I'm quoted in today's Irish Times on the threats made by JC Decaux against Fusio resulting in their taking down their Dublin Bikes App.
Leave aside for a moment the PR stupidity of this strategy.
Ignore if you will the dubious legal basis of their claim. (Without going into the finer points of copyright in facts, database rights, clickwrap agreements or possible passing off, the vague nature of their complaint - "Following our conversion, I confirm that you do not have the rights to use the information published on the web site http://www.dublinbikes.ie/. In particular the data concerning the stations is the property of JCDecaux and cannot be used without our prior authorisation" - makes it clear that they have little idea what they are talking about.)
Think instead about the issue of principle. A body which is operating in partnership with Dublin City Council is attempting to stop an Irish company from providing - free of charge - facts to the public about the service which they offer, without giving any justification for doing so, and without offering an alternative of their own. (I'm happy to see that at least some of our politicians understand the absurdity of this.)
I spoke to the press office in Dublin City Council today, who made it clear that they regard this matter as nothing to do with them. But why not? DCC were happy to work with Fusio to develop the app. Is there no provision in their contract with JCD establishing an obligation to provide information to the public about the service? Will they make sure that future contracts address this type of situation? (And - while I'm on the topic of the contract - why does JCD own the domain dublinbikes.ie? Is there any provision in the contract for the domain to revert to DCC on its expiry?)
Friday, September 25, 2009
Tuesday, September 15, 2009
Ryanair screen scraping: New litigation
I've blogged before about Ryanair's case against Travelfusion and Bravofly in respect of screen scraping. According to RTE News, this case has now been joined by a fresh set of proceedings in the High Court by Ryanair against Ticketpoint, Reisebuero and Billigfluege, alleging that they are using screen scraping to resell Ryanair tickets at higher prices.
According to the news report, Ryanair is complaining that the three companies are "applying a service charge and credit card charges to the prices". I wonder who they got that idea from?
According to the news report, Ryanair is complaining that the three companies are "applying a service charge and credit card charges to the prices". I wonder who they got that idea from?
Thursday, September 03, 2009
Lori Drew decision published - Breach of terms of use as a criminal offence
When Lori Drew was prosecuted for bullying via MySpace which led to the suicide of Megan Meier many people were worried about the prosecution theory of the case. The basis of the charge was not the bullying itself but rather that by failing to comply with MySpace's terms of use Lori Drew had committed an offence of unauthorised access to a computer. If accepted, this theory would have criminalised failure to abide by terms of use - terms which most users never read and which are often vague and imprecise in their scope - and effectively permitted site owners to provide that a breach of their rules would now be a crime. As Andy Grossman put it, the effect would be that "every site on the Internet gets to define the criminal law. That’s a radical change. What used to be small-stakes contracts become high-stakes criminal prohibitions."
Consequently there was some relief two months ago when the trial judge indicated that he would quash the jury's guilty verdict, but his short oral statement of reasons on that day didn't go into detail as to why the prosecution case was flawed. The full written judgment has now been published, and shows that the trial judge applied the void for vagueness doctrine to find that a prosecution based on simple breach of terms of use would not give fair warning to users as to what actions might be criminal and would criminalise vast numbers of users without providing even minimal guidelines to govern prosecutions.
Would a similar result be reached in Ireland? The position is complicated slightly by the peculiar wording of the relevant offence - which speaks of "access without lawful excuse" rather than "unauthorised access" - but the same underlying principles would apply. The domestic caselaw - in particular King v Attorney General [1981] IR 223 - has established the proposition that the ingredients of an offence must be set out with precision and clarity and this has since been reinforced by ECHR jurisprudence requiring accessibility and foreseeability in criminal offences (e.g. CR v. United Kingdom). In light of those principles, it seems likely that the Irish courts would follow the reasoning in the Lori Drew case.
Some key portions of that ruling are worth quoting:
Consequently there was some relief two months ago when the trial judge indicated that he would quash the jury's guilty verdict, but his short oral statement of reasons on that day didn't go into detail as to why the prosecution case was flawed. The full written judgment has now been published, and shows that the trial judge applied the void for vagueness doctrine to find that a prosecution based on simple breach of terms of use would not give fair warning to users as to what actions might be criminal and would criminalise vast numbers of users without providing even minimal guidelines to govern prosecutions.
Would a similar result be reached in Ireland? The position is complicated slightly by the peculiar wording of the relevant offence - which speaks of "access without lawful excuse" rather than "unauthorised access" - but the same underlying principles would apply. The domestic caselaw - in particular King v Attorney General [1981] IR 223 - has established the proposition that the ingredients of an offence must be set out with precision and clarity and this has since been reinforced by ECHR jurisprudence requiring accessibility and foreseeability in criminal offences (e.g. CR v. United Kingdom). In light of those principles, it seems likely that the Irish courts would follow the reasoning in the Lori Drew case.
Some key portions of that ruling are worth quoting:
If a website’s terms of service controls what is “authorized” and what is “exceeding authorization” - which in turn governs whether an individual’s accessing information or services on the website is criminal or not, section 1030(a)(2)(C) would be unacceptably vague because it is unclear whether any or all violations of terms of service will render the access unauthorized, or whether only certain ones will.
For example, in the present case, MySpace’s terms of service prohibits a member from engaging in a multitude of activities on the website, including such conduct as “criminal or tortious activity,” “gambling,” “advertising to . . . any Member to buy or sell any products,” “transmit[ting] any chain letters,” “covering or obscuring the banner advertisements on your personal profile page,” “disclosing your password to any third party,” etc... The MSTOS does not specify which precise terms of service, when breached, will result in a termination of MySpace’s authorization for the visitor/member to access the website.
By utilizing violations of the terms of service as the basis for the... crime, that approach makes the website owner - in essence - the party who ultimately defines the criminal conduct. This will lead to further vagueness problems. The owner’s description of a term of service might itself be so vague as to make the visitor or member reasonably unsure of what the term of service covers. For example, the MSTOS prohibits members from posting in “band and filmmaker profiles . . . sexually suggestive imagery or any other unfair . . . [c]ontent intended to draw traffic to the profile.”
Moreover, website owners can establish terms where either the scope or the application of the provision are to be decided by them ad hoc and/or pursuant to undelineated standards. For example, the MSTOS provides that what constitutes “prohibited content” on the website is determined “in the sole discretion of MySpace.com . . . .” Additionally, terms of service may allow the website owner to unilaterally amend and/or add to the terms with minimal notice to users.
Because terms of service are essentially a contractual means for setting the scope of authorized access, a level of indefiniteness arises from the necessary application of contract law in general and/or other contractual requirements within the applicable terms of service to any criminal prosecution.
Treating a violation of a website’s terms of service, without more, to be sufficient to constitute “intentionally access[ing] a computer without authorization or exceed[ing] authorized access” would result in transforming section 1030(a)(2)(C) into an overwhelmingly overbroad enactment that would convert a multitude of otherwise innocent Internet users into ... criminals... If any conscious breach of a website’s terms of service is held to be sufficient by itself to constitute intentionally accessing a computer without authorization or in excess of authorization, the result will be that section 1030(a)(2)(C) becomes a law “that affords too much discretion to the police and too little notice to citizens who wish to use the [Internet].”Eric Goldman has analysis of the decision and its implications for legal responses to cyberbullying - suggesting that the decision is likely to encourage lawmakers to introduce new offences of online harassment.
Monday, August 31, 2009
The Pirate Bay block takes effect
Today, September 1st, is the day that the Eircom is scheduled to start blocking The Pirate Bay. It will be interesting to see how it is implemented and whether there are any technical side effects (along the lines of the recent IWF / Wikipedia fiasco). If you're an Eircom customer, perhaps you might post a comment as to whether you can still access thepiratebay.org or the other URLs / IP addresses which are being blocked or whether you've noticed any other effects of the blocking.
Friday, August 28, 2009
Eircom, three strikes and false positives
Some of these cases will be due to Eircom's own incompetence in issuing up to 250,000 wireless routers with easily guessable passwords - which will result in some people piggybacking on Eircom users' connnections. But there is a wider problem, in that the investigators used by the music industry have a track record of making false copyright infringement claims.
A particularly interesting study from the University of Washington (Zeropaid story | Full details and paper) shows the risks.
In that study, the researchers document receiving 487 notices under the DMCA: all wrongfully alleging that files were being illegally shared over BitTorrent. Among the alleged culprits were three laserjet printers which between them were accused on nine separate occasions of downloading movies. (Bad printers! No toner for you tonight.)
The research conclusions?
Practically any Internet user can be framed for copyright infringement today.In light of these findings, I wonder how reliable the evidence presented by the music industry to Eircom will be, and whether the flaws identified in this study will be addressed. So far, all we have to go on are leaked details of a draft protocol between Eircom and the music industry on the information to be provided with each accusation.
By profiling copyright enforcement in the popular BitTorrent file sharing system, we were able to generate hundreds of real DMCA takedown notices for computers at the University of Washington that never downloaded nor shared any content whatsoever.
Further, we were able to remotely generate complaints for nonsense devices including several printers and a (non-NAT) wireless access point. Our results demonstrate several simple techniques that a malicious user could use to frame arbitrary network endpoints.
Even without being explicitly framed, innocent users may still receive complaints.
Because of the inconclusive techniques used to identify infringing BitTorrent users, users may receive DMCA complaints even if they have not been explicitly framed by a malicious user and even if they have never used P2P software!
Those details are, however, too vague at this stage to be useful.
For example, the draft apparently provides that "the information which will be provided by the record companies will be of the same type as that used in the three previous disclosure actions in the Irish High Court". What precisely does this mean? Similarly, the protocol appears to require the music industry to provide "the digital fingerprint/hash for copyright material detected". Does this mean that before a complaint can be made, the investigators must download the entire file allegedly shared by the user? There is also apparently provision for "reputable annual independent certification that the necessary ... I.T. ... controls relating to the obtaining, generating and processing of data by Detecnet ... have been complied with". Will this require certification that the types of problems identified by the University of Washington and others have been solved? In fairness to Eircom, it does appear that it has made some efforts to include elements in the agreement which might meet some of these problems. But without more detail on the agreement it's impossible to be confident that innocent users (or printers!) will not be wrongly accused.
Tuesday, August 25, 2009
Technical aspects of The Pirate Bay blocking
Eircom's block of The Pirate Bay comes into force on September 1st. With that in mind it might be worth examining precisely what Eircom is obliged to do. The relevant portion of the court order (to which Eircom consented) is the following:
Whatever the reason, this highlights one problem with the order - there's no provision for the possibility that an IP address or domain name initially associated with TPB later comes to be associated with a different and innocent site. I'm told (by someone who should know) that this is unlikely at least in the short term in the case of TPB - but that's no excuse for an order which doesn't even consider this risk, much less provide for any safeguard.
Of course, the order doesn't specify the methods to be used by Eircom to "block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs". Any thoughts on what these might be and their possible pitfalls?
IT IS ORDEREDAstute readers might have guessed that the list of IP addresses would rapidly go out of date and checking today that seems to be the case. This might be related to the fact that earlier today TPB upped and moved servers in response to the Swedish authorities ordering their connectivity provider to disconnect them from the internet.
(1) Pursuant to Section 40(4) of the Copyright and Related Rights Act, 2000 that the Defendant do block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs listed in the Schedule attached hereto together with such other domain names IP addresses and URLs as may reasonably be notified as related domain names by the Plaintiffs to the Defendant from time to time...
Schedule
The Pirate Bay main site
Thepiratebay.org main site is hosted on a server with IP address 192.121.86.15
The Pirate Bay trackers
The Pirate Bay current tracker URL is:
http://tracker.thepiratebay.org:80/announce
udp://tracker.thepiratebay.org:80/announce
This URL resolves to the following IP addresses:
192.121.86.2
192.121.86.3
192.121.86.4
192.121.86.5
192.121.86.6
192.121.86.7
192.121.86.8
Domain names that re-direct to The Pirate Bay
Piratebay.net
Piratebay.org
Piratebay.se
Thepiratebay.com
Thepiratebay.net
Thepiratebay.nu
Thepiratebay.se
Pro-piracy.nl
Smais.org
Thepiratebay.org
Piratebay.no
The re-directs are all hosted on the main server with IP 192.121.86.15 (owned by The Pirate Bay)
The Pirate Bay .torrent files
The Pirate Bay .torrent files are hosted on IP 192.121.86.19 with (sub)domain
http://torrents.thepiratebay.org
Whatever the reason, this highlights one problem with the order - there's no provision for the possibility that an IP address or domain name initially associated with TPB later comes to be associated with a different and innocent site. I'm told (by someone who should know) that this is unlikely at least in the short term in the case of TPB - but that's no excuse for an order which doesn't even consider this risk, much less provide for any safeguard.
Of course, the order doesn't specify the methods to be used by Eircom to "block or otherwise disable access by its subscribers to the Website ThePirateBay.org and related domain names IP addresses and URLs". Any thoughts on what these might be and their possible pitfalls?
Friday, August 21, 2009
Computer forensics, proprietary methods and peer review
As I prepare my course materials for the new course in Digital Investigations and the Law I find myself revisiting cases which I intended to blog when they were initially decided but which never made it to the screen. Here's an interesting one from 2005 which discusses when a court will compel computer forensics experts to reveal their proprietary methods, and which raises some interesting questions about whether such methods are compatible with the general approach of the courts towards expert witnesses.
In Mulcahy v Avoca Capital Holdings [2005] IEHC 136 (full text not available but summarised here) the plaintiff was the subject of disciplinary procedures by his employer including allegations of "improper dealing with the e-mail inboxes of senior members of staff and ... improper dealing with the company's IT systems". He brought an action in the High Court seeking to stop the disciplinary process.
In order to deal with the allegations against him, the plaintiff sought to have his computer forensics experts examine certain computers belonging to the employer. Access was granted by the court, but a dispute arose as to whether the plaintiff's experts would be entitled to keep secret their proprietary methods for carrying out the examination.
Significantly, Clarke J. held that while a court would not unnecessarily require an expert to reveal confidential methods, by acting as an expert witness a person exposed their methodology to scrutiny in court and fair procedures demanded that the other party be able to assess and challenge that approach in appropriate cases.
The relevant passage is worth quoting in full as the judgment doesn't seem to be freely available online:
But perhaps the most interesting aspect of this case, as compared with the use of other expert witnesses such as doctors or engineers, is the tacit assumption that computer forensics experts will be using methods which are confidential to them or home-grown.
Perhaps in the relatively early years of computer forensics as a discipline this assumption might have been justified - though today it's beginning to look increasingly shaky with the move towards open source forensics tools as well as commercial products such as EnCase. Nevertheless it raises an interesting question - should the courts accept expert testimony when the underlying tools or methods have not been the subject of peer review to ensure their reliability?
Although the Irish courts have yet to adopt an approach similar to the US Daubert standard, there has been at least one recent judgment in which "expert" testimony has been rejected where it hasn't been shown to have a "properly established scientific provenance" or "the requisite degree of expert peer approval". (See DPP v. Michael Joseph Kelly (2008) in relation to the controversial CUSUM technique for determining the author of a document.) In light of this decision, one wonders how the Irish courts might evaluate the use of proprietary computer forensics tools today.
For more on this issue, Meyers and Rogers (2004) is a good starting point.
In Mulcahy v Avoca Capital Holdings [2005] IEHC 136 (full text not available but summarised here) the plaintiff was the subject of disciplinary procedures by his employer including allegations of "improper dealing with the e-mail inboxes of senior members of staff and ... improper dealing with the company's IT systems". He brought an action in the High Court seeking to stop the disciplinary process.
In order to deal with the allegations against him, the plaintiff sought to have his computer forensics experts examine certain computers belonging to the employer. Access was granted by the court, but a dispute arose as to whether the plaintiff's experts would be entitled to keep secret their proprietary methods for carrying out the examination.
Significantly, Clarke J. held that while a court would not unnecessarily require an expert to reveal confidential methods, by acting as an expert witness a person exposed their methodology to scrutiny in court and fair procedures demanded that the other party be able to assess and challenge that approach in appropriate cases.
The relevant passage is worth quoting in full as the judgment doesn't seem to be freely available online:
The final point I would like to comment on is the argument put forward in evidence on behalf of Grant Thornton [acting for the plaintiff], which amounted to a plea for the protection of their proprietary methods. A court must always, in circumstances such as this, be concerned not to expose experts to any unnecessary exposure of the benefits of their craft, as it were, but it does have to be said that a person who presents themselves as willing to act as an expert in proceedings necessarily exposes their methods to investigation in court. Just to put it at its mildest, if Grant Thornton and Ritz [acting for the defendant]were to give evidence in a trial which conflicted as to their findings, the only way the court could resolve that conflict would be by investigating their methods and forming a view as to which method is better. So it seems to me, as a matter of principle and a matter of practice in this case, an expert just cannot stand on ceremony in that way; by being available to give forensic evidence in proceedings and expert is potentially exposing his methods to detailed investigation. He cannot say, "I am going to give evidence but I am not going to tell people how I carried out my inquiries." While a court should not make any directions that would unnecessarily expose the skills of an expert, it nonetheless seems to me that there is a limit to the extent to which those methods can be protected and, therefore, on the facts of this case I would not place any significant weight on that concern on their part. (Emphasis added.)This decision is in one sense unsurprising: past decisions such as State (D&D) v. Groarke [1990] 1 IR 305 have shown a judicial willingness to look behind an expert's opinion to the procedure on which it is based.
But perhaps the most interesting aspect of this case, as compared with the use of other expert witnesses such as doctors or engineers, is the tacit assumption that computer forensics experts will be using methods which are confidential to them or home-grown.
Perhaps in the relatively early years of computer forensics as a discipline this assumption might have been justified - though today it's beginning to look increasingly shaky with the move towards open source forensics tools as well as commercial products such as EnCase. Nevertheless it raises an interesting question - should the courts accept expert testimony when the underlying tools or methods have not been the subject of peer review to ensure their reliability?
Although the Irish courts have yet to adopt an approach similar to the US Daubert standard, there has been at least one recent judgment in which "expert" testimony has been rejected where it hasn't been shown to have a "properly established scientific provenance" or "the requisite degree of expert peer approval". (See DPP v. Michael Joseph Kelly (2008) in relation to the controversial CUSUM technique for determining the author of a document.) In light of this decision, one wonders how the Irish courts might evaluate the use of proprietary computer forensics tools today.
For more on this issue, Meyers and Rogers (2004) is a good starting point.
Wednesday, August 19, 2009
Eircom to block the Pirate Bay from September; UPC not so keen
In the latest twist in the Irish filesharing wars, it's emerged today that Eircom will start blocking access to The Pirate Bay from the first of September, while UPC has rejected music industry demands that it do so also. (The Irish Times | RTE). So what's going on?
First - the Eircom situation. When Eircom settled the case brought against it by the music industry it agreed - in addition to implementing a three strikes system against its users - not to oppose any application to the court to block access to The Pirate Bay. The predictable result was that an unopposed application would be granted without any real judicial scrutiny - and this has now happened. On the 24th of July, on the consent of Eircom, Mr. Justice Charleton in the High Court granted an order requiring it to:
Despite this, however, the music industry appears to have been emboldened by the order, which takes us on to the UPC situation. It seems that the plaintiffs then wrote to UPC demanding that it also block The Pirate Bay, lest customers "migrate" from Eircom, and threatening immediate proceedings unless it blocked access also. UPC - which is already being sued by the music industry in separate proceedings essentially demanding it implement "three strikes" - has rejected this demand, and indicated that it will vigorously defend any additional action also.
The current state of play raises some interesting questions. For example: Will users begin to migrate from Eircom? Is it appropriate for a court - even on consent - to make an order which will have the effect of blocking user access to a great deal of legitimate content? (While the percentage of legal torrents on The Pirate Bay might be contested, there's no doubt but that it indexes a great deal of legitimate content.) Should such an order allow plaintiffs to (apparently unilaterally) determine which sites are "related" and require those to be blocked also? Why have Eircom been so shy about revealing the existence of the blocking? Expect these, and other issues to come to the fore over the next few days.
Adrian Weckler has more, including the UPC press release.
First - the Eircom situation. When Eircom settled the case brought against it by the music industry it agreed - in addition to implementing a three strikes system against its users - not to oppose any application to the court to block access to The Pirate Bay. The predictable result was that an unopposed application would be granted without any real judicial scrutiny - and this has now happened. On the 24th of July, on the consent of Eircom, Mr. Justice Charleton in the High Court granted an order requiring it to:
block or otherwise disable access by its subscribers to the website thePirateBay.org and related domain names, IP addresses and URLs ... together with such other domain names, IP addresses and URLs as may reasonably be notified as related domain names by [the music company plaintiffs] to [eircom] from time to time.That order requires Eircom to put such a block in place from the start of September (and, remarkably, to block additional sites designated by the plaintiffs as "related" - something presumably designed to avoid evasion but which may be prone to abuse). Crucially, however, Mr. Justice Charleton stressed that he had only heard one side, and that consequently any decision he made was on the basis of one side putting forward an unopposed application - expressly noting that had the matter being argued, a different conclusion might have been reached by a different court. In short, the order has no precedential value.
Despite this, however, the music industry appears to have been emboldened by the order, which takes us on to the UPC situation. It seems that the plaintiffs then wrote to UPC demanding that it also block The Pirate Bay, lest customers "migrate" from Eircom, and threatening immediate proceedings unless it blocked access also. UPC - which is already being sued by the music industry in separate proceedings essentially demanding it implement "three strikes" - has rejected this demand, and indicated that it will vigorously defend any additional action also.
The current state of play raises some interesting questions. For example: Will users begin to migrate from Eircom? Is it appropriate for a court - even on consent - to make an order which will have the effect of blocking user access to a great deal of legitimate content? (While the percentage of legal torrents on The Pirate Bay might be contested, there's no doubt but that it indexes a great deal of legitimate content.) Should such an order allow plaintiffs to (apparently unilaterally) determine which sites are "related" and require those to be blocked also? Why have Eircom been so shy about revealing the existence of the blocking? Expect these, and other issues to come to the fore over the next few days.
Adrian Weckler has more, including the UPC press release.
Friday, August 14, 2009
Overseeing Surveillance - Lessons from the UK Experience?
In a previous post I pointed out the remarkable lack of transparency in the oversight of surveillance in Ireland. This has become all the more worrying since July when the remit of this oversight system was extended (by the Criminal Justice (Surveillance) Act 2009) beyond telephone tapping and data retention to include also the planting of covert audio bugs, video cameras and gps trackers. In effect, the Designated Judge has now been given (by ad hoc extensions of his role) oversight of most forms of surveillance - with public accountability in respect of this oversight remaining limited to a single page annual report.
Two recently published documents from the UK illustrate a better model of oversight.
The first is the 2008 Report of the Interception of Communications Commissioner. The primary role of this official - a retired judge - is similar to that of the Irish Designated Judge in relation to interceptions and data retention. Unlike our uninformative annual report, however, the Interception Commissioner gives much more detail in relation to his work. Here are some examples:
Two recently published documents from the UK illustrate a better model of oversight.
The first is the 2008 Report of the Interception of Communications Commissioner. The primary role of this official - a retired judge - is similar to that of the Irish Designated Judge in relation to interceptions and data retention. Unlike our uninformative annual report, however, the Interception Commissioner gives much more detail in relation to his work. Here are some examples:
In short, I meet officers in the agencies undertaking interception work and officials in the departments of the Secretaries of State/Ministers which issue the warrants. Prior to each visit, I obtain a complete list of warrants issued or renewed or cancelled since my previous visit. I then select, largely at random, a sample of warrants for inspection. These include both warrants and attendant certificates. In the course of my visit I satisfy myself that those warrants fully meet the criteria of RIPA, that proper procedures have been followed and that the relevant safeguards and Codes of Practice have been followed. During each visit I review each of the files and the supporting documents and discuss the cases with the officers concerned. I can, if I need to, view the product of interception. It is of paramount importance to ensure that the facts justified the use of interception in each case and that those concerned with interception fully understand the safeguards and the Codes of Practice...That report gives a similar level of detail in relation to communications data issues. Here's an example:
During 2008, I visited a total of nine communication service providers (CSPs) and internet service providers (ISPs) consisting of the Royal Mail and the communications companies who are most engaged in interception work. These visits, mostly outside London, are not formal inspections but are designed to enable me to meet both senior staff in each company as well as the personnel who carry out the work on the ground, and for them to meet and talk to me. I have no doubt that the staff in the CSPs and ISPs welcome these visits. We discussed the work that they do, the safeguards that are in place, any errors that have occurred, any legal or other issues which are of concern to them, and their relationships with the intercepting agencies...
Fifty errors and breaches [in relation to interceptions] have been reported to me during the course of 2008. This is a marked increase when compared with the total of 24 errors and breaches reported in my last Annual Report. I consider the number of errors to be too high. By way of example, details of some of these errors are recorded below...
the police took swift action when information from a reliable source suggested that a number of very young children were at immediate risk of falling into the hands of a paedophile ring. Subscriber information relating to an Internet Protocol (IP) Address was obtained in order to locate an address for the children but unfortunately it would appear this was not correct. The police entered the address and arrested a person who was completely innocent and further enquiries are continuing. This was a very unfortunate error and the whole process of obtaining data relating to IP addresses has been re-examined. In this case there was confusion between the Internet Service Provider and the public authority over how the data should be interpreted, particularly in relation to the critical international time zones. Better checks and balances have been put in place to help clarify the process, which includes liaison with the SPoC trainers and these should help to prevent similar errors in the future.The second recent document from the UK is the Report of the Chief Surveillance Commissioner for 2008/2009. This report covers some of the same areas where the Designated Judge now has responsibilities, particularly in relation to the planting of covert bugs and video surveillance. Again the level of review is quite detailed:
Common causes of errorThe significance of these reports lies not so much in the specifics, but in the fact that they illustrate a more effective form of regulating surveillance. The Irish model - in which oversight is minimal and given as a part-time duty to a busy judge - seems increasingly unsustainable in comparison.
The areas that have received the most criticism on inspection – and this applies equally to all types of public authority – in this reporting period are:
(a) a continuing failure on the part of Authorising Officers properly to demonstrate that less intrusive methods have been considered and why they have been discounted in favour of the tactic selected;
(b) the continuing preference to interpret private information as limited to biographical data rather than recognise the wider meaning decided by the European Court of Human Rights. A specific act of surveillance may not be intrusive but a combination of acts may enable the construction of a profile; this requires careful consideration when judging whether an individual’s private life is subject to interference;
(c) the failure of Authorising Officers, when cancelling authorisations, to give directions for the management and storage of the product of the surveillance;
(d) the continuing confusion with regard to the need for authorisation when surveillance equipment (such as CCTV) is focused on an individual in a public place. It is not where the CCTV is placed (which may be overt or covert) but the manner in which the camera is used that is determinative of whether the surveillance is covert;
(e) Authorising Officers not knowing the capability of the surveillance equipment which they are authorising. For instance, there are differences between video cameras that record continuously and those activated by motion; and between thermal image and infra-red capability. These differences may have an important bearing on how a surveillance operation is conducted and the breadth of the authorisation being granted. Therefore, a simple authorisation for ‘cameras’ is usually insufficient;
(f) poor internal audit by senior management. The Central Record of Authorisations is often in a form not conducive to quick review or status check. Sometimes it is apparent that there has been no meaningful internal audit between OSC inspections; and
(g) those conducting covert surveillance basing their activity on what was requested rather than on what was specifically authorised. R v Sutherland underpins the importance of briefing those conducting the surveillance beforehand on the specific authorisation.
Friday, August 07, 2009
Eircom briefing note on "three strikes" filesharing settlement leaked
I've just stumbled on a document on scribd which purports to be a "Briefing Note on arrangement between Eircom and the Irish Recorded Music Association (IRMA) with regard to Copyright Infringement" dating from March. While there's no indication as to who posted the document or whether it is authentic, it certainly appears to be genuine and to reflect Eircom's position. There are some very interesting details in the document as to how Eircom proposes to implement "three strikes" and here's an excerpt:
Update (19.08.09): Torrentfreak and SiliconRepublic have since run stories about this document.
Under the draft protocol, the notification shall include the following information (at a minimum):Full text.
* details of copyright holder (name and address);
* why the notification is being sent (i.e. setting out the breach of copyright);
* the actual copyright work that has been infringed (information on copyright material, for example artist, song, title and album title);
* the IP address;
* the time stamp of when the investigation was initiated;
* the time stamp of when the investigation was completed, the peer to peer application/software used by the customer;
* and, the digital fingerprint/hash for copyright material detected;
The last item, the digital fingerprint/hash of the copyright material detected, allows eircom to verify that the copyright work identified by the record companies is in fact owned by them.
In addition, the information which will be provided by the record companies will be of the same type as that used in the three previous disclosure actions in the Irish High Court involving the parties and eircom will not act upon a notification from the record companies that does not contain the information set out above.
eircom has also requested that the record companies provide independent certification that the notification has been lawfully obtained by and on behalf of the record companies.
The record companies are also to provide reputable annual independent certification that the necessary legal, I.T., entity level and regulatory controls relating to the obtaining, generating and processing of data by Detecnet (or any other supplier engaged by the record companies) have been complied with.
Update (19.08.09): Torrentfreak and SiliconRepublic have since run stories about this document.
Thursday, August 06, 2009
Locational Privacy
The EFF have published an excellent short report on locational privacy (pdf) which highlights the threats posed by data retention and other technological developments. Here's an excerpt:
What is locational privacy?(via Mathias Klang)
Locational privacy (also known as “location privacy”) is the ability of an individual to move in public space with the expectation that under normal circumstances their location will not be systematically and secretly recorded for later use. The systems discussed above have the potential to strip away locational privacy from individuals, making it possible for others to ask (and answer) the following sorts of questions by consulting the location databases:
• Did you go to an anti-war rally on Tuesday?
• A small meeting to plan the rally the week before?
• At the house of one “Bob Jackson”?
• Did you walk into an abortion clinic?
• Did you see an AIDS counselor?
• Have you been checking into a motel at lunchtimes?
• Why was your secretary with you?
• Did you skip lunch to pitch a new invention to a VC? Which one?
• Were you the person who anonymously tipped off safety regulators about the rusty machines?
• Did you and your VP for sales meet with ACME Ltd on Monday?
• Which church do you attend? Which mosque? Which gay bars?
• Who is my ex-girlfriend going to dinner with?
Of course, when you leave your home you sacrifice some privacy. Someone might see you enter the clinic on Market Street, or notice that you and your secretary left the Hilton Gardens Inn together. Furthermore, in the world of ten years ago, all of this information could be obtained by people who didn’t like you or didn’t trust you.
But obtaining this information used to be expensive. Your enemies could hire a guy in a trenchcoat to follow you around, but they had to pay him. Moreover, it was hard to keep the surveillance secret — you had a good chance of noticing your tail ducking into an alley.
In the world of today and tomorrow, this information is quietly collected by ubiquitous devices and applications, and available for analysis to many parties who can query, buy or subpoena it. Or pay a hacker to steal a copy of everyone’s location history.
It is this transformation to a regime in which information about your location is collected pervasively, silently, and cheaply that we’re worried about.
Friday, July 31, 2009
Big news for small print: Court of Appeal gives the thumbs up for website disclaimers
Struan Robertson, editor of OUT-LAW.COM has a frank and useful discussion of what the decision means for online businesses.
Tuesday, July 28, 2009
Sutherland Institute v. Continuative: Is it time to take the U out of UDRP?
OUT-LAW has a good report of the WIPO panel decision in Sutherland Institute v. Continuative LLC - a decision which by focusing on the location of the parties makes me wonder whether it's misleading to describe the UDRP as a "Uniform" Dispute Resolution Policy.
On the face of it this was a relatively straightforward case. The complainant was a right wing Utah think thank hosted at SutherlandInstitute.org while the respondent set up a parody site at SutherlandInstitute.com. A screengrab of a portion of both pages shows the difference:

Despite the fact that the respondent did not defend the proceedings, the panelist found in their favour, holding that it had not been established that they had registered and used the domain "in bad faith" as required by the UDRP. This isn't of itself a surprising outcome, but it's the reasoning underpinning this conclusion which I find interesting. The key passage is this:
Gerald Levine has more, including an interesting discussion of an alternative choice of law approach under the UDRP.
On the face of it this was a relatively straightforward case. The complainant was a right wing Utah think thank hosted at SutherlandInstitute.org while the respondent set up a parody site at SutherlandInstitute.com. A screengrab of a portion of both pages shows the difference:
Despite the fact that the respondent did not defend the proceedings, the panelist found in their favour, holding that it had not been established that they had registered and used the domain "in bad faith" as required by the UDRP. This isn't of itself a surprising outcome, but it's the reasoning underpinning this conclusion which I find interesting. The key passage is this:
Because this proceeding involves political speech that is strongly protected under the U.S. Constitution, the Panel will not in these proceedings involving two U.S. parties attempt to identify bad faith elements that are not specifically enumerated in the Policy. If the right of political speech is to be interfered with based upon Complainant’s service mark incorporated in Respondent’s disputed domain name, it is preferable that a federal or state court make that application of the concept of “bad faith”.This passage relies on the fact that the parties are both US based to apply US law. As such it takes advantage of rule 15(a) of the UDRP which gives a panel a remarkably wide discretion to decide claims based on "any rules and principles of law that it deems applicable". This has often been used by panelists to apply domestic rules of law where the parties are both from the same jurisdiction - to the extent that the Berkman Center's excellent Analysis of UDRP Issues assumes this to be the norm. Indeed, this practice is supported by paragraph 176 of the WIPO Final Report which led up to the adoption of the UDRP, which states:
In applying the definition of abusive registration given above in the administrative procedure, the panel of decision-makers appointed in the procedure shall, to the extent necessary, make reference to the law or rules of law that it determines to be applicable in view of the circumstances of the case. Thus, for example, if the parties to the procedure were resident in one country, the domain name was registered through a registrar in that country and the evidence of the bad faith registration and use of the domain name related to activity in the same country, it would be appropriate for the decision-maker to refer to the law of the country concerned in applying the definition.Against this, however, is a strong body of opinion which argues that national law should not be imported into the UDRP - that to do so will lead to a lack of uniformity and to inconsistent outcomes. For example, in McMullan Bros & Maxol v. Web Names, the panelist ruled that:
5.10 Paragraph 15(a) of the Rules requires a Panel to make its decision "in accordance with the Policy, these Rules and any rules and principles of law that it deems applicable." This might justify applying the without prejudice doctrine in this case, but the Panel is unconvinced. The Policy provides an international procedure for international application by a panel comprising panelists who may come from a jurisdiction unconnected with either party. To import a national rule simply because both parties come from the same jurisdiction may result in similar cases being decided in a different manner dependant upon geographical accident. This is a conclusion that this Panel finds inherently unattractive. At times resort to national law may be unavoidable (for example when determining the existence of a trademark recognised by the Policy), but the Panel sees no reason for doing so in this case.Similarly Wotherspoon & Cameron argue that:
The UDRP was developed by reference to the status of national laws and international treaties. In our view, it already reflects a somewhat harmonized version of these laws. The practice of referring to territorial laws undermines a central purpose of the UDRP — to provide a uniform mechanism for resolution of domain name disputes in the face of the borderless nature of the Internet. By continuing to refer to national laws, Panels will reinforce jurisdiction specific intellectual property rights and undermine the goal of a global uniformity in resolving domain name disputes.This clash of views highlights an unresolved tension within the UDRP as to how to deal with choice of law issues. There is an obvious attraction in the use of national law where a matter is very closely connected with one jurisdiction. But doing so - even if permitted by the UDRP - does run the risk of eroding its "uniform" nature. Also, this growing practice adds an extra layer of complexity to UDRP proceedings - forcing parties to address choice of law issues as well as the substance of any claim - and may also result in registrants and trademark holders gaming the system by choosing to establish themselves in the jurisdictions which they see as most friendly to their side.
Gerald Levine has more, including an interesting discussion of an alternative choice of law approach under the UDRP.
Friday, July 17, 2009
Bill published to transfer RegTel premium rate functions to Comreg
That legislation has now emerged, in the form of the Communications Regulation (Premium Rate Services) Bill 2009. According to the explanatory memorandum, the purpose of the Bill is to provide for:
• the transfer of the function of regulating premium rate services to the Commission for Communications Regulation, hereinafter called the Commission.Key elements here are the introduction of a licence to provide premium rate services and the creation of a range of criminal offences including acting without a licence and overcharging / charging for services which were not requested.
• the licensing of premium rate services by the Commission.
• offences, penalties and rights of appeal in relation to the regulation of premium rate services.
• the funding of expenses incurred by the Commission in exercise of its regulatory functions.
• the transfer of staff and responsibility for certain legal proceedings, respectively, from Regtel to the Commission.
• compliance by the Commission with the same obligations in relation to Ministerial directions, reporting and accountability responsibilities in respect of premium rate services as it has in respect of electronic communications and postal services.
More from the Irish Times | Siliconrepublic.
(I'm a bit late blogging this story - I lost sight of this Bill in the flurry of legislative activity during the run up to the summer vacation, particularly the rushing through of the Criminal Justice (Surveillance) Act 2009 and the introduction of the Communications (Retention of Data) Bill 2009. More on these anon.)
Wednesday, July 08, 2009
Eircom hacking shows flaws in Irish computer crime law
Today's Irish Times has a report of an apparent denial of service attack against Eircom:
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
MANY OF Eircom’s 500,000 internet subscribers have been left offline or experienced delays in web browsing at times this week because of a suspected attack by hackers.I've said it before but it's worth repeating: Irish law does not adequately deal with computer crime at the moment (with denial of service attacks being one of many areas left without adequate sanctions) and legislation to implement the Cybercrime Convention and the Framework Decision on Attacks Against Information Systems is now long overdue.
Some customers who tried to connect to popular sites such as RTÉ, Facebook or Bebo were redirected to incorrect websites, often displaying images of advertising or scantily clad women.
The company blamed the problems on “an unusual and irregular volume of internet traffic” directed at its website, which affected the systems and servers that provide access to the internet for its customers.
Internet discussion groups speculated that the problems were caused by a hacker accessing Eircom’s domain name server (DNS) system through a denial-of-service attack.
This involves a target site being saturated with messages and requests to the point it can no longer function properly.
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
Whether or not such an attack would amount to an offence under Irish law will vary depending on the precise structure of the attack.
For example, suppose that A sets out to harm B by sending several million emails to B’s server. The effect is not only to use up B’s bandwidth but also to use his disk capacity. In this case, it might be possible to charge A with criminal damage under section 2 of the Criminal Damage Act 1991, on the basis that A has damaged B’s data within the meaning of section 1 by adding to it without lawful excuse.
This result is supported by the English decision in DPP v. Lennon. In that case the defendant was a 16 year old who took umbrage at the circumstances of his dismissal and sent five million emails to his former employer with the expressed intention of “causing a bit of a mess up”. He was charged with unauthorised modification to a computer system with intent to impair the operation of the computer, contrary to section 3(1) of the Computer Misuse Act 1990 (the equivalent provision to section 2 of the Criminal Damage Act 1991). His defence was that the company had implicitly consented to receiving emails and as such he had not made unauthorised modifications. Although the trial judge accepted this argument, on appeal the Divisional Court held that any implied consent did not extend to emails sent for the purpose of disrupting the system. Per Jack J.:“I agree, and it is not in dispute, that the owner of a computer which is able to receive emails is ordinarily to be taken as consenting to the sending of emails to the computer. His consent is to be implied from his conduct in relation to the computer. Some analogy can be drawn with consent by a householder to members of the public to walk up the path to his door when they have a legitimate reason for doing so, and also with the use of a private letter box. But that implied consent given by a computer owner is not without limit. The point can be illustrated by the same analogies. The householder does not consent to a burglar coming up his path. Nor does he consent to having his letter box choked with rubbish. That second example seems to me to be very much to the point here. I do not think that it is necessary for the decision in this case to try to define the limits of the consent which a computer owner impliedly gives to the sending of emails. It is enough to say that it plainly does not cover emails which are not sent for the purpose of communication with the owner, but are sent for the purpose of interrupting the proper operation and use of his system.”However, if the facts of a denial of service attack are varied slightly then criminal damage may no longer be an appropriate charge. Suppose for example that C sets out to hinder access to D’s publicly available website, and does so by programming several computers to repeatedly download large pages from the site. The result is to use up D’s bandwidth and ensure that other users cannot get through to the site, though the server itself continues to function. What crime, if any, has been committed?
In this case C would not have damaged D’s data (assuming that C downloaded data only and did not make any modifications to the data on the server). It might be argued that C has committed criminal damage to the server itself given the extended definition of “damage” under section 1, which includes situations where a person “whether temporarily or otherwise, render[s] inoperable or unfit for use or prevent[s] or impair[s] the operation of” property.
Such a charge would, however, prevent some difficulties. It might be successful if the effect of a denial of service attack was to cause the server to crash – that temporary inoperability would certainly seem to constitute damage within the meaning of section 1. In the hypothetical above, however, C has not rendered the server inoperable but merely inaccessible – which would seem to fall outside the scope of the criminal damage offence.
On the other hand, using the reasoning in DPP v. Lennon it might be possible to characterise the attack as unauthorised access contrary to section 5 of the Criminal Damage Act 1991. The argument could be made that while public websites carry with them an implied permission to access the site, this permission does not (to use the words of Jack J.) cover visits which are “the purpose of interrupting the proper operation and use of [the] system”, so that such a visit would constitute operation of the server with intent to access data without lawful excuse.
Friday, July 03, 2009
Search engines and safe harbours
Danny O'Brien has a strong piece in today's Irish Times arguing that Irish and European law is holding back development of online businesses by imposing excessive liabilities on search engines. Here's an excerpt:
In the US, the law specifically carves out a protection against liability for "information location tools" - search engines, in other words.I'm in agreement with Danny and would go one step further - rather than limit a new immunity to search engines, we should extend it to other online intermediaries such as content aggregators. This 2006 report from the UK Department of Trade and Industry is a good starting point for understanding how content aggregators and others are deterred by possible liability.
It is the same sort of "safe harbour" that protects web hosting services from being sued over their customers' content and internet service providers and mobile phone companies from being penalised for making temporary caches of websites to cut down connection costs and speed up connections.
No such protection exists in Europe for search engines. However the very fact that these US search engine companies are so large and, moreover, have large subsidiaries in Europe and beyond, gives them a little more protection from midnight raids than start-ups like SurfTheChannel.
It also provides them with something of an economic advantage over any upstart European search engine.
When Bing, the new Microsoft search engine, was launched, only a few noted that its "video search" effectively embedded copyrighted content on to Microsoft's own website (try typing The Office into its video search and see what happens).
If that had been a European search engine launched by a plucky new start-up, you can bet that its lawyers would have warned them off such a feature.
This effectively means that one of the biggest selling points of Microsoft's Google competitor is out of bounds for any European contender...
Perhaps the best solution would be for individual countries in the EU to make themselves more business friendly.
The e-commerce directive already allows individual nations to carve out wider exceptions than those listed.
Countries like Spain, Portugal and Austria have all included some protection to search engines, as well as anyone providing a weblink to another website.
Perhaps Ireland could create its own "safe harbour" in national law for new internet start-ups.
That way, we could draw investment from other countries who want the benefit of being able to find what we need on the internet but are scared to alienate the vested interests who would rather choke it. (emphasis added)
Thursday, July 02, 2009
The Music Industry v. ISPs - Round 2 - UPC and BT vow to fight
UPC
The company is now preparing its defence and intends to vigorously defend its position in Court...BT are more laconic:
UPC has made its position clear from the outset -- it will not agree to a request that goes beyond what is currently provided under existing legislation. There is no basis under Irish law requiring ISPs to control, access or block the internet content its users download. In addition, the rights holders' proposal gives rise to serious concerns for data privacy and consumer contract law.
Irish and European law maintains a careful balance between the rights and obligations of copyright owners, internet users and ISPs. The three strikes policy that was agreed in private with eircom as part of the settlement, and any attempt to impose in upon the industry generally, seriously undermines that balance.
It is unfortunate that the rightsholders did not take up UPC's suggestion that it convene a stakeholder forum in which their concerns could be addressed. UPC indicated that it would be willing to participate in such a forum provided all relevant parties that have a vested interest in this matter were included (eg ISPs, the Data Protection Commission, the National Consumer Agency and relevant Departments of the Government). (Emphasis added)
BT Ireland believes there is no legal basis for such a claim and the proceedings will accordingly be strongly defended.
Tuesday, June 30, 2009
Quote of the day
Beware the Four Horsemen of the Information Apocalypse: terrorists, drug dealers, kidnappers, and child pornographers. Seems like you can scare any public into allowing the government to do anything with those four.- Bruce Schneier
Thursday, June 25, 2009
Bord Gais Laptop Loss
I wrote an opinion piece for the Sunday Business Post on the recent Bord Gais laptop loss - using it as a jumping off point to argue for a data breach notification law in Ireland. Here's an excerpt:
It hasn’t been a good week for personal information. Last Tuesday, the HSE admitted that it had lost an unencrypted laptop containing sensitive information, including particular social work case notes on nine families.More from the Digital Rights Ireland perspective here. What Irish bloggers have been saying about the Bord Gais scandal here.
Remarkably, the HSE had not reported this loss to the Data Protection Commissioner, who learned of the incident from media reports. The HSE incident was eclipsed the following day when Bord Gáis revealed that it had lost an unencrypted laptop with account details - including bank and credit card information - on 75,000 customers, exposing them to the risk of identity theft.
Unfortunately, these are not isolated incidents. In the last year alone, multiple cases have come to light: notably Bank of Ireland, which lost personal data on more than 30,000 life assurance customers; the Office of the Comptroller and Auditor General, which lost information on 380,000 social welfare recipients; and Airtricity which posted the financial details of 1,200 customers on its website for six weeks.
Why have Irish organisations been so slipshod with the information we have entrusted to them? One problem is that the bodies that hold the data suffer little direct damage if the data is lost - it is the individual, not the company, who suffers the harm. Consequently, there is little financial incentive for them to take adequate measures to protect our data.
This is compounded by a lack of transparency. Under Irish law, there is no express obligation for a company that has lost customer data to notify anyone - neither the customer nor the Data Protection Commissioner.
The result is that organisations try to cover up data breaches to save face. Consequently, if your details are leaked, it is entirely possible that the first you will know of it is when you discover that your fraudulent alter ego has enjoyed a spending spree on your credit card or run up huge debts in your name. By then, it’s too late.
Thursday, June 18, 2009
The Music Industry v. ISPs - Round 2
After their inconclusive action against Eircom, this time the music industry is suing UPC and BT. Proceedings were issued on Tuesday according to the (stupidly not hot-linkable) search facility on courts.ie. Expect the cat to be put among the pigeons shortly.
I believe that litigation demanding that ISPs monitor what their users do and/or disconnect users based on three unproven allegations is unjustified - for the reasons why, see the Digital Rights Ireland site in relation to user monitoring and three strikes.
Subscribe to:
Posts (Atom)