Friday, August 24, 2012

Submission to consultation on Communications Data Bill

I've sent a response to the consulation of the Joint Committee on the draft Communications Data Bill. Having been buried in meetings and battles with bureaucracy it was done at the last minute so may read as something of a tired stream of consciousness. Nevertheless I reproduce it below in the hope that if I've made any errors in the analysis my sharp eyed reader will put me straight.  I incorporated the Open Rights Group's draft letter to parliament on the subject as part of the submission, so that bit at least should be fine!


I would like to register my objection to the Draft Communications Bill.

My key concerns include:

Home Office vague on justifications for the Bill and the Bill does not solve the complex problems it has been posited as addressing

In multiple media engagements the Home Secretary and other supporters of the Bill mention "protecting the public" from all four horsemen of the infocalypse - terrorists, drug dealers, child abusers and organised crime - and more, on several occasions quoting the Met police chief as insisting passing this legislation is a "matter of life and death".

Building multiple massive databases of intimate personal communications data makes the public more vulnerable to the four horsemen not less so. That such mass surveillance will not work can be demonstrated mathematically.

Floyd Rudmin, Professor of Social & Community Psychology at the University of Tromsø in Norway, analysed President Bush’s authorisation of the National Security Agency’s (NSA) secret monitoring of the email messages and phone calls of all Americans (The Politics of Paranoia and Intimidation Why does the NSA engage in mass surveillance of Americans when it's statistically impossible for such spying to detect terrorists? May 24, 2006 by Floyd Rudmin

“The US Census shows that there are about 300 million people living in the USA.
Suppose that there are 1,000 terrorists there as well, which is probably a high
estimate. The base-rate would be 1 terrorist per 300,000 people. In percentages,
that is .00033%, which is way less than 1%. Suppose that NSA surveillance has an
accuracy rate of .40, which means that 40% of real terrorists in the USA will be
identified by NSA's monitoring of everyone's email and phone calls. This is
probably a high estimate, considering that terrorists are doing their best to avoid
detection. There is no evidence thus far that NSA has been so successful at finding
terrorists. And suppose NSA's misidentification rate is .0001, which means that .01% 
of innocent people will be misidentified as terrorists, at least until they are
investigated, detained and interrogated. Note that .01% of the US population is
30,000 people. With these suppositions, then the probability that people are terrorists
given that NSA's system of surveillance identifies them as terrorists is only
p=0.0132, which is near zero, very far from one. Ergo, NSA's surveillance system
is useless for finding terrorists.”

Rudmin takes one basic statistic – 300 million people in the US – and takes a conservative guess at some others e.g. the proportion of terrorists in the population. He then does wonderfully simple analysis to prove mass surveillance is useless for finding terrorists. The kind of conditional probability calculation done here by Rudmin is based on Bayes’ Theorem, taught in most introductory college statistics classes and is mathematically very sound.

Mathematically the 4 horsemen are not problems that lend themselves to data mining. Even highly accurate data mining systems will swamp investigators with false positives when dealing with a large population. Law enforcement authorities end up investigating and alienating large numbers of innocent people. Finding the horsemen is a needle in a haystack problem and you can’t find the needle by throwing infinitely more hay on your stack and/or creating multiple giant and exponentially growing data haystacks.

That such mass databases are useless for finding terrorists is clear. That they also make the public less safe is associated with the impossibility of securing mass silos of valuable personal data. Computer scientists simply do not know how to keep databases of the magnitude of those envisaged in the Bill secure from external hackers or the multitude of insiders who have access to these databases as a routine part of their jobs.  Security experts like Ross Anderson, Peter Sommer, Bruce Schneier and Richard Clayton have written extensively about this.  To understand this you have to think about how such systems can fail - how they fail naturally, through technical problems and errors (a universal problem with computers), and how they can be made to fail by attackers (insiders and outsiders) with malign intentions e.g. the four horsemen. When the inevitable hacks, leaks, data contaminations happen, what then?

Part 1 of the draft bill is indefensible

Part 1 of the draft bill gives the Secretary of State unlimited powers to mould data access regulations in perpetuity without the need to consult parliament in any meaningful way:

(1) The Secretary of State may by order—
(a) ensure that communications data is available to be obtained from telecommunications operators by relevant public authorities in accordance with Part 2, or
(b) otherwise facilitate the availability of communications data to be so obtained from telecommunications operators.
(2) An order under this section may, in particular—
[...]
(b) impose requirements or restrictions on telecommunications operators or other persons or provide for the imposition of such requirements or restrictions by notice of the Secretary of State"

There is no mechanism for amending such Henry VIII orders and they usually get rubber-stamped by Parliament without material scrutiny.  The Secretary of State and her successors get to order anyone to do anything that can be related to facilitating access to communications data:

If you combine this with, as barrister Francis Davey points out (see ‘The Communications Data Bill (first look)’, Sunday, 17 June 2012 at http://www.francisdavey.co.uk/2012/06/communications-data-bill-first-look.html), with the broad definitions given in clause 28 of the bill, e.g.

"“person” includes an organisation and any association or combination of persons
[..]
“telecommunications operator” means a person who—
(a) controls or provides a telecommunication system, or
(b) provides a telecommunications service,
“telecommunication system” means a system (including the apparatus comprised in it) that exists (whether wholly or partly in the United Kingdom or elsewhere) for the purpose of facilitating the transmission of communications by any means involving the use of electrical or electro-magnetic energy,
“telecommunications service” means a service that consists in the provision of access to, and of facilities for making use of, a telecommunication system (whether or not one provided by the person providing the service)"

- this Bill could theoretically, as currently drafted mean that we might be obliged to keep "who, what, when and where" records of family and friends social gatherings which involve listening to music, TV watching, internet or mobile phone use, electronic gaming or just chatting. Unlikely though that might currently seem and far though it may be from the current government’s intentions, the wording of the bill must be viewed in the light of the inevitable progressive function creep (discussed below) and through the lens of a less benevolent future government.

Inversion of innocent until proven guilty principle

The notion that the day to day activity of every citizen should be recorded in the expectation that those records can, in future, be mined for nefarious activity is anathema to a healthy functioning liberal democracy.

Control of my data

I have no control over my data, once it is collected by third parties’ on behalf of the government. The government is placing me at risk without my consent. The risks include
1.         That police have access to a record of my political beliefs and social habits
2.         That these records could be shared with private investigators or journalists
3.         That these records could be unlawfully accessed by foreign governments or criminal gangs, and aid further identity fraud, blackmail or account hacking

This runs counter to everything governments including ours are trying to do through promotion of good privacy practice and data protection policies.

Suspicion should be the test for surveillance

The government of course has the right to intercept and record information when someone is suspected of a serious crime. But these proposals mean collection of data without suspicion: which is in effect mass surveillance. Due process requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To instigate the new set of legal norms envisaged in the Communications Data Bill which subsequently give the entire population less protection than a hitherto genuine suspected criminal, based on a standard of reasonable suspicion, is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is unlawful.

Accessing big data sets opens up new police surveillance powers

Being able to compare location data, contact histories, websites visited and so on will give the police the generalized ability to track any group, from sports fans to political protesters. This will create extreme risks for whistleblowers, journalists’ sources and legitimate but inconvenient forms of protest.

This is not “preservation” of capacity but a huge extension of policing powers, which deserves proper democratic debate, starting with a full public consultation.

Undermining of Fundamental Rights

The proposals fundamentally undermine the right to privacy guaranteed in the Human Rights Act and article 8 of the European Convention on Human Rights. The Bill also undermines fundamental rights relating to freedom of assembly, speech, religion and association.

Comms data and traffic data cannot be separated simply in the way that the Bill assumes


Function Creep

I can only echo the concerns on function creep expressed by Paul Bernal in his submission to the consultation:

"when a system is built for one purpose, that purpose will shift and grow, beyond the original intention of the designers and commissioners of the system. It is a familiar pattern, particularly in relation to legislation and technology intended to deal with serious crime, terrorism and so forth. CCTV cameras that are built to prevent crime are then used to deal with dog fouling or to check whether children live in the catchment area for a particular school. Legislation designed to counter terrorism has been used to deal with people such as anti-arms trade protestors – and even to stop train-spotters photographing trains.

In relation to the Communications Data Bill this is a very significant risk – if a universal surveillance infrastructure is put into place, the ways that it could be inappropriately used are vast and multi-faceted. What is built to deal with terrorism, child pornography and organised crime might creep towards less serious crimes, then anti-social behaviour, then the organisation of protests and so forth. Further to that, there are many commercial lobbies that might push for access to this surveillance data – those attempting to combat breaches of copyright, for example, would like to monitor for suspected examples of ‘piracy’. In each individual case, the use might seem reasonable – but the function of the original surveillance, and the justification for its initial imposition, can be lost."

The temptation for public and commercial services to use the data gathered for purposes not originally intended will be overwhelming. If it can be done it will be done regardless of original good intentions.

RIPA needs to be fixed first

Data retention is already excessive and creating risks. The access policies for police are too wide and lack judicial supervision. There is no notification policy for people who been placed under surveillance.

These problems should be fixed before the government suggests new surveillance powers.

We are in a recession

Spending billions of pounds surveilling innocent people while cutting back on policing seems wrongheaded. I would rather money is spent on front line intelligence, policing, detection  and emergency response work.

Bad examples to foreign governments

There are no democratic governments that force companies to aid surveillance through collection and creation of new data sets. How can the UK seriously stand up for human rights while abusing the privacy of millions of innocent citizens?

Conclusion

The government has failed to make the case for the need for the new powers proposed in the draft Bill. There is a significant danger in measures like the CDB of stumbling by default into a police state, just because the technology of mass surveillance is now more readily available and nominally more sophisticated. We need to avoid deploying these technologies blindly in response to some perceived threat. Without sufficient reasoned analysis of the purpose and detailed requirements of the technical systems we propose to build to counter these threats, we could find ourselves building technological monsters. Building an infrastructure of surveillance makes our citizens and our state more vulnerable not less so to attacks by criminal elements such as the four horsemen of the infocalypse and rogue states with malevolent intent.

Thursday, August 02, 2012

Malte Spitz: Your phone company is watching

Malte Spitz: Your phone company is watching "Every time you use your mobile phone let it be a reminder that you have to fight for self determination in a digital age."



Tell your friends privacy is a value of the 21st century and it is not outdated... tell your political representatives that just because companies and state agencies can store certain information doesn't mean they have to [or should be allowed to] do it.

Wednesday, August 01, 2012

DEA & robust evidence of copyright infringement

Consumer Focus last week published a really important report by Dr Richard Clayton of Cambridge University on collecting robust evidence of online copyright infringement through peer-to-peer filesharing. The report was commissioned to help Ofcom:
"in the implementation of the Digital Economy Act 2010 through a statutory Initial Obligations Code. When it comes to taking action against people accused of infringement, the standards of evidence are critical. The Digital Economy Act 2010 requires that the Initial Obligations Code makes provisions on the ‘means of obtaining evidence’ and the ‘standard of evidence’ for copyright owners who want to lodge ‘copyright infringement reports’ against consumers with their internet service provider (ISP).
The report provides advice on standards and procedures which should be adopted to ensure that copyright owners can reliably identify an internet connection which has been used to infringe copyright through peer-to-peer filesharing. Dr Clayton then describes how ISPs can robustly match internet subscriber details to IP addresses, which are dynamically allocated to domestic internet connections. Under the Digital Economy Act 2010 subscribers, who are the bill payers for an internet connection, can appeal a notification of alleged copyright infringement if they can show that they did not commit the alleged infringement, and took ‘reasonable steps’ to prevent others from infringing. Dr Clayton therefore concludes his expert report on traceability by assessing how subscribers to an internet connection could identify who may have used their connection to infringe copyright."
Saskia Walzel, policy manager at Consumer Focus responsible for copyright policy, has a nice article in ORGZine explaining the key findings.
In outline the report covers:
  • the theoretical basis for monitoring file sharing activity and detailed advice on how this should be done properly - this monitoring is theoretically possible but it is essential that the practical details are right
  • the need for good record keeping to ensure all this monitoring can be audited, errors detected and corrected
  • the problems ISPs will face 
  • a "doctrine of perfection" in relation to the gathering of evidence (if the ISP receives a batch of data containing just a single error then the whole batch should be rejected) that needs to be applied to reduce the risk of systemic failures leading to widespread false accusations of copyright infringement
  • the problems with identifying suspected subscribers when ISPs are using large scale NATs (which breach end to end neutrality)
  • the fact that the ISP customer may be unable to identify who has been using their account for inappropriate file sharing
  • p2p designs and development and likely evolution to evade the kind of monitoring the DEA requires
  • when an ISP writes to a customer about alleged copyright infringement it is recommended that an outline of how the monitoring system works should be included; they should also be told "the full range of scenarios" as to how file sharing can occur on their account without their knowledge.
The reality of the Digital Economy Act's (DEA) online infringement of copyright provisions (sections 3 - 18) may finally begin to hit home next year (theoretically) when thousands of people start to get accusatory letters about copyright infringement from their ISPs. The UK courts have not fully tested evidence presented in such copyright infringement cases as the few that have been pursued were eventually settled out of court. So there is no authoritative legal guidance on standards of evidence or process. Richard Clayton's report is, therefore, an invaluable contribution, particularly so for the clarity with which he analyses the technical, evidentiary, monitoring and systems processes involved.

The report describes, in detail, the kinds of procedures and standards that need to be followed and the how, what, when, where, who and why of specific technical evidence that needs to be collected to be confident of identifying a specific IP address used in copyright infringement.  It is unacceptable just to crudely harvest IP addresses and send out threatening letters as the now infamous ACS Law crew did. There has to be a clear unbroken chain of solid, reliable, technically sound, recordable, auditable evidence, delivered through a robust investigative process, leading from the infringement to the alleged offending IP address.

Establishing the IP address is only the first step according to the DEA. The ISP then has to identify the customer associated with that IP address at the relevant time and notify them of a complaint by a copyright owner. The customer then has to decide whether to appeal. There's a £20 fee for appealing but if they can prove that they personally didn't engage in copyright infringement and took “reasonable steps” to prevent others from infringing they'll win the appeal.

Unfortunately, as Richard Clayton very articulately explains in the report, the ISP customer whose name is on the account may not be able to identify who has been using their internet connection for file sharing.  The reasons are many (see paragraphs 108 to 134 of the report).  That finding alone raises important questions about the DEA online copyright infringement provisions and whether they can be operated fairly and with due process.

I highly recommend reading the report in full. It should be required reading for anyone who considers themselves an informed citizen. It's a very accessibly written technical document on how to gather, robustly and reliably, digital forensic evidence of internet users' alleged misuse of peer to peer technologies.  Richard Clayton makes no comment about the privacy or ethical issues associated with all this - though there are clear warnings e.g. about the need for the monitoring system design to be open to the public, as 'secret' or proprietary designs are not capable of creating reliable results - but the pervading sense of this report is overwhelmingly one of: if you have to do this then you damn well better do it properly and with due process.

Dr Clayton should be highly commended for producing a unique, terrific report on an important subject which even the most geekily challenged reader can peruse with little difficulty.

Monday, July 30, 2012

Brailsford, trolling and modern day Murrows

Further kudos to Dave Brailsford, the performance director of British cycling.

I heard Victoria Derbyshire on Radio 5 live this morning idiotically attempting to goad him into getting into a row with the press. It's really irritating when media 'personalities' try to create controversy out of nothing by provoking people. Ms Derbyshire asked Mr Brailsford what he thought about the severe critcism of some of the Sunday papers. He quite reasonably and good naturedly responded that he didn't read them.

Ms Derbyshire replied that she did not want to be the bearer of bad news (I believed her but millions wouldn't) but the newspapers had described Mark Cavendish's failure to win the gold medal in the Olympic cycling road race on Saturday as a "disaster", "catastrophic" and other similar such exaggerations and harbingers of doom. She wanted to know what Mr Brailsford's reaction to that criticism was and would not let go.

He calmly again explained he didn't read the papers but that the team had given everything in their efforts in the race and he was proud of them and could not have expected any more.

It is ridiculous to characterise the failure of a sports star to win a race as a 'disaster' (a sudden ruinous event or great misfortune or mishap causing great loss of life, damage, or hardship e.g. an earthquake, a flood or a plane crash). Even more so to lend such descriptions credence. And worse again when so called 'respected' journalists, like Derbyshire, try to incite heated reactions to such unadulterated nonsense in order to create a story out of nothing. With the Olympics in town it's not as if they are exactly short of sports stories anyway! I'm no believer in golden ages when the media reported rather than created stories but we could do with a few more Edward R. Murrows influencing the modern news agenda.

Ms Derbyshire tried every angle she could think of to stir up a row - what did they do wrong; how was Mark Cavendish feeling; why didn't the team do something different; how were the team reacting to it and each other; how did Mr Brailsford feel about the press criticism; what would he do differently; surely if they got another chance they would try something different.

Mr Brailsford batted it all away calmly and neutrally and expertly refused to get pushed into lashing out at media trolling. There are a lot of cycling events to come and the team have prepared well and are hoping for success. Judge them by all means on the medal haul at the end of the Games rather than the disappointment of failing to win the first. Well done Mr Brailsford and good luck to you and your team... apart, of course, from when you're up against the Irish!


Friday, July 27, 2012

High Court:Twitter joke trial had no clothes

Paul Chambers has finally received some justice from the courts. The High Court has today overturned his conviction relating his joke, on Twitter, about blowing up Robin Hood Airport or as the police, CPS, magistrates and Crown Court would describe it: sending, by a public electronic communication network, a message of a "menacing character" contrary to sections 127(1)(a) and (3) of the Communications Act 2003. S127 says:
"(1)A person is guilty of an offence if he—
(a)sends by means of a public electronic communications network a message or other matter that is grossly offensive or of an indecent, obscene or menacing character...
(3)A person guilty of an offence under this section shall be liable, on summary conviction, to imprisonment for a term not exceeding six months or to a fine not exceeding level 5 on the standard scale, or to both."
The basic story is well known. Chambers (@pauljchambers on Twitter) was going to Belfast to meet a woman he had connected with via Twitter. Due to adverse weather the Robin Hood Airport in Doncaster closed. The High Court (Lord Judge, Mr Justice Owen, Mr Justice Griffith Williams) continues the story at paragraph 12 -
On 6 January 2010, following an alert on “Twitter”, the appellant became aware of problems at Doncaster, Robin Hood Airport, due to adverse weather conditions. He and Crazycolours had a dialogue on “Twitter”. Two messages were referred to in the Crown Court. They were:
“@ Crazycolours: I was thinking that if it does then I had
decided to resort to terrorism”:
“@ Crazycolours: That’s the plan! I am sure the pilots will be expecting me to demand a more exotic location than NI”.
In context, this seems to have been a reference to the possibility of the airport closing, but the picture was incomplete because no reply from Crazycolours was produced. Some two hours later, when he heard that the airport had closed, he posted the following message:
“Crap! Robin Hood Airport is closed. You’ve got a week and a bit to get your shit together otherwise I am blowing the airport sky high!!”
There was no evidence anyone found this joke threatening.  In fact nothing was done about it by anyone until 11 January 2010, some five days later when the duty manager responsible for security at Robin Hood Airport, while off duty at home, found it. He didn't know if it was a joke but thought even if it was it could cause major disruption.  So he referred it to his manager. Procedure dictated that his manager should refer "credible threats" immediately to the Ministry of Defence. "Non credible" threats were to be referred to the police. He judged it non credible and referred it to the airport police. The airport police referred it to South Yorkshire police.

They then, seven days after the original tweet, sent the anti-terrorist squad round to Paul Chambers' workplace and arrested him on suspicion of involvement in a bomb hoax.  They made very sure his work colleagues knew why they were there and Chambers was subsequently sacked.

At some stage during his extended questioning by the police Chambers responded to a question about whether "some" people might get concerned about his tweet by saying "Yah. Hmm mmm".  This would come back to haunt him as it was given significant emphasis in his subsequent magistrates trial and appeal in the Crown Court.  In any case in the S. Yorks police credit goes to the investigating officer who when the investigation was completed recorded the incident officially (on the 10th February) thus:
“Male detained re making threats to Doncaster Robin Hood Airport. The male in question has been bailed and his phone/computer has been seized – there is no evidence at this stage to suggest that there is anything other than a foolish comment posted on “Twitter” as a joke for only his close friends to see.”
However, someone at S. Yorkshire police consulted the Crown Prosecution Service and they decided to charge Paul Chambers with menacing threats via a public electronic communications network contrary to section 127(1)(a).

What is notable about the story is that nobody, from the airport manager and his boss through to the police officers who did the investigation, thought there was a credible threat. An  investigating police officer was the only one to go on record to say he accepted it was a joke.

Everyone else was playing CYA. They knew Chambers' tweet was a joke even if they didn't find it funny.  There was no urgency about the way they acted.  It was all about ticking the right boxes on the right forms to be seen to be following procedures.

He was convicted and that conviction subsequently upheld by the Crown Court which was "satisfied" that the tweet was "menacing per se" and that "an ordinary person" seeing it "would see it that way and be alarmed. The airport staff did see it and were sufficiently concerned to report it."
"18. The Crown Court went on to hold “that the required mens rea … is that the person sending the message must have intended the message to be menacing, or be aware that it might be taken to be so …” The court was satisfied that the appellant was, at the very least, aware that his message was of a menacing character." 
As to that latter point the Crown Court put a disproportionate emphasis on Chambers' "Yah hmm mmm" response to the police interview question about whether he thought "some" people might be alarmed by his tweet. One indistinct response amidst hours of questioning was evidence that Chambers "was, at the very least, aware that his message was of a menacing character"? It brings to mind Cardinal Richelieu's mantra about finding enough evidence in a mere six lines of anything any honest man has written to hang him.

The Crown Court, in fairness, did go onto to pose a significant series of really interesting questions for the High Court about how s127(1)(a) should be interpreted.  The High Court reproduces these questions in paragraph 19 of their decision but I'll leave it to the real lawyers to dissect those. For the purposes of this treatise, suffice it to say those questions demonstrate a significant part of the problem with these types of cases is s127 itself, not just the CYA mentality of some of the actors involved.

The High Court agreed with the Crown Court that tweeting is sending messages by means of a "public electronic communications network" even though Twitter is a private company. This analysis is at para 21 - 25. There is a fault line in this analysis at paragraph 21 where emphasis is given to "potential recipients of the message" being "the public as a whole". If that is read across to Facebook, Google or any other tech giant operational practices it could have significant implications for personal privacy.  However that's not the primary focus here.  The Court then gets to the heart of the case, the actus reus or the conduct of the accused.

They point out that it is appropriate to have a s127 type offence relating to the internet and it is merely an updating of the prohibition against the misuse of the telephone to communicate menacing messages. They also don't believe s127 created "some newly minted interference with the first of President Roosevelt’s essential freedoms – freedom of speech and expression."
"Satirical, or iconoclastic, or rude comment, the expression of unpopular or unfashionable opinion about serious or trivial matters, banter or humour, even if distasteful to some or painful to those subjected to it should and no doubt will continue at their customary level, quite undiminished by this legislation. Given the submissions by Mr Cooper, we should perhaps add that for those who have the inclination to use “Twitter” for the purpose, Shakespeare can be quoted unbowdlerised, and with Edgar, at the end of King Lear, they are free to speak not what they ought to say, but what they feel."
The problem comes in trying to figure out how to actually interpret s127. An offence cannot be proved unless the content of the message was of a menacing character. But there is “disappointingly little coherence in English law’s approach to threat offences” (Smith and Hogan’s Criminal Law, 13th edition, at p951) so "we do not think that an analysis of the numerous other offences based on threats, including blackmail, takes the interpretation of this statutory provision any further." So the Court gives its interpretation at paragraph 30 initially of what s127 cannot cover.
"In short, a message which does not create fear or apprehension in those to whom it is communicated, or who may reasonably expected to see it, falls outside this provision, for the very simple reason that the message lacks menace."
They go on at paragraph 31 to admonish the Crown Court, gently:
"In any event, the more one reflects on it, the clearer it becomes that this message did not represent a terrorist threat, or indeed any other form of threat. It was posted on “Twitter” for widespread reading... Much more significantly, although it purports to address “you”, meaning those responsible for the airport, it was not sent to anyone at the airport or anyone responsible for airport security, or indeed any form of public security. The grievance addressed by the message is that the airport is closed when the writer wants it to be open. The language and punctuation are inconsistent with the writer intending it to be or to be taken as a serious warning... it is difficult to image a serious threat in which warning of it is given to a large number of tweet “followers” in ample time for the threat to be reported and extinguished."
In paragraph 32, Lord Judge, Mr Justice Owen and Mr Justice Griffith Williams emphasise the point that a menacing message "does not cease to be so just because it was not received or because the person who received it was not, in the context of the present prosecution, menaced. The effect of the message on those who read it is not excluded from the consideration." Nevertheless they then quietly eviscerate the chain of authority responsible for the case ending up in court - saying no one was sufficiently bothered by the tweet to engage in any urgent security measures, other than to make sure their asses were covered by referring it up the line. Nobody thought it was a credible threat or took any action other than to refer it to the next actor in the chain of procedure.
"More important, because they would have been quite uninfluenced by their knowledge of the appellant deduced from his previous messages, the two gentlemen responsible for the safety of the airport showed no anxiety or urgency in dealing with it. It was treated and addressed as if it was not a credible threat. The airport police took no action. No evidence was provided to suggest that even minimal consequential protective measures were taken at the airport, or that the level of perceived threat was heightened. Indeed, notwithstanding the nature of the “threat”, we can detect no urgent response to it. Police action was not exactly hurried. After the investigation, the South Yorkshire Police concluded that the appellant presented no threat. Although this conclusion reflected the outcome of the investigation rather than the immediate reaction to the text of the message, it was in fact entirely consistent with the attitude and approach of those who had seen the message before the investigation began."
The noble judges are no less scathing about the decision of the Crown Court whilst declaring that "proper respect must be paid" to that court's finding that Mr Chambers tweet was of a menacing character. I can just hear Nigel Hawthorne as Sir Humphrey "With respect Prime Minister..."
"No weight appears to have been given to the lack of urgency which characterised the approach of the authorities to this problem, while the fact that those responsible for security at the airport decided to report it at all, which was treated as a significant feature, rather overlooked that this represented compliance with their duties rather than their alarmed response to the message. By contrast, disproportionate weight seemed to be placed on the response of the appellant in interview to how “some” people might react, without recognising that the care needed to approach such a widely phrased question in context. The response was part of the interview as a whole, when looking back at what the appellant admitted he had done and his assertions that it was a joke. The question based on what “some” people might think embraced everyone, included those who might lack reasonable fortitude. This entirely equivocal response added nothing which supported the contention that the message was of a menacing character."
In other words everyone was ignoring the fact that this prosecution - this whole case - had no clothes. It was a joke and everyone knew it but were playing CYA. And because everyone was playing CYA certain factors were accorded disproportionate significance - Mr Chambers one "Ya hmm mmm" response amidst hours of questioning, the 'no smoke without fire' CYA referrals up the chain by airport management, airport police, S. Yorkshire police, CPS and eventually courts. Not enough prominence was given to the simple fact that the tweet lacked any conceivable menace - Mr Chambers had been joking and everybody knew it but nobody was prepared to admit it. The High Court therefore conclude:
"34... that, on an objective assessment, the decision of the Crown Court that this “tweet” constituted or included a message of a menacing character was not open to it. On this basis, the appeal against conviction must be allowed."
There was no threat, no menace, no actus reus, no criminal conduct.  Since there was no criminal act they don't need to consider in detail whether there was any criminal intent or mens rea. They do, however, address the issue briefly in the final page of the decision (paragraphs 35 - 38).
"In consequence we are unable to accept that it must be proved that, before it can be stigmatised as criminal, the sender of the message must intend to threaten the person to whom it was or was likely to be communicated, or that such a specific purpose is a necessary ingredient of the offence. That would, in effect involve an offence of specific intent which Parliament elected not to create...
38. We agree with the submission by Mr Robert Smith QC that the mental element of the offence is satisfied if the offender is proved to have intended that the message should be of a menacing character (the most serious form of the offence) or alternatively, if he is proved to have been aware of or to have recognised the risk at the time of sending the message that it may create fear or apprehension in any reasonable member of the public who reads or sees it. We would merely emphasise that even expressed in these terms, the mental element of the offence is directed exclusively to the state of the mind of the offender, and that if he may have intended the message as a joke, even if a poor joke in bad taste, it is unlikely that the mens rea required before conviction for the offence of sending a message of a menacing character will be established. The appeal against conviction will be allowed on the basis that this “tweet” did not constitute or include a message of a menacing character; we cannot usefully take this aspect of the appeal further."
So there's a sting in the tail here.  Even without intending menace someone can still be convicted under s127 if they "recognised the risk at the time of sending the message that it may create fear or apprehension in any reasonable member of the public".

Even by this test, though, Paul Chambers' joke should never have got anywhere near a courtroom. Congratulations to Mr Chambers and his legal team for having the perseverance to pursue this case to an ultimately just conclusion.

Kudos too to Lord Judge, Mr Justice Owen and Mr Justice Griffith Williams who, albeit it in the politest of legalise, were prepared to call out the CYA elephant in the room. Ironically, with CYA situations, the higher up the chain of authority a non issue goes, the riskier it becomes for individual actors to call a halt to the nonsense. The feeling that 'it must be a big deal if it's got this far' just increases all the way up and the pressure to 'do something about it' just builds and builds. And since no one can be blamed for following procedure or orders, the safe option is always to do so.

Systems built on the premise that, at every stage, the right option is the perceived risky option will regularly lead to the kind of systemic insanity that led to the persecution, prosecution and unjust conviction of Paul Chambers. The insanity becomes an emergent and defining feature of the system. When it is the criminal justice system, weighed down already by decades of fear induced, hyperactive, unintelligible law making of the political digerati, then we all have reasons to be concerned. Thankfully, on this occasion, Paul Chambers' odious and ridiculous conviction has finally been quashed.

Update: Edited for typographical errors.  Also according to one of his lawyers, David Allen Green, the High Court has now issued an order that Paul Chambers' legal costs be covered.

Wednesday, July 25, 2012

Panasonic HDD goes again

Well my Panasonic DMR EX75 DVD recorder failed again on Sunday - same old capacitor problem. First replacement lasted 12 months. Last one lasted 8.

I was out of capacitors, so it was back to Charles Hyde & Son and for £1.31 each I ordered three which arrived within a couple of days. They came with a small pack of sweets which was a nice touch my kids appreciated!

Replacing the capacitor as previously solved the problem. I'm not sure how long the latest one is going to last. The unit was running quite hot and successive solderings are getting more difficult to do and taking their toll on the capacitor base legs. I also initially thought I might have left a dry joint on one of the legs then over-compensated with too much solder leaving a blob but it seems to be working ok, at least for the moment. Maybe the blob will act as a buffer against the overheating caused by the design flaw?  We'll have to wait and see. 

Friday, July 20, 2012

GNI digital freedoms in international law report

I attended the launch of the Global Network Initiative (GNI) report Digital Freedoms in International Law: Practical Steps to Protect Human Rights Online at the Free Word Centre in London last month. In a report relating to the first panel of the day, Who controls access to our communications?, I suggested I'd stick a note here on the second panel, Exporting surveillance and censorship: is regulation an answer?, when time and space allowed. Heather Brooke chaired the panel which included joint author of the report, Ian Brown (Senior Research Fellow, Oxford Internet Institute), Eric King (Head of Research, Privacy International) and Tom Smith (Head of Export Control Organisation (ECO), Department for Business, Innovation and Skills).

Mr Smith opened proceedings explaining he takes decisions on behalf of Vince Cable on licensing the export of military and 'dual use' goods.  This involves a two stage process:
  • The first question is does it need a licence? The yes or no depends in most cases on whether it is on a control list. The control list is governed by the Wassenar arrangement agreed by 41 key countries involved in arms exports. The content of the list depends on which civilian goods have military application.  So for example if something contained cryptography it could be refused a licence.  If it is decided that the goods/services do need a licence then
  • They look at "consolidated criteria" against which all export licences issued are judged on a case-by-case basis.
The story of Creativity Software sales to Iran last year kinda hit the UK Department for Business, Innovation and Skills (BIS) out of the blue. As did later similar stories like the Italian company supplying US sourced surveillance technology to the despotic Syrian regime. BIS started looking into it and did three things.
  1. Got EU legislation in place to block supplies of this kind of tech to Syria.  Mr Smith's team worked as technical secretariat to the EU on this.
  2. The UK took the lead to put this on the table at Wassenar.  The technology at the heart of the controversy was not controlled and they wanted it to be. The have been two discussions at Wassenar. For an international arms control issue it is moving like lightning - these things can take years - but it still appears to be incredibly slow in practice.  He wants it sped up but some countries are procrastinating.  The UK are working with the US and Germany to get an international control list.  His ministers are behind this but will not back emergency unilateral legislation in the UK
  3. ECO and BIS are reaching out with various degrees of success to the companies involved in this field.
The UK is taking the lead on this but he admitted don't fully have a handle on the problem in terms of putting controls in place. The UK government, ECO and BIS have certain skills and leverage but need help.

Eric King from Privacy International was next up. Part of the process he used to research the issue was to attend trade shows for the companies involved in flogging these technologies. He discovered a web of very complicated trading dominated by US, UK and German companies.  They get together at trade shows (on surveillance and arms sales).  Their product pitches are incredible to listen to.  The rule of law, privacy, civil rights don't exist as far as these people are concerned. They act like cowboys.  The way they dress - eg black shirts, red jackets & ties - company names like Panopticon, excitable conscience-free talk about facilitating mass surveillance and countrywide interception is the order of the day.

These people are not shipping boxes off the shelf with no idea of what they are doing or who they are dealing with.  They are surveillance consultants.  They do the installation and the tech support.  A UK/German company (who I think he called Gamma?) regulate via DRM the number of intelligence agents who can use the technology; and charge by the number of people they spy on.  These companies talk openly at the trade shows and in their promotional materials about spying on political opponents and left leaning universities.

It is really important that export controls be put in place. This is the only way to deal with them. There is a phenomenal amount to be done to hold these companies to account for the terrifying human rights abuses they are perpetrating and facilitating.

Ian Brown then had the opportunity to talk about the GNI digital freedoms report. He opened by asking rhetorically is regulation necessary and then immediately answering yes. If we need it then how do we make it effective?

Some issues that the stakeholders they engaged with raised -
  • Dual use - some technologies have military and civilian applications. We cannot ban everything that can be put to nefarious uses
  • When is a device a mass surveillance device as opposed to a lawful interception device?
  • What about the context e.g use of the technology in countries without the rule of law?
  • There is very broad availability of these technologies.  So there would be little or no point in taking unilateral action in the UK on them.
  • There is a thriving second hand market in these surveillance technologies
  • Wassenar had some very sensible rules e.g. there is no point in adding certain goods to the control list because you cannot control their export
  • The EU relies on member states to enforce export controls and yet many member states do not have export controls
  • Civil society made the point that definitions have to be precise.  Too narrow and you miss important stuff.  Too broad and you hinder democracy activists who can use technology for positive ends
It is good that Wassenar is evolving.  Its purpose is to control military and dual use goods and technologies.  The GNI report recommends the definition of military and dual use be extended to cover things used to abuse human rights.

By and large cryptography control is obsolete.  Besides we want democracy activists in repressive regimes to have access to cryptography and easy to use cryptography at that.  In one Iranian case Nokia-Siemens equipment was used to find and arrest a 'dissident' activist.

The Communications Assistance for Law Enforcement Act (CALEA) in the US required back doors to be built into communications technologies to facilitate government surveillance.

Nokia-Siemens said they were not going to make any more money out of regimes like Iran.  They separated off that branch of the company. Amasys (?), a French company doing business with Libya did the same thing. They sold of that part of the company.

The responsible thing for these organisations to do would be to be transparent about what they have shipped to whom and where.

It is not the only solution to the problem - this has to be tackled on multiple fronts - but export controls can help. There is kit which should be controlled but is not, yet.

Syria and Iran are easy to demonise - they are pariah states.  But there is a spectrum.  There are numerous other countries the UK patronises that are involved in well documented human rights abuses.

There followed a series of questions from the floor.

To what extent will enforcement be pursued against companies who break the rules?

Mr Smith from ECO replied it is largely a question for the CPS on whether to prosecute. BIS pursue a number of prosecutions every year.  They win some and lose some. One of the questions the CPS ask is whether there is a legitimate defence where the company can reasonably plead ignorance of the uses to which their good would be put.

Ian Brown also responded to this question making the point that despite concerns about the effectiveness of export controls, without them all other methods of control will be circumvented. And if we relied on the reputation of companies we would not do business with arms dealers.

The next question related to the extent to which government acts as salesmen for the arms industry - to what extent is the government selling surveillance equipment. Also, hacking tools are not just used for domestic surveillance but for international spying. To what extent are concerns about spying taken into account i.e arming other countries to spy on the UK? What are the concerns about selling zero day exploits abroad?

BIS do not think the UK government are with knowledge aforethought selling surveillance equipment abroad. Do they explicitly take into account whether goods considered for licencing will be used against the UK - yes.

Would it be good if there was an international forum for the control of technology used to abuse human rights? Yes.

Are the UK government going to say they have to protect surveillance technology export in the interests of protecting the export of other technology? No.

The companies that are doing the most damage are software companies that come out of telcos. There are a clutch of these companies around Berlin run by ex- Stasi officers.

Some of these companies have decent motives and genuinely want to supply protective technology and tools to democracy activists. But there are a lot of people in the field who are glorying in dealing with despotic regimes, wreaking havoc and having a whale of a time, says Eric King of PI.

There was a question about the Communications Data Bill (CDB aka the Snoopers' Charter). Mr Smith from ECO BIS is confident that the motivation of those pushing the CDB is pure.

Specialist companies dealing in this area do not respond well to external pressure. We have to put export controls in place and sue them. A couple of recent cases have been pursued against Cisco under the US Alien Torts Act accusing them of aiding and abetting torture and imprisonment. It can be difficult to get evidence but if companies are selling stuff and don't do due diligence they should be held liable.

The final comment from the floor was that pressure should be applied to the venture capitalists funding these companies.

A concluding comment was then requested from the three panelists.

Ian Brown emphasised the point that it is principally governments who can make a difference.  Ethical consumerism would help as would ethical capitalism on the part of the companies involved in these technologies.

Tom Smith said it is difficult but important to get these technologies under control and BIS are working hard to that end.

And finally Eric King said it is really important to get export controls on this stuff.  That rounds off the notes on the second panel but I think it is worth finishing with the executive summary and recommendations from the report again. Plus a recommendation that it is essential reading for anyone with an interest in digital freedoms in international law.
"With around 2.3 billion users, the Internet has become part of the daily lives of a significant percentage of the global population, including for political debate and activism. While states are responsible for protecting human rights online under international law, companies responsible for Internet infrastructure, products and services can play an important supporting role. Companies also have a legal and corporate social responsibility to support legitimate law enforcement agency actions to reduce online criminal activity such as fraud, child exploitation and terrorism. They sometimes face ethical and moral dilemmas when such actions may facilitate violations of human rights. In this report we suggest practical measures that governments, corporations and other stakeholders can take to protect freedom of expression, privacy, and related rights in globally networked digital technologies. These are built on a detailed analysis of international law, three workshops in London, Washington DC and Delhi, and extensive interviews with government, civil society and corporate actors. "
Even if you're not a digital policy geek, the full executive summary (page 4-7) and the recommendations (p41-44) should be essential reading for everyone.

Wednesday, July 18, 2012

Commission on Bill of Rights 2nd consultation

Just appeared in my inbox are two emails from Marie Colton of the Commission on a Bill of Rights Secretariat, attached to which is a message from Sir Leigh Lewis, Chair of the Commission and a copy of the Commission’s recently published second consultation paper. The Chairman says:
"I am writing to provide you with a copy of a second consultation paper that the Commission on a Bill of Rights is making public today.

As you may be aware, the Commission was established by the UK Government in March 2011 primarily to investigate the creation of a UK Bill of Rights. Over the last 15 months, we have consulted widely on the issues which form part of our mandate. In particular, we published a discussion paper in August of last year which attracted over 900 responses. We have also met with numerous groups and individuals from around the UK and held a series of seminars to enable us to seek and receive views. Further details about our work, terms of reference and consultation programme can be found on the Commission’s website (www.justice.gov.uk/about/cbr/index.htm). Our thanks go to all those who have already contributed to our work and deliberations – whether by meeting with us, participating at one of our events, and/or submitting a response to our first discussion paper.

With less than six months to go until we must report, our Commission is now at a significant stage in its work. In particular, we have to decide whether or not to recommend a UK Bill of Rights and, if so, what form and content any such Bill might have. We have therefore decided to publish a second consultation paper to provide a further opportunity for you to tell us your views on a number of the key issues covered by our terms of reference and I am very pleased to attach a copy. If you responded to our first consultation last summer or have otherwise already conveyed your views to us, you do not need to repeat what you have already said which we have already taken very carefully into account. We would, however, very much like to hear from you again both on the further questions set out in this paper or if your views have developed or changed since you first responded. Equally, if you did not respond to our first consultation, that is no bar whatsoever to giving us your views now which we would greatly welcome.  

The deadline for responding to the consultation paper is 30 September 2012.

We greatly look forward to hearing your views.

Yours sincerely,

Sir Leigh Lewis KCB
Chair"
In the thick of a multitude of battles with zombie bureaucrats over entirely unrelated matters, I did draft and send a response to the original consultation in August last year. I realised, sadly after submitting, that my clumsy legal terminological inexactitudes and inadvertent misuse of legal and constitutional terms probably led to my submission being filed under whatever euphemism the Commission were then using for 'clueless'. It was a classic example of importance of not writing at the margins of your time and sending off (what you, at least, consider to be) significant papers, in a hurry, without first giving them your full attention and running the draft past informed friends and colleagues.

The questions in this second consultation are as below.
"Q1: What do you think would be the advantages or disadvantages of a UK Bill of Rights? Do you think that there are alternatives to either our existing arrangements or to a UK Bill of Rights that would achieve the same benefits? If you think that there are disadvantages to a UK Bill of Rights, do you think that the benefits outweigh them? Whether or not you favour a UK Bill of Rights, do you think that the Human Rights Act ought to be retained or repealed?
Q2: In considering the arguments for and against a UK Bill of Rights, to what extent do you believe that the European Convention on Human Rights should or should not remain incorporated into our domestic law?
Q3: If there were to be a UK Bill of Rights, should it replace or sit alongside the Human Rights Act 1998?
Q4: Should the rights and freedoms in any UK Bill of Rights be expressed in the same or different language from that currently used in the Human Rights Act and the European Convention on Human Rights? If different, in what ways should the rights and freedoms be differently expressed?
Q5: What advantages or disadvantages do you think there would be, if any, if the rights and freedoms in any UK Bill of Rights were expressed in different language from that used in the European Convention on Human Rights and the Human Rights Act 1998?
Q6: Do you think any UK Bill of Rights should include additional rights and, if so, which? Do you have views on the possible wording of such additional rights as you believe should be included in any UK Bill of Rights?
Q7: What in your view would be the advantages, disadvantages or challenges of the inclusion of such additional rights?
Q8: Should any UK Bill of Rights seek to give guidance to our courts on the balance to be struck between qualified and competing Convention rights? If so, in what way?
Q9: Presuming any UK Bill of Rights contained a duty on public authorities similar to that in section 6 of the Human Rights Act 1998, is there a need to amend the definition of ‘public authority’? If so, how?
Q10: Should there be a role for responsibilities in any UK Bill of Rights? If so, in which of the ways set out above might it be included?
Q11: Should the duty on courts to take relevant Strasbourg case law ‘into account’ be maintained or modified? If modified, how and with what aim?
Q12: Should any UK Bill of Rights seek to change the balance currently set out under the Human Rights Act between the courts and Parliament?
Q13: To what extent should current constitutional and political circumstances in Northern Ireland, Scotland, Wales and/or the UK as a whole be a factor in deciding whether (i) to maintain existing arrangements on the protection of human rights in the UK, or (ii) to introduce a UK Bill of Rights in some form?
Q14: What are your views on the possible models outlined in paragraphs 80-81 above for a UK Bill of Rights?
Q15: Do you have any other views on whether, and if so, how any UK Bill of Rights should be formulated to take account of the position in Northern Ireland, Scotland or Wales?"
 Paragraphs 80-81 referred to in Q14 are as follows:
"80.
One possible model for a UK Bill of Rights in this context is a Bill that might sit alongside the existing Human Rights Act and contain substantially similar provisions and rights to those currently found in Schedule 1 to the Act. Under this model these rights might apply UK wide but be exercisable in respect of reserved matters only. Such an instrument might also include a separate chapter containing rights that applied only to England, as
well as a statement that acknowledged the competence of the Northern Ireland Assembly, the Scottish Parliament and the National Assembly for Wales to enact legislation conferring additional rights to meet the particular needs of those countries. Any additional rights passed by the devolved legislatures would, by virtue of the existing devolution statutes, relate to devolved matters only. In the view of some such a model might simply reflect what already happens in practice in respect of rights protection under the devolution statutes.8
81.
Another possible model might be a UK Bill of Rights that contained additional rights in respect of Northern Ireland, Scotland and Wales but which would not enter into force in respect of those countries without the consent of the respective devolved legislature."
I would highly encourage engagement with the consultation. I wouldn't put it past the political digerati to stoke up some public mischief using the possible Bill of Rights and Human Rights Act as political footballs, in order to divert attention from their endless woes and pathological ineptitude. So the importance of this Commission cannot be overstated.

Saturday, July 14, 2012

Olympics rights and wrongs

An old friend of the family, James Grote, hugely deserving of the honour, carried the Olympic torch through Oxford early on Tuesday morning.  My wife and younger son got up early to watch it pass a couple of hundred yards from our house, as the crow flies. They both came back buzzing with the excitement of it all.

Before I became a modern day curmudgeon about the political and corporate pollution and exploitation of it all, I shared that sense of awe and magic surrounding major sporting events like the Olympics, world cup & European championship finals, FA cup final, various athletics events, Gaelic games, Tour de France and even Wimbledon.

However, the government are turning London and the Olympic venues into a police state for the duration of the games. Visitors from totalitarian states won't see any difference in their treatment around the venues than that they receive from authorities at home; as they watch the VIPs being ferried, in official Olympic vehicles, rapidly and smoothly down Olympic designated lanes, whilst they wait to be processed by security with the rest of us ordinary plebs .

Special laws, like the London Olympic Games and Paralympic Games Act 2006 and the Olympic Symbol (Protection) Act of 1995, relating to the protection of corporate sponsors of the games are probably the most restrictive ever, in their scope and potential penalties should they be deliberately or inadvertently transgressed. The former law gives LOCOG the power to prevent unauthorised associations with the Olympics.  Officially sanctioned associations are called "London Olympic Association rights".  Businesses along the torch route in Oxford have been told to cover their signs as they are not entitled to any publicity that might be remotely associated with the Olympics.

The intellectual property, promotional and economic rights of the sponsors are more important than the civil rights of people attending or even linking to the website of the games or just watching the torch relay. The IOC, LOCOG and the big companies involved defend their intellectual property vigorously and some would say viciously. Never forget, for example that within the confines of the Olympic Park McDonalds is watching you.
"Due to sponsorship obligations with McDonalds LOCOG have instructed the Catering team that they are no longer able to serve chips on their own within the Olympic Park.
The only loophole to this is if they are served with fish."

I've got two tickets for a quarter final football match at Wembley and amongst the items I'm banned from bringing are musical instruments, "professional style cameras", containers with a capacity greater than 100ml. Oh but I can bring essential medication if I also bring a letter from a doctor saying I need it.

Then there is the catch all no "items with corporate or inappropriate branding, sponsorship, promotional or marketing material or literature, except for official Games merchandise and/or other football related clothing worn in good faith, any unofficial or counterfeit merchandise".

The job of the general public is to quietly acquiesce to over-reaching, abusive security theatre and consume and cheer the Olympics bread and circuses.  I love sport and like my family really want to enjoy the games. The Olympics are supposed to be about building a better world through sport - better, higher, faster, stronger - excellence, respect, friendship built on ethical values; development through sport, education through sport, peace through sport.  That idealism sadly gets lost in the real world.

I will use my tickets and hope that kids in particular can revel in and remember the excitement of the occasion. But it's really difficult to set aside the industrial scale political and corporate malfeasance surrounding it all.  Let's face it, if we all decided to engage exclusively with ethical political, public, social, economic, private and civil society actors/agents/individuals/institutions and hold them to those ethical values, the world would be a much better place.

Perhaps those of us lucky enough to have got tickets for Olympic events might start by wearing T-shirts with the insignia 'UK taxpayer: Official Sponsor of London 2012'.  After all we are paying the biggest part of the multi billion pound bill. Or would LOCOG and the IOC consider that ambush marketing?

Friday, July 13, 2012

Terry: he said it but not proven racially aggravated insult

The John Terry judgment is very readable and clear. The short version:

Did John Terry use threatening, abusive/insulting words.. within.. hearing/sight of a person likely to be caused.. distress? Yes.

Was it a racially aggravated abuse/insult under S28 of the Crime and Disorder Act (CDA) 1998, S5 of Public Order Act 1986 & S31(1)(c) & (5) of CDA there's a doubt, so...not guilty.

From the judgment:
"John Terry faces one allegation. It is said that on the 23rd October 2011 at
Loftus Road Stadium London, W12 he used threatening, abusive or insulting
words or behaviour or disorderly behaviour within the hearing or sight of a
person likely to be caused harassment, alarm or distress and the offence was
racially aggravated in accordance with section 28 of the Crime and Disorder
Act 1998, contrary to Section 5 of the Public Order Act 1986 and section
31(1)(c) and (5) of the Crime and Disorder Act 1998.

To summarize:
     There is no doubt the words “Fucking black cunt” were directed at Mr
Ferdinand.
     Overall I found Anton Ferdinand to be a believable witness on the
central issue.
     It is inherently unlikely that he should firstly accuse John Terry of
calling him a black cunt, then shortly after the match completely deny
that he had made such a comment, and then maintain that false
account throughout the police investigation and throughout this trial.
There is no history of animosity between the two men. The supposed
motivation is slight.
     Mr Terry’s explanation is, certainly under the cold light of forensic
examination, unlikely. It is not the most obvious response. It is
sandwiched between other undoubted insults.
     I believe that he is an unwilling witness, and would have preferred that
this matter not come to court.
There were discrepancies in his evidence. To a large extent this is what
you would expect from a truthful witness. Much of what happened;
happened in a brief period of time, in circumstances where the result of
the game was more important than any individual argument between
two players. I will return later to the discrepancies.
[...]
So the question for me now is whether there is a doubt that the offence is
made out. In all criminal courts in this country a defendant is found guilty
only if the court, be it a jury, magistrate, or a judge, is sure of guilt. If there
is a reasonable doubt then the defendant is entitled to be acquitted.
[...]
Conclusion 
The prosecution has presented a strong case. There is no doubt that John
Terry uttered the words “fucking black cunt” at Anton Ferdinand. When he
did so he was angry. Mr Ferdinand says that he did not precipitate this
comment by himself accusing Mr Terry of calling him a black cunt.
Even with all the help the court has received from television footage,
expert lip readers, witnesses and indeed counsel, it is impossible to be  
sure exactly what were the words spoken by Mr Terry at the relevant time. It is
impossible to be sure exactly what was said to him at the relevant time by
Mr Ferdinand.

[...]
Weighing all the evidence together, I think it is highly unlikely that Mr
Ferdinand accused Mr Terry on the pitch of calling him a black cunt.
However I accept that it is possible that Mr Terry believed at the time, and
believes now, that such an accusation was made. The prosecution evidence
as to what was said by Mr Ferdinand at this point is not strong. Mr Cole
gives corroborating (although far from compelling corroborating)  
evidence on this point. It is therefore possible that what he said was not intended as
an insult, but rather as a challenge to what he believed had been said to
him.  
In those circumstances, there being a doubt, the only verdict the court can
record is one of not guilty." 
John Terry was on trial for using racially aggravated "threatening, abusive or insulting words or behaviour or disorderly behaviour within the hearing or sight of a person likely to be caused harassment, alarm or distress" as set out in section 28 of the Crime & Disorder Act 1998, Section 5 of the Public Order Act 1986 and section 31(1)(c) and (5) of the Crime and Disorder Act 1998.

The case was not proven beyond doubt, so he was found not guilty.


None of the actors in this little drama have come out of it looking too good. The footballers behaved badly.  They also seem to believe that vicious verbal abuse and offensive language is ok as long as there is no reference to colour?

The law (s5) determines that engaging in insulting words or behaviour is a criminal offence. That's pretty offensive itself in a modern democracy.

So I guess there are three remaining questions on the case.

Was it ok for the court to postpone the case until after the European championship finals for John Terry's convenience?

Do the FA now follow up by charging Mr Terry with misconduct as per the Suarez case last year?

More importantly, does the case help or hinder the campaign to get section 5 of the Public Order Act 1986 repealed or updated?

Monday, July 09, 2012

New laptop set up: just switch on and go...?

I've been setting up a new computer today.  Am I getting slower or is setting up a new laptop computer getting more tortuous? Maybe it's just that this is an infrequently used skill?  Anyway it took most of the morning and part of the afternoon.
  • Sorted battery out.
  • Did new computer Windows 7 rigmarole
  • Ignoring McAfee advice that I needed to register a McAfee account before removal, I removed McAfee first via the Windows uninstaller; then rebooted and downloaded McAfee removal tool; ran this as an administrator and rebooted again
  • Installed Sophos via remote user disk (the Open University has a licence covering home users). Not as smooth as it should have been; again had to run as an administrator and of course Windows 7 doesn't facilitate the easy set up from starting of an administrator account; (for OU readers run it from the OUlocal.bat file in the main folder rather than the sophos-install.bat file in the sophos folder - for some reason trying to install from the latter file gets part way through and then tries to connect to a network printer and fails)
  • Next installed Firefox
  • Revise to personal preference the privacy and proxy and security Firefox settings
  • Install Skype; find user's lost Skype password; set preferred privacy settings
  • Install Thunderbird
  • Set up email account on Thunderbird; again this took a little longer than expected because I made a series of simple errors when entering the IMAP and smtp server settings
  • Next step should be installing Enigmail GPG extension for Thunderbird
  • Next and most importantly installed Linux, Ubuntu 12.04 in this case
  • Couple of reboots later and Ubuntu is running smoothly
  • Needed language support update
  • Needed about 230MB of other updates via the Software Updater
  • Install Synaptic package manager
  • Install Thunderbird for Linux and set up account
  • Install Enigmail GPG extension
  • Install Skype for Linux; set privacy settings etc
  • Install recordMyDesktop
  • Install Chrome and Flash for Linux (there are going to be no further Flash updates for Linux but Google are taking over and will integrate to Chrome)
  • Install audio/video codecs
  • Set Ubuntu privacy settings to suit
  • Set Firefox proxies, security, privacy settings
  • Install LibreOffice Global Menu
Then you're pretty much ready to go.  Now that wasn't too difficult was it? Though why is it I still think I've missed something obvious?

Just on the Ubuntu 12.04, it's worth checking out Joey Sneddon's 10 things to do after installing Ubuntu 12.04. and Sean from novelldesktop's 5 things to do after installing Ubuntu 12.04.

Thursday, July 05, 2012

ECJ upholds first sale doctrine for software

Little noticed on a busy newsweek the Court of Justice of the European Union (CJEU) (also known as the European Court of Justice, ECJ), on Tuesday, emphatically upheld the first sale doctrine for software in the EU. So when you purchase software in the EU, regardless of what the small print in the licence says, you are purchasing something which you can sell on second hand, without the copyright owner's permission or interference. The original copyright owner's exclusive right of reproduction, however, is not exhausted by the first sale. In other words, software companies still control the copyright just not the right to resell copies of the software they have already sold.

Oracle had sued a German company, UsedSoft which has been selling second hand copies of its software. And cheekily, some might believe, some UsedSoft's customers have been getting their copy of the Oracle software from Oracle's own website and are entitled to have any updates and bug fixes the original user had.

The case will now go back to the German Federal Court of Justice for a final decision.

The 2009 directive on the legal protection of computer programs theoretically implements a first sale doctrine for software in the EU - first sale in the EU of a copy of a computer program exhausts the right of distribution of that copy in the EU. The bottom line theoretically is that when you purchase software in the EU you are not just licensing the use of the software as every commercial software licence says, you have bought a copy which you're entitled to sell on.

Oracle thought they could bypass the directive through get out clauses in their licences, as is standard practice in the software industry. So it's nice to see the ECJ stand by the letter and spirit of the directive.

Contract pretty much trumps everything in the US courts so this will have been a surprise to Oracle but not necessarily totally unexpected, since the ECJ Advocate General, Yves Bot, issued his advisory opinion along the same lines in April.

The Court issued a very accessible 2 page statement on the decision on Tuesday.
"An author of software cannot oppose the resale of his ‘used’ licences allowing the use of his programs downloaded from the internet
The exclusive right of distribution of a copy of a computer program covered by such a licence is exhausted on its first sale
UsedSoft is a German undertaking which markets licences acquired from customers of Oracle. Customers of UsedSoft who are not yet in possession of the software download it directly from Oracle’s website after acquiring a ‘used’ licence. Customers who already have that software can purchase a further licence or part of a licence for additional users...
Oracle brought proceedings against UsedSoft in the German courts, seeking an order for it to cease those practices. The Bundesgerichtshof (Federal Court of Justice, Germany) ... made a reference to the Court of Justice for it to interpret, in this context, the directive on the legal protection of computer programs.1.
Under that directive, the first sale in the EU of a copy of a computer program by the copyright holder or with his consent exhausts the right of distribution of that copy in the EU.
By its judgment delivered today, the Court explains that the principle of exhaustion of the distribution right applies not only where the copyright holder markets copies of his software on a material medium (CD-ROM or DVD) but also where he distributes them by means of downloads from his website.
Where the copyright holder makes available to his customer a copy – tangible or intangible – and at the same time concludes, in return form payment of a fee, a licence agreement granting the customer the right to use that copy for an unlimited period, that rightholder sells the copy to the customer and thus exhausts his exclusive distribution right. Such a transaction involves a transfer of the right of ownership of the copy. Therefore, even if the licence agreement prohibits a further transfer, the rightholder can no longer oppose the resale of that copy.
The Court observes in particular that limiting the application of the principle of the exhaustion of the distribution right solely to copies of computer programs that are sold on a material medium would allow the copyright holder to control the resale of copies downloaded from the internet and to demand further remuneration on the occasion of each new sale, even though the first sale of the copy had already enabled the rightholder to obtain appropriate remuneration...
Moreover, the exhaustion of the distribution right extends to the copy of the computer program sold as corrected and updated by the copyright holder...
The Court points out, however, that if the licence acquired by the first acquirer relates to a greater number of users than he needs, that acquirer is not authorised by the effect of the exhaustion of the distribution right to divide the licence and resell only part of it.
Furthermore, the Court states that an original acquirer of a tangible or intangible copy of a computer program for which the copyright holder’s right of distribution is exhausted must make the copy downloaded onto his own computer unusable at the time of resale. If he continued to use it, he would infringe the copyright holder’s exclusive right of reproduction of his computer program. In contrast to the exclusive right of distribution, the exclusive right of reproduction is not exhausted by the first sale. However, the directive authorises any reproduction that is necessary for the use of the computer program by the lawful acquirer in accordance with its intended purpose. Such reproduction may not be prohibited by contract.
 In this context, the Court’s answer is that any subsequent acquirer of a copy for which the copyright holder’s distribution right is exhausted constitutes such a lawful acquirer. He can therefore download onto his computer the copy sold to him by the first acquirer. Such a download must be regarded as a reproduction of a computer program that is necessary to enable the new acquirer to use the program in accordance with its intended purpose.
Therefore the new acquirer of the user licence, such as a customer of UsedSoft, may, as a lawful acquirer of the corrected and updated copy of the computer program concerned, download that copy from the copyright holder’s website."
I find it interesting that the UsedSoft v Oracle decision protects the ability of UsedSoft's customers to get their 'used' copy of the software from Oracle's website.  I can't see that that protection would have been upheld by any US court.

Another key element was the Court's decision to specifically neutralise the relative distribution channels as a material factor. Software is software whether you get it on a physical medium or through the Net.

I wish I could share the prevailing optimism on the wider impact of the decision but I suspect the software and games cos. et al will continue to use restrictive licences and make it difficult through drm etc to pass on second hand games through sales, borrowings or donations. Though the legal departments of those same companies will even now be working on a form of words to insert in the licences to address the 'problems' thrown up by the ECJ.

The real breakthrough on end user licence agreements (or EULAs) will come when there's a successful challenge in a supreme court on the basis of unfair contract terms.

Notes
1. Directive 2009/24/EC of the European Parliament and of the Council of 23 April 2009 on the legal protection of computer programs (OJ 2009 L 111, p. 16).