Wednesday, November 28, 2007

Harry Potter and the (Re)Order of the Artists: Are We Muggles or Goblins?

Thanks to Mike Madison for pointing out that Gary Pulsinelli has written the article probably quite a few IP scholars have been thinking of writing a version of, ever since the last Harry Potter book was published. Abstract:
In Harry Potter and the Deathly Hallows, author J.K. Rowling attributes to goblins a very interesting view of ownership rights in artistic works. According to Rowling, goblins believe that the maker of an artistic object maintain an ongoing ownership interest in that object even after it is sold, and is entitled to get it back when the purchaser dies. While this view may strike some as rather odd when it is applied to tangible property in the ?muggle? world, it actually has some very interesting parallels to the legal treatment of intangible property, particularly in the areas of intellectual property and moral rights. Because of the way these parallels have been developing and growing, we seem to be becoming more goblinish in our willingness to recognize ongoing rights in artistic objects, including allowing the artist to collect a commission on subsequent resale of the work. Practical and social considerations suggest that we are unlikely to go as far as recognizing a permanent personal right in the creator that lets him or her reclaim such an object after a sale or other transfer is made. However, we are moving closer to recognizing some forms of the collective right that the goblins actually seem to demand, a cultural moral right in important cultural objects that enables the descendants of that culture as a group to demand the return of the object. Thus, we muggles may not be as far from the goblins as we may have at first believed.


Must make a point of reading it properly.

Grimmelmann's Library of Babel

Now that we're on the subject of Google I should recommend James Grimmelmann's excellent essay Information Policy for the Library of Babel to be published in the forthcoming edition of the Maryland Journal of Business and Technology Law.
"Borges’s 1941 short story The Library of Babel describes an unbelievably large library containing all possible books. Within the the “total” and “endless” reaches of the Library,”[t]here [is] no personal problem, no world problem, whose eloquent solution [does] not exist—somewhere …” but also “[f]or every rational line or forthright statement there are leagues of senseless cacophony, verbal nonsense, and incoherency.” As Borges describes it, the Library is the greatest imaginable source of information: it contains “The Vindications—books of apologiae and prophecies that would vindicate for all time the actions of every person in the universe and that held wondrous arcana for men’s futures.”

But the Library’s vastness and disorganization also make it almost completely useless: “[T]he chance of a man’s finding his own Vindication … can be calculated to be zero.” The image of the Library is haunting and suggestive. What would we do if we took it at face value? In this bagatelle of an essay, I propose to do just that: set out a few principles of sensible information policy for the Library of Babel."

[James Grimmelmann. 2007. "Information Policy for the Library of Babel" Maryland Journal of Business and Technology Law
Available at: http://works.bepress.com/james_grimmelmann/16]

The Google Complement - Free Content

Nicholas Carr might suggest that Google is on Martin's side in the future of content debate. Essentially he says Google wants content to be free because this complements its core business thereby making that business stronger.
Because the sales of complementary products rise in tandem, a company has a strong strategic interest in reducing the cost and expanding the availability of the complements to its core product. It’s not too much of an exaggeration to say that a company would like all complements to be given away. If hot dogs became freebies, mustard sales would skyrocket. It’s this natural drive to reduce the cost of complements that, more than anything else, explains Google’s strategy. Nearly everything the company does, including building big data centers, buying optical fiber, promoting free Wi-Fi access, fighting copyright restrictions, supporting open source software, and giving away Web services and data, is aimed at reducing the cost and expanding the scope of Internet use. To borrow a well-worn phrase, Google wants information to be free - and that is why Google strikes fear into so many different kinds of companies.

That actually also goes to the heart of why I (the poor man's Lessig remember) am no longer as pessimistic as I used to be about future limited access to content through tollbooths concentrated in few hands, even though drm is not going away. Large commercial entities are lined up on both sides of the divide and Google is likely to have more weight than all the most rational, evidence-based arguments academics, other experts and activists can muster. As Lessig says of his next ten year project, tackling corruption in US politics, it's all about the money.

The value of play

The Old Bridge Public library in New Jersey held a Wii tournament for senior citizens a few weeks ago, as part of a project to help pensioners become more technically literate. The library assistant director, Allan Kleiman, explained that it was a lot less intimidating and significantly more sociable to learn to use the Wii than to learn to use a computer. He's got a point. The social side of gaming is often overlooked by critics and it's pretty difficult for anyone to have an informed discussion about teh educational and social potential of gaming without having direct experience of using computer games in a variety of contexts.

Making the technology available also draws the younger folks into the library and ironically seems in turn to lead to more books getting loaned out, in contrast to the widely toted notion that computer games take kids away, to the detriment of their development, from the much more cerebral, engaging, but humble book.

It gets back to the Charles Nesson/Yochai Benkler assertion that we will become intelligent and creative 'readers'/users of new technology through being intelligent creators/users of and through new technology i.e. the try it out and see what works model of life. Keep playing and tinkering and find out for yourself rather than waiting for others to dictate to you.

RIAA ordered to detail expenses per song lost in P2P case

In UMG v Lindor, yet another RIAA v individual case the judge has ordered the RIAA to disclose the actual expenses incurred for each of the songs at issue in the case.

The defendant is arguing that the statutory damages of between $750 and $150,000 per song is excessive and they need to have an idea of the real cost to the record companies before damages can be assessed. That seems like a reasonable request.

The RIAA say they can't provide those figures without going to enormous expense. The temptation here is to omit a hollow laugh but actually we could look at this as the record labels finally admitting that no one knows or can possibly know the real extent of the impact of P2P file sharing, infringing and non infringing, on their market, despite the perennial estimates that it amounts to billions of dollars.

U.S. withdraws subpoena seeking identity of 24,000 Amazon customers

Via SiliconValley.com: U.S. withdraws subpoena seeking identity of 24,000 Amazon customers

Super Mario comes out fighting for patent

Earlier this year the UK Patent Office refused to award patent protection to a software technique Nintendo use in the Super Mario Kart game to get crashed cars quickly back on the track. Now another similar decision on software patents has been appealed to the High Court, according to IPKat, who says:

"The appellants allege that the UK-IPO’s practice undermines the ability of British industry to protect inventions reliant upon the development of new software. Each applicant has developed novel software, the control and distribution of which they say is critical to the success of their business. Nicholas Fox of Beresford & Co. said in the lead-up to the appeal,

Copyright protection only protects code against copying. In contrast, patent protection enables a company to monopolise an invention even if competitors independently come up with the same idea. In order to protect their commercial interests companies need patent claims directed towards the products and processes that are sold in the market place. In the case of computer based inventions this means that claims to disks and downloads embodying an invention are required.

In Court, the appellants argued that software on a disk represented a "dormant technical effect in waiting", analogous to a medical pill that just sat there doing nothing until the patient took it. Using the same principle, the software would produce a technical effect when run on the computer. [IPKat comment: this seems a new argument, and an interesting approach, but arguing by analogy is rarely helpful; after all, medicines themselves are not excluded under section 1(2)]

They argued that, following the landmark IBM decision T 1173/97 at the EPO, a computer program product is not excluded from patentability under Article 52(2) and (3) EPC if, when it is run on a computer, it produces a "further technical effect" which goes beyond the normal physical interactions between program and computer, i.e. between software and hardware. The EPO approach has been broadly consistent in its decisions since then."

Thanks to David Gerard via ORG for the link.

The Future of Reading

In the spirit of the debate Martin Weller and I, Will Woods and Patrick McAndrew had several weeks ago, on the future of content, Steven Levy has a terrific article in Newsweek this week on the future of the book, featuring Amazon's new ebook reader, the Kindle.

Tuesday, November 27, 2007

The Biometrics Cure

Ben Goldacre has a nice article on the government's cure-all-security-ills answer - biometrics - to last week's HMRC-NAO data loss.

Essentially ministers who think biometrics will make data misuse impossible are misinformed at best or lying at the other end of the spectrum.

As Ben points out, the thing about biometrics is that they may be unique (though they won't be for long when forged) but they are not secret. We leave fingerprints and bits of dna in the forms of loose hairs or bits of skin lying around all over the place, so our biometrics are most definitely not secret. And biometric technologies are not particularly good, in spite of government ministers' apparent belief to the contrary. So the notion that the HMRC-NAO data leak would not have been a problem if we'd been using biometrics or that we are going to tackle data security through biometrics is naive and stupid.

If you'd like some of succinct but serious and robust outlines of why this is so check out Ross Anderson's book, (chapter 13 current edition, chapter 15 new edition due in the new year), this Jerry Fishenden essay, and the brilliant letter below (which I hope Ian, Ross and co don't mind me re-producing in full) to the UK Parliament's Joint Committee on Human Rights.
Mr Andrew Dismore MP
Chair, Joint Committee on Human Rights
Committee Office
House of Commons
7 Millbank
London SW1P 3JA

cc: Committee members; David Smith, Deputy Information Commissioner

26 November 2007

Dear Mr Dismore,

The government, in response to the recent HMRC Child Benefit data breach, has asserted that personal information on the proposed National Identity Register (NIR) will be 'biometrically secured':

"The key thing about identity cards is, of course, that information is protected by personal biometric information. The problem at present is that, because we do not have that protection, information is much more vulnerable than it should be." - The Chancellor, Hansard Column 1106, 20/11/07

"What we must ensure is that identity fraud is avoided, and the way to avoid identity fraud is to say that for passport information we will have the biometric support that is necessary, so that people can feel confident that their identity is protected." - The Prime Minister, Hansard Column 1181, 21/11/07


These assertions are based on a fairy-tale view of the capabilities of the technology, and in addition, only deal with one aspect of the problems that this type of data breach causes.

Ministers assert that people's information will be 'protected' because it will be much harder for someone to pass themselves off as another individual if a biometric check is made. This presupposes that:

(a) the entire population can be successfully biometrically enrolled onto the National Identity Register, and successfully matched on every occasion thereafter - which is highly unlikely, given the performance of biometrics across mass populations generally and especially their poor performance in the only, relatively small-scale, trial to date (UKPS enrolment trial, 2004). Groups found to have particular problems with biometric checks include the elderly, the disabled and some ethnic groups such as Asian women;

(b) biometrics are 'unforgeable' - which is demonstrably untrue. Biometric systems have been compromised by 'spoofing' and other means on numerous occasions and, as the technology develops, techniques for subverting the systems evolve too;

(c) every ID check will be authenticated by a live biometric check against the biometric stored on the NIR or at the very least against the biometric stored on the chip on the ID card which is itself verified against the NIR. [N.B. This would represent a huge leap in the cost of the scheme which at present proposes only to check biometrics for 'high value' transactions. The network of secure biometric readers alone (each far more complex and expensive than, e.g. a Chip & PIN card reader) would add billions to the cost of rollout and maintenance.]

Even if, in this fairy-tale land, it came to pass that (a) (b) and (c) were true after all (which we consider most unlikely), the proposed roll-out of the National Identity Scheme would mean that this level of 'protection' would not - on the Home Office's own highly optimistic projections - be extended to the entire population before the end of the next decade (i.e. 2020) at the earliest.

Furthermore, biometric checks at the time of usage do not of themselves make any difference whatsoever to the possibility of the type of disaster that has just occurred at HMRC. This type of data leakage, which occurs regularly across Government, will continue to occur until there is a radical change in the culture both of system designer and system users. The safety, security and privacy of personal data has to become the primary requirement in the design, implementation, operation and auditing of systems of this kind.

The inclusion of biometric data in one's NIR record would make such a record even more valuable to fraudsters and thieves as it would - if leaked or stolen - provide the 'key' to all uses of that individual's biometrics (e.g. accessing personal or business information on a laptop, biometric access to bank accounts, etc.) for the rest of his or her life. Once lost, it would be impossible to issue a person with new fingerprints. One cannot change one's fingers as one can a bank account.

However, this concentration on citizens 'verifying' their identity when making transactions is only one issue amongst many when considering the leakage of personal data. Large-scale losses of personal data can have consequences well beyond an increase in identity fraud. For example, they could be potentially fatal to individuals such as the directors of Huntingdon Life Sciences, victims of domestic violence or former Northern Ireland ministers.

It is therefore our strongest recommendation that further development of a National Identity Register or National Identity Scheme (including biometric visas and ePassports) should be suspended until such time that research and development work has established beyond reasonable doubt that these are capable of operating securely, effectively and economically on the scale envisaged.

Government systems have so far paid little attention to privacy. Last week's events have very significant implications indeed for future government information systems development.

We would be pleased to clarify any of these points or provide further information if useful to the Committee.

Yours sincerely,

Professor Ross Anderson
Dr Richard Clayton
University of Cambridge Computer Laboratory

Dr Ian Brown
Oxford Internet Institute, University of Oxford

Dr Brian Gladman
Ministry of Defence and NATO (retired)

Professor Angela Sasse
University College London Department of Computer Science

Martyn Thomas CBE FREng

Child database plan under attack

From the Independent: Child database plan under attack following missing discs debacle

It seems the schools secretary Ed Balls has ordered a review of the Children Act database(s) in the wake of the HMRC-NAO data loss debacle. Good news on the surface but it has little or no prospect of it having any effect other than window dressing, in a transparent attempt to be seen to be doing something. If he was really serious he'd start by getting Terri Dowty, Ross Anderson, Ian Brown and the other folks who produced the report for the Information Commissioner last year, highlighting the risks to children’s safety of the government’s policy of creating large, centralised databases on children, in a room and listening seriously to them and acting on their advice, rather than treating them as outcasts with agendas to be ignored.

Sunday, November 25, 2007

An analysis of the latest Harry Potter case

C.E. Petit believes that the latest Harry Potter case against the Harry Potter Lexicon folks has more to do with Warner Bros than J.K. Rowling. Couldn't agree more.

BSA make money from threatening small businesses

The BSA are reportedly making a lot of money out of threatening small businesses with expensive court proceedings.

"An analysis by The Associated Press reveals that targeting small businesses is a lucrative strategy for the Business Software Alliance, the main global copyright-enforcement watchdog for such companies as Microsoft Corp., Adobe Systems Inc. and Symantec Corp.

Of the $13 million that the BSA reaped in software violation settlements with North American companies last year, almost 90 percent came from small businesses, the AP found."

ICO launch young people privacy awareness site

The Information Commissioner's Office has launched a web site to encourage young people to take privacy seriously on social networking sites.

Saturday, November 24, 2007

The 25M data loss correspondence

Spyblog has done a lovely dissection of the correspondence related to the loss of child benefit data containing the personal details of 25 million people.

Friday, November 23, 2007

ARCH on the HMRC data loss

ARCH has been deluged with requests for advice in the wake of the HMRC data loss.

"I doubt there’s anyone who doesn’t know about HMRC’s Child Benefit debacle by now. As you can imagine, we’re a bit busy and the phone has got heat exhaustion.

This is the press release we put out earlier (NB the numbers have gone up since we sent this out):

FOR IMMEDIATE RELEASE 20TH NOVEMBER 2007

CHILDREN’S RIGHTS ORGANISATION ‘STUNNED’ BY HMRC DATA LOSS

Action on Rights for Children is stunned to learn that HMRC has lost computer disks containing the details of the UK’s 15 million children.

Terri Dowty, Director of ARCH said: “This appalling security lapse has placed children in the UK in immediate danger especially those who are already vulnerable. Child Benefit records contain every child’s address and date of birth. We are not surprised that the Chair of HMRC’s Board has resigned immediately.”

Last year Terri Dowty co-authored a report for the Information Commissioner which highlighted the risks to children’s safety of the government’s policy of creating large, centralised databases containing sensitive information about children. The government chose to dismiss the concerns of the reports authors.

“The government has recently passed regulations allowing them to build databases containing details of every child in England. They have also announced an intention to create a second national database containing the in-depth personal profiles of children using services. They have batted all constructive criticism away, and repeatedly stressed that children’s data is safe in their hands.

“The events of today demonstrate that this is simply not the case, and all of our concerns for children’s safety are fully justified.”

NOTES TO EDITORS

The report ‘Children’s Databases: Safety and Privacy’ can be downloaded from: http://www.fipr.org/childrens_databases.pdf"



Kim Cameron says the government should be listening to folks like Terri.

"Here is more context on the HMRC identity catastrophe.

According to Terri Dowty, Director of Action on Rights for Children (ARCH):

“This appalling security lapse has placed children in the UK in immediate danger especially those who are already vulnerable. Child Benefit records contain every child’s address and date of birth [italics mine - Kim]. We are not surprised that the Chair of HMRC’s Board has resigned immediately.”

Last year Terri Dowty co-authored a report for the British Information Commissioner which highlighted the risks to children’s safety of the government’s policy of creating large, centralised databases containing sensitive information about children. But the government chose to dismiss the concerns of the reports authors.

Dowty’s remarks demonstrate a clear instance of my thesis that reduction of identity leakage is still not considered to be a “must-have” rather than a “nice-to-have”

“The government has recently passed regulations allowing them to build databases containing details of every child in England. They have also announced an intention to create a second national database containing the in-depth personal profiles of children using services. They have batted all constructive criticism away, and repeatedly stressed that children’s data is safe in their hands.

“The events of today demonstrate that this is simply not the case, and all of our concerns for children’s safety are fully justified.”

The report ‘Children’s Databases: Safety and Privacy’ can be downloaded here.

I urge fellow architects, IT leaders, policy thinkers and technologically aware politicians to consider very seriously the advice of advocates like Terry Dowty. We can deeply benefit from building safe and privacy-enhancing systems that are secure enough to withstand attack and procedural error. Let’s work together to translate this thinking to those who are less technical. We need to explain that all the functionality required for government and business can be provided in ways that enhance privacy, rather than diminish it or set society up for failure.

Today the “inconvenient” input of people like Terry Dowty is often dismissed - much the way other security concerns used to be - until computer systems began to fall under the weight of internet and insider attacks…"

Kim Cameron on UK's identity Chernobyl

I hope Kim Cameron doesn't mind me quoting him in full on the HMRC 25 million data loss

" The recent British Identy Chernobyl demands our close examination.

Consider:

  • the size of the breach – loss of one person’s identity information is cause for concern, but HMRC lost the information on 25 million people (7.5 million families)
  • the actual information “lost” – unencrypted records containing not only personal but also banking and national insurance details (a three-for-one…)
  • the narrative – every British family with a child under sixteen years of age made vulnerable to fraud and identity theft

According to Bloomberg News,

Political analysts said the data loss, which prompted the resignation of the head of the tax authority, could badly damage the government.

“I think it’s just a colossal error that I think could really rebound on the government’s popularity”, said Lancaster University politics Professor David Denver.

“What people think about governments these days is not so about much ideology, but about competence, and here we have truly massive incompetence.”

Even British Chancellor Alistair Darling said,

“Of course it shakes confidence, because you have a situation where millions of people give you information and expect it to be protected.

Systemic Failure

Meanwhile, in parliament, Prime Minister Gordon Brown explained that security measures had been breached when the information was downloaded and sent by courier to the National Audit Office, although there had been no “systemic failure”.

This is really the crux of the matter. Because, from a technology point of view, the failure was systemic.

From a technology point of view, the failure was systemic.

We are living in an age where systems dealing with our identity must be designed from the bottom up not to leak information in spite of being breached. Perhaps I should say, “redesigned from the bottom up”, because today’s systems rarely meet the bar. It’s not that data protection wasn’t considered when devising them. It is simply that the profound risks were not yet evident, and guaranteeing protection was not seen to be as fundamental as meeting other design goals - like making sure the transactions balanced or abusers were caught.

Isn’t it incredible that “a junior official” could simply “download” detailed personal and financial information on 25 million people? Why would a system be designed this way?

To me this is the equivalent of assembling a vast pile of dynamite in the middle of a city on the assumption that excellent procedures would therefore be put in place, so no one would ever set it off.

There is no need to store all of society’s dynamite in one place, and no need to run the risk of the collosal explosion that an error in procedure might produce.

Similarly, the information that is the subject of HMRC’s identity catastrophe should have been partitioned - broken up both in terms of the number of records and the information components.

In addition, it should have been encrypted - even rights protected from beginning to end. And no official (A.K.A insider) should ever have been able to get at enough of it that a significant breach could occur.

Gordon Brown, like other political leaders, deserves technical advisors savvy enough to explain the advantages of adopting new approaches to these problems. Information technology is important enough to the lives of citizens that political leaders really ought to understand the implications of different technology strategies. Governments need CTOs that are responsible for national technical systems in much the same ways that chancellors and the like are responsible for finances.

Rather than being advised to apologize for systems that are fundamentally flawed, leaders should be advised to inform the population that the government has inherited antiquated systems that are not up to the privacy requirements of the digital age, and put in place solutions based on breach-resistance and privacy-enhancing technologies.

The British information commissioner, Richard Thomas, is conducting a broad inquiry on government data privacy. He is quoted by the Guardian as saying he was demanding more powers to enter government offices without warning for spot-checks.

He said he wanted new criminal penalties for reckless disregard of procedures. He also disclosed that only last week he had sought assurances from the Home Office on limiting information to be stored on ID cards.

“This could not be more serious and has to be a serious wake-up call to the whole of government. We have been warning about these dangers for more than a year.

I have never understood why any politician in his (or her) right mind wouldn’t want to be on the privacy-enhancing and future-facing side of this problem."

The Infringement Age

From TechDirt: The Infringement Age: How Much Do You Infringe On A Daily Basis?

"Boing Boing points us to a paper from John Tehranian, called Infringement Nation: Copyright Reform and the Law/Norm Gap (pdf), which attempts to show how far out of whack copyright laws are, with the simple tale of a hypothetical law professor (coincidentally named John, of course) going about a normal day, tallying up every big of copyright infringement he engages in. Replying to an email with quoted text? Infringement! Reply to 20 emails? You're looking at $3 million in statutory damages. Doodle a sketch of a building? Unauthorized derivative work. Read a poem outloud? Unauthorized performance. Forward a photograph that a friend took? Infringement! Take a short film of a birthday dinner with some friends and catch some artwork on the wall in the background? Infringement!
"By the end of the day, John has infringed the copyrights of twenty emails, three legal articles, an architectural rendering, a poem, five photographs, an animated character, a musical composition, a painting, and fifty notes and drawings. All told, he has committed at least eighty-three acts of infringement and faces liability in the amount of $12.45 million (to say nothing of potential criminal charges). There is nothing particularly extraordinary about John’s activities. Yet if copyright holders were inclined to enforce their rights to the maximum extent allowed by law, he would be indisputably liable for a mind-boggling $4.544 billion in potential damages each year. And, surprisingly, he has not even committed a single act of infringement through P2P file sharing. Such an outcome flies in the face of our basic sense of justice. Indeed, one must either irrationally conclude that John is a criminal infringer—a veritable grand larcenist—or blithely surmise that copyright law must not mean what it appears to say. Something is clearly amiss. Moreover, the troublesome gap between copyright law and norms has grown only wider in recent years."
While the paper calls this "infringement nation," it clearly goes beyond our nation. We are living in the "infringement age," where it's impossible not to infringe on copyrights every single day -- yet many people still don't understand why it makes sense to change copyright laws to make them more reasonable."

The poor man's Benkler and Lessig

Martin Weller, at a fascinating seminar given by John Naughton on Yochai Benkler's book, The Wealth of Networks, today described our recent exchange on the future of content as a debate between 'the poor man's Larry Lessig' (me - the pessimist) and 'the poor man's Yochai Benkler' (Martin - the optimist).

There are worse things in life than being thought of as the poor man's Lessig. John reckons I should stick it on the back cover of my book. When Martin becomes famous maybe I'll stick it on the front as a quote from the poor man's Benkler himself.

Update: I should have said that John set up a useful wiki for the seminar and Martin has very helpfully saved me the pleasure of producing a succinct summary of session.

John first set the context for the book, talking about the semiotics of the title and borrowed Castell's term about informed bewilderment to describe our current state when we look at the changes around us. That is, we have no shortage of data about what's happening, but we are still unsure as to what it all means. Benkler's book can be seen as an attempt to cast a scholarly light on this state of bewilderment.

Part of the reason for this bewilderment is that our analytical tools are not as useful as they once were (which is not to say they are completely useless). As John put it economics can be categorised as the analysis of scarcity, whereas what we have in a digital world is abundance. The scarce resource now is attention, and here the competition is now greatly increased from the days of TV dominance.

John also talked about the 'convergence fantasies' of many industries which always boil down to 'converge on to my device'. He argued that convergence happened long ago - onto the net.

He summarised Benkler's book as having six main arguments:

  • Until recently we had a highly industrialised info economy
  • This marginalised non market cultural production (“social production”)
  • ICT has reduced the cost of production and publication
  • Greatly enhanced power and potential of social production
  • This has major implications for economic, social cultural and political life
  • There will be a struggle between old world and new world.

We then went on to discuss three issues:

  1. How plausible is Benkler's analysis?
  2. What might it mean for education (and the OU)?
  3. What might it mean for society?

In terms of 1) I made the point that to an extent it was empirically true - that in open source communities, wikipedia, flickr, etc social production was already a major economic force. So even though critics (Carr, Gorman, Keen et al) may argue against it, the best response is 'yes but look at the facts'. I was reminded of Clay Shirky's memorable phrase regarding AT & T programmers when they first saw open source support in action:

"They didn't care that they'd seen it work in practice, because they already knew it couldn't work in theory."


Martin's given his blog a makeover too now he's in line for Edublog's best ed tech support blog award. Very post modern. Yet another reminder of the need to do something about the b2fxxx look and feel. Tony Hirst has also been nominated in the same category. Good luck to both.

Idealgovernment on the HMRC data loss

William Heath's initial reaction to the HMRC 25 million data loss is worth reading.

"CIO responsibility

Paul Gray who chairs the Board of HMRC assumed responsibility and has gone, but this is fairly and squarely a CIO responsibility. We need CIOs to run reliable systems that respect people’s personal data, and to educate their Boards about the political and business risks of what they are being asked to do in creating e-enabled “transformed” public services. I dont believe they have. I wonder how HMRC’s CIO and the HMG CIO see this today.

[...]

People like Ross Anderson are dismissed as “having an agenda” and vilified behind their backs (or in the case of Simon Davies, publicly).

[...]

Value of the data

What were those disks worth? The FT tells us a person’s full bank account details sell for £15-200 on the black market. We’re dealing here with a fuller profile also including NI number and dates of birth for the whole family. And there are 25m records, and 7.25m families. Assuming the families have one bank account each that values the data at £100m-£1.5bn.

[...]

Now, it is implied this data was lost by a nitwit, and doubtless there are some honest incompetents still working in the ever-leaner HMRC. But plenty of people working there will be smart. And if it’s possible to create disks of this sort of value, which can easily be copied before they’re posted, we can see there has been an irresistible temptation for some time now. It would be extraordinary, an unbelievable tribute to the universal integrity of human nature (and an insult to the energy and ingenuity of the contempory British crook) if this data had not been stolen already, perhaps many times.

Restitution

After rightly resisting for about six hours the shrill Paxman/Peter (thingy from Radio Five-Live) calls for the government to recompense any financial loss we read in today’s FT that Darling says the government WILL cover losses. This means that banks (who are now the only people able to manage this greatly increased risk) can pay out money to the wrong place confident that the taxpayer will pick up the bill.

[...]

Lessons for the ID System

The Chancellor seems to think this episode strengthens the case for ID cards. I disagree.

It may underline the case for good ID management now and in future, but underlines that
- government is not the right place to do it (remember the Home Office is way below HMRC on the scale for competence, quality and morale of staff etc)
- such data should not be centralised
- it’s bad enough losing our NI numbers and account details but worse still to put our biometrics into wide circulation
- and that government is clueless about restitution when it all goes wrong (which is the only thing we want - we all know nothing is secure).

The more we control and manage our own data the less likely this sort of thing is to happen. And we are the ones who care about it most. "

William is also working with Blindside to provide the government with some constructive feedback on this incident. Sadly Nu Labouts ...sorry... Nu Labour is so committed to transformational government - putting more and more personal data into bigger and bigger databases to which hundreds of thousands of people need access as a routine part of their job - that it is virutally impossible to break through their fingers in the ears NOT LISTENING NOT LISTENING instinctive reaction to any feedback, constructive or otherwise, on the subject. One of the most important things government could do is, as Wendy G says in commenting, is to:

"stop dismissing the advice of
knowledgeable experts such as those at FIPR, No2ID,
Privacy International, the LSE, Cambridge University’s
security folks (Ross Anderson et al), and ORG as to
the risks involved on the grounds that they are “a
vocal minority” (that can be safely ignored)"

Thursday, November 22, 2007

Amnesty International campaign against Torture

Via Cory:

"Amnesty International's "Unsubscribe Me" campaign invites us to unsubscribe from the use of torture in fighting the "war on terror;" to tell the world's governments that torture cannot be done in our name. As part of the campaign, they've released an incredibly moving and disturbing video reenacting a CIA-approved "stress position" torture taken straight out of a CIA interrogation manual. In order to make the film, the directors put the actor into a stress position for six hours -- the whimpers and trembling we see are real, the anguish you feel even when you choose to do this, let alone when you are kidnapped and subjected it for weeks, months or years. Amnesty is making two more videos and then doing a theatrical release for all three. We will never be made free by adopting the tactics of dictatorships. Link"

The Amnesty site warns that the video should not be viewed by under 14s.