access to that which is strictly necessary. Nor are member states obliged to set down such procedures.

Para 63 complains that the blanket data retention mandated doesn't make any distinction between categories of data. Para 64 says there is not even an attempt to justify the arbitrary period of retention chosen of between 6 months and 2 years.

Then comes the clincher.
"65.  It follows from the above that Directive 2006/24 does not lay down clear and precise rules governing the extent of the interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter. It must therefore be held that Directive 2006/24 entails a wide-ranging and particularly serious interference with those fundamental rights in the legal order of the EU, without such an interference being precisely circumscribed by provisions to ensure that it is actually limited to what is strictly necessary." [My emphasis]
"66.   Moreover, as far as concerns the rules relating to the security and protection of data retained by providers of publicly available electronic communications services or of public communications networks, it must be held that Directive 2006/24 does not provide for sufficient safeguards, as required by Article 8 of the Charter, to ensure effective protection of the data retained against the risk of abuse and against any unlawful access and use of that data. In the first place, Article 7 of Directive 2006/24 does not lay down rules which are specific and adapted to (i) the vast quantity of data whose retention is required by that directive, (ii) the sensitive nature of that data and (iii) the risk of unlawful access to that data, rules which would serve, in particular, to govern the protection and security of the data in question in a clear and strict manner in order to ensure their full integrity and confidentiality. Furthermore, a specific obligation on Member States to establish such rules has also not been laid down." [My emphasis]
Para 67 says the 2006 directive doesn't specify a high enough data security threshold and doesn't require the irreversible destruction of data at the end of the retention period. Then in 68 the ECJ has serious concerns that the data retention directive does not require data to be retained within the borders of the EU. So control by independent authority of data protection and access to the retained data cannot be fully ensured. Such control is an essential corner stone of EU data protection law.

And that's the ballgame

They conclude:
"69. Having regard to all the foregoing considerations, it must be held that, by adopting Directive 2006/24, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter.
70. In those circumstances, there is no need to examine the validity of Directive 2006/24 in the light of Article 11 of the Charter.
71.  Consequently... Directive 2006/24 is invalid."
In short, the data retention directive presents a disproportionate interference with the fundamental rights to respect for private and family life and the protection of personal data. Consequently the directive is invalid, null and void. And because it is invalid on privacy grounds the ECJ don't see the need to pursue the question of whether it also might be invalid on the grounds of Article 11 of the Charter of Fundamental Rights relating to freedom of expression.

If the Charter of Fundamental Rights proves to have staying power as the legislative architecture protecting the rights of EU citizens into the distant future, then this ECJ decision could well prove to be historic. On a par with the civil rights cases of the US Supreme Court such as Brown v the Board of Education or the NYT v Sullivan. Only time will tell whether it achieves that fame or notoriety but it was certainly a welcome development in the battle to avoid a mass surveilled future.

Congratulations and thanks to TJ McIntyre, Simon McGarr and Digital Rights Ireland and to Mr Seitlinger, Mr Tschol et al and the Austrian Constitutional Court the Verfassungsgerichtshof in what was a long and difficult battle and a hard fought but very welcome victory in the end. 

US Supreme Court on patent trolls: make 'em pay when they lose

The US Supreme Court yesterday issued decisions in two cases essentially relating to patent trolls, Octane Fitness v. Icon Health & Fitness and Highmark Inc. v. Allcare Health Management System, Inc.
US law (35 USC § 285) says patent suit losers should pay the winners legal costs but only in "exceptional circumstances". In practice, in spite of the mountains of ridiculous patents and strategic business patent lawsuits, very few cases are held to be sufficiently exceptional for the court to award such costs. Which is a licence for patent trolls to pursue their extortion rackets with relish.

The decisions in the Octane and Highmark cases theoretically make the awarding of legal costs to winners easier. Take the Octane decision:
"No. 12–1184. Argued February 26, 2014—Decided April 29, 2014
The Patent Act’s fee-shifting provision authorizes district courts toaward attorney’s fees to prevailing parties in “exceptional cases.” 35 U. S. C. §285. In Brooks Furniture Mfg., Inc. v. Dutailier Int’l, Inc., 393 F. 3d 1378, 1381, the Federal Circuit defined an “exceptional case” as one which either involves “material inappropriate conduct” or is both “objectively baseless” and “brought in subjective bad faith.” Brooks Furniture also requires that parties establish the “exceptional” nature of a case by “clear and convincing evidence.” Id., at 1382.
Respondent ICON Health & Fitness, Inc., sued petitioner Octane Fitness, LLC, for patent infringement. The District Court granted summary judgment to Octane. Octane then moved for attorney’s fees under §285. The District Court denied the motion under the Brooks Furniture framework, finding ICON’s claim to be neither objectively baseless nor brought in subjective bad faith. The Federal Circuit affirmed.
Held: The Brooks Furniture framework is unduly rigid and impermissibly encumbers the statutory grant of discretion to district courts.Pp. 7–12.
(a) Section 285 imposes one and only one constraint on district courts’ discretion to award attorney’s fees: The power is reserved for“exceptional” cases. Because the Patent Act does not define “exceptional,” the term is construed “in accordance with [its] ordinary meaning.” Sebelius v. Cloer, 569 U. S. ___, ___. In 1952, when Congress used the word in §285 (and today, for that matter),“[e]xceptional” meant “uncommon,” “rare,” or “not ordinary.” Webster’s New International Dictionary 889 (2d ed. 1934). An “exceptional” case, then, is simply one that stands out from others with respect to the substantive strength of a party’s litigating position (considering both the governing law and the facts of the case) or the unreasonable manner in which the case was litigated. District courts may determine whether a case is “exceptional” in the case-by-caseexercise of their discretion, considering the totality of the circumstances. Cf. Fogerty v. Fantasy, Inc., 510 U. S. 517. Pp. 7–8.
(b)
The Brooks Furniture framework superimposes an inflexible framework onto statutory text that is inherently flexible. Pp. 8–11."
Justice Sotomayor, writing for the Court in the unanimous decision, goes on (p7-8):
"We hold, then, that an “exceptional” case is simply one that stands out from others with respect to the substantive strength of a party’s litigating position (considering both the governing law and the facts of the case) or the unreasonable manner in which the case was litigated. District courts may determine whether a case is “exceptional” in the case-by-case exercise of their discretion, considering the totality of the circumstances.6 As in the comparable context of the Copyright Act, “‘[t]here is no precise rule or formula for making these determinations,’ but instead equitable discretion should be exercised ‘in light of the considerations we have identified.’” Fogerty v. Fantasy, Inc., 510 U. S. 517, 534 (1994)."
So district courts can be confident that decisions (to award legal costs to those successfully defending themselves from bogus patent troll lawsuits) in "exceptional" cases won't be overturned as long as "exceptional" is construed as:
  • “in accordance with [its] ordinary meaning” (in 1952)
  • "uncommon"
  • "rare"
  • "not ordinary"
and now, in the wake of the Supreme Court decision yesterday, 29 April, 2014,
  • "stands out from others with respect to the substantive strength of a party’s litigating position (considering both the governing law and the facts of the case) or the unreasonable manner in which the case was litigated."
I doubt adding "stands out from to the list of "ordinary" meanings of "exceptional" will make a great deal of difference either to patent trolling or to the US Federal Appeals Court judges willingness to overturn lower court decisions they disapprove of in this area. Call me a skeptic but given the money and power embodied in such patent suits, I suspect it will take something stronger to break the cycle of legitimate patent applicants and defendants paying the price; whilst the well-resourced, wielding sharp-suited lawyers and huge portfolios of often indefensible patents, make off with the prizes.

Tuesday, April 29, 2014

Free is a lie - Aral Balkan at TNW

Take 32 mins and listen to Indie phone's Aral Balkan's talk at the recent TNW conference.



Balkan opens with a simple thought experiment. He's setting up a hypothetical business, Schnail Mail, which will solve the problem of mail delivery by delivering letters and parcels of all shapes and sizes anywhere in the world for free. He asks his audience how many of them would sign up for it. Sounds like an attractive enterprise so many would. In the interests of full disclosure he then explains that by the way Schnail mail will open and forensically examine all letters and parcels to learn about their customers, obviously in the interests only of offering them a better service. How many would now sign up? Not very many though there were still a hard core half a dozen or so. In any case the Schnail Mail business model is the Google, Facebook, [big tech co of choice] "free" service business model.

The business model of "free" is the business model of mass surveillance. We effectively hand over quarries of personal data for these corporations to mine for their own ends. He quotes Eric Schmidt noting Google knows who you are, where you are and what you are thinking; and Facebook knowing people are on the path to a relationship before those people possibly even know it themselves.

He also quotes the Google executive chairman saying:
"If you have something you don't want everyone to know maybe you shouldn't be doing it in the first place."
That's not the kind of world Balkan wants. Privacy is not about whether you have something to hide. It's about having control of what you want to share and what to keep to yourself. But in the world of "free" mass surveillance you don't have that control. The corporations do and they have acquired that control by deceit because consumers largely have no idea of the information they have surrendered/bartered in exchange for "free" services.  If we make the panopticon the default that leads to a society where anything we want to keep private has an association of guilt attached. Privacy becomes only about hiding bad things. Balkan rejects that notion.

Ordinary consumers currently have no choice - all roads lead to digital feudalism regardless of which corporate walled garden is chosen. Techies say use free and open source alternatives. But ordinary mortals have not got the time, skills or resources to architect or build our own FOSS, experience-led digital privacy assured shells to shield our rich personal data quarries / digital personas, thereby enabling us to participate in the information society without compromising our privacy. So techies, entrepreneurs, the market have to start to provide custom built user friendly privacy enhanced technologies. One such effort is Balkan's indie phone.

The true cost of "free" he says is our privacy, our civil liberties, our human rights.

Good luck to Mr Balkan with his indie phone venture. His success will likely depend on the degree to which he can manage the pathological calculus that is -

Privacy vs Convenience/attraction/gratification/access/community/conformity/convenience
- in addition to the small matter of taking on the power of the mass surveillance addicted market incumbents.

Friday, April 25, 2014

Feynman, education & public engagement on digital rights

This Horizon programme on Richard Feynman is full of terrific engaging Feynman observations.



I'll just pick out two that are close to home at the moment.

Feynman talks about teaching and how he didn't really know how to do it. To hook everyone with our different interests and different learning styles and aptitudes the teacher has to take a chaotic approach. Otherwise the teaching will only reach or appeal to one kind of person. The implication is that all the rest are locked out. He gives a lovely example of the stories he used to make up for his son exploring wood-like worlds which turned out to be tiny people living in a carpet land; and caves where the air flowing in was cold and air flowing out was warm - this turned out to be the dog's nose; then they could explore the respiratory systems and learn all kinds of real world things in a fun way. His daughter, on the other hand, didn't like him making up stories. She liked him to read proper stories from proper books. She had a different personality and different way of taking on the world

The top down superficial dogmatic ill-informed rhetoric driving formal education systems in the UK at the moment (and which has been doing so for a long time) has lead to systems that fail most of the people most of the time. They fail the teachers/lecturers trying to make them work against all the odds and they fail the children and older students that get processed from year to year, standardised widgets all.

The second thing that struck me was Feynman's ruse for avoiding the drudgery of academic administration. He would refuse to do it by claiming he was irresponsible and by implication could not be relied upon to do it properly. So every time he was asked e.g sit on an admissions committee he would say he didn't care about students (he did) and couldn't be bothered and anyway would be irresponsible. He'd say to himself let so and so do it - it was selfish but it left him time to do physics.

To do any kind of substantive work it takes absolute solid lengths of time. If you're working on something complex, he describes it like a house of cards. It's wobbly. All the ideas holding it together are like the cards. If you forget one or lose it the whole thing collapses and you have to start all over. If you are weighed down with administration you'll never have the time to do anything deep.

Well I've had three books in draft for several years and not had a substantive run at any of them. Much though I'd like to offload or avoid a chunk of my admin duties, Feynman style, that's not a realistic option in the short to medium term. The privilege of working at an amazing institution like The Open University brings with it the duty to engage in the requisite battles to protect its core values and terrific students and staff. I have an equivalent duty, however, to engage deeply with my academic areas of interest - including the digital rights arena - particularly when they have an impact that extends way beyond the boundaries of a single institution.

So something has to give and I've decided, no doubt to the collective background sigh of relief from organisational behaviour theorists, to abandon one of my draft books. Perhaps a little ironically it is the one on the convergent evolutionary bureaucratic cancerous insanity of large organisations. It is incredible the degree to which care, trust, goodwill, decency, simple understanding of the difference between right and wrong - the fundamentals of providing a good product or service - can get completely decimated in the labyrinth of tightly coupled, complex, often mutually exclusive and diametrically opposed rules, regulations, procedures, good intentions, sociopathic ambitions, agendas and ignorant digital Taylorism that constitute modern large mature organisations. Both in the private and public sectors. NASA's 'Criticality 1' waiver system - a procedure for bypassing safety procedures which had determined space shuttle components/systems were so dangerous as to be life threatening - is a classic example. The working title was The Insanity of Bureaucracy and the sound bite description, 'if large organisations were people they'd be diagnosed clinically insane.'

Will the dropping of the Insanity of Bureaucracy give me more space to work my tome on systems failure in the regulation of the Net? We'll see. The latter began as a collection of case studies on the emergent effects of the scientific and technical ignorance of policymakers. But in a world of mass surveillance these real life stories are not really enough. There is an urgent need for academics, techies, lawyers, engineers, scientists, educators to be better at explaining - through as many forums, physical and virtual, political and institutional, mass media, social networks and any other social, physical, technological, economic, environmental or cognitive construct of influence -  the maths, science and technology that forms the infrastructure of our information society. In ways and through narratives that are engaging, convincing, evidence based, entertaining (if necessary), chaotically as Feynman says, widely accessible and with memes that stick -
  • privacy AND security NOT privacy OR security
  • mass surveillance doesn't work
  • mass surveillance is sinister
  • mass surveillance is odious
  • mass surveillance is monstrous
  • mass surveillance is wrong
  • mass surveillance is poisonous
  • mass surveillance is corrosive
  • did I say mass surveillance doesn't work
  • we need intelligence lead targeted technological surveillance of individuals about whom there is reasonable cause to harbour suspicion NOT mass surveillance ... ok now you can see why I'd never get a job in PR or politics... (Marcus Lipton MP in 1957 (at 1min 50s) declared phone tapping of a suspected gangster "most sinister", "odioius" and "montrous", as did the outraged mainstream media at the time. How times have changed.)
  • censorship is odious...
  • hate mongering is poisonous...
  • demonisation of [minority target of choice] is monstrous...
  • Extraordinary rendition is odious, monstrous, wrong...
  • torture is odious, monstrous, wrong... 
  • enclosure of the public domain is wrong...
  • the best network is the hardest to monetise...
  • communications infrastructure is a public good...
  • concentration of control of communications infrastructure is contrary to the public good...
  • sound bite attack dog 'public debate' undermines our capacity to engage in informed, enlightened, collective, democratic policy making in the public good ... see - I can't do PR...
  • and just to prove I can't do PR... complex corporate welfare regulatory instruments built into secretly negotiated international trade agreements, which undermine both the sovereignty of nation states and fundamental liberties, and which are substantively written by the industries they are tailored to benefit, are contrary to the public good...
One book is a drop in ocean of this kind of essential public engagement but it is a drop I really need to carve out some time and space to deliver. Then when the grandkids, if I'm lucky enough to have any and supposing they can cope with the dysfunctional world we bequeath them, ask what the hell I was doing when my generation was so busy normalising the destruction fundamental liberties in the metaphorical blink of a historical eye, I may at least have a story or two to tell and a battered old monograph to point to on the shelf.

The third book in the Corrigan cognitive hinterland is a young adult novel with a Cory Doctorow type Little Brother / Homeland theme but in a sporting context. That's simply proving very difficult to write and has given me a greater respect than ever for children's authors who do an incredible job. (Cory's books are terrific btw and should be required reading for teens and adults everywhere). My kids sometimes encourage me to stop, rewind and repeat in short sentences using words of preferably no more than two syllables. I naturally point out that 'sentences', 'preferably and 'syllables' breach those rules... but writing for young adults is a much more challenging task than I had expected it to be.

The wet Friday afternoon contemplative musing will have to stop there for now, as the relentless clamour of the zombiecrats for boxes to be ticked, forms to be filled and meetings to be attended must be soothed. That's this evening. Tomorrow real students in a real classroom await and though there are reports to be filed in the aftermath, OU students almost invariably cheer me up.

Monday, April 21, 2014

Russia's surveillance state

The autumn 2013 issue of the World Policy Journal has the best outline of Russian mass surveillance I've seen to date By Andrei Soldatov and Irina Borogan. Not so long ago, Western media and politicians would have been all over this, condemning the unethical behaviour of the Russian state. But I guess that's difficult and/or potentially embarrassing when you've spent a lot of effort defending the same behaviour on the part of Western governments.
"In March 2013, the Bureau of Diplomatic Security at the U.S. State Department issued a warning for Americans wanting to come to the Winter Olympics in Sochi, Russia next February: Beware of SORM. The System of Operative-Investigative Measures, or SORM, is Russia’s national system of lawful interception of all electronic utterances—an Orwellian network that jeopardizes privacy and the ability to use telecommunications to oppose the government. The U.S. warning ends with a list of “Travel Cyber Security Best Practices,” which, apart from the new technology, resembles the briefing instructions for a Cold War-era spy...
But the Russian surveillance effort is not limited to the Sochi area, nor confined to foreigners. For years, Russian secret services have been busy tightening their hold over Internet users in their country, and now they’re helping their counterparts in the rest of the former Soviet Union do the same. In the future, Russia may even succeed in splintering the web, breaking off from the global Internet a Russian intranet that’s easier for it to control.
Over the last two years, the Kremlin has transformed Russia into a surveillance state—at a level that would have made the Soviet KGB (Committe for State Security) envious. Seven Russian investigative and security agencies have been granted the legal right to intercept phone calls and emails. But it’s the Federal Security Service (FSB), the successor to the KGB, that defines interception procedures...
...In Russia, FSB officers are also required to obtain a court order to eavesdrop, but once they have it, they are not required to present it to anybody except their superiors in the FSB. Telecom providers have no right to demand that the FSB show them the warrant. The providers are required to pay for the SORM equipment and its installation, but they are denied access to the surveillance boxes.
The FSB has control centers connected directly to operators’ computer servers. To monitor particular phone conversations or Internet communications, an FSB agent only has to enter a command into the control center located in the local FSB headquarters. This system is replicated across the country. In every Russian town, there are protected underground cables, which connect the local FSB bureau with all Internet Service Providers (ISPs) and telecom providers in the region. That system, or SORM, is a holdover from the country’s Soviet past and was developed by a KGB research institute in the mid-1980s. Recent technological advances have only updated the system. Now, the SORM-1 system captures telephone and mobile phone communications, SORM-2 intercepts Internet traffic, and SORM-3 collects information from all forms of communication, providing long-term storage of all information and data on subscribers, including actual recordings and locations."
They are still working on how to deal with social networks but see mass surveillance, threats, net filtering, structural Balkanization of the net and the amoral self interest of the big tech companies (including Facebook and Google) as the key drivers of the evolution towards a much more controlled future.

Saturday, April 19, 2014

Intelligence Gathering and the Unowned Internet

The Berkman Center at Harvard has hosted a 90 minute discussion on  Intelligence Gathering and the Unowned Internet involving Yochai Benkler, Bruce Schneier and Jonathan Zittrain, Terry Fisher plus John DeLong and Anne Neuberger the latter two being from the National Security Agency.



The video is essential viewing and John Naughton's thoughts triggered by the discussion are also well worth a further 5 to 10 minutes of your time.

Thursday, April 17, 2014

Cory Doctorow & Barton Gellman at SXSW

Cory Doctorow and Barton Gellman discussing Edward Snowden, secure communications, encryption tools so easy your boss can use them, privacy, the revealing nature of metadata and mass surveillance, at SXSW should be required viewing.


Snowden quizzes Putin about mass surveillance on Russian TV

Edward Snowden just got to quiz Russian president Vladimir Putin about whether Russia engages in mass surveillance...


Guess what? Major surprise. Putin said no they don't. They fight crime and terrorism not like the rich Americans by spying on everyone but by engaging in surveillance controlled by the rule of law.

Call me a skeptic but it's a little unlikely Mr Putin has not heard of SORM not to mention a variety of other unethical surveillance and intelligence practices.

It is disappointing Edward Snowden would get sucked into such a publicity stunt though I guess he would not have had a lot of choice in the matter.

Update: Edward Snowden has defended his decision to participate in the TV show with Putin. In fairness, he makes a good case.

Wednesday, April 16, 2014

Suing the state: hidden rules within the EU-US trade deal

Thanks to Glyn Moody for pointing me at this excellent short video explaining the dangers of the investor state dispute settlement (ISDS) provisions in the proposed EU-US trade deal.



Additionally it is really worth reading Corporate Europe Observatory's excellent analysis of ISDS, Still not loving ISDS: 10 reasons to oppose investors’ super-rights in EU trade deals.

Tuesday, April 15, 2014

ORG Stop UK Internet Censorship Campaign

The Open Rights Group want to launch a campaign to educate the public about the dangers of software filters.



They need help to accumulate the requisite finances.

UK media ignore Guardian's Pulitzer Prize

We learned last night that the Guardian and the Washington Post have shared the Pulitzer prize for public service for their stories, based on documents leaked by Edward Snowden, on the US and UK governments' mass surveillance practices.

The story of the award has topped the news agenda all over the world - NYT, LA Times, The Times of Israel, Le Monde. The Times of India, even Fox News offered grudging repect whilst not missing the chance to denigrate Snowden.

In the UK the accolade has been ignored by The Times, The Daily Telegraph and the Daily Mail, though it got coverage from the BBC, The Indpendent and the FT.

A reminder. perhaps, of the need, always, to be alert to the underlying agenda(/s), motives and values of the controlling mind(/s) of the organisations from which we source our news.