Monday, October 08, 2012

Cole v Shearer: how the media damage free speech

If Alan Shearer has the right to get paid vast sums of money to use the national public service broadcaster as a pulpit for criticising Ashley Cole, including calling for him to be banned from the England team, does Cole have the right to respond by highlighting a comment of another Twitter user which said:
"Alan Shearer says @TheRealAC3 needs to be banned for comments. I want his opinion on bans for kicking Neil Lennon in the head. #GlassHouses"
The comment refers to this incident in a Newcastle v Leicester match in 1998 when Shearer kicked Neil Lennon in the face. Shearer was England captain at the time. Lennon now manages Glasgow Celtic.



The tweet has now been removed from Cole's account, presumably on the receipt of advice or possibly second thoughts about the stink it might cause.

During a regular appearance on Match of the Day on Saturday Shearer called for Cole to be banned because he posted the following on Twitter on Friday (also subsequently removed from his account):
""Hahahahaa, well done #fa I lied did I, #BUNCHOFTWATS."
On balance I'd suggest deliberately kicking someone in the face is a more serious offence than calling the FA a bunch of twats. So it was a pretty reasonable question from Cole and the supporter he quoted really.

Given the sensitivities of the modern media ecology, starved as it is of celebrity opinion [sic] and the capacity to comment thereon, whether he was #wise to ask it on Twitter is another issue. The 'acceptable' approach might have been to ignore Shearer or issue a statement through an agent to "express disappointment at the former England captain's comments".

The newspapers and broadcasters have raised an almighty storm around this. Yet they are the first to complain when players and clubs employ PR people to lock them out and keep players and managers "on message".  The injection of Twitter gives them an extra excuse to go over the top. I've asked the question before but what is it about Twitter that makes the conventional media and authorities lose all sense of proportion?

The sight of the BBC getting it's underwear in an unholy twist over the inability to include the word "twat" in any of its many broadcast stories about the furore has been somewhat amusing. "Twat" hardly comes anywhere near the top of the table of explosive expletives. Until the BBC police got exorcised about it I wasn't even inclined to think of it as being in the top division - too weedy or apologetic to qualify as a proper insult really. The long line of journalists, commentators' and ex-footballers' uncontrolled (or dare I say feigned?) anger at Cole's FA twat comment, however, has been something to behold.  It's fairly doubtful that any of these bandwagon critics have not called the FA something significantly stronger than "twat" on more than one occasion during the course of their careers. And you know what? Good for them. They are entitled to their opinion. It does feel a bit like hypocrisy to now stir up the twitter/media lynch mob to target Cole, though.

We live in a democratic state that allegedly values freedom of expression. That means people like Shearer and Cole who live in the football and media bubble that has little connection with the real world are also entitled to speak freely. Shearer has a media approval rating that currently grants him the privilege of a large salary, large audience and the capacity to say things that are valued by those media, because of who he is rather than what he says. Giving Shearer effectively a more approved right to speak than Cole is a classic demonstration of the country's and the media circus's incapacity to apply the value of free speech, even before the addition of a large captive broadcast audience is factored in.

Should Shearer be sanctioned by the BBC for calling for someone to be suspended from work for saying something he found disagreeable? Of course not. Will he be? No.

Should Cole be sanctioned by the FA for saying something they, many in the media and the FA themselves disapproved of? No. Will he be? Yes.

If freedom of expression means anything, it means that free speech must be granted to those whose opinions are nasty, disagreeable, indefensible, outrageous, despicable, disgraceful, disgusting, idiotic and sometimes just different, surprising, incredible, unthinkable, implausible and paradigm shifting.

Freedom of expression is a right to speak, not a right to an audience. It's also a right not to be oppressed, harassed, persecuted, ill-treated or locked away by the state for your beliefs, thoughts or statements. It is to be hoped that our society as well as our state would value such rights.  Though in the UK there is no absolute free speech privilege and all manner of ways to trip over criminal sanctions for saying the wrong thing in the wrong way in the wrong place - s127 (1)(a) Communications Act 2003, s4-5 Public Order Act 1986, s1 Malicious Communications Act 1988, Contempt of Court Act 1981 (as amended 1991) and a host of anti terror regulations to name a few.

Every time the rabid news media stir a storm or incite a virtual lynch mob over a misplaced word or phrase by a 'celebrity', a politician, or whichever poor unfortunate becomes the latest to come to public attention, then they hammer another nail in the cause of freedom of expression and healthy democracy.   

It is already impossible to hold an informed public debate on challenging issues. The substance is set aside as the media frenziedly feed on an inarticulately phrased comment or poorly chosen word. Meaning is distorted and politicians resort to soundbite and bullet points to get their message across. So Romney comfortably wins a televised presidential debate by trotting out camera friendly practiced phrases and Obama loses by inarticulately trying to explain government is complicated. The party conference season in the UK sees the same empty soundbite nonsense trotted out here with the media primed to pounce on the first politician that says something off message.

The Cole v Shearer storm in a teacup will blow over and the football carnival is not that important in the scheme of things but the collateral damage these events do to the real world is worth paying attention to. Let people speak.  Then ignore them, debate them, explain the error of their ways to them or others, educate or just sit on the sidelines and treat it as entertainment, if you think it worthy of your attention. But let them speak.

I don't trust myself, the FA, the media or the government to determine who should be allowed to speak, where, about what, when, through what media, whatever the motivation of the speaker. So let them speak and to use an old cliche deal with bad speech through better speech. Banning from the workplace, threatening and/or sending in the 'something must be done' lynch mob are all disproportionate responses to a couple of footballers having a verbal/comment spat.

Tuesday, October 02, 2012

MP's response on parental controls

I copied my to short response to the consultation by the Department for Education on parental internet controls to my MP, Nicola Blackwood. Ms Blackwood has now contacted me about my concerns at the proposals as below.
"Dear Mr Corrigan,

Thank you for contacting me with your concerns regarding proposals for filtering of adult online content, and I apologise for the delay in my response.

I appreciate you taking the time to share your thoughts and personal experience with me on this issue, which I have read with interest. I am sorry to hear of the problems you have had with your own blog because of filters imposed by Orange, which I appreciate must have been very frustrating. You experience also raises an important point about site filtering, and one which I know Ministers will take very seriously into account as plans develop.
I believe that the internet is, by and large, a force for good. It is central to our lives and our economy and the Government has to be wary about regulating or passing legislation which might stifle it. Nevertheless, the advent of the internet has brought a number of problems, such as the proliferation of pornographic material on the internet.
The Government is therefore committed to ensuring that children can use the internet safely without access to unsuitable adult material. Some safeguards are already in place, with the managers of websites featuring mature content having a legal responsibility to indicate clearly on their front page that their site is unsuitable for anybody under the age of 18. Additionally, if a website charges for access then any adult content must be placed behind a credit card barrier to reduce further the risk of children and young people accessing it.
As you are aware, moves are now underway to strengthen and extend these safeguards. For instance, on 28 October 2011 a new code of practice on parental controls was launched by the four major Internet Service Providers - BT, Sky, TalkTalk and Virgin. This code means that new customers will be presented with an unavoidable choice of whether or not to activate parent controls. Through regular information updates, I understand that existing customers will also be offered the opportunity to activate parental controls.
In addition to this, the UK Council for Child Internet Safety is working on the adoption of a system whereby customers are always presented with an unavoidable choice about whether or not they want filters and blocks installed on their home internet service, through an approach known as "active choice". The Department for Education is now consulting on this proposal, and on what more can be done to keep children safe online.
I note your concern that network filters could end up blocking innocuous or educational content. However, I would emphasise that these proposals do not seek to impose unnecessary censorship on internet users, but are designed to give parents the tools they need to ensure their child's safety online.
While I believe that education of parents and children about the potential dangers of the internet is very important as a tool to help families avoid undesirable content, I would still welcome other practical measures to increase internet security for those instances when children access the internet in the absence of parents, teachers or guardians, and may come across anything from disturbing adult or violent material to online scams or sites containing viruses.

You also write that you feel more time and resources need to be spent on tracking and prosecuting online child abusers, preventing abuse and helping victims of grooming. I would assure you that this agenda is very high on the list of Ministers’ priorities, and that I am also actively engaged at a local level with relevant groups and organisations to try to make sure we are taking the most proactive approaches we can to tackling this threat to children and young people.

I have written to the new Culture Secretary Maria Miller MP to pass the concerns you have raised to her direct attention. I have also asked for further information as to what monitoring or filtering measures can be implemented to identify more subtle grooming and befriending techniques used by abusers, such as posing as a young person, where there may be no adult language, images or other filterable content in use. I shall of course be glad to pass on any substantive response I receive in due course.

Thank you once again for taking the time to contact me on this issue and I hope this response is helpful.

Kind regards,
Nicola"
My further response to Nicola is as follows.
"Nicola,

Thanks for your response. I note your well intentioned support for filters and your belief in the government line that the proposals “do not seek to impose unnecessary censorship on internet users, but are designed to give parents the tools they need to ensure their child's safety online.”

One of the long lasting negative legacies of the previous government was the waste of billions of pounds on technology they didn’t understand, in the misplaced hope that it would magically help to solve multiple political, economic and social problems they were also incapable of defining.

Unfortunately the hope that a filtering technology can fix the range of problems you outline here – children accessing disturbing adult or violent material, online scams or sites containing viruses – has been around ever since the US Supreme Court struck down the anti-indecency provisions of the Communications Decency Act in 1997. In those days even some technologists believed that technical filters were a workable alternative option to overly broad speech regulation. I don’t know of any serious computer scientist today who believes that upstream network level filtering can address the issue of access to content potentially harmful to minors. Not only will it not solve that problem, it will create a whole range of additional problems.

Mandating network filters is like imposing a restrictive architecture on the internet.  I try to explain to my students the perils of such an approach via the example of prolific 20th-century New York City planner, Robert Moses. Moses built highway bridges along roads to the parks and beaches in Long Island that were too low for buses to pass under. Hence the parks and beaches were accessible only to car owners – many of them white middle class or wealthy. Poor people without cars, mainly African Americans and other minorities, would be forced to use other parks and beaches accessible by bus. Thus social relations between black and white people were regulated, an example of discriminatory regulation through architecture. Moses vehemently denied that there was any racist intent on his part. Yet his intent was irrelevant. The architecture regulated behaviour whether he intended to or not. Likewise it is irrelevant that the government “do not seek to impose unnecessary censorship on internet users”. Mandated filters will impose such censorship whilst at the same time facilitating access to material it is hoped that they will block.

A defining feature of the future of our economy and our society will be the architecture of the internet. It will change the world in ways probably more fundamental than the printing press. Locking it down in crude unworkable ways will only be damaging.

My earlier note to the consultation, copied to you, only scratched the surface of the catalogue of problems with what is being proposed here. Apologies for that – I didn’t have the time to make a comprehensive submission.

Many of the submissions to the consultation opposing the proposal are much more detailed and articulate.  The ISPs – including TalkTalk, often cited as being in favour – are against default filtering and have explained it is neither necessary nor effective.  You mention you would welcome practical measures to address security in an unsupervised access context. But from a practical technical perspective default blocking is almost impossible.

The optional ‘HomeSafe’ filter offered by TalkTalk and taken up by less than a tenth of their customers is reported to have significant flaws. It cost them £20 million. (The operation of HomeSafe is also potentially unlawful under a range of statutes including the Data Protection Act, Regulation of Investigatory Powers Act, Computer Misuse Act, Copyright Designs & Patents Act, amongst others.  But that’s a complex story for another day, although mandated filtering proposals would likely trip over similar regulatory hurdles). It is ineffective but at least it remains optional.

There are (and have been for a long time) ISP, free and commercially available parental control software filters.  They are crude, ineffective and overbroad. They are also trivially bypassed by smart tech savvy kids. They are, however, optional and parents can use/buy them and set the levels to suit their own household needs whilst always bearing in mind the software’s limitations.

Giving parents the impression that government mandated filters deployed centrally on the network are effective induces a false sense of security.

There is no detail on how blacklists would be managed or implemented in system software. Who decides what is harmful to minors and how do they decide this?

There is no detail on due process or how to get legitimate sites removed from such blacklists. Though trivial to bypass crude filters have and do damage small businesses where customers don’t necessarily have the required understanding of filter circumvention measures. As COADEC says, “Default blocking inadvertently blocks perfectly legal and legitimate businesses and organisations, and a reporting and redress process that is complicated, and lengthy, could seriously inhibit a business who launches their site to discover it has incorrectly been blocked."

It will be hugely expensive for ISPs and probably government, since ISPs will not want to be solely responsible for the cost of such investment.

Additionally the legal hurdles – existing UK law – facing the implementation of such a system are huge.

So if I could summarise briefly with a business case assessment:

Q1 What problem are we trying to solve?
A1 This is ill defined but suppose we take the problem as children “accessing disturbing adult or violent material, online scams or sites containing viruses” that you mention

Q2 What is the proposed solution?
A2 Mandated network filters

Q3 How well does it solve the problem?
A3 Not at all.

Q4 What other problems does it create?
A4 Many including parental false sense of security, complex operational issues, damaged internet, probably insurmountable economic, political and legal problems

Q5 How much does it cost?
A5 Tens if not hundreds of millions of pounds.

Q6 Is it worth it?
A6 No.

As I say, I understand the well intentioned support for the proposals. But I hope this goes some way towards showing you how unworkable they are. There really is no practical alternative, in this context, to the education of parents and children about the benefits and potential dangers of the internet and the tools they use to access it.

Regards,

Ray"

Friday, September 28, 2012

High Court: Detention of 15 year old asylum seeker unlawful

The Queens Bench division of the High Court has just ruled (AAM (A Child) v Secretary of State for the Home Department [2012] EWHC 2567 (QB) (27 September 2012) that the detention of a 15 year old Iranian asylum seeker was unlawful.

This is the case of the lad who arrived on the back of a lorry with no documents, money or anywhere to go and was assessed as being a man in his 20s rather than the 15 year old he claimed to be.

The Court decided that he had been falsely imprisoned for a period of 44 days. Additionally the Home Secretary was found, by proxy, to have breached the boy's Article 5 European Convention on Human Rights (ECHR) rights to liberty and security. The key elements of the decision appear to be -
"66. The Defendant submitted that an immigration officer who was exercising the power of detention was in an analogous position to that of a police officer having reasonable grounds on which to arrest, or the hospital trust admitting the patient on the basis of an application which appeared to be in order.

67. I do not consider that it is permissible to extend the powers of an immigration officer to detain in this way in the absence of express provision. In reaching that conclusion, I rely upon the well-established common law principle that "the right to liberty is of fundamental importance and that the courts should strictly and narrowly construe general statutory powers whose exercise restricts fundamental common law rights and/or constitutes the commission of a tort": per Lord Dyson in R (Lumba) v Secretary of State for the Home Department [2012] 1 AC 245, at [53]…
Grounds of challenge to the legality of detention
(1) Age Assessment
113. In this case, Ms Noons said in evidence that she did not see it as her role to check whether or not the assessment was Merton-compliant. Indeed, she candidly admitted that she did not know what the Merton criteria were, and I concluded that she did not have the requisite training to decide whether or not the assessment was Merton-compliant. I accept the Claimant's submissions that, on the evidence, Ms Noon's decision to detain was unlawful because she failed to ask herself the right questions or take reasonable steps to acquaint herself with the information needed to make her decision. She did not follow the EIG policy and UKBA Guidance which I have referred to above. It was clear from the face of the assessment that there was no appropriate adult present; that it had been signed by only social worker; and that there were no comments by the Claimant on the social worker's adverse findings. This should have prompted Ms Noons to make further enquiries of the local authority. If she had done so, it could have become apparent at a much earlier stage that the local authority assessment was not Merton compliant, as was subsequently conceded by the local authority. …
(2) Section 55, Borders, Citizenship and Immigration Act 2009
130. My conclusion is that, by failing to have regard to the need to safeguard and promote his welfare as a child, the immigration officers erred in law, rendering the decision to detain unlawful.
3) Article 5 ECHR
142. In this case, it is established on the evidence that the Defendant, when detaining the Claimant: a) failed to have regard to his best interests as a child, contrary to Article 3 UNCRC;
b) detained him with adults and failed to consider an alternative to detention, contrary to Article 37 UNCRC.
143. Therefore I conclude that the Claimant's detention was in breach of Article 5(1) ECHR, and hence unlawful under s.6(1) HRA 1998.
(4) Detention in breach of policy and Hardial Singh principles
… 160. I accept that there was administrative delay in conducting the Claimant's initial screening interview. But in my view his detention was not unlawful, applying Hardial Singh principles. The purpose for which he was being detained was to obtain the necessary information to decide whether leave to enter should be granted or refused. The period of detention was reasonably necessary to achieve that purpose, taking into account the particular circumstances of his case, namely, that he was not eligible for the fast track process nor for Oakington. In my view, the Defendant acted with reasonable diligence and expedition. I do not consider that the delay in transferring the file, and the failure to meet the benchmark for conducting a screening interview, were sufficiently serious failings so as to justify a finding that detention was unlawful on Hardial Singh grounds. For the same reasons, the length of detention did not breach Article 5, as it did not "exceed that reasonably required for the purpose pursued" (Saadi, at [74]) nor did it breach paragraph EIG 55.1.3.
Conclusion
161.For the reasons set out above, the Claimant's detention was unlawful, and therefore he was falsely imprisoned for a period of 44 days. 162. The Claimant's detention was also in breach of Article 5 ECHR and the Human Rights Act 1998."

Monday, September 10, 2012

Regulation and trust in the digital economy: an uneasy relationship


A copy of the slides for and the transcript* of my talk at the Trust in the Digital Economy workshop at Aberdeen University last week.



Regulation and trust in the digital economy: an uneasy relationship

Good morning Aberdeen.

Abstract
What have terrorism, copyright infringement, spam, child protection and organised crime got in common?  They have all been cited by policymakers as reasons for introducing internet related laws. Unfortunately too many of these regulations are passed by legislatures lacking a rudimentary understanding of the technologies they are attempting to control. This has significant implications for innovators, economic agents and citizen consumers which go to the heart of what it means to engender trust in the digital economy.

Introduction
In the next 20 minutes I’m going to shoot through some basic behavioural economic theory and give a couple examples of regulations which I believe undermine trust in the digital economy. One of these is an existing law, the Digital Economy Act (DEA) 2010 and one is passing through parliament at the moment, the Communications Data Bill (CDB).

Whilst I’m outlining these ideas I’d like you to keep in mind that trust in the digital economy is one of the most fundamental issues of the 21st century.  We need to trust more people, more institutions and more complex systems than ever before. We need to trust them from further away and via the internet and technologies many of us don’t understand. So creating trust and engendering trust is more difficult than ever before.

The scale of it all also means that the bad guys can do more damage than ever and yet the traditional bad guys – the four horsemen of the infocalypse, drug dealers, child abusers, organized crime and terrorists – are not the key threats to trust, since they are few in number and operate at the fringes of society. The key threats arise from powerful governments and large organisations (including large criminal organisations) using their power to subvert trust. The global financial meltdown is the key case study of recent times. 

I’d also like you to remember that the number of people and institutions we trust every day is huge – the utility companies and their employees that provide my energy and water, the food I’ve consumed in the past 24 hours that I didn’t have to test chemically before eating it, the airports, airlines, pilots, ground staff, air crew, transport and security infrastructure that got me here today, [1] the websites I booked it all through, the police and public services that support order and stability.

3 Stakeholders’ model

Ok so getting back to the economics it’s useful to have a model through which to frame or attempt to understand some of these complex issues.  One way to think of it is through groups of stakeholders.  We can outline three generic groups of stakeholders in the digital economy –

  • the innovators/creators who come up with the ideas that form the basis of our products & services
  • the economic agents – by economic agents I mean commerce, public services and government – that get products and services to the public
  • the public – citizen consumers

I don’t like the word ‘citizen’ or ‘consumer’ but both together serve to separate this group from the other two.

For trust to thrive we need to look after the interests of all three sets of stakeholders.  All three need to thrive and that balance of interests is theoretically assumed to be delivered through Adam Smith’s invisible hand of the market working in harmony with enlightened governance.

Each of these three sets of stakeholders constitutes complex ecologies in themselves. Different innovators have different interests.  Different economic agents have often competing and/conflicting interests.  You only have to think about internet file sharing and the postulated damage it has done to the traditional large music labels, online news v newspapers, Amazon v ordinary bookshops.

There are fierce legal battles in the mobile and tablet computing space with  more than 50 Android patent cases being litigated globally. In the past couple of weeks a US jury had awarded Apple more than $1 billion in damages against Samsung.  The same week a Korean court issued injunctions against the sale of Apple and Samsung products for infringing each others’ patents. Last week Samsung won their latest court battle with Apple in Japan. These two companies alone are facing off against each other in courtrooms in ten different jurisdictions.  In the UK Samsung currently have the upper hand but only because the judge considered Apple’s products “much cooler”.

If you buy into some of the political rhetoric in the context of the US presidential race then the Government is against everybody.

So the reality is more complex than the model but for now let’s stick with the 3 stakeholder groups.

Behavioural forces model

What is it, then, that regulates the behaviour of these sets of stakeholders?  Yochai Benkler and Lawrence Lessig suggest there are four key forces:

  • social norms
  • the market
  • the environment or architecture
  • the law

Social norms dictate how we behave in social groups. When I first moved to the south of England to work, I didn't know I was not supposed to say hello to a stranger on a train. My attempts to engage someone in conversation were subject to suitably disdainful and horrified looks from my fellow passengers, who tried valiantly to ignore me. Having been normalised after 20 years, I can dish out the dirty looks with the best of them.

Social norms punish deviation after the event.

Market forces also regulate behaviour. Markets dictate that we don't get access to something unless we offer something of value in exchange. The price of cigarettes is potentially a constraint on a child's opportunity to smoke. Unlike social norms, market forces regulate at the time of the transaction. If children have no money, retailers will not sell them cigarettes.

Law and legal regulations provide the framework through which governments prescribe what is acceptable behaviour and what is not. Law acts as a threat. If we don't follow the law there is a risk that we will be found out and punished. I could cheerfully strangle several of the zombie bureaucrats I deal with on a daily basis but in addition to having some ethical concerns about murder, I’d prefer not to deal with the legal consequences of engaging in such activity.

Under the law, as with social norms, the punishment happens after the event.

‘Architecture’ or the built environment and the laws of physics – i.e. how the physical world is (and the limits of the laws of physics) – also regulate behaviour. Architecture is particularly important in the context of the digital economy, since digital technologies are entirely human constructs and designs.

Like market forces, constraints on behaviour imposed by architecture happen when we are trying to engage in that behaviour. For example, if a building has steep steps at the entrance and no other way in, it is difficult for a wheelchair user to enter the building unaided.

Prolific 20th-century New York City planner Robert Moses built highway bridges along roads to the parks and beaches in Long Island that were too low for buses to pass under. Hence the parks and beaches were accessible only to car owners – many of them white middle class or wealthy. Poor people without cars, mainly African Americans and other minorities, would be forced to use other parks and beaches accessible by bus. Thus social relations between black and white people were regulated, an example of discriminatory regulation through architecture.
It should be noted that Moses vehemently denied that there was any racist intent on his part. In one sense, his intent is irrelevant. The architecture regulated behaviour whether he intended to or not.

Architecture is also self-regulating – the steep steps get in the wheelchair user's way because they are steep and they are steps! Laws, norms and markets can only constrain when a ‘gatekeeper’ chooses to use the constraints they impose.

There were a couple of stark examples of architecture and technology regulating behaviour in an uncontrolled way in the past week.  On the evening of the 2nd of September roving network bots shut down the live streaming of the Hugo Awards ceremony just as Neil Gaiman was getting an award for his scripting of a Dr Who story, The Doctor’s Wife. The company policing the stream for copyright infringement, Ustream, could not stop the bots from censoring the live video streaming of one of the world’s most prestigious science fiction award ceremonies; a ceremony which could not be viewed live anywhere else other than by those physically present there.  Ustream could not shut down the bots once these automated stream killers decided to block the video because the bots were programmed and deployed by a third party company, Vobile, which was subcontracted by Ustream to do automated takedowns. The bots saw Dr Who clips and decided their broadcast wasn’t allowed regardless of rights clearances or fair use.

Ustream have reportedly discontinued their business relationship with Vobile.[2] Vobile’s CEO tells a different story to Ustream explaining that Vobile only notifies the main client when their bots find a match for material tagged copyrighted in their database.  They have no control over takedowns which were entirely the remit of Ustream as far as the Hugo Awards were concerned.[3]

Who is really responsible is irrelevant to the overriding point though that technological architecture inappropriately shut down a legitimate internet broadcast without due cause or justification.

In a postscript to the story overzealous drm bots hit the video of Michelle Obama’s speech to the Democratic National Convention a few days later. This time the bots didn’t shut down the live stream but blocked access to the video after the event.[4] What’s amusing about this is the Democratic Party’s long history of support for entertainment industry lobbying for more and more stringent copyright laws.

Architecture is a massively important regulator in the context of the digital economy.

Force of law

Here’s a pictorial representation of the four forces regulating an individual. It’s an over-simplified picture again because the different forces also interact with each other and have different powers of influence depending on the context and the stakeholder in question.
For the rest of this talk I’d like to focus mainly on the distorting power of one of the forces – ill-informed laws – in undermining trust in the digital economy.  I have chosen a couple of examples from recent times to illustrate the issue. Both are laws that attempt to enforce dangerous surveillance/controlling technological architectures.

  • The Digital Economy Act (DEA) 2010
  • The Communications Data Bill (CDB) currently under consideration

DEA

The Digital Economy Act was passed in the “wash up” of laws just before the last general election.  The process is supposed to be used only for uncontroversial measures that are agreed between the front benches of the main political parties.  The DEA was very controversial, however, and over 20,000 people and multiple big telcos and technology companies wrote to the MPs in an ultimately futile effort to get it blocked. BT and TalkTalk have subsequently unsuccessfully challenged it through the courts.

Sections 3-18 of the DEA essentially make ISPs responsible for policing the internet for copyright infringement.  Detailed provisions relate to:

  • notifying subscribers of reported infringements
  • providing infringement lists to copyright owners
  • obligations to limit internet access
  • obligations  to engage in website blocking (the current government have decided to abolish this since Ofcom said it was unworkable)

Ofcom and the government are working on the details of how this will all operate in practice.  The Hargreaves ‘Review of Intellectual Property and Growth’ cited the passage of the DEA as an example of the distortion of public policy by questionable evidence.

The reality of the Digital Economy Act's (DEA) online infringement of copyright provisions (sections 3 - 18) may finally begin to hit home next year (theoretically) when thousands of people start to get accusatory letters about copyright infringement from their ISPs. The UK courts have not fully tested evidence presented in such copyright infringement cases as the few that have been pursued were eventually settled out of court. So there is no authoritative legal guidance on standards of evidence or process.

In any case the systematic threatening of large numbers of people by ISPs on behalf of the copyright industries is unlikely to be conducive to engendering trust in the digital economy.

It was not even clear until very recently whether the process of identifying the accounts of suspected copyright infringers could be done with any degree of forensic integrity. Thanks to a report[5] by Dr Richard Clayton of Cambridge University for Consumer Focus it appears that as long as a careful detailed set of procedures which he outlines in the report are followed this may be possible.[6] But he emphasises that his blueprint is time limited and will be useless once peer to peer network technologies evolve to incorporate encryption routinely.

There is a lot of heated rhetoric exchanged through the mainstream media whenever new copyright regulations like the DEA come along (and there have been a lot of them over the past 15 or 20 years).  So it might be instructive to take some of the heat out of the debate by looking at the impact of copyright law on our three sets of stakeholders.

Take innovators/creators.  We can imagine that there is an optimum standard of copyright law that will encourage innovators to maximise their creative/inventive activity. As strength of copyright increases from nothing the economic incentive to create becomes greater.  But there will be a point at which the incentive decreases since it gets so strong that it prevents creators building on the work of earlier creators. Copyright in the UK and many other jurisdictions lasts now for the life of the author plus 70 years. So creative artists are theoretically precluded from using most of 20th century culture, as the basis or inspiration for their work.

We can also imagine that the public might prefer copyright to be weaker to enable them to access more creative work at cheaper prices.

Similarly the economic agents – agents, music, film, software, media companies and publishers – that get creative work from the creators to market might prefer stronger copyright laws.

In theory we could tweak copyright law to balance the interests of all three sets of stakeholders. We could measure the effects, feed that evidence back into the policymaking process and ultimately evolve an informed, evidence based set of copyright laws.  Choice of the optimum level won’t be ideal for all the stakeholders but it should be possible to agree a compromise to balance the interests of all three.

That’s not the way it worked with the DEA. There was no evidence just effective lobbying by the large entertainment industries.  The big winners with the DEA are some agents – a select few large music labels and movie companies who hold the copyright on commercially valuable works – and some creators – mostly the tiny percentage of global superstars who earn large sums from royalties.

The losers with the DEA was everybody else – the public, other creators and other economic agents, in particular the ISPs who have to engage in very costly technology investment and operational processes to police copyright on the Net.

The other big loser was trust.  It is not good business practice to threaten, throttle or block the internet connections of your customers.

CDB

The second regulatory vehicle I’d like to look at briefly is the Communications Data Bill. Section 1 of the Bill essentially gives the Secretary of State and her successors a blank cheque and they get to order anyone to do anything that can be related to facilitating access to communications data. Yes she gets carte blanche to order tracking, monitoring, surveillance, watching, interception, collection and use of any data she likes about everybody, however and whenever she feels like it with essentially no meaningful oversight or accountability. 

S9 of the Bill relates to the authorisations for obtaining data by police and other public authorities.

The government has the right to intercept and record information when someone is suspected of a serious crime. They have the right to engage targeted intelligence led surveillance on anybody. They should not have the right to engage in monitoring everyone.  But these proposals mean collection of data without suspicion or oversight: which is in effect uncontrolled mass surveillance. Due process requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To instigate the new set of legal norms envisaged in the Communications Data Bill which subsequently give the entire population less protection than a hitherto genuine suspected criminal is indefensible. The gathering of mass data to facilitate future unspecified fishing expeditions is also unlawful.

There is a significant danger in measures like the CDB of stumbling by default into a police state, just because the technology of mass surveillance is now more readily available and nominally more sophisticated. We need to avoid deploying these technologies blindly in response to some perceived threat. Without sufficient reasoned analysis of the purpose and detailed requirements of the technical systems we propose to build to counter these threats, we could find ourselves building technological monsters. Building an infrastructure of surveillance makes our three sets of stakeholders – innovators/creators, economic agents and the public – more vulnerable not less so to attacks by criminal elements such as the four horsemen of the infocalypse and rogue states with malevolent intent.

ISPs will evolve from the copyright police of the DEA to surveillance agents of the state under the CDB and that kind of mass surveillance is no way to engender trust. It also doesn’t work as any of the economists in the room with an understanding of Bayes theorem and the base rate fallacy will tell you.[7]

Under the CDB the only winners are the suppliers of the technology of surveillance. All other stakeholders lose and the damage to trust is potentially irreparable, in spite of the public being hugely forgiving of mass data collection.

We get bad laws when governments don’t understand technology

It’s a caricature but governments generally have two simplistic perspectives on technology:

  1. It is a magic solution to ill defined political problems that can be easily presented to the rabid 24 hour news media
  2. It is a terrifying tool that is used by the four horsemen of the infocalypse for nefarious ends, therefore requiring blanket surveillance.

The internet they see as TV on steroids or an online shopping centre best controlled by the entertainment industry.

This ignorance is bad for our three sets of stakeholders

    • Innovators/creators
    • Agents
    • Public
The laws this ignorance fosters, such as the DEA and CDB, undermine trust. And they undermine it in ways that are at best difficult or almost impossible to remedy. Mandating and building technological architectures of surveillance is bad for everyone but the agents who monetise and control those technologies.

Conclusion

The innovators and the public are hugely forgiving of or blind to economic agents’ (both commerce and government) data gathering.

That gives the powerful agents – commercial and government – substantial responsibility. Data pollution is the environmental disaster of the digital age and it is going to play havoc with trust in the digital economy.

For commercial agents delivering secure convenient products and services at a reasonable price, not suing the competition based on dodgy law, is the key to success.

For governments, can I recommend Professor Chris Reed’s doctrine of creative inertia when it comes to making laws about the internet, especially in relation to mandating architecture of surveillance? Mainly, don’t. And if you must, take the time, the care and the considerable cognitive effort that is required to find out what it is you’re dealing with first.

In relation to trust in the digital economy where have we got to?

Firstly we should understand, as my friend John Naughton says, that the internet is a global machine for springing surprises.

So:
  • Innovators need to engage with it
  • Governments need to apply creative inertia principle to regulating, especially with respect to surveillance architectures. They also need make a better effort to understand it (and those subsets of stakeholders who do understand it need to get better at explaining it to them)
  • Commercial agents, particularly those making hay from bad regulations e.g. entertainment companies and surveillance technology companies, need to understand that unfettered data pollution will come back to bite all three sets of stakeholders
  • And citizen consumers need to get educated, engaged and active

That’s it and if you have been, thanks for listening.
 

*Transcript of the talk as written rather than as delivered.  I spent a little longer on the DEA than I intended and didn't cover the CDB other than in outline

[1] Following some interesting experiences at Heathrow airport yesterday I was tempted to change my talk to outline how lack of trust nearly led to me not making it here at all but that’s a story for another day.  See http://b2fxxx.blogspot.co.uk/2012/09/the-chief-immigration-officer-and-me-or.html for the details.
[2] How copyright enforcement robots killed the Hugo Awards http://io9.com/5940036/how-copyright-enforcement-robots-killed-the-hugo-awards.
[3]See Don’t blame the copyright bots, says CEO of copyright bot company http://www.slate.com/blogs/future_tense/2012/09/07/vobile_ceo_yangbin_wang_copyright_bots_didn_t_kill_ustream_s_hugo_awards.html
[7] See Rudmin, Floyd (2006) ‘The Politics of Paranoia and Intimidation: Why does the NSA engage in mass surveillance of Americans when it is statistically impossible for such spying to detect terrorists?’ http://www.counterpunch.org/rudmin05242006.html for a lovely succinct illustration of this.

Saturday, September 08, 2012

The chief immigration officer and me...

...or how I briefly became the Mehran Karimi Nasseri of Heathrow

I’ve been in Aberdeen for a conference on trust in the digital economy.

Funny enough I nearly didn’t make it and by the time I got there was very tempted to change my talk to outline why.

It all started with the booking of a BA/Bmi flight to Aberdeen via the internet.

Everything was fine with the booking. The confirmation email came through. I printed the itinerary and ignored the small print since I’ve done this so many times before. That was my first mistake.

Before logging off I did a quick check with the neat little “Which terminal” search gadget on the Heathrow website.

That was my second mistake.

You see I trusted the answer I got.

Heathrow flights to Aberdeen, it said, go from Terminal 1. (Though, interestingly enough I just did the search again and it says BA flights to Aberdeen go from terminals 1 and 5 and Bmi flights go from terminal 1). A glimpse at the final page of the confirmation email confirms the flight back from Aberdeen on the Thursday lands at terminal 1. My misplaced trust is re-inforced.

Ok off I go to the Heathrow parking site and book my parking for the 36 hours or so I’ll be away. Extortionate. But will I pay the extra £6 to park in the business class carpark and get back to my car 15 to 20 minutes earlier upon return. Hang it, it’s £6, so yes. Been working long hours and the extra 20 minutes at home won’t do me any harm. All done.

24 hours before departure I get the email that tells me I can now check in online. I click the link, go through the steps and print the boarding pass. No need to check that. I’ve seen too many of them. Mistake number 3.

Morning of departure I hear on the radio that there’s been a vehicular collision between junctions 4 and 3 of the M4. Balderdash that’s Heathrow. I’ll have to set out earlier than I intended. Luckily by the time I decided I have to set out the accident and the road have cleared so I get an extra hour’s grace.

Finding the car park at Heathrow is the usual exercise in multiple road junctions and signage overload but I make it without incident. And things are looking up – the bus driver is just on his way out of the car park when he spots me, stops at the exit and hails me over. What a decent chap. Fortunately I was to encounter a number of decent and caring people in the next few hours.

Off the bus and into terminal which has changed since I was last here and I head straight for security with my boarding card. Just as I reach security I realise I’ve left my passport at home. That was mistake number 4. Ridiculously it is a good idea to always have your passport with you even on domestic flights. Anyway I explain to the security guy I’m only going to Aberdeen and wonder if it will be ok if I don’t have my passport.

“Dinnaw may. We’s just sehcurihy. Check wi the BA desk”

No problem. Sensible suggestion. So I head for the nearest BA desk where a helpful chap assures me I don’t need a passport to fly from Heathrow to Aberdeen. Back I go to departures initial security check desks where my first encounter is busily checking someone’s boarding card so I go to his colleague. She scans my home printed boarding card and gets the ok from the system and waves me through.

Head for the x-ray machines. Laptop out. Jacket off. Belt and watch. They also want my kindle out of the bag, so out it comes. Hang onto trousers since I’ve lost a couple of inches round the waist with the help of the bike. No beep from the scanner as I walk through so I get away without a pat down.

Belt back on, I can stop hanging onto my trousers. Get all the gear back in the bag and I’m set for the waiting lounge. Check the screens for my flight. That’s strange. It’s not there. There is a BA flight at 14.30 but not 14.10. Need the gents then I’ll consult security.

Back to the vicinity of the x-ray machines and there is a group of security people here chatting. I explain my flight isn’t on the board and I’m puzzled. None of them are too concerned as they assure me Aberdeen flights go from terminal 1. Then star number 1 of the show appears. She’s called into the conversation and genuinely takes me under her wing. “Don’t worry. It’s really confusing. BA and Bmi have been changing the numbers of their flights and the same flight changes sometimes on the screens. Let’s go and look and I’ll show you.”

No one has any doubt but that I’m at the correct terminal. We get back to the screens, spot the 14.30 BA flight again and my guardian angel of terminal 1 explains I need to watch flight details they will change back and forth between the number on the screen and my flight number.

We wait. No change. She’s puzzled. Never mind it’s just a system problem. All the Aberdeen flights go from gate 8 so just head down there when the time comes. Thanks a lot for your help. I’m partly but not entirely re-assured. At this point I decide to check my flight itinerary. Sure enough in the small print near the end it says I’m flying out of terminal 5. Terminal 5! How the heck do I get there from here in time?

Back to x-ray machine area where guardian angel has not wandered too far and explain my itinerary and my boarding pass (which I now decided to glance at too) both say terminal 5. Uh oh. Guardian angel says don’t worry. Let’s go see the suited security guys and get a definitive answer off the system.

“Can you check this flight number for me? The gentleman is flying to Aberdeen but his boarding pass says terminal 5. Couple of phone calls. Check the system. Yup I’m going out from terminal 5. Now what? Can I make it on time?

Guardian angel: “ don’t worry you have plenty of time. Just head down towards the gates and follow the flight connections signs which will lead you to a bus that will take you straight to terminal 5. You’ll be there in 10 minutes.” From start to finish this lady was terrific. She saw a passenger with a non-standard problem and helpfully took it upon herself to sort it out. Kudos to her.

I make my way via the air side bus to terminal 5. Here’s where the problems really begin. I get directed through a BA desk but beyond that is Border Control. Now I know there are difficulties ahead.

I explain to the very kind BA desk staffer that I haven’t got my passport, erroneously started out at terminal 1 and got sent over here via the bus. The very agreeable woman scans my boarding pass, says she doesn’t need my passport and I should be ok as long as “they”, gesturing to Border Control let me though; but by the way they have changed my seat number from 32A to 22D. She doesn’t know why. Possibly because the Airbus 319 only has 22 rows of seats. So I’m a little unsure why I might have been put in row 32 in the first place. She prints me a new boarding pass, wishes me a pleasant flight and waves me through.

I know this isn’t going to work. The queues are long. The border staff are under pressure. I get to the head of the queue and explain to my border control guard that I haven’t got my passport for reasons outlined earlier.

“Sir how did you even get here? You shouldn’t be airside at all.” I explain again. He’s very courteous but explains he cannot let me through border control without a passport. He’s thinking on his feet though about how to help. “Sir what nationality are you?” Though I can tell he’s already pegged my accent, I explain I’m Irish. “I’m sorry sir. If you’d have been British and held a British passport I could have called your details up on the computer in a few minutes and checked you out.” He’ll have to consult his boss, the chief immigration officer. But for the moment I’ll have to wait until the queues clear.

Fair enough.

I wait. The queues are shortening. They clear. My border guard (there were 4 on duty) goes off to talk to management. He walks with the aid of a stick so I feel doubly guilty for making his life difficult.

I do get the opportunity while waiting to watch border control in action. They are efficient and courteous. I don’t like the quizzing of ethnic minority small children to check the woman they are with is their mother. Don’t get me wrong. It’s done in a friendly way. Big smile. “Hello what’s your name? Where’s your mum?” And checking to see if the chid indicates the woman. They are doing their job.

My guard gets back and says he cannot process me though border control without officially approved identification documents. I have credit cards but the only photo ID I have is an Oxford University library card. He might be able to do something with a driving licence but even that is not officially approved. “But the chief immigration officer will arrange to have a security person escort you to your flight though a different route. The chief immigration officer is arranging that for you now sir. “

Thanks. I really appreciate your help. I still don’t fully appreciate, yet, the Mehran Karimi Nasseri (or Tom Hanks in 'The Terminal') nature of my situation. But everyone is being as helpful as they can given the circumstances and even if I don’t get to fly (my flight time is creeping up fast) I’ll at least get a blog post on airport security out of this. How did a passenger get to border control for a domestic flight and what went wrong to get him there?

I tell the officer that ironically I’m going to Aberdeen to give a talk about trust. Not a flicker of amusement. Border control is a serious business.

Guardian angel number 2, a security lady called Kat, appears. She’s is just brilliant. The border control man who I’ve also got to like a lot by now explains my predicament to Kat. He also notes I’m a security, airline and port authority problem not a border control problem. Kat thinks and says no worries she has an idea of how to get me to the right gate for the flight. Off we go following thanks to my professional border man.

Cognisant of the imminent scheduled departure of my flight Kat moves quickly and talks to a colleague (boss?) on her walkie talkie. She explains my situation and how she is going to deal with it. She just needs his (it is a male, I can hear his responses) ok to pass through a security gate.

He says no. No way. Not a chance. I’m border control’s problem. Get them to let me through.

Right. We stop. U-turn.

Back to my friend at Border Control. Fortunately the queues aren’t too bad and we indicate we’ll wait to the lady who is free until my friend deals with his last current passenger. He gives us a weary glance. And explains again I’m not getting through there. But he’s not giving up on me.

He and my wonderful security Kat agree I’m a security failure in terminal 1. He also points out again that though he’s not letting me through I’m an airline and port authority problem and if both agree I can get on my flight then they should be able to get me physically there via a different route to border control. Let’s go consult the airline.

We go to the BA desks just ahead of border control. The woman who had printed my new boarding pass is no longer there. The one member of BA staff who is there is actively disinterested, glances repeatedly at me as though I might be something nasty she just stepped in and makes it abundantly clear she doesn’t want to get involved. The first unhelpful person I’ve encountered today. Remarkable how I could have achieved such pariah status in the eyes of someone I have barely met properly or even spoken to.

So Kat, Border man and I head for the BA desks behind which are offices in which the duty officer resides. We explain my story to the man at the desk and though he’s not sure what to do he’s helpful and quickly summons the duty officer, another star of the day.

My flight departure time has by now come and gone. The duty officer is great. Guardian Kat and Border man explain the situation and border man explains the rules. The duty officer grins cheerily and tells me I’m a first. Nice to know I’ve brightened someone’s day and regained membership of humanity after the unfortunate attitude of the previous BA woman. The duty officer has a think and meanwhile the border man explains (he has noted it a couple of times before) that I really am a Tom Hanks. No documents, so I can’t get through Border Control either to get on my flight or get out of the airport. An undocumented alien who should not be where I am right now.

“I really am Tom Hanks!” I’m still thinking this is going to make a great story. He also notes the titles of a couple of border control statutes which might be applied under one of which exists a power to search me for drugs. But since he’s getting to know me now, he almost smiles and says he’s not going to search me for drugs, as he has absolutely no reason to be suspicious on that account. I risk “I think I need a couple of paracetamol for a headache.”

Duty officer has a solution. Pretty much the solution that guardian Kat has previously come up with. Border man says cheerio and good luck and shakes my hand. I thank him sincerely and say goodbye to another star.

Luckily for me, though my flight has long since gone, I believe, duty manager discovers it’s been delayed and I still have a shot at making it. Though they’ll book me on a later flight if not. Guardian Kat, duty manager and I take off again. We get to a BA desk near – to the side of border control. The lady there wants to check my documents etc. Duty star sorts that out and waves me and Guardian Kat on our way. My final encounter with star number 3.

Kat and I are moving quickly again. Dodging crowds and queues we get to another set of security and X-ray machines. Kat gets me and my bag to the front of the queue and she and I traverse security again. She has to put her walkie talkie etc through the machine too. We take off again at an increased pace once I’m belted up and repacked again. Kat and duty manager have let the airline and port staff at the gate know I’m on the way and we learn that the flight is just boarding.

I make it in time to be the penultimate passenger on the plane. I thank Kat yet again for all her help. She’s been an absolute diamond and deserves a commendation for going above and beyond the call of duty.

And that’s the bottom line. When we make mistakes and there are system failures we need caring dedicated people to fix things.

If everyone had taken the attitude that they were just following the rules, or worse the attitude of the BA woman who apparently found me to be unforgivably distasteful, then I might still be stuck at Heathrow.  As it was I encountered 4 stars – security guardian at terminal 1, professional border man at terminal 5, my guardian security Kat and the BA duty officer, who all cared enough and actively made it their business to help out a traveler with problems.The decent car park bus driver must also get an honorary mention along with this band of heroes - he didn't have to stop for me on his way out of the car park but he did. He put me in a good mood and that undoubtedly helped with the perils ahead. It might have been him that made all the difference.

I realised in the final dash for the plane that I didn’t know any of their names and that’s when I asked and discovered my guardian angel was called Kat. So thank you again bus driver, security Kat, Ms Terminal 1, border man and BA duty officer. Apologies for not getting to know your names but thanks for your care, your energy and your unfailing courteousness in getting me to my planned destination and for making what could have been a difficult experience extraordinarily stress free.

I hadn’t planned, on getting up on that Wednesday morning to make anyone's lives difficult and certainly not the lives of such helpful people.

Postscript

The return leg from Aberdeen was a little smoother. Roll up to the airport on the bus. Check in at the self service check in. Print my boarding pass there. Through security to the departure lounge. The 54 seat Embraer aircraft I flew back on is a neat little machine and London is spectacular from the air at night.

I got a brief but beautiful bird's eye view of the Olympic stadium at just about the time Jonnie Peacock was winning the T43/T43 100m final at the Paralympics. The bonus was also that my flight landed at Terminal 1. No complicated Heathrow business this time. Straight out onto the car park bus and I'm on my way home. I had to do a 25 mile detour due to a road closure and an idiot in a BMW who tried to kill me, him and everyone around us on the M4. But that's a story for another day.