Monday, April 18, 2005

Irish ISPs refuse to disclose users' identities

Fergus Cassidy points out that at least two Irish ISPs (Eircom.net and BT Ireland) have said that they will not disclose user details to IRMA without a court order. More details in the Irish Times (April 16 2005 - subscription only):
Eircom and BT Ireland confirmed yesterday that this customer data was protected under the Data Protection Act and they would not be giving the names to Irma. "We can't reveal names of customers to them because of data protection laws. But if there is a criminal inquiry, we can deal with gardai, but only the gardai," said a BT Ireland spokeswoman.

Irma will now have to seek injunctions from the High Court to compel the service providers to supply the information they need to prosecute. It said it is confident that the courts will force firms to supply the data. However, legal experts warned that there is no such guarantee.

"Internet firms are justified in not voluntarily disclosing such detail. It is then up to the music companies to show in court that they have sufficient evidence that particular individuals have been illegally distributing music files," said solicitor Paul Lambert.

US ISP sued for disclosing customer info

From CNET News.com
Comcast, the top U.S. cable TV network operator, is being sued by a Seattle-area woman for disclosing her name and contact information, court records showed Thursday.

In a lawsuit filed in King County, Wash., Dawnell Leadbetter said that she was contacted by a debt collection agency in January and told to pay a $4,500 for downloading copyright-protected music or face a lawsuit for hundreds of thousands of dollars.

Leadbetter, a mother of two teenage children, was a customer of Comcast's high-speed Internet access service.

The company, Settlement Support Center, based in Washington state, was using information that the Recording Industry of Association of America had obtained in a Philadelphia lawsuit over the illegal sharing of digital music files, said Lory Lybeck, the lawyer representing Leadbetter.

But no court authorized Comcast to release names and addresses of its customers, or notified his client that her information had been given to an outside party, Lybeck said.

Wednesday, April 13, 2005

Online Anonymity - Ryanair Edition

From the Guardian:
Pilots' leaders have accused Ryanair of an extraordinary attack on free speech in a high court battle over a website that contains anonymous criticisms of the airline by some of its employees.

The Irish low-cost carrier is trying to unmask the identity of pilots responsible for controversial remarks about its working practices on a message board run jointly by the British and Irish pilots' unions. Ryanair has drawn first blood by securing an injunction from a Dublin judge that bans the unions from destroying the codenames used by pilots on the Ryanair European Pilots' Association's website.

Jim McAuslan, general secretary of the British Airline Pilots' Association (Balpa), said: "We shall vigorously defend our position in refusing to divulge names of pilots who discuss with one another their problems and aspirations."

...

Union leaders say confidentiality is crucial in the aviation industry. They point out that pilots use online forums to report safety concerns. If anonymity is jeopardised concerns may never be aired.
Ryanair hasn't been shy about using the law to shut down sites which show it in a bad light. In this case, though, the site isn't public - access is limited to Ryanair pilots who register and are given a password.

The implication is that the real aim behind this litigation is to silence discussion of Ryanair's practices and to intimidate pilots who are afraid to speak under their own names. If so, that would be an improper use of the court process. The case raises some fundamental issues regarding freedom of speech and a full hearing in the High Court could be very interesting.

Tuesday, April 12, 2005

IRMA follows through on its threats

From RTE news - IRMA taking cases against internet piracy:
"The Irish Recorded Music Association has said it is pursuing cases against 17 people for illegally uploading music onto the internet."
It will be interesting to see how Irish ISPs respond to demands that they identify subscribers alleged to have shared music - in particular whether they make voluntary disclosure of this information.

Update - it's now clear that IRMA have yet to commence litigation. They've now requested that ISPs identify the users from their IP address and filesharing usernames. ISPs might or might not be able to do this voluntarily - but for the reasons I discussed here they should refuse voluntary disclosure and insist on a court order. Users should be wary of any ISP that's willing to hand over their personal information based on the mere accusation of a private body with no official standing. Irish ISPs should take a lead from their English counterparts' refusal of voluntary disclosure in the Motley Fool and later the BPI filesharing litigation.

Monday, February 07, 2005

Filesharing litigation one step closer in Ireland

Eircom.net has a very interesting interview with Dick Doyle, head of the Irish Recorded Music Association (Irma), who confirms that litigation against Irish filesharers is on its way:
After a lengthy educational and information campaign, the gloves are off. Irma's coming to get you. "We couldn't do anything until there was a legal alternative like iTunes," admits [Dick Doyle]. The organisation has retained a top US internet spy firm to monitor Irish traffic downloading 100 selected tracks.

"It's a mixture of chart music, rap music, Irish content such as the Corrs and U2 and also local Irish artists whose fan base will be in Ireland," confirms Doyle. Since mid-December, this unnamed US firm has been gathering information about Irish computers downloading these songs illegally.

"I'd say we'd probably get the first inkling of what's happening by the end of the first quarter," says Doyle of potential illegal download litigation against Irish people. "I'll have to take it to the [Irma] board but if they say go for it, something could certainly happen by the summer."

In the US about 7,000 people are being sued by the record industry for illegal downloading, with a further 500 or so in Europe. Just 12 individuals are facing litigation in the UK. "We were surprised the UK was so low but I can't see us going lower than that."

Doyle is clearly gung-ho about the prospect of litigation:

The worldwide lawsuits grabbed public attention when it emerged that a 12-year-old honours student girl in New York was one of those being sued by the industry. Boo hoo, says Doyle detailing the girl's offences, which included sharing over 1,000 songs. She settled the case for $2,000.

"The best thing about that 12-year-old being sued was that it became headline news in the Washington Post and the Los Angeles Times. They [the music industry] had been trying for a year-and-a-half to get attention and couldn't even get a headline and then this happened."

via ethos.org


Thursday, December 02, 2004

Australia rejects Internet filtering?

From NEWS.com.au:

THE Federal Government had rejected mandatory filtering of the internet to stop child pornography, Parliament was told today.

Communications Minister Helen Coonan said the government had recently reviewed ways of preventing child pornography, including a British-style national internet filtering system but rejected it.

Senator Coonan said the study had found such a filter would cost around $45 million a year initially and $33 million a year in later years.

She said it also had the potential to choke the internet and drive up costs for consumers and small business.

"The biggest issue is not so much the money but such an expensive scheme would not necessarily solve the problem and small to medium ISPs (internet service providers) would be driven out of business for little or no benefit," Senator Coonan said. "What does work is greater information and parental supervision and that is the kind of program that the government is promoting."


This decision rejects a well organised campaign, led by the Australia Institute, pushing for mandatory filtering. It still, however, leaves Australia with one of the most restrictive Internet censorship regimes to be found in a democracy. Electronic Frontiers Australia has comments on the filtering proposals, and an overview of the Australian Internet censorship system.

Friday, November 26, 2004

ISP resorts to denial of service attacks on spammers

From The Register:

"Lycos Europe has started to distribute a special screensaver in a controversial bid to battle spam. The program - titled Make Love Not Spam, and available for Windows and the Mac OS - sends a request to view a spam source site. When a large number of screensavers send their requests at the same time the spam web page becomes overloaded and slow.

The servers targeted by the screensaver have been manually selected from various sources, including Spamcop, and verified to be spam advertising sites, Lycos claims. Several tests are performed to make sure that no server stops working. Flooding a server with requests so that the server is unable to respond to the volume of requests made - a process known as a distributed denial of service (DDoS) attack - is considered to be illegal.

Lycos believes the program will eventually hurt spammers. 'Spamvirtised' sites typically don't sell advertising, so they have to pay for bandwidth. Therefore more requests means higher bills, Lycos argues."
This is an interesting twist on the usual denial of service attack. Is Lycos exposing itself (and potentially the users of the screensavers) to criminal liability? In Ireland and the UK the answer would most likely be no - as I argue in this article on computer crime, current law fails to address this sort of attack, which falls outside the unauthorised access offences and the damage offences. However, Lycos might well be in trouble if it targets US based spammers - see Jeff Nemerofksy's piece on "Interruption of Computer Services to Authorised Users".

Before you ask: Lycos isn't necessarily shielding itself from liability by "making sure that no server stops working". Some jurisdictions do seem to require an attack which brings down a server, but equally some of the US laws mentioned in that article criminalise the degradation of service as well as an outright denial of service.

Friday, November 12, 2004

Anonymity and the Internet

Internet use is seldom truly anonymous. In most cases, ISPs keep records which will link users with their online activities. Consequently, litigants or potential litigants often approach ISPs looking for disclosure of users' identities. The most high profile examples have been in the music industry's file sharing cases, which are now set to come to Ireland.

May ISPs voluntarily disclose this information? Must they notify their users before doing so? Can litigants obtain a court order compelling an ISP to reveal the identity of a user? On what terms? I discuss the legal issues involved in this article, which originally appeared in the Commercial Law Practitioner.

Since that article was written, there has been a decision on this point in England, where Blackburne J. issued an order compelling disclosure. The full decision isn't yet available - but it appears from the news coverage that he didn't consider giving the alleged file-sharers an opportunity to make submissions before their identity was revealed. This is unfortunate. At a minimum, it ignores earlier English authority suggesting that users should be notified and given a chance to challenge any order.