Thursday, September 07, 2006

Schools may fingerprint kids without parental consent

The Register reports that "Parents cannot prevent schools from taking their children's fingerprints, according to the Department for Education and Skills and the Information Commissioner...

The Information Commissioner's Office (ICO) is drawing up guidance on the use of fingerprints for purposes other than law-enforcement. The guidance will say once and for all whether parents can prevent their children's fingerprints being taken.

David Smith, deputy Information Commissioner, said it was a complex issue that was still being worked out, but it was likely that parents did not have an automatic right to decide whether their children's biometrics could be taken by a school."

Kim Cameron's iTunes drm problems

Kim Cameron is not pleased that a Bob Dylan album he has bought from iTunes doesn't work as he expected because of Apple's drm. He is very annoyed.

I see Martin's been having a few problems with his iPods too. Now if folks like Kim Cameron and Martin Weller, who are pretty good with technical gadgets of all kinds, are tripping over drm to this extent, then the chances of the rest of us ordinary mortals navigating these waters without mishap are slim to negligible. Market fundamentalists would suggest that such a situation would mean that drm won't be long for this world. I suspect it may hang on in there for some time inflicting just the kind of woes experienced by Kim and Martin before it finally gets put to rest.

Wednesday, September 06, 2006

Crime and Disorder Reduction Partnerships

Garrick Alder has been developing nauseous feelings about Crime and Disorder Reduction Partnerships.
VERY soon now, crime and disorder will be mapped out on a house-to-house level and displayed on the internet. The maps will be searchable by anyone, including insurance companies, and will also incorporate aerial photography. Backstage, vast amounts of highly sensitive data - including your medical notes - will be sloshed around on local government and emergency services intranet - and across the internet too. Members of the public will be encouraged to submit complaints of anti-social behaviour via email. The resulting crime maps will be used to provide information for, among other things, decisions about architecture in afflicted areas.

And the best thing about the new Crime and Disorder Reduction Partnerships (CDRPs) is that no one knows about them.

The CDRPs are hybrids composed of elements from (and data-sharing between) local councils, police forces, ambulance trusts, social services, trading standards, fire brigades, youth teams... you name it. These bodies have swapped notes (occasionally and informally) for years but what is happening now is something totally new in the British experience. What was previously a grapevine between the different bodies is becoming a hotline instead, as a new system is bolted laboriously into place.

How did this happen? And why haven't you noticed before now? Let's take the two questions in order.

The first is very simple: The "Labour" party's Crime and Disorder Act 1998 placed "a duty on local authorities to consider the crime and disorder implications of all their policies and practices." Which was all very well as far as it went, since Britain's local councils were constitutionally committed to just that anyway and always had been. But the "Labour" party's Police Reform Act 2002 then extended the same duty to police forces .. and fire authorities... and NHS Primary Care Trusts.

And it didn't place anyone in charge.
Thanks to ARCH for the link.

Thursday, August 31, 2006

Report on copyright barriers to education

The Berkman Center have published a new Foundational White Paper on The Digital Learning Challenge: Obstacles to Educational Uses of Copyrighted Material in the Digital Age. Well worth a read. Those folks in the open learning community who have have recently picked up on the possible hurdles the law might create in our domain, as a result of the Blackboard litigation, might find the report particularly interesting. If you only have time for one of the case studies I'd recmomend the one focussing on DRM technology.

Blackboard say they will not sue universities

The Association for Learning Technology folks have had a teleconference with Blackboard about the concerns raised by their patent litigation. Blackboard's General Legal Counsel told the ALT that the key independent claims in the patent are numbers 1 and 36:

"Each of the other 44 claims (that is, the dependent claims) are dependent upon claims 1 and/or 36 and/or others of the dependent claims. The overall invention described in the patent draws upon a large number of elements, and it is only claims 1 and 36 that Blackboard asserts, through the patent, that it invented as stand alone inventions. The remaining claims relate to features that, as stand alone elements, might have already been invented elsewhere. Blackboard indicated that people who think the patent is a statement by Blackboard that it had itself invented what is described in each of the 44 claims as stand-alone elements are understandably offended. But the fact is that it is only claims 1 and 36 that Blackboard believes it invented as stand-alone inventions, and it is only infringement of these two independent claims that would result in Blackboard being able to obtain redress."

He also said the company has no plans to sue individual universities or undermine open source projects:

"We have a stated business policy of not going after individual universities, nor are we focusing on Open Source initiatives."

Whereas universties including my own can take some comfort from this, stated business policies do tend to change over time. As to the inventions claimed in items 1 and 36, item 1, when translated from the legalese basically says Blackboard have a patent on:

Any system of online courses which can be accessed via different computers by different users. Those people can be students, instructors or system administrators. The courses sit on a computer server and the kind of access a user gets to one or more courses depends on whether they are a student, teacher or administrator.

Item 36 when translated means:

A community of users can use the system. Each user can have various different roles (student, instructor or administrator) and access privileges based on these roles. Courses can be put on a server and users given the requisite degree of access.

I remain unconvinced that either of these central claims meets the "new" or "inventive step" requirements needed to be patentable.

Thanks to Ley for the ALT pointer.

Sunday, August 20, 2006

Former Ambassador calls terror arrests a PR exercise

Craig Murray the former ambassador at odds with the UK government's actions in relation to the "war on terror", is getting skeptical about whether the recent arrests related to a planned large scale terrorist attack targeting multiple airliners have any substance beyond a public relations exercise for the government. I've been taking a break from writing and my reading in the past couple of weeks has been limited exclusively to entertaining fiction, so I haven't caught up with all this yet but Murray's piece is worth a read.

"In all of this, the one thing of which I am certain is that the timing is deeply political. This is more propaganda than plot. More than 1,000 British Muslims have been arrested under anti-terrorist legislation, but only 12% have been charged. That is harassment on an appalling scale. Of those charged, 80% were acquitted. Most of the few convictions - just over 2% of arrests - are nothing to do with terrorism, but some minor offence the police happened upon while trawling through the lives they have wrecked.

Plainly, Islamist terrorism does exist. But its growth is encouraged by our adherence to neocon foreign policy, by our support for appalling regimes abroad, and by our trampling on the rights of Muslims in the UK."

Friday, August 18, 2006

NSA spying unconstitutional says judge

A federal judge has declared the Bush administration's NSA domestic spying program unconstitutional. The NYT has a report as do all the usual outlets. Civil liberties groups are pretty pleased.

Update: Some notable extracts from the decision - On page 23-24,

"It was never the intent of the Framers to give the President such unfettered control, particularly where his actions blatantly disregard the parameters clearly enumerated in the Bill of Rights. The three separate branches of government were developed as a check and balance for one another. It is within the court's duty to ensure that power is never condensed into a single branch of government."

From Page 33:

"The President of the United States, a creature of the same Constitution which gave us these Amendments, has undisputedly violated the Fourth [Amendment] in failing to procure judicial orders as required by FISA, and accordingly has violated the First Amendment Rights of these Plaintiffs as well."

On page 40:

"The Government appears to argue here that, pursuant to the penumbra of Constitutional language in Article II, and particularly because the President is designated Commander in Chief of the Army and Navy, he has been granted the inherent power to violate not only the laws of the Congress but the First and Fourth Amendments of the Constitution, itself.

We must first note that the Office of the Chief Executive has itself been created, with its powers, by the Constitution. There are no hereditary Kings in America and no power not created by the Constitution. So all "inherent power" must derive from that Constitution."

Federal judges don't get much blunter than that.

Saturday, August 05, 2006

Blackboard patent litigation rouses the elearning community

Well at least the open and e-learning* communities have been getting worked up about the Blackboard patent litigation, even if no one else has. Here's a sample from Stephen Downes and Alex Reid. Reid says:

"With any luck this ridiculous claim will fall flat, meanwhile a few observations on why this was a bad idea, even from their own perspective.

1. Though increasing numbers of faculty may be entering the area of online education, the practice is still heavily reliant upon a small number of faculty. They are the early adopters who then turn around and evangelize for technology, encourage campus support for new technologies, and support other faculty in taking that first step. On my campus, you'd be talking about a dozen or so faculty. Our campus has used Web CT (bought up by Blackboard last year).

Why would I, or any of these faculty, invest our time in learning or developing practices within a strictly proprietary environment that is wholly counter not only to the principles of academic freedom but also to the potential of global communication. After all, this is roughly analogous to giving some publisher a patent for textbooks!

2. Technology education is currently a field of scholarly investigation. Developments in online pedagogy rely upon such research. This far-reaching patent would essentially put an end to any research in online pedagogy. Why research new cooking recipes when you'll be sued if you make anything but a Big Mac?

3. There may be a lot of money to be made in the area of online education, but not by teachers. It may be the case that many faculty are unaware of Blackboard's patent claims or haven't thought through the implications. However, when this situation is properly presented as an infringement on academic freedom, I think there will be a significant response. Specifically, it is difficult, if not impossible in most cases, to require faculty to teach online. If the choice is between Blackboard and not being online then we must not offer online courses.

However, I do not think we need to make this choice. Instead, perhaps Blackboard's patent is the evil impetus to move us away from a "course-based system" of "online courses:" the bad idea that they want to claim as their fundamental intellectual property.

What happens if I establish a wiki, not associated with any particular course or even necessarily with my college? I let anyone create an account and participate on the wiki. I might post material on the wiki and require my students to read it, just as I might ask students to read material on other websites. I might require students to add to the wiki. But it wouldn't be a course-based wiki. That is, it wouldn't be created for a course. It wouldn't start and end with the course. The participants on the wiki would not be limited to students registered in the course. It wouldn't even be limited to members of the college community.

Similarly, I have this blog. I use it for a number of purposes that have no direct relation to the courses I teach. I've been running it for a couple years now. If I invite my students to post here, does it suddenly become a course-based website. I don't think so.

This is the direction in which we need to head anyway, away from the "course-centric" philosophy of "management" systems. Indeed the whole notion of courses and course-credit is atavistic anyway, left over from a time when formal learning was restricted to limited times and spaces. Yes, I suppose we are still in that "time," but we are also one foot out from under it.

In my view, the very fact that Blackboard's claim begins and ends on the notion of the course is testament to their lack of vision and innovative thinking. Unfortunately higher education has long demonstrated an equal inability to innovate, but perhaps it doesn't have to stay that way."

Well said.

*Just as a matter of interest, I don't believe there is any such thing as 'e-learning', any more than there is e-commerce, e-government or e-anything else. e-anything is just the activity supported, facilitated or complimented by new technologies. What's really important for education is open learning, whatever format or vessel facilitates it. The Blackboard patent, in spite of the pedagogic strait jacket the architecture and thinking imposes, is still bad news, in my opinion, for open learning.

Friday, August 04, 2006

SpyBlog on Net-ID-me

SpyBlog has a wonderful analysis of the much hyped children's ID system Net-ID-Me system launched recently, which supposed to protect kids from online predators.

"

Why was the service launched in public, without the following points having been addressed ?

Where is there any assurance that all of the staff at NetIDme have been subjected to at least the same level of checks on the Criminal Records Bureau , as if they were employed at a school ?

There is no such assurance...

Why is there no use of Secure Sockets Layer version 3 (SSL) or Transport Layer Security version 1.0 session encryption either when filling in the sensitive personal details such as Nickname and Password during registration, or to protect the online credit card details, or for a child to actually log on to the service via the website...

Illegal data processing of personal information ? Is NetIDme Limited properly registered under the Data Protection Act 1998 ?

The company's entry on the the Register of Data Controllers Registration Number: Z8752777 shows only 3 statutory Purposes, under the Data Protection Act:

  • Staff Administration
  • Advertising, Marketing & Public Relations
  • Accounts & Records

All with possible data transfers "Worldwide"

i.e. there nothing about the actual NetIDme service , customer registration, credit card name and address details, personal details of children, "sophisticated IP address tracking", audit log files etc. etc...

The NetIDme scheme claims to
When you’ve completed the online registration, a form will be sent out to your home. The form needs to be signed by you, and your details must be confirmed by a professional person who knows you well (such as your teacher, doctor or lawyer). If you’re under 18, your parent or guardian must also sign the form.

How exactly, can NetIDme make sufficient checks on the authenticity of such signatures, when the UK Identity and Passport Service (IPS) cannot do so for Passport applications ?

If their checks on signatures and "sponsors" are not at least as good as those by the UK IPS, then what possible use are they in preventing false or multiple applications for NetIDme accounts ?"

The original is a must read though as it has load more useful information on the scheme. Needless to say SpyBlog doesn't recommend the service.

Thursday, August 03, 2006

Blackboard sues for patent infringement

Education systems supplier, Blackboard, having recently been granted a broad patent (no. 6,988,138) in the US on technology used for "internet-based education support systems and methods" didn't let any grass grow under its feet before suing Desire2Learn Inc for allegedly infringing said patent. The patent has also been passed in Australia, New Zealand and Singapore and is pending in the EU and various other parts of the world.

Excuse my foaming at the mouth about this but the patent is nonsense on stilts and generically could be interpreted to describe what we have been doing here at the Open University for at least a generation and certainly for the 11 years that I've been here. I suspect Centrinity's FirstClass will be on Blackboard's lawyers' list of targets as well as the open source Moodle system the OU are adopting.

Well, if it takes this kind of patent litigation to wake the education sector (I emphatically reject the notion that universities constitute an "industry") up to the damage that can be done by an imbalance in the intellectual property system then maybe it will serve some useful purpose. The experience could well be painful. Remember Blackboard are the company that sued two technology students, under computer hacking and intellectual property laws, for daring to understand their technology and trying to present a paper on it at a security conference. From Chapter 2 of my forthcoming book, Back to the Future: Digital Decision Making:

"In 2003, two students decided to publish a research paper on an electronic security problem. The two, Billy Hoffman of the Georgia Institute of Technology and Virgil Griffith of the University of Alabama had discovered a security hole in Blackboard’s university ID card system. They decided to publish a paper on the problem at a security conference in Georgia but Blackboard’s lawyers stepped in wielding the DMCA, trademark and computer hacking laws and got a court to issue an injunction preventing the disclosure of the details of the problem.

The students eventually reached an out of court settlement with Blackboard apologising to the company for their actions and agreeing to "refrain from any further unauthorized access to or use of the System," including "any transaction designed to better understand or determine how the System works." "

Jennifer Jenkins of Duke University has a terrific write up of the case at the Chilling Effects Clearinghouse.

Wednesday, August 02, 2006

EDRI-gram newsletter - Number 4.15, 2 August 2006

The latest EDRI-gram newsletter is available and full of interesting digital rights stories as usual. The three that caught my eye were the Telecom Italia wiretapping scandal, Digital Rights Ireland's data retention challenge and the delay of the EU's Schengen Information System II "that allows the competent authorities in the Member States to obtain information regarding certain categories of persons and property."

The panacea of parental choice in education

The chairman of the parliamentary education select committee, Barry Sheerman, thinks formal education should start at the later age of seven and that the "belief that parental choice can achieve good education for all is naive." He's right.

Surveillance induced depression

Some of Kim Cameron's friends have been getting depressed with the increase in mass surveillance.

"You know, this whole pervasive surveillance thing is getting depressing, especially when you combine it with RFIDs and ubicomp and similar technologies. It’s Big Brother, Little Brother, Uncle Private Eye, Little Snoopy Sister, and every other nosy parker you can think of.

If you’re interested in these sorts of things, my old buddy Bruce Sterling, who surfaces in the blog from time to time, writes pretty often about them in his Wired blog, Beyond the Beyond, which I highly recommend anyway on the grounds that Bruce is about as on top of things as anyone can be without having his head explode."

He only wanted a header...

Simon Hattenstone has been getting self conscious about watching kids having a kick about in the park and admonished by his young daughter for asking them for a header.

Generating this kind of anxiety and suspicion out of innocent behaviour is something our society specialises in and it is dangerously corrosive and destabilising. A few years back I was in a playground with my children. I spotted one of the older kids in the park pulling one of the smaller ones off the top of what was a very tall ladder from the little fellah's perspective. He could have got quite a bump if he hadn't managed to hang on. I told the bigger kid to stop, whereupon he ran off wailing "MUUUM THAT MAN TOLD ME OFF." Within seconds I was being screamed at by the mother. Well it was at least easy to see from whence her son had derived his bullying tendencies.

Fear and anxiety begets fear and anxiety and associated fearful and aggressive behaviour. The more we whip up disproportionate fear and hysteria about relatively small but spectacularly and understandably emotive risks related to everything from child protection to terrorist attacks, the more we undermine the basis of a healthy society.

The wisdom of H.L. Mencken

Quote of the day:

"I BELIEVE THAT LIBERTY IS THE ONLY GENUINELY VALUABLE THING THAT MEN HAVE INVENTED, AT LEAST IN THE FIELD OF GOVERNMENT, IN A THOUSAND YEARS. I BELIEVE THAT IT IS BETTER TO BE FREE THAN TO BE NOT FREE, EVEN WHEN THE FORMER IS DANGEROUS AND THE LATTER SAFE. I BELIEVE THAT THE FINEST QUALITIES OF MAN CAN FLOURISH ONLY IN FREE AIR - THAT PROGRESS MADE UNDER THE SHADOW OF THE POLICEMAN'S CLUB IS FALSE PROGRESS, AND OF NO PERMANENT VALUE. I BELIEVE THAT ANY MAN WHO TAKES THE LIBERTY OF ANOTHER INTO HIS KEEPING IS BOUND TO BECOME A TYRANT, AND THAT ANY MAN WHO YIELDS UP HIS LIBERTY, IN HOWEVER SLIGHT THE MEASURE, IS BOUND TO BECOME A SLAVE." HENRY LOUIS MENCKEN (1880-1956)

Sunday, July 30, 2006

Blair buys Cliff's copyright rhetoric

Tony Blair, according to the Sunday Times has bought Cliff Richard's and the BPI's rhetoric about extending the term of copyright on sound recordings.

"The Sunday Times has obtained a written record of an internal Labour meeting at which the prime minister sets out his priorities.

At the meeting of the national executive committee on July 19 last year Blair said that despite the “dominating global headlines” and recent terror attacks, Labour must not lose sight of the domestic agenda.

In the midst of such high-profile issues as the liberalisation of the Post Office and public apathy to elections, Blair “addressed concerns” about copyright laws “whereby Cliff Richard and the Rolling Stones only receive 50 years’ protection compared with 70 years in the rest of Europe”, according to one member’s detailed written record. "

EU plan to fingerprint all children

The Observer reports this morning on an EU plan to fingerprint all children in member states.

"British children, possibly as young as six, will be subjected to compulsory fingerprinting under European Union rules being drawn up in secret. The prints will be stored on a database which could be shared with countries around the world.

The prospect has alarmed civil liberties groups who fear it represents a 'sea change' in the state's relationship with children and one that may lead to juveniles being erroneously accused of crimes. Under laws being drawn up behind closed doors by the European Commission's 'Article Six' committee, which is composed of representatives of the European Union's 25 member states, all children will have to attend a finger-printing centre to obtain an EU passport by June 2009 at the latest.

The use of fingerprints and other biometric data is designed to prevent passport fraud and allow European member states to meet US entry visa requirements"

Yet again the claim that fingerprints are required on passports to meet US requirements is trotted out without question. Yet again it will be believed. Yet again it is wrong. The US only require a digital photo on the passport at the moment. Besides, they fnigerprint all foreign visitors now themselves under the US VISIT programme.

They know not what they do and unsurprisingly those reporting on what they do are also somewhat confused.

Update: John Lettice, the Register's resident ID polemisist has a few choice things to say about the kiddiprinters.

Friday, July 28, 2006

Censorship or privacy protection?

Another small skirmish in the battles over genetically modified crops has been playing out in France. A French court has ordered Greenpeace to take down webpages identifying the location of fields growing genetically modified crops. Greenpeace says it is censorship. The court said the environment advocacy group were invading the farmers' privacy. They've also protested the decision by going into one of the fields concerned and cutting an X in a circle into the crop.


Greenpeace France spokesman, Arnaud Apoteker, says "As we are now forbidden to publish these maps of GE maize on our webpage, we have gone into the fields and marked the field for real." Greenpeace reckon that EU regulations make it an obligation for member states to maintain publicly accessible registers of the location of GM crop growth. The words 'irritated judge', 'contempt', 'court' and 'of' come to mind, though not necessarily in that order.

French drm law turns poisonous

The various shenanigans in France surrounding the implementation of the 2001 EU copyright directive have latterly turned poisonous. Jean-Baptiste Soufron has the details:

"Disappearance of Fair Use provisions, new liability of software developers, increased liability of users, compulsory licensing for DRM producers, etc.

To sum it up, the Court decided to censor 4 provisions supposed to protect software developers and internet users...

The Court erases the exception that protected software developers who were specifically working on collaborative software, research or file sharing. Given the decision, any French developers working on such softwares could be sued by DRM producers or copyright holders. Even when it software is intended for non-copyrighted contents. So, no matter whether people use P2P software for some distributed business model or just to share Creative Commons-music, it’s already illegal...

The Court deletes the interoperability exception that was supposed to protect competition and free software developers. Without prior authorization, it will not be possible anymore to develop a software that could interact with DRM-encumbered content. This is true for Free Software developers, but it is also true for start-ups like Archos or Dailymotion...

The Court deletes the system that was punishing internet users with a 38 or 75 euros fine. Consequently, they will be sued under the default procedures and risk up to 5 years and 500 000 euros.

- On top of that, the Constitutional Court decided that it was normal to annihilate the French version of Fair Use. Without regards for the importance of cultural exchange amongst individuals, it even precised that it was normal for DRM producers obstacle à toute copie, which means "to forbid any copy". Nothing less.

All the balance will now depend on the newly created DRM Regulation Authority. This will decide the minimum amount of copies that can be done, etc.

But most importantly, the Law creates a compulsory licensing scheme for DRM producers. When asked, the DRM Regulation Authority can mandate companies like Apple to communicate essential information on their DRM to competitors: le demandeur peut obtenir l’accès aux informations essentielles à l’interopérabilité, meaning that competitors will have the opportunity to ask for essential informations necessary for interoperability.

The Court only precised that they would need to be indemnified for this. To quote them: cette communication devra entraîner leur indemnisation, this communication will have to be indemnified. But the principle is still the same: DRM producers can be mandated to license their technology to competitors.

Given these various points, the DADVSI is by far the hardest internet Law ever passed in the world. It seriously impedes the development of French startups in this sector."