Wednesday, January 26, 2005
Latest attempt to pass sw directive fails
The latest attempt to sneak the software patent directive through an agriculture and fisheries meeting has failed thanks to another rear-guard action by Polish officials on Monday last.
Isenberg's freedom to connect
David S. Isenberg has a wonderful short essay in his latest Smart Letter, reproduced in full below, with David's permission via a creative commons license
THE LIMITS OF FREEDOM TO CONNECT
Confessions of a Customer
by David S. Isenberg
Recently, Verizon blacklisted whole ranges of IP
addresses in Europe, denying mail delivery to their
U.S. customers. The problem, Verizon said, was that
spammers were using some of these IP addresses.
This might be framed in several ways, one of which
is as an attack on customers' Freedom to Connect.
One might suggest that if you don't like Verizon's
policy, you can opt out! That is, thanks to the End-
to-End property of the Internet, Verizon's customers
can use Verizon as an access provider only and get
their email services from other providers.
Here's a true story. I am a Verizon DSL customer.
I do this. I connect to the Internet via Verizon
DSL, but Earthlink runs my incoming mail server and
Fastmail runs my outgoing server.
However, I am not your average DSL customer. Other
people might not know that alternative mail services
are possible. Setting up alternative mail services
could be intimidating and non-transparent. Thank
goodness I have network-savvy friends to help me
understand things like POP and SMTP.
One could perhaps use a right-to-vote as an analogy
to explore this further. During the 2004 campaign,
there were reports from Philadelphia of men in suits
and official looking cars appearing in poor
neighborhoods telling people that if they voted they
might be arrested for overdue child support or
unpaid traffic tickets. If true, were these men
violating peoples' right to vote? Perhaps you could
say they weren't. Almost certainly they were wrong
in a technical sense; there probably were not
"outstanding warrant inspectors" at the polls. Lets
assume that the reported vague threats were simply
vague threats. Were these men violating peoples'
right to vote?
Back to Verizon. The main reason I went to Verizon
was that Cablevision (Optimum Online) began limiting
my ability to send email. First it somehow capped
the number of emails I could send in a certain time
period. I am not sure exactly how the cap worked,
but I could only send 150 SMART Letters at a time
(from my list of about 3000) before the cap kicked
in. This could be viewed -- in isolation -- as
reasonable, e.g., to control spam sent by zombies in
peoples' Windows PCs.
Then I switched my Cablevision-connected client to
the Fastmail SMTP server. For a while this worked,
then it didn't. Cablevision was blocking Port 25.
People smarter than I pointed out that I could use
Fastmail with other ports. Sure, but maybe
Cablevision would block those ports too. And
Cablevision itself offered a workaround, pay $109
instead of $45 for the "business service" and Port
25 comes unblocked. I asked the service rep what
else the $109 bought me and he said, "That's about
it."
Was Cablevision violating my Freedom to Connect? I
am "free" to find workarounds if I know enough to
hack them. I am still "free" to connect at $109 if I
can afford it. I am still "free" to use other ports
besides Port 25 to send out email -- until these are
also blocked. And I am still "free" to switch from
one of two (count 'em, two) providers to the other.
Again, please permit me an analogy. This is kind of
like telling the protesters they are "free" to speak
over there in some isolated barbed wire cage where
nobody is likely to hear or notice what they are
saying.
What happens to my "Freedom to Connect" when both
providers clamp down on it in the same ways, and
there is no third provider?
Borrowing liberally from Pastor Niemoller, first
they came to limit my email server, but I was not a
heavy email user so I did nothing, then they came
for Port 25, but I didn't need to use Port 25, so I
did nothing, then . . . and soon I realized that the
Internet had become a walled garden where the only
content I could see was Cablevision-approved
content, and the only sites I could access were
Verizon-approved sites . . .
"These examples are just hypothetical, of course.
It can't happen here," said the frog in the pot of
lukewarm water.
THE LIMITS OF FREEDOM TO CONNECT
Confessions of a Customer
by David S. Isenberg
Recently, Verizon blacklisted whole ranges of IP
addresses in Europe, denying mail delivery to their
U.S. customers. The problem, Verizon said, was that
spammers were using some of these IP addresses.
This might be framed in several ways, one of which
is as an attack on customers' Freedom to Connect.
One might suggest that if you don't like Verizon's
policy, you can opt out! That is, thanks to the End-
to-End property of the Internet, Verizon's customers
can use Verizon as an access provider only and get
their email services from other providers.
Here's a true story. I am a Verizon DSL customer.
I do this. I connect to the Internet via Verizon
DSL, but Earthlink runs my incoming mail server and
Fastmail runs my outgoing server.
However, I am not your average DSL customer. Other
people might not know that alternative mail services
are possible. Setting up alternative mail services
could be intimidating and non-transparent. Thank
goodness I have network-savvy friends to help me
understand things like POP and SMTP.
One could perhaps use a right-to-vote as an analogy
to explore this further. During the 2004 campaign,
there were reports from Philadelphia of men in suits
and official looking cars appearing in poor
neighborhoods telling people that if they voted they
might be arrested for overdue child support or
unpaid traffic tickets. If true, were these men
violating peoples' right to vote? Perhaps you could
say they weren't. Almost certainly they were wrong
in a technical sense; there probably were not
"outstanding warrant inspectors" at the polls. Lets
assume that the reported vague threats were simply
vague threats. Were these men violating peoples'
right to vote?
Back to Verizon. The main reason I went to Verizon
was that Cablevision (Optimum Online) began limiting
my ability to send email. First it somehow capped
the number of emails I could send in a certain time
period. I am not sure exactly how the cap worked,
but I could only send 150 SMART Letters at a time
(from my list of about 3000) before the cap kicked
in. This could be viewed -- in isolation -- as
reasonable, e.g., to control spam sent by zombies in
peoples' Windows PCs.
Then I switched my Cablevision-connected client to
the Fastmail SMTP server. For a while this worked,
then it didn't. Cablevision was blocking Port 25.
People smarter than I pointed out that I could use
Fastmail with other ports. Sure, but maybe
Cablevision would block those ports too. And
Cablevision itself offered a workaround, pay $109
instead of $45 for the "business service" and Port
25 comes unblocked. I asked the service rep what
else the $109 bought me and he said, "That's about
it."
Was Cablevision violating my Freedom to Connect? I
am "free" to find workarounds if I know enough to
hack them. I am still "free" to connect at $109 if I
can afford it. I am still "free" to use other ports
besides Port 25 to send out email -- until these are
also blocked. And I am still "free" to switch from
one of two (count 'em, two) providers to the other.
Again, please permit me an analogy. This is kind of
like telling the protesters they are "free" to speak
over there in some isolated barbed wire cage where
nobody is likely to hear or notice what they are
saying.
What happens to my "Freedom to Connect" when both
providers clamp down on it in the same ways, and
there is no third provider?
Borrowing liberally from Pastor Niemoller, first
they came to limit my email server, but I was not a
heavy email user so I did nothing, then they came
for Port 25, but I didn't need to use Port 25, so I
did nothing, then . . . and soon I realized that the
Internet had become a walled garden where the only
content I could see was Cablevision-approved
content, and the only sites I could access were
Verizon-approved sites . . .
"These examples are just hypothetical, of course.
It can't happen here," said the frog in the pot of
lukewarm water.
Tuesday, January 25, 2005
Legal Challenge to the Children Act
Action on Rights for Children (ARCH) are considering a legal challenge to the information sharing provisions of the Children Act, passed in November last year.
The Information Commissioner and parliament's human rights committee have both cited concerns about the then bill, prior to its approval by parliament, on a slim margin of about a dozen votes.
The Children Act 2004, Section 12 requires that the Secretary of State "establish and operate, or make arrangements for the operation and establishment of, one or more databases" and "require children's services authorities in England to establish and operate databases containing information" on all the children in the country. The databases will include the following details on each child:
" (a) his name, address, gender and date of birth;
(b) a number identifying him;
(c) the name and contact details of any person with parental responsibility for him (within the meaning of section 3 of the Children Act 1989 (c. 41)) or who has care of him at any time;
(d) details of any education being received by him (including the name and contact details of any educational institution attended by him);
(e) the name and contact details of any person providing primary medical services in relation to him under Part 1 of the National Health Service Act 1977 (c. 49);
(f) the name and contact details of any person providing to him services of such description as the Secretary of State may by regulations specify;
(g) information as to the existence of any cause for concern in relation to him;
(h) information of such other description, not including medical records or other personal records, as the Secretary of State may by regulations specify."
In addition, "Any person or body establishing or operating a database under this section must in the establishment or operation of the database have regard to any guidance, and comply with any direction, given to that person or body by the Secretary of State" and that direction may relate to "the transfer and comparison of information between databases."
The usual questions come right back:
What problem are they trying to solve?
What is the technical architecture of the system they are building to solve the problem?
How well does it solve the problem?
How can it fail and what other problems does it cause?
How much does it cost both monetarily and in respective of other personal, societal, economic and environmental trade offs?
Is it worth it?
What was that quote I vaguely remember but don't have the time to look up - "If you want to create a big brother/surveillance state/society, then start with the children and let them grow up knowing nothing else" or words to that effect. No doubt someone will email me with the correct quote.
The Information Commissioner and parliament's human rights committee have both cited concerns about the then bill, prior to its approval by parliament, on a slim margin of about a dozen votes.
The Children Act 2004, Section 12 requires that the Secretary of State "establish and operate, or make arrangements for the operation and establishment of, one or more databases" and "require children's services authorities in England to establish and operate databases containing information" on all the children in the country. The databases will include the following details on each child:
" (a) his name, address, gender and date of birth;
(b) a number identifying him;
(c) the name and contact details of any person with parental responsibility for him (within the meaning of section 3 of the Children Act 1989 (c. 41)) or who has care of him at any time;
(d) details of any education being received by him (including the name and contact details of any educational institution attended by him);
(e) the name and contact details of any person providing primary medical services in relation to him under Part 1 of the National Health Service Act 1977 (c. 49);
(f) the name and contact details of any person providing to him services of such description as the Secretary of State may by regulations specify;
(g) information as to the existence of any cause for concern in relation to him;
(h) information of such other description, not including medical records or other personal records, as the Secretary of State may by regulations specify."
In addition, "Any person or body establishing or operating a database under this section must in the establishment or operation of the database have regard to any guidance, and comply with any direction, given to that person or body by the Secretary of State" and that direction may relate to "the transfer and comparison of information between databases."
The usual questions come right back:
What problem are they trying to solve?
What is the technical architecture of the system they are building to solve the problem?
How well does it solve the problem?
How can it fail and what other problems does it cause?
How much does it cost both monetarily and in respective of other personal, societal, economic and environmental trade offs?
Is it worth it?
What was that quote I vaguely remember but don't have the time to look up - "If you want to create a big brother/surveillance state/society, then start with the children and let them grow up knowing nothing else" or words to that effect. No doubt someone will email me with the correct quote.
French IP Code
I found the first few paragraph's of the French intellectual property code really interesting:
"Chapter I: Nature of Copyright
Article L111-1.
The author of a work of the mind shall enjoy in that work, by the mere fact of its creation, an exclusive incorporeal property right which shall be enforceable against all persons.
This right shall include attributes of an intellectual and moral nature as well as attributes of an economic nature, as determined by Books I and III of this Code.
The existence or conclusion of a contract for hire or of service by the author of a work of the mind shall in no way derogate from the enjoyment of the right afforded by the first paragraph above."
It clearly shows the different ethos compared to the US constitution's Article 1, Section 8, Clause 8 gaurantee
"To promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries"
The French focus is on "exclusive incorporeal property right which shall be enforceable against all persons" and the on US the function of intellectual property as an incentive to "promote the Progress of Science and useful Arts."
"Chapter I: Nature of Copyright
Article L111-1.
The author of a work of the mind shall enjoy in that work, by the mere fact of its creation, an exclusive incorporeal property right which shall be enforceable against all persons.
This right shall include attributes of an intellectual and moral nature as well as attributes of an economic nature, as determined by Books I and III of this Code.
The existence or conclusion of a contract for hire or of service by the author of a work of the mind shall in no way derogate from the enjoyment of the right afforded by the first paragraph above."
It clearly shows the different ethos compared to the US constitution's Article 1, Section 8, Clause 8 gaurantee
"To promote the Progress of Science and useful Arts, by securing for limited Times to Authors and Inventors the exclusive Right to their respective Writings and Discoveries"
The French focus is on "exclusive incorporeal property right which shall be enforceable against all persons" and the on US the function of intellectual property as an incentive to "promote the Progress of Science and useful Arts."
Monday, January 24, 2005
International Journal of Communications Law and Policy
The Autumn 2004 edition of the International Journal of Communications Law and Policy is decicated to the subject of cybercrime and authors tackle the problems of fighting digital technology facilitated crime and the potential civil liberties implications of this.
A rich set of articles includes:
Architectural Regulation and the Evolution of Social Norms
BY LEE TIEN
Reference: IJCLP Web-Doc 1-Cy-2004
Transborder Search: A new perspective in law enforcement?
BY NICOLAI SEITZ
Reference: IJCLP Web-Doc 2-Cy-2004
The Fourth Amendment Unplugged: Electronic Evidence Issues & Wireless Defenses -
Wireless Crooks & the Wireless Internet Users Who Enable Them
BY TARA McGRAW SWAMINATHA
Reference: IJCLP Web-Doc 3-Cy-2004
Launch on Warning: Aggressive Defense of Computer Systems
BY CURTIS E. A. KARNOW
Reference: IJCLP Web-Doc 4-Cy-2004
Real World Problems of Virtual Crime
BY BERYL A. HOWELL
Reference: IJCLP Web-Doc 5-Cy-2004
Privacy vs. Piracy
BY SONIA K. KATYAL
Reference: IJCLP Web-Doc 7-Cy-2004
Technology, Security and Privacy:
The Fear of Frankenstein, the Mythology of Privacy and the Lessons of King Ludd
BY KIM A. TAIPALE
Reference: IJCLP Web-Doc 8-Cy-2004
Characteristics of a Fictitious Child Victim: Turning a Sex Offender’s Dreams Into His Worst Nightmare
BY JAMES F. MCLAUGHLIN
Reference: IJCLP Web-Doc 6-Cy-2004
For example, Beryl A. Howell's article on "Real World Problems of Virtual Crime" abstract:
"Theoretical debates about how best to address cybercrime have their place, but, in the real world, companies and individuals face harmful new criminal activity that poses unique technical and investigatory challenges. One of the greatest challenges posed by this new technology is how to combat wrongdoing effectively without netting innocent actors. This Article will present three case studies drawn from recent high-profile news stories to illustrate the pitfalls of legislating in the e-crimes arena."
A rich set of articles includes:
Architectural Regulation and the Evolution of Social Norms
BY LEE TIEN
Reference: IJCLP Web-Doc 1-Cy-2004
Transborder Search: A new perspective in law enforcement?
BY NICOLAI SEITZ
Reference: IJCLP Web-Doc 2-Cy-2004
The Fourth Amendment Unplugged: Electronic Evidence Issues & Wireless Defenses -
Wireless Crooks & the Wireless Internet Users Who Enable Them
BY TARA McGRAW SWAMINATHA
Reference: IJCLP Web-Doc 3-Cy-2004
Launch on Warning: Aggressive Defense of Computer Systems
BY CURTIS E. A. KARNOW
Reference: IJCLP Web-Doc 4-Cy-2004
Real World Problems of Virtual Crime
BY BERYL A. HOWELL
Reference: IJCLP Web-Doc 5-Cy-2004
Privacy vs. Piracy
BY SONIA K. KATYAL
Reference: IJCLP Web-Doc 7-Cy-2004
Technology, Security and Privacy:
The Fear of Frankenstein, the Mythology of Privacy and the Lessons of King Ludd
BY KIM A. TAIPALE
Reference: IJCLP Web-Doc 8-Cy-2004
Characteristics of a Fictitious Child Victim: Turning a Sex Offender’s Dreams Into His Worst Nightmare
BY JAMES F. MCLAUGHLIN
Reference: IJCLP Web-Doc 6-Cy-2004
For example, Beryl A. Howell's article on "Real World Problems of Virtual Crime" abstract:
"Theoretical debates about how best to address cybercrime have their place, but, in the real world, companies and individuals face harmful new criminal activity that poses unique technical and investigatory challenges. One of the greatest challenges posed by this new technology is how to combat wrongdoing effectively without netting innocent actors. This Article will present three case studies drawn from recent high-profile news stories to illustrate the pitfalls of legislating in the e-crimes arena."
How a fake doctor took £1½m and helped 1,000 people to get asylum from the Times and
UK gov ready to u-turn on passport-ID card link? at the Register.
John Lettice's piece at the Rgister requires a little concentration on the part of the reader but is well worth the effort, particularly if you're concerned about the proposed national ID card scheme.
UK gov ready to u-turn on passport-ID card link? at the Register.
John Lettice's piece at the Rgister requires a little concentration on the part of the reader but is well worth the effort, particularly if you're concerned about the proposed national ID card scheme.
Tony Blair against ID cards
By the way, who do you think might have said this:
"Instead of wasting hundreds of millions of pounds on compulsory ID cards...let that money provide thousands more police offiers on the beat."
It was Tony Blair! It was in 1995, however, two years before he became prime minister.
"Instead of wasting hundreds of millions of pounds on compulsory ID cards...let that money provide thousands more police offiers on the beat."
It was Tony Blair! It was in 1995, however, two years before he became prime minister.
Barriers to ID card suppliers
The draft legislation for the national ID card is being rushed through the committee stage in parliament, despite there being nearly 200 amendments already proposed. And Spyblog has pointed out a potentially interesting disincentive to organisations tempted to supply the technical infrastructure. They are stretching a point but Section 31 Tampering with the Register etc, could be interpreted to mean that anyone who supplies technology for the system which does not work perfectly could go to jail for 10 years.
Maybe someone should point that out to the many vendors scrambling for a piece of the ID card action.
On ID cards, the No2ID campaign have issued their latest newsletter, which as usual is very informative. The campaign are paticularly vexed about the government's response to their 3230-signature petition against ID cards.
Though I guess it is necessary, I'm not sure an irritated response to a re-hashed empty public relations statement is going to help progress their cause, which I wholeheartedly agree with.
Essentially they need to get the newspapers, all the established civil liberties groups (who essentially agree with them anyway)and commerce and industry on their side to build up a head of steam. Pointing out the clear negative technical and economic effects of the ID card scheme and the industries which are going to be affected (all of them), would help get the trade associations and multinational companies on board. If major commerce were convinced to start rallying against the cards then New Labour would fold on the scheme overnight (probably to Gordon Brown's relief and Tony Blair's chagrin).
As to the government's notion that the ID card will help prevent ID fraud as a basis for making us more secure, any security specialist who knows their job will tell you that either the government are being economical with truth or they really don't understand what they are dealing with. As Bruce Schneier says,in the context of a possible ID card scheme in the US:
"In fact, everything I've learned about security over the last 20 years tells me that once it is put in place, a national ID card program will actually make us less secure.
My argument may not be obvious, but it's not hard to follow, either. It centers around the notion that security must be evaluated not based on how it works, but on how it fails.
It doesn't really matter how well an ID card works when used by the hundreds of millions of honest people that would carry it. What matters is how the system might fail when used by someone intent on subverting that system: how it fails naturally, how it can be made to fail, and how failures might be exploited.
The first problem is the card itself. No matter how unforgeable we make it, it will be forged. And even worse, people will get legitimate cards in fraudulent names.
Two of the 9/11 terrorists had valid Virginia driver's licenses in fake names. And even if we could guarantee that everyone who issued national ID cards couldn't be bribed, initial cardholder identity would be determined by other identity documents ... all of which would be easier to forge.
Not that there would ever be such thing as a single ID card. Currently about 20 percent of all identity documents are lost per year. An entirely separate security system would have to be developed for people who lost their card, a system that itself is capable of abuse.
Additionally, any ID system involves people... people who regularly make mistakes. We all have stories of bartenders falling for obviously fake IDs, or sloppy ID checks at airports and government buildings. It's not simply a matter of training; checking IDs is a mind-numbingly boring task, one that is guaranteed to have failures. Biometrics such as thumbprints show some promise here, but bring with them their own set of exploitable failure modes.
But the main problem with any ID system is that it requires the existence of a database. In this case it would have to be an immense database of private and sensitive information on every American -- one widely and instantaneously accessible from airline check-in stations, police cars, schools, and so on.
The security risks are enormous. Such a database would be a kludge of existing databases; databases that are incompatible, full of erroneous data, and unreliable. As computer scientists, we do not know how to keep a database of this magnitude secure, whether from outside hackers or the thousands of insiders authorized to access it.
And when the inevitable worms, viruses, or random failures happen and the database goes down, what then? Is America supposed to shut down until it's restored?
Proponents of national ID cards want us to assume all these problems, and the tens of billions of dollars such a system would cost -- for what? For the promise of being able to identify someone?
What good would it have been to know the names of Timothy McVeigh, the Unabomber, or the DC snipers before they were arrested? Palestinian suicide bombers generally have no history of terrorism. The goal is here is to know someone's intentions, and their identity has very little to do with that.
And there are security benefits in having a variety of different ID documents. A single national ID is an exceedingly valuable document, and accordingly there's greater incentive to forge it. There is more security in alert guards paying attention to subtle social cues than bored minimum-wage guards blindly checking IDs.
That's why, when someone asks me to rate the security of a national ID card on a scale of one to 10, I can't give an answer. It doesn't even belong on a scale."
Maybe someone should point that out to the many vendors scrambling for a piece of the ID card action.
On ID cards, the No2ID campaign have issued their latest newsletter, which as usual is very informative. The campaign are paticularly vexed about the government's response to their 3230-signature petition against ID cards.
Though I guess it is necessary, I'm not sure an irritated response to a re-hashed empty public relations statement is going to help progress their cause, which I wholeheartedly agree with.
Essentially they need to get the newspapers, all the established civil liberties groups (who essentially agree with them anyway)and commerce and industry on their side to build up a head of steam. Pointing out the clear negative technical and economic effects of the ID card scheme and the industries which are going to be affected (all of them), would help get the trade associations and multinational companies on board. If major commerce were convinced to start rallying against the cards then New Labour would fold on the scheme overnight (probably to Gordon Brown's relief and Tony Blair's chagrin).
As to the government's notion that the ID card will help prevent ID fraud as a basis for making us more secure, any security specialist who knows their job will tell you that either the government are being economical with truth or they really don't understand what they are dealing with. As Bruce Schneier says,in the context of a possible ID card scheme in the US:
"In fact, everything I've learned about security over the last 20 years tells me that once it is put in place, a national ID card program will actually make us less secure.
My argument may not be obvious, but it's not hard to follow, either. It centers around the notion that security must be evaluated not based on how it works, but on how it fails.
It doesn't really matter how well an ID card works when used by the hundreds of millions of honest people that would carry it. What matters is how the system might fail when used by someone intent on subverting that system: how it fails naturally, how it can be made to fail, and how failures might be exploited.
The first problem is the card itself. No matter how unforgeable we make it, it will be forged. And even worse, people will get legitimate cards in fraudulent names.
Two of the 9/11 terrorists had valid Virginia driver's licenses in fake names. And even if we could guarantee that everyone who issued national ID cards couldn't be bribed, initial cardholder identity would be determined by other identity documents ... all of which would be easier to forge.
Not that there would ever be such thing as a single ID card. Currently about 20 percent of all identity documents are lost per year. An entirely separate security system would have to be developed for people who lost their card, a system that itself is capable of abuse.
Additionally, any ID system involves people... people who regularly make mistakes. We all have stories of bartenders falling for obviously fake IDs, or sloppy ID checks at airports and government buildings. It's not simply a matter of training; checking IDs is a mind-numbingly boring task, one that is guaranteed to have failures. Biometrics such as thumbprints show some promise here, but bring with them their own set of exploitable failure modes.
But the main problem with any ID system is that it requires the existence of a database. In this case it would have to be an immense database of private and sensitive information on every American -- one widely and instantaneously accessible from airline check-in stations, police cars, schools, and so on.
The security risks are enormous. Such a database would be a kludge of existing databases; databases that are incompatible, full of erroneous data, and unreliable. As computer scientists, we do not know how to keep a database of this magnitude secure, whether from outside hackers or the thousands of insiders authorized to access it.
And when the inevitable worms, viruses, or random failures happen and the database goes down, what then? Is America supposed to shut down until it's restored?
Proponents of national ID cards want us to assume all these problems, and the tens of billions of dollars such a system would cost -- for what? For the promise of being able to identify someone?
What good would it have been to know the names of Timothy McVeigh, the Unabomber, or the DC snipers before they were arrested? Palestinian suicide bombers generally have no history of terrorism. The goal is here is to know someone's intentions, and their identity has very little to do with that.
And there are security benefits in having a variety of different ID documents. A single national ID is an exceedingly valuable document, and accordingly there's greater incentive to forge it. There is more security in alert guards paying attention to subtle social cues than bored minimum-wage guards blindly checking IDs.
That's why, when someone asks me to rate the security of a national ID card on a scale of one to 10, I can't give an answer. It doesn't even belong on a scale."
Friday, January 21, 2005
Software patent directive through agriculture
Looks like there may be another attempt to pass the EU software patent directive at an EU Council agriculture and fisheries meeting on Monday.
Even if the proposal did have merit and had not been widely criticised, sneaking it through in an underhand way like this is bound to create suspicion.
Even if the proposal did have merit and had not been widely criticised, sneaking it through in an underhand way like this is bound to create suspicion.
Berkman Center Report on Digital Media
The Berkman Center's, Digital Media Project have released
"a new report assessing how the digitization of music and movies has transformed not only businesses but copyright law and the idea of intellectual property. The report -- Copyright and Digital Media in a Post-Napster World -- updates a foundational whitepaper, released originally in 2003, to reflect major areas of change. In addition to new lawsuits and proposed legislation, one of the major developments since 2003 lies in international policy changes. The White Paper includes an International Supplement that offers an overview of the most fundamental shifts."
John Palfrey, Donna Wentworth and Derek Slater were amongst the contributers.
Donna also pointed me at what she calls the book review to end all book reviews by Robert S. Boynton
"Who owns the words you're reading right now? if you're holding a copy of Bookforum in your hands, the law permits you to lend or sell it to whomever you like. If you're reading this article on the Internet, you are allowed to link to it, but are prohibited from duplicating it on your web site or chat room without permission. You are free to make copies of it for teaching purposes, but aren't allowed to sell those copies to your students without permission. A critic who misrepresents my ideas or uses some of my words to attack me in an article of his own is well within his rights to do so. But were I to fashion these pages into a work of collage art and sell it, my customer would be breaking the law if he altered it. Furthermore, were I to set these words to music, I'd receive royalties when it was played on the radio; the band performing it, however, would get nothing. In the end, the copyright to these words belongs to me, and I've given Bookforum the right to publish them. But even my ownership is limited. Unlike a house, which I may pass on to my heirs (and they to theirs), my copyright will expire seventy years after my death, and these words will enter the public domain, where anyone is free to use them. But those doodles you're drawing in the margins of this page? Have no fear: They belong entirely to you...
In December 2004, Google announced "Google Print," a project to bring millions of easily searchable, digitized books to the Internet. The project, which has already begun and may take a decade to complete, will further heighten awareness of our vexed relationship to intellectual property. After digitizing the entire holdings of Stanford and the University of Michigan libraries (as well as sections of the libraries of Harvard, Oxford and the New York Public Library), Google Print will search the texts of these books—although one will only be able to read the entire text of those works whose copyright has lapsed and are therefore in the public domain. As for copyrighted titles, one will be able to search their text for names and key phrases but won't be allowed to read the books themselves (a function like Amazon's helpful, but similarly limited, "Search inside this book" service). Instead, one will be directed to a library or bookstore where the book can be located.
As amazing an effort as Google Print is (creating nothing less than a virtual "universal library of knowledge"), its logical goal—giving readers full access to the entire contents of that library—will be undercut by our intellectual property laws. It is an inherently unstable situation, and it is only a matter of time before someone (Amazon? Random House?) develops software to link this vast cache of literature to a convenient print-on-demand service (for which the hardware already exists). When it becomes possible to hold an inexpensive, physical copy of one of Google's digitized titles in one's hands—but only if it was first published prior to 1923 and is therefore in the public domain—people will begin to understand the implications of having something so obviously beneficial (universal access to universal knowledge) tethered to laws from another era. Google Print may be the Trojan Horse of the copyright wars...
Boyle is one of the founders of "digital environmentalism," the movement that is fashioning a new understanding of what the public domain—the "commons," as Boyle and others have called it—might be. The great achievement of the environmental movement, from which Boyle draws inspiration, was its ability to convince a swath of the population—consumers and industrialists alike—that they all had a stake in this thing called "the environment," rather than just the small patch of land where they lived. Similarly, digital environmentalists are raising our awareness of the intellectual "land" to which people ought to feel entitled.
Digital environmentalism is a two-pronged movement, with one group raising the awareness of the cultural stakes of intellectual property among everyday citizens, and the other pressing for legislative and legal change. The difference between the two is one of emphasis, with each participating in the battles of the other. Neither are anarchists or utopians; rather, both perceive of themselves as conservatives in the traditional sense of the term."
Well worth reading the entire piece. Terrific analysis.
"a new report assessing how the digitization of music and movies has transformed not only businesses but copyright law and the idea of intellectual property. The report -- Copyright and Digital Media in a Post-Napster World -- updates a foundational whitepaper, released originally in 2003, to reflect major areas of change. In addition to new lawsuits and proposed legislation, one of the major developments since 2003 lies in international policy changes. The White Paper includes an International Supplement that offers an overview of the most fundamental shifts."
John Palfrey, Donna Wentworth and Derek Slater were amongst the contributers.
Donna also pointed me at what she calls the book review to end all book reviews by Robert S. Boynton
"Who owns the words you're reading right now? if you're holding a copy of Bookforum in your hands, the law permits you to lend or sell it to whomever you like. If you're reading this article on the Internet, you are allowed to link to it, but are prohibited from duplicating it on your web site or chat room without permission. You are free to make copies of it for teaching purposes, but aren't allowed to sell those copies to your students without permission. A critic who misrepresents my ideas or uses some of my words to attack me in an article of his own is well within his rights to do so. But were I to fashion these pages into a work of collage art and sell it, my customer would be breaking the law if he altered it. Furthermore, were I to set these words to music, I'd receive royalties when it was played on the radio; the band performing it, however, would get nothing. In the end, the copyright to these words belongs to me, and I've given Bookforum the right to publish them. But even my ownership is limited. Unlike a house, which I may pass on to my heirs (and they to theirs), my copyright will expire seventy years after my death, and these words will enter the public domain, where anyone is free to use them. But those doodles you're drawing in the margins of this page? Have no fear: They belong entirely to you...
In December 2004, Google announced "Google Print," a project to bring millions of easily searchable, digitized books to the Internet. The project, which has already begun and may take a decade to complete, will further heighten awareness of our vexed relationship to intellectual property. After digitizing the entire holdings of Stanford and the University of Michigan libraries (as well as sections of the libraries of Harvard, Oxford and the New York Public Library), Google Print will search the texts of these books—although one will only be able to read the entire text of those works whose copyright has lapsed and are therefore in the public domain. As for copyrighted titles, one will be able to search their text for names and key phrases but won't be allowed to read the books themselves (a function like Amazon's helpful, but similarly limited, "Search inside this book" service). Instead, one will be directed to a library or bookstore where the book can be located.
As amazing an effort as Google Print is (creating nothing less than a virtual "universal library of knowledge"), its logical goal—giving readers full access to the entire contents of that library—will be undercut by our intellectual property laws. It is an inherently unstable situation, and it is only a matter of time before someone (Amazon? Random House?) develops software to link this vast cache of literature to a convenient print-on-demand service (for which the hardware already exists). When it becomes possible to hold an inexpensive, physical copy of one of Google's digitized titles in one's hands—but only if it was first published prior to 1923 and is therefore in the public domain—people will begin to understand the implications of having something so obviously beneficial (universal access to universal knowledge) tethered to laws from another era. Google Print may be the Trojan Horse of the copyright wars...
Boyle is one of the founders of "digital environmentalism," the movement that is fashioning a new understanding of what the public domain—the "commons," as Boyle and others have called it—might be. The great achievement of the environmental movement, from which Boyle draws inspiration, was its ability to convince a swath of the population—consumers and industrialists alike—that they all had a stake in this thing called "the environment," rather than just the small patch of land where they lived. Similarly, digital environmentalists are raising our awareness of the intellectual "land" to which people ought to feel entitled.
Digital environmentalism is a two-pronged movement, with one group raising the awareness of the cultural stakes of intellectual property among everyday citizens, and the other pressing for legislative and legal change. The difference between the two is one of emphasis, with each participating in the battles of the other. Neither are anarchists or utopians; rather, both perceive of themselves as conservatives in the traditional sense of the term."
Well worth reading the entire piece. Terrific analysis.
Carvivore retirement reports outdated
There have been recent reports on the FBI retiring their surveillance tool Carnivore, which have been irritating Orin Kerr.
"The Associated Press reports that the FBI has retired its "Carnivore" Internet surveillance tool. (It actually happened about two years ago, but no one knew about it until now.) The Carnivore debate was premised on a profound misunderstanding of Internet surveillance practices...
Why did the FBI retire Carnivore? For a reason I explained in an article published two years ago on the Patriot Act (see footnote 247 if you're really interested): in the last few years, the private sector finally caught up with the government. Commercial surveillance tools now have the same privacy-enhancing filter technology that the Carnivore tool has, meaning that the government no longer needs to use Carnivore. Strange, but true."
"The Associated Press reports that the FBI has retired its "Carnivore" Internet surveillance tool. (It actually happened about two years ago, but no one knew about it until now.) The Carnivore debate was premised on a profound misunderstanding of Internet surveillance practices...
Why did the FBI retire Carnivore? For a reason I explained in an article published two years ago on the Patriot Act (see footnote 247 if you're really interested): in the last few years, the private sector finally caught up with the government. Commercial surveillance tools now have the same privacy-enhancing filter technology that the Carnivore tool has, meaning that the government no longer needs to use Carnivore. Strange, but true."
Thursday, January 20, 2005
California proposal jolts Felten
Ed Felten was shocked to find that the latest proposal to regulate P2P networks by California would make him a candidate for the slammer.
"Kevin Murray, a California legislator, has introduced a bill that would fine, or imprison for up to one year, any person who "sells, offers for sale, advertises, distributes, disseminates, provides, or otherwise makes available" software that allows users to connect to networks that can share files, unless that person takes "reasonable care" to ensure that the software is not used illegally. TechDirt argues that my TinyP2P program would violate the proposed law.
Actually, the bill would appear to apply to a wide range of general-purpose software:
"[P]eer-to-peer file sharing software" means software that once installed and launched, enables the user to connect his or her computer to a network of other computers on which the users of these computers have made available recording or audiovisual works for electronic dissemination to other users who are connected to the network. When a transaction is complete, the user has an identical copy of the file on his or her computer and may also then disseminate the file to other users connected to the network.
That definition clearly includes the web, and the Internet itself, so that any software that enabled a user to connect to the Internet would be covered. And note that it's not just the author or seller of the software who is at risk, but also any advertiser or distributor. Would TechDirt be committing a crime by linking to my TinyP2P page? Would my ISP be committing a crime by hosting my site?"
"Kevin Murray, a California legislator, has introduced a bill that would fine, or imprison for up to one year, any person who "sells, offers for sale, advertises, distributes, disseminates, provides, or otherwise makes available" software that allows users to connect to networks that can share files, unless that person takes "reasonable care" to ensure that the software is not used illegally. TechDirt argues that my TinyP2P program would violate the proposed law.
Actually, the bill would appear to apply to a wide range of general-purpose software:
"[P]eer-to-peer file sharing software" means software that once installed and launched, enables the user to connect his or her computer to a network of other computers on which the users of these computers have made available recording or audiovisual works for electronic dissemination to other users who are connected to the network. When a transaction is complete, the user has an identical copy of the file on his or her computer and may also then disseminate the file to other users connected to the network.
That definition clearly includes the web, and the Internet itself, so that any software that enabled a user to connect to the Internet would be covered. And note that it's not just the author or seller of the software who is at risk, but also any advertiser or distributor. Would TechDirt be committing a crime by linking to my TinyP2P page? Would my ISP be committing a crime by hosting my site?"
Wednesday, January 19, 2005
Response from SiteKiosk
I've just had an email from Thorsten Abdinghoff, Technical Sales Manager for PROVISIO GmbH, offering to add the url for this blog to the list of allowed sites for their SiteKiosk filter system.
Many thanks to Thorsten.
Many thanks to Thorsten.
Jail for P2P developers in California?
A new bill being introduced in California could lead to jail time for developers of P2P software. Not clever.
Initial IT Support response
I've just had a phone call from a very helpful IT specialist called Brice at Initial, in response to the email I sent yesterday about having this blog blocked. He said he'll be able to get the block lifted but it will involve sending someone down to Harben House to do it because no one in the conference centre would have the expertise. Initial apparently use sitekiosk.com software, which comes bundled with filters. I've emailed SiteKiosk vendor, PROVISIO GmbH (contact@provisio.de), to see what they have to say. Apparently they have 2500 customers for their SiteKiosk sofware, based in 50 countries all blocked from a blog on the politics of technology.
Maybe I should ask Ben Edelmann at Harvard to look into it.
Maybe I should ask Ben Edelmann at Harvard to look into it.
Americans on trial in China
Two Americans are amongst those on trial in a Shanghai court in China for selling pirated DVDs through eBay and a Russian website.
Tuesday, January 18, 2005
Candian DOJ watch US patent case
The Canadian Department of Justice have filed an amicus brief in a US patent case.
"The federal government has stepped into the middle of a high-stakes patent infringement battle between Research in Motion Inc. and a U.S. company, claiming a recent U.S. court ruling against the creator of the iconic BlackBerry communications device threatens to chill innovation by Canadian firms and give extra-territorial reach to U.S. patent law."
"The federal government has stepped into the middle of a high-stakes patent infringement battle between Research in Motion Inc. and a U.S. company, claiming a recent U.S. court ruling against the creator of the iconic BlackBerry communications device threatens to chill innovation by Canadian firms and give extra-territorial reach to U.S. patent law."
Filter stories
There are two more filtering stories I wanted to point to in the light of the Verizon decision to block email from selected parts of Europe including the UK.
The Australian Securities and Investments Commission would like Aussie ISPs to block fraudulent websites because Aussies allegedly "tend to be quite susceptible" to them. The Australian trade association representing ISPs are not keen on the idea, not surprisingly. Firstly, I seriously doubt Australians are any more susceptible to online scams than any other nationality but continue to be amazed by the huge numbers of people who are taken in by things like phishing and the Nigerian 519 emails [which, amongst other things, is a function of greed and simultaneous trust in the output of technology, however skeptical these folk would be of a similar offer on a street corner].
Secondly it raises a whole host of questions, similar to those asked by folk like Cyber Rights in relation to things like high tech crime, hate speech and child pornography on the Internet and how organisations such as the Internet Watch Foundation are operated, overseen and regulated. Plus who pays for it?
Ultimately forcing ISPs to filter out suspected fraud sites is no substitute for spending money on well trained police officers, skilled in the prevention, detection and prosecution of high tech crimes.
The second filtering story was the report in Net Family News pointing to websites that evaluate filter software. Just remember that installing filter software can instil a false sense of security. It is easy to believe the problem of children getting access to inappropriate material is solved once the software is installed. Yet it has been demonstrated repeatedly that these filters do allow pornography, for example, to get through. In this case, there is no substitute for talking to and trusting your children (and they will probably be more skilled in disabling such software than you will be in installing it in any case).
Plus I remain irritated about filter software blocking this blog, presumably because it has xxx in the title. I've not been back to Harben House since I discovered they were censoring me, so I've no idea whether they did as promised and had a human being review the block. But I've emailed them again to ask, in the first instance, what the outcome of their promised investigation was.
The Australian Securities and Investments Commission would like Aussie ISPs to block fraudulent websites because Aussies allegedly "tend to be quite susceptible" to them. The Australian trade association representing ISPs are not keen on the idea, not surprisingly. Firstly, I seriously doubt Australians are any more susceptible to online scams than any other nationality but continue to be amazed by the huge numbers of people who are taken in by things like phishing and the Nigerian 519 emails [which, amongst other things, is a function of greed and simultaneous trust in the output of technology, however skeptical these folk would be of a similar offer on a street corner].
Secondly it raises a whole host of questions, similar to those asked by folk like Cyber Rights in relation to things like high tech crime, hate speech and child pornography on the Internet and how organisations such as the Internet Watch Foundation are operated, overseen and regulated. Plus who pays for it?
Ultimately forcing ISPs to filter out suspected fraud sites is no substitute for spending money on well trained police officers, skilled in the prevention, detection and prosecution of high tech crimes.
The second filtering story was the report in Net Family News pointing to websites that evaluate filter software. Just remember that installing filter software can instil a false sense of security. It is easy to believe the problem of children getting access to inappropriate material is solved once the software is installed. Yet it has been demonstrated repeatedly that these filters do allow pornography, for example, to get through. In this case, there is no substitute for talking to and trusting your children (and they will probably be more skilled in disabling such software than you will be in installing it in any case).
Plus I remain irritated about filter software blocking this blog, presumably because it has xxx in the title. I've not been back to Harben House since I discovered they were censoring me, so I've no idea whether they did as promised and had a human being review the block. But I've emailed them again to ask, in the first instance, what the outcome of their promised investigation was.
Copyright killing documentaries
Interesting article in the Globe and Mail yesterday about the increasing difficulties documentary film makers are having as a result of the changes in the copyright landscape of recent times.
"As Americans commemorate Martin Luther King Jr. and his legacy today, no television channel will be broadcasting the documentary series Eyes on the Prize. Produced in the 1980s and widely considered the most important encapsulation of the American civil-rights movement on video, the documentary series can no longer be broadcast or sold anywhere.
Why?
The makers of the series no longer have permission for the archival footage they previously used of such key events as the historic protest marches or the confrontations with Southern police. Given Eyes on the Prize's tight budget, typical of any documentary, its filmmakers could barely afford the minimum five-year rights for use of the clips. That permission has long since expired, and the $250,000 to $500,000 needed to clear the numerous copyrights involved is proving too expensive.
This is particularly dire now, because VHS copies of the series used in countless school curriculums are deteriorating beyond rehabilitation. With no new copies allowed to go on sale, "the whole thing, for all practical purposes, no longer exists," says Jon Else, a California-based filmmaker who helped produce and shoot the series and who also teaches at the Graduate School of Journalism of the University of California, Berkeley."
"As Americans commemorate Martin Luther King Jr. and his legacy today, no television channel will be broadcasting the documentary series Eyes on the Prize. Produced in the 1980s and widely considered the most important encapsulation of the American civil-rights movement on video, the documentary series can no longer be broadcast or sold anywhere.
Why?
The makers of the series no longer have permission for the archival footage they previously used of such key events as the historic protest marches or the confrontations with Southern police. Given Eyes on the Prize's tight budget, typical of any documentary, its filmmakers could barely afford the minimum five-year rights for use of the clips. That permission has long since expired, and the $250,000 to $500,000 needed to clear the numerous copyrights involved is proving too expensive.
This is particularly dire now, because VHS copies of the series used in countless school curriculums are deteriorating beyond rehabilitation. With no new copies allowed to go on sale, "the whole thing, for all practical purposes, no longer exists," says Jon Else, a California-based filmmaker who helped produce and shoot the series and who also teaches at the Graduate School of Journalism of the University of California, Berkeley."
Monday, January 17, 2005
Schneier on Secure Flight evaluation group
Bruce Schneier is now also a member of a working group evaluating the replacement of the CAPPS II passenger profiling programme, "Secure Flight."
"I am participating in a working group to help evaluate the effectiveness and privacy implications of the TSA's Secure Flight program. We've had one meeting so far, and it looks like it will be an interesting exercise.
For those who have not been following along, Secure Flight is the follow-on to CAPPS-I. (CAPPS stands for Computer Assisted Passenger Pre-Screening.) CAPPS-I has been in place since 1997, and is a simple system to match airplane passengers to a terrorist watch list. A follow-on system, CAPPS-II, was proposed last year. That complicated system would have given every traveler a risk score based on information in government and commercial databases. There was a huge public outcry over the invasiveness of the system, and it was cancelled over the summer. Secure Flight is the new follow-on system to CAPPS-I.
Many of us believe that Secure Flight is just CAPPS-II with a new name. I hope to learn whether or not that is true.
I hope to learn a lot of things about Secure Flight and airline passenger profiling in general, but I probably won't be able to write about it. In order to be a member of this working group, I was required to apply for a U.S. government SECRET security clearance and sign an NDA, promising that I would not disclose something called "Sensitive Security Information."
SSI is one of three new categories of secret information, all of I think have no reason to exist. There is already a classification scheme -- CONFIDENTIAL, SECRET, TOP SECRET, etc. -- and information should either fit into that scheme or be public. A new scheme is just confusing. The NDA we were supposed to sign was very general, and included such provisions as allowing the government to conduct warrantless searches of our residences. (Two federal unions have threatened to sue the government over several provisions in that NDA, which applies to many DHS employees. And just recently, the DHS backed down.)
After push-back by myself and several others, we were given a much less onerous NDA to sign."
So why is he participating at all given his concerns? He says:
" I hope I can help make Secure Flight an effective security tool. I hope I can help minimize the privacy invasions on the program if it continues, and help kill it if it is ineffective. I'm not optimistic, but I'm hopeful.
I'm not hopeful that you will ever learn the results of this working group. We're preparing our report for the Aviation Security Advisory Committee, and I very much doubt that they will release the report to the public."
"I am participating in a working group to help evaluate the effectiveness and privacy implications of the TSA's Secure Flight program. We've had one meeting so far, and it looks like it will be an interesting exercise.
For those who have not been following along, Secure Flight is the follow-on to CAPPS-I. (CAPPS stands for Computer Assisted Passenger Pre-Screening.) CAPPS-I has been in place since 1997, and is a simple system to match airplane passengers to a terrorist watch list. A follow-on system, CAPPS-II, was proposed last year. That complicated system would have given every traveler a risk score based on information in government and commercial databases. There was a huge public outcry over the invasiveness of the system, and it was cancelled over the summer. Secure Flight is the new follow-on system to CAPPS-I.
Many of us believe that Secure Flight is just CAPPS-II with a new name. I hope to learn whether or not that is true.
I hope to learn a lot of things about Secure Flight and airline passenger profiling in general, but I probably won't be able to write about it. In order to be a member of this working group, I was required to apply for a U.S. government SECRET security clearance and sign an NDA, promising that I would not disclose something called "Sensitive Security Information."
SSI is one of three new categories of secret information, all of I think have no reason to exist. There is already a classification scheme -- CONFIDENTIAL, SECRET, TOP SECRET, etc. -- and information should either fit into that scheme or be public. A new scheme is just confusing. The NDA we were supposed to sign was very general, and included such provisions as allowing the government to conduct warrantless searches of our residences. (Two federal unions have threatened to sue the government over several provisions in that NDA, which applies to many DHS employees. And just recently, the DHS backed down.)
After push-back by myself and several others, we were given a much less onerous NDA to sign."
So why is he participating at all given his concerns? He says:
" I hope I can help make Secure Flight an effective security tool. I hope I can help minimize the privacy invasions on the program if it continues, and help kill it if it is ineffective. I'm not optimistic, but I'm hopeful.
I'm not hopeful that you will ever learn the results of this working group. We're preparing our report for the Aviation Security Advisory Committee, and I very much doubt that they will release the report to the public."
Subscribe to:
Posts (Atom)