It's been a busy few days for copyright law in Ireland. First the important decision in Koger v. HWM, and now the landmark decision in EMI v. UPC (RTÉ | Irish Times), which derailed music industry plans to compel ISPs to introduce "three strikes" in Ireland.
I'm still digesting the 82 pages of the judgment, but in the meantime here's the full text for your delectation:
EMI v. UPC
Monday, October 11, 2010
Tuesday, September 21, 2010
Google Transparency Report launched
The New York Times has a story today about Google's new Transparency Report. The Report - which expands on an earlier initiative - tracks government intervention on the internet and shares internal data from Google in three broad categories:
* Government inquiries for information about users;
* Government requests to remove content (both hosted content and search results); and
* Traffic flows.
In each case the data is broken down by country. In relation to the UK, for example, the map shows that for the period January-June 2010 there were:
There's no data given for Ireland for the same period. This may mean one of two things - either there were no Irish requests to take down information or access user information during that period, or else (probably more likely) there were so few Irish requests that Google has chosen not to reveal the statistics. For what it's worth, during the previous six month period Google indicates that there were fewer than 10 Irish government requests to remove content, of which 50% were complied with.
1343 data requests
48 removal requests, for a total of 232 items; and
62.5% of removal requests were fully or partially complied with
Blogger
o 1 court order to remove content
o 1 item requested to be removed
Video
o 3 court orders to remove content
o 32 items requested to be removed
Groups
o 1 court order to remove content
o 1 items requested to be removed
Web Search
o 8 court orders to remove content
o 144 items requested to be removed
YouTube
o 6 court orders to remove content
o 29 non-court order requests to remove content
o 54 items requested to be removed
The traffic flow portion of the report is new and particularly interesting - by visualising the amount of data flowing to a particular country it graphically illustrates government attempts to block access to particular sites. Here, for example, is a graph of YouTube traffic to Turkey from March 2010 onwards. The abrupt drops in traffic appear to coincide with the Turkish government's ongoing attempts to block users from viewing YouTube and other Google services.
Google must be congratulated for providing this information - along with Herdict and Chilling Effects (which is also supported by Google) the information provided will be invaluable in tracking attempts to control the flow of information on the net. However, as Lilian Edwards and Christopher Soghoian have pointed out this is still only a start - greater detail as to the types of content being targeted and the legal basis for requests is necessary to make sense of the raw numbers. Perhaps in the next revision?
Friday, September 10, 2010
Monitoring online radicalisation
I was at the fascinating Terrorism and New Media conference in DCU yesterday taking part in a panel discussion "Monitoring the Internet for Violent Radicalisation: Ethical and Legal Issues", along with Mina al Lami (LSE), Paul Durrant (ISPAI) and Sadhbh McCarthy (Centre for Irish and European Security).
The discussion was under the Chatham House Rule so I won't be putting names to views, but the other panelists and the audience had some interesting perspectives which I thought worth jotting down.
There was a definite concern that anti-terror laws (especially in the UK) may make criminals of researchers. Cases such as the recent University of Nottingham arrests have made academics increasingly nervous and uncertain as to whether they can carry out their work in a way which is compliant with the law. From a purely practical perspective (at a conference where the majority of participants were from outside Ireland) there is a fear that the contents of one's laptop might be legal in country A but not in country B.
On a related point researchers were worried as to their legal and ethical responsibilities if they find material which might provide evidence of a crime or indications that a crime might be committed in the future. For Irish researchers section 9 of the Offences Against the State Act 1998 presents particular problems, making failure to volunteer certain information to Gardaí punishable by up to five years' imprisonment unless the researcher has a "reasonable excuse" for that failure. There seems to be a relatively low level of awareness of this and other reporting obligations.
The source material for studies in this area - jihadi forums, bulletin boards, chatrooms, etc. also presented difficulties for researchers. What ethical standards apply to the use of material deliberately published for a global audience? Does it matter whether individuals have used their real name or a pseudonym? Does it matter whether material is on an open forum or requires registration? Are researchers justified in deceit as to their identity or institutional affiliation in signing up to these forums? While there has been a good deal written on these issues (well summarised here) it seemed that these points still trouble researchers.
Finally, there was a substantial consensus that existing EU practice doesn't provide adequate ethical review of research in this area. When funding decisions are being made, there is a narrow focus on legality - asking "will researchers be breaking the law?" - rather than on wider ethical questions such as "is it desirable to develop particular tools of censorship or mass surveillance?" The INDECT project was cited as a prime example of inadequate ethical review, which (perhaps not surprisingly) has led to widespread media criticism.
The discussion was under the Chatham House Rule so I won't be putting names to views, but the other panelists and the audience had some interesting perspectives which I thought worth jotting down.
There was a definite concern that anti-terror laws (especially in the UK) may make criminals of researchers. Cases such as the recent University of Nottingham arrests have made academics increasingly nervous and uncertain as to whether they can carry out their work in a way which is compliant with the law. From a purely practical perspective (at a conference where the majority of participants were from outside Ireland) there is a fear that the contents of one's laptop might be legal in country A but not in country B.
On a related point researchers were worried as to their legal and ethical responsibilities if they find material which might provide evidence of a crime or indications that a crime might be committed in the future. For Irish researchers section 9 of the Offences Against the State Act 1998 presents particular problems, making failure to volunteer certain information to Gardaí punishable by up to five years' imprisonment unless the researcher has a "reasonable excuse" for that failure. There seems to be a relatively low level of awareness of this and other reporting obligations.
The source material for studies in this area - jihadi forums, bulletin boards, chatrooms, etc. also presented difficulties for researchers. What ethical standards apply to the use of material deliberately published for a global audience? Does it matter whether individuals have used their real name or a pseudonym? Does it matter whether material is on an open forum or requires registration? Are researchers justified in deceit as to their identity or institutional affiliation in signing up to these forums? While there has been a good deal written on these issues (well summarised here) it seemed that these points still trouble researchers.
Finally, there was a substantial consensus that existing EU practice doesn't provide adequate ethical review of research in this area. When funding decisions are being made, there is a narrow focus on legality - asking "will researchers be breaking the law?" - rather than on wider ethical questions such as "is it desirable to develop particular tools of censorship or mass surveillance?" The INDECT project was cited as a prime example of inadequate ethical review, which (perhaps not surprisingly) has led to widespread media criticism.
Monday, August 30, 2010
"It is unlikely that hackers will delay their next attack to suit the timetables of government departments"
In light of the ongoing attacks on the CAO website I argue in the Sunday Business Post that action on cybercrime and a national cybersecurity strategy are long overdue.
Tuesday, August 10, 2010
Putting the "Entertainment" into Media and Entertainment Law
Ever wondered what a letter from Lindsay Lohan's lawyers would look like? Perhaps you wanted to know how Britney Spears and Kevin Federline agreed to enter into a fake marriage? Or maybe you wanted to see how contestants in American Idol sign their rights away on entering the show? If so, look no further. US law professor Eric Johnson has put together an excellent compendium of materials on media and entertainment law for his courses. Unlike traditional materials, however, his compendium includes not just the (relatively staid) decisions of the courts but also dressing room requirements, the bluff and bluster of correspondence, and more. As he explains:
I'm a strong believer in assigning readings other than judicial opinions. So my compendium includes contracts, demand letters, and various litigation pleadings. These documents are especially valuable reading in entertainment law and media law, where industry custom, intimidation tactics, creative lawyering, ignorance, bullying, and fear all combine to play a role that rivals that of the law itself.
Wednesday, July 14, 2010
Access controlled
The new book Access Controlled from the OpenNet Initiative is now available
States no longer fear pariah status by openly declaring their intent to regulate and control cyberspace. The convenient rubric of terrorism, child pornography, and cyber security has contributed to a growing expectation that states should enforce order in cyberspace, including policing unwanted content... Internet censorship is becoming a global norm.As with Access Denied, the book is divided into two parts: opening with analytical chapters examining developments from data retention to the Global Network Initiative and followed by individual country and regional profiles. The latter are extremely useful overviews of the state of play worldwide - for me, however, the real strength of the book lies in the first six chapters in which a strong line up of authors consider international developments. Colin Maclay's chapter Protecting Privacy and Expression Online: Can the Global Network Initiative Embrace the Character of the Net? was a particular highlight, shining a light on a promising but as yet immature and relatively unexamined development.
Strongly recommended.
Friday, July 02, 2010
Hotline.ie 2009 Annual Report
Hotline.ie has just published its annual report for 2009 which makes for interesting reading. 2009 marks the 10th anniversary of the Hotline, which started operations in November 1999.
By way of background, Hotline.ie is an industry self-regulatory body (or perhaps co-regulatory: the boundaries are fluid) run by the ISPAI using funding from members and from the European Commission. The role of the Hotline is to receive complaints from the public about illegal content online and to act as a filter for those complaints - for example, if illegal material is found to be hosted in Ireland it will be notified to the Garda Síochána and/or the ISP; if hosted abroad it will be notified to the local authorities via either the INHOPE network or the Garda Síochána. Although it deals with reports of illegal content generally the primary focus of the Hotline is on preventing the distribution of child pornography.
Key statistics from the report:
(This statistic, however, appears to reflect the passive role of the Hotline, which is limited to receiving complaints from members of the public - it has no proactive role to actively search out child pornography. Recent media coverage of Irish p2p users downloading and uploading child pornography suggests that a significant number of Irish users may be sharing child pornography via p2p but that this is not registering on the Hotline radar.)
One particularly interesting part of the report was its analysis of those countries where child pornography is most often found to be hosted. Until recently the US and Russia were generally regarded as the worst offenders in this regard - recently, however, Russia appears to have improved its enforcement somewhat. Although the US continues to head this list, there has been a striking fall in the number of child pornography websites detected there, which may suggest that US procedures for taking down these sites are becoming more effective:
By way of background, Hotline.ie is an industry self-regulatory body (or perhaps co-regulatory: the boundaries are fluid) run by the ISPAI using funding from members and from the European Commission. The role of the Hotline is to receive complaints from the public about illegal content online and to act as a filter for those complaints - for example, if illegal material is found to be hosted in Ireland it will be notified to the Garda Síochána and/or the ISP; if hosted abroad it will be notified to the local authorities via either the INHOPE network or the Garda Síochána. Although it deals with reports of illegal content generally the primary focus of the Hotline is on preventing the distribution of child pornography.
Key statistics from the report:
* 2117 total number of reports processed by the Hotline.Although the number of complaints had increased, the number of child pornography images reported was significantly reduced:
* 284 of the above were determined as illegal under Irish law.
* 9 of the 284 proved to be duplicate reports, resulting in,
* 275 unique illegal reports. Of these:
* 9 were other issues (such as racism, threats of violence against individuals and financial scams that had an Irish connection).
* 267 were assessed as child sexual abuse and were forwarded for action through INHOPE or to An Garda Síochána for national investigation or forwarding via Interpol to other jurisdictions. One of these reports was of child grooming, all others were cases of child pornography.
the reports assessed as illegal under Irish law numbered 536 in 2008 compared with 284 in 2009, a very significant drop of 252. Analysis of the figures suggests that the decline reflects that the public simply do not encounter illegal content with the same frequency as in previous years. Similar observations have been reported by other INHOPE hotlines. This could be a turning point reflecting some degree of success due to the sustained worldwide effort to counter child abuse images on the Internet.One complaint related to child pornography on the web hosted in Ireland (the first time this had been detected):
The problem of weak log-on/password security was highlighted last October when the Hotline had its first absolutely confirmed report of a child pornography website in Ireland. The Garda investigation discovered that because of weak log-on/passwords the site had been hacked by criminals based outside the jurisdiction. The CSAM had been placed in a separate directory which was not navigatable from the shop website. However, clicking on the link in the banner site which held the full URL led directly to the planted directory. This contained PHP routines which created a pay-site portal with preview images pulled in from hosts in other countries.The complaints, as in previous years, overwhelmingly related to images hosted on the web and via spam emails, with complaints relating to p2p and Usenet being a vanishingly small proportion of the total:
The UK hotline, the International Watch Foundation (IWF), received a report about a banner site advertising a wide range of different child pornography sources. One of the banners linked to an IP address in Ireland. The IWF forwarded the report to Hotline.ie. Our content analysts verified that the content was indeed illegal under Irish law and confirmed the trace. The ISP was a major data centre in Dublin but we discovered that the IP was in fact sub-leased to a web developer/small hosting service in Co. Cork who had created and maintained the website on behalf of the client, a small retail business.
(This statistic, however, appears to reflect the passive role of the Hotline, which is limited to receiving complaints from members of the public - it has no proactive role to actively search out child pornography. Recent media coverage of Irish p2p users downloading and uploading child pornography suggests that a significant number of Irish users may be sharing child pornography via p2p but that this is not registering on the Hotline radar.)
One particularly interesting part of the report was its analysis of those countries where child pornography is most often found to be hosted. Until recently the US and Russia were generally regarded as the worst offenders in this regard - recently, however, Russia appears to have improved its enforcement somewhat. Although the US continues to head this list, there has been a striking fall in the number of child pornography websites detected there, which may suggest that US procedures for taking down these sites are becoming more effective:
Friday, June 25, 2010
Technology, privacy and domestic violence
Privacy advocacy in Ireland faces a number of challenges. Often it's met with the old canard "if you've nothing to hide you've nothing to fear" - implying that privacy is something for wrongdoers and criminals. A related problem has been a lack of wider public concern about privacy issues: while occasional issues (such as the recent series of data breaches) trigger public interest, more often issues such as data retention tend to be seen as rather esoteric and remote from people's day to day lives.
This makes a recent story on domestic violence charity Women's Aid all the more significant in showing that privacy issues should be of much wider concern:
This makes a recent story on domestic violence charity Women's Aid all the more significant in showing that privacy issues should be of much wider concern:
In its annual report for 2009, to be released today, the charity has noted an increase in disclosures of women being abused, controlled and stalked through technology.This story also reflects a significant wider trend not just in online privacy but in digital rights generally - slowly but surely these rights are being recognised as important by mainstream civil society groups. For example, earlier this week in the UK the National Union of Journalists agreed to support legal challenges to the Digital Economy Act while in Europe the consumers' group BEUC recently adopted a specific strategy on consumer rights in the digital environment. This trend is important in that it promises to enlist greater support for digital rights - but presents a new challenge for digital rights groups to liaise with and educate other civil society groups.
Director of the charity Margaret Martin said it was very concerned at the development.
She said callers disclosed that current or former boyfriends, husbands and partners were using many forms of technology to control, coerce and intimidate them.
Women had disclosed that home and mobile phone calls were monitored, as well as their texts. Some women also found cameras secretly installed to monitor them in their own homes.
Abusers tracked and scrutinised online use and demanded access to private e-mail and social networking accounts.
Some women said their partners and ex-partners had placed lies about them on internet sites. Others had been photographed and filmed without their consent, sometimes having sex, and the images were uploaded to the internet...
“Quite often it prevents women from seeking help as they fear their partner will see that they have rung a helpline, looked at a domestic violence website or spoken of the abuse to their friends, family or colleagues in an e-mail or text.”
Friday, June 18, 2010
May newspapers publish the whereabouts of released rapists? Murray v. Newsgroup Newspapers interlocutory decision handed down
The High Court (Irvine J.) today gave an interlocutory judgment in the important case of convicted rapist Michael Murray who is seeking to restrain newspapers from publishing his photograph or details of his whereabouts. The case follows extensive publicity given to him post-release (e.g.) which he claims is threatening his safety and jeopardising his rehabilitation.
Today's judgment refuses to grant an interlocutory injunction which would restrain the newspapers pending a full trial - significantly noting that there is a "public interest in being informed of the identity and whereabouts of a convicted criminal who may pose a risk to the community" (p.59). The Northern Irish decision in the similar case of Callaghan v. Independent News and Media was distinguished as involving a criminal who posed a lesser threat to the community and who faced a greater risk of being physically attacked once his identity was known.
Full text of judgment:
Murray v. Newsgroup Newspapers and others
Today's judgment refuses to grant an interlocutory injunction which would restrain the newspapers pending a full trial - significantly noting that there is a "public interest in being informed of the identity and whereabouts of a convicted criminal who may pose a risk to the community" (p.59). The Northern Irish decision in the similar case of Callaghan v. Independent News and Media was distinguished as involving a criminal who posed a lesser threat to the community and who faced a greater risk of being physically attacked once his identity was known.
Full text of judgment:
Murray v. Newsgroup Newspapers and others
Monday, May 17, 2010
Book review: Bound by Law
I've written a short review of the superb Bound by Law? Tales from the Public Domain for the film studies journal Scope. Here's an excerpt:
You seldom find lawyers writing comic books. It's not that we have anything against them. We're happy to litigate about them (as fans of Alan Moore's Watchmen can testify, having seen Zack Snyder's film adaptation delayed by litigation between Twentieth Century Fox and Warner Brothers). We're even sometimes their subject (just consider the central role of Harvey Dent / Two-Face in the Batman canon). But writing comic books? What might the clients think? Or the tenure committee? And how might a profession known for its verbosity cope with the tight constraints of the speech bubble?Full review.
This makes Bound by Law? a rare beast indeed – a comic book written (and drawn) by lawyers which also manages to be a clear and entertaining introduction to the legal issues faced by filmmakers in the minefield that is intellectual property law. The authors are academics at UC Davis School of Law (Aoki) and Duke University Law School (Boyle and Jenkins) with a track record of innovative research at the point where law, creativity and the public domain intersect. In this book they set out to look at the position of documentary makers and how intellectual property law constrains what they do, with a view to illustrating the wider argument that the law has become imbalanced and is in need of reform.
The focus of their work is neatly set out by this example:
A cell phone happened to ring during the filming of Marilyn Agrelo and Amy Sewell's Mad Hot Ballroom, a documentary about New York City kids in a ballroom dancing competition. The ring tone was the Rocky theme song … EMI, which owns the rights to the Rocky song asked for – guess how much? $10,000. In another scene, they were filming a foosball game and one of the players spontaneously yelled "Everybody dance now" – a line from the C&C Music Factory hit. Warner Chappell demanded $5,000 for the use of the line (14).
This demonstrates an ongoing problem for documentary film makers -- the problem of documenting the world when certain aspects of the world (music playing in the background, artwork on the walls, even trademarks appearing on products) may be off limits. This book is full of examples of situations where documentary makers have found their work stifled as a result. But how did we arrive at a situation where rights holders demand payment of large sums for transient and incidental excerpts of their works? And what should we do about it?
Saturday, May 01, 2010
For a safer and cleaner internet
I was extremely impressed with this cynical but accurate video about EU internet blocking proposals. Enjoy:
For more, see the Cleanternet website.
For more, see the Cleanternet website.
Tuesday, April 27, 2010
Music Industry says "Child Pornography is Great"
”Child pornography is great,” the speaker at the podium declared enthusiastically. ”It is great because politicians understand child pornography. By playing that card, we can get them to act, and start blocking sites. And once they have done that, we can get them to start blocking file sharing sites”.Christian Engström MEP has more.
The venue was a seminar organized by the American Chamber of Commerce in Stockholm on May 27, 2007, under the title ”Sweden — A Safe Haven for Pirates?”. The speaker was Johan Schlüter from the Danish Anti-Piracy Group, a lobby organization for the music and film industry associations, like IFPI and others...
”One day we will have a giant filter that we develop in close cooperation with IFPI and MPA. We continuously monitor the child porn on the net, to show the politicians that filtering works. Child porn is an issue they understand,” Johan Schlüter said with a grin, his whole being radiating pride and enthusiasm from the podium.
And seen from the perspective of IFPI and the rest of the copyright lobby, he of course had every reason to feel both proud and enthusiastic, after the success he had had with this strategy in Denmark.
Today, the file sharing site The Pirate Bay is blocked by all major Internet service providers in Denmark. The strategy explained by Mr. Schlüter worked like clockwork.
Sunday, March 21, 2010
Update on Eircom, IRMA and "three strikes" in Ireland
In all the excitement surrounding St. Patrick's day this week the fact that Eircom and the music industry were back in court on Tuesday didn't really receive the attention it deserves.
The background to Tuesday's hearing lies in last January's settlement under which Eircom agreed to introduce a "three strikes" system to disconnect users accused of filesharing by the music industry. Under that agreement (which has never been made public, but details of which have leaked) the record companies seem to have been required to show that they - and Eircom - would be acting in compliance with data protection law.
The Data Protection Commissioner, however, threw a spanner in the works, as summarised by the Sunday Times:
Unfortunately, that hearing seems to have been something of a case of Hamlet without the Prince. With the Data Protection Commissioner not represented, the court was hearing only from parties with a vested interest in the three strikes procedure and was deprived of an independent and impartial perspective.
I don't yet have a full transcript of the hearing, but I understand that the court was asked to rule on three broad questions:
1. Do IP addresses (in the hands of the music industry) constitute personal data?
2. Is the settlement agreement itself compatible with the Data Protection Acts?
3. If IP addresses are personal data, are they "sensitive personal data" in a context where they might reveal the commission of a criminal offence?
Other issues that arose included the fundamental rights implications of disconnecting users, whether users waived those rights by agreeing to Eircom's terms of use, and whether the Eircom/IRMA agreement was compatible with the new Telecoms Package rules on disconnecting users in relation to proportionality, necessity and procedural safeguards (including judicial review). Judgment is expected next week.
The background to Tuesday's hearing lies in last January's settlement under which Eircom agreed to introduce a "three strikes" system to disconnect users accused of filesharing by the music industry. Under that agreement (which has never been made public, but details of which have leaked) the record companies seem to have been required to show that they - and Eircom - would be acting in compliance with data protection law.
The Data Protection Commissioner, however, threw a spanner in the works, as summarised by the Sunday Times:
As part of the agreement, Irma said it would use piracy-tracking software to trace IP addresses, which can identify the location of an internet user, and pass this information to Eircom. The company would then use the details to identify its customer, and take action.Consequently, arguments on these issues were heard on Tuesday, throwing up some interesting new information. (It emerged for example that Eircom has agreed to throttle user traffic after strike two, and that Eircom will have three staff devoted to running the three strikes procedure.)
But the office of the Data Protection Commissioner (DPC) has indicated that using customers’ IP addresses to cut off their internet connection as a punishment for illegal downloading [presumably this should be uploading] does not constitute "fair use" of personal information. Irma and Eircom have asked the High Court to rule on whether these data-protection concerns mean the 2009 settlement cannot be enforced...
The Eircom case was reopened in the High Court last month and Judge Peter Charleton will hear submissions from both sides on March 16. The record companies asked for the DPC to be joined to the High Court action, but it refused on the basis that no one would guarantee to pay its legal costs.
Charleton will first have to decide whether an IP address constitutes "personal information" under data protection law. If it does, then data controllers are required to "get and use the data fairly". They are also required to use that data for "only one or more clearly stated purposes". The DPC does not think this includes cutting off their internet service.
"The EU telecoms directive indicated people have a fundamental right to an internet connection," said a source involved in the case. "So the judge must decide whether processing a person’s IP address to cut them off is a proportionate response to discovering they have downloaded pirated music."
Unfortunately, that hearing seems to have been something of a case of Hamlet without the Prince. With the Data Protection Commissioner not represented, the court was hearing only from parties with a vested interest in the three strikes procedure and was deprived of an independent and impartial perspective.
I don't yet have a full transcript of the hearing, but I understand that the court was asked to rule on three broad questions:
1. Do IP addresses (in the hands of the music industry) constitute personal data?
2. Is the settlement agreement itself compatible with the Data Protection Acts?
3. If IP addresses are personal data, are they "sensitive personal data" in a context where they might reveal the commission of a criminal offence?
Other issues that arose included the fundamental rights implications of disconnecting users, whether users waived those rights by agreeing to Eircom's terms of use, and whether the Eircom/IRMA agreement was compatible with the new Telecoms Package rules on disconnecting users in relation to proportionality, necessity and procedural safeguards (including judicial review). Judgment is expected next week.
Friday, March 05, 2010
Cloud computing controversy won't clear
It seems as though the controversy caused by the Chief State Solicitor's advice about purchasing cloud computing just won't go away. John Collins has an update in today's Irish Times. Here's an excerpt:
ON A Thursday afternoon early last month an e-mail with the subject line "eTenders – Cloud Computing Warning" began to arrive in the inbox of public servants.Previously on this blog: 1|2
Sent by the National Public Procurement Operations Unit, which operates the Government’s electronic tendering website, eTenders, the brief communication said the Chief State Solicitor’s Office had advised "that issues such as data protection, confidentiality and security and liability are not necessarily dealt with in a manner that would be necessary for public-sector responsibilities" by cloud services.
The e-mail was quickly forwarded around Ireland’s technology industry. Not only are companies such as Microsoft, IBM and HP investing millions into research centres and data centres here to support the new model of delivering software and other services over the internet, but Minister for Communications Eamon Ryan last year identified cloud computing as one of six "pillars" that would drive the creation of a smart economy.
In fact, Ryan is understood to have been extremely annoyed at the message being sent out, and his advisers have moved to soothe the nerves of some of the major technology multinationals based here.
While not renowned for its technology expertise, one of the roles of the Chief State Solicitor’s Office is to review commercial agreements for public bodies before they sign them.
"They must have reviewed a contract which wasn’t up to scratch and now they have concluded all cloud contracts are like this," says Philip Nolan, a partner in legal firm Mason Hayes + Curran who specialises in technology contracts. "It’s a totally disproportionate reaction and the IT industry is recoiling in shock."
Nolan equates the advice given by the Chief State Solicitor’s Office to someone saying 12 years ago "don’t buy anything using e-commerce because it’s not secure".
Describing the e-mail as "damaging", Ed Byrne, general manager of Hosting365, a local firm that provides a platform to support cloud computing, says eTenders should have instead "outlined the questions that need to be asked before buying a cloud service".
According to Byrne, this would have included questions such as where is the service based, who is the supplier, how much money can it save and what levels of support can be expected.
Tuesday, March 02, 2010
Ryanair v. Billigfluege.de - Full decision now available
I've just received a copy of the decision of Hanna J. in Ryanair v. Billigfluege.de and uploaded it to Scribd. At first glance it appears to represent a significant win for site owners who wish to control screenscraping, indexing and other uses of their content:
Ryanair v. Billigfluege.de
Ryanair v. Billigfluege.de
Monday, March 01, 2010
Ryanair screenscraping: Irish court accepts jurisdiction, rules on enforceability of website terms of use
You might have noticed that Ryanair has an ongoing legal campaign to stop sites from scraping its content and then reselling flights. (Blogged previously by me: 1|2|3.)
Until now, however, Ryanair found itself stymied by jurisdictional problems, and in two separate decisions the Irish High Court held that it did not have jurisdiction to hear its claims. (The first decision saw Ryanair thwarted by its own terms of use which provided for the English courts to have jurisdiction; the second involved prior Swiss proceedings which caused the Irish court to decline jurisdiction in favour of the Swiss court.)
In the most recent development in this saga, Ryanair has now amended its terms of use to provide for the exclusive jurisdiction of the Irish courts, and has succeeded in establishing jurisdiction in Dublin in an action against Billigfluege and Ticket Point. According to the Irish Times Hanna J. held as follows:
This appears to be the first time an Irish court has ruled on whether site terms of use are enforceable, and the passage quoted seems to adopt a very wide browsewrap theory whereby visitors to a website will be bound by terms of use without any positive act on their part, provided that a hyperlink to the terms is "clearly visible". I'm not entirely sure that this result is correct - as Andres Guadamuz notes in a similar context, there are issues of acceptance and consideration in these cases - and it will be interesting to read the full decision to see whether and how these issues are considered.
The potential implications of this decision are also important. If the broad approach above is followed it would appear to have the potential to eliminate screenscraping entirely, and to enable site owners to assert exclusivity over information which is not protected by copyright or database right - in effect creating a new quasi intellectual property right and upsetting the balance created by statute. (Just witness the Dublin Bikes iPhone app case.) Hopefully if this case goes to a full hearing we will see these points raised and considered in detail.
Until now, however, Ryanair found itself stymied by jurisdictional problems, and in two separate decisions the Irish High Court held that it did not have jurisdiction to hear its claims. (The first decision saw Ryanair thwarted by its own terms of use which provided for the English courts to have jurisdiction; the second involved prior Swiss proceedings which caused the Irish court to decline jurisdiction in favour of the Swiss court.)
In the most recent development in this saga, Ryanair has now amended its terms of use to provide for the exclusive jurisdiction of the Irish courts, and has succeeded in establishing jurisdiction in Dublin in an action against Billigfluege and Ticket Point. According to the Irish Times Hanna J. held as follows:
The exclusive jurisdiction clause contained in [Ryanair’s] website’s terms of use was binding on [Billigfluege and Ticket Point] in circumstances where those terms were at all times available for inspection by [Billigfluege and Ticket Point] as users of or visitors to the website, [Ryanair] having taken appropriate steps to ensure that the terms were brought to the user’s attention through their inclusion on the website via a clearly visible hyperlink.The full decision isn't available online yet, but from this excerpt it may be very significant indeed.
If you use the site, you agree not to breach its terms and if you do so, the exclusive jurisdiction clause set out in the Terms of Use makes it clear that Ireland is the appropriate jurisdiction for the purposes of litigating any disputes that may arise as a result.
This appears to be the first time an Irish court has ruled on whether site terms of use are enforceable, and the passage quoted seems to adopt a very wide browsewrap theory whereby visitors to a website will be bound by terms of use without any positive act on their part, provided that a hyperlink to the terms is "clearly visible". I'm not entirely sure that this result is correct - as Andres Guadamuz notes in a similar context, there are issues of acceptance and consideration in these cases - and it will be interesting to read the full decision to see whether and how these issues are considered.
The potential implications of this decision are also important. If the broad approach above is followed it would appear to have the potential to eliminate screenscraping entirely, and to enable site owners to assert exclusivity over information which is not protected by copyright or database right - in effect creating a new quasi intellectual property right and upsetting the balance created by statute. (Just witness the Dublin Bikes iPhone app case.) Hopefully if this case goes to a full hearing we will see these points raised and considered in detail.
Friday, February 19, 2010
Government departments not up in the clouds
After last week's story about the Department of Finance issuing warnings about the use of cloud computing, Sean Sherlock TD followed up by asking whether the warnings stemmed from any particular incident; whether government departments are already using cloud computing; and if so what safeguards are in place. The results are interesting: the Finance warnings don't appear to be the result of any mishap in central government as not one department is yet using cloud computing. (Though the Minister for Communications, Eamon Ryan, did say that his Department is actively promoting its use.)
Thursday, February 18, 2010
Alternative routes to identifying "anonymous" online users
David Robinson and Harlan Yu have posted a superb series of posts on Freedom to Tinker (1,2,3) about tactics which might be used to identify anonymous internet posters, even in cases where IP addresses might not have been logged by the site which hosts the comment. The key insight is that sites typically embed multiple external services (such as advertising, stats counters and video hosting) which may either individually or in combination enable the identity of particular users to be pinned down:
[P]laintiffs' lawyers in online defamation suits will typically issue a sequence of two "John Doe" subpoenas to try to unmask the identity of anonymous online speakers. The first subpoena goes to the website or content provider where the allegedly defamatory remarks were posted, and the second subpoena is sent to the speaker's ISP. Both entities—the content provider and the ISP—are natural targets for civil discovery. Their logs together will often contain enough information to trace the remarks back to the speaker's real identity. But when this isn't enough to identify the speaker, the discovery process traditionally fails.
Are plaintiffs in these cases out of luck? Not if their lawyers know where else to look.
There are numerous third party web services that may hold just enough clues to reidentify the speaker, even without the help of the content provider or the ISP. The vast majority of websites today depend on third parties to deliver valuable services that would otherwise be too expensive or time-consuming to develop in-house. Services such as online advertising, content distribution and web analytics are almost always handled by specialized servers from third party businesses. As such, a third party can embed its service into a wide variety of sites across the web, allowing it to track users across all the sites where it maintains a presence.
The traceability of any given site visitor will still depend on context: the number of third party services used by the site, the popularity of each third party service across the web, the types of identifying data that these parties collect and store, whether the speaker used any online anonymity tools, and many other site-specific factors.Of course, these tactics are likely to be expensive. Also, in an Irish context the uncertainty as to whether a result will be achieved may mean that a court will be less willing to grant a Norwich Pharmacal order (which is a discretionary remedy (PDF) - not something which is available as of right). But nevertheless, the research is important - particularly as it illustrates that traditional methods of ensuring online anonymity (such as TOR routing) may be vulnerable to indirect attack.
Despite the variability in third party tracing capabilities, the nearly simultaneous connections to a few third party services means that the results of tracing can be combined. By sleuthing through information held in third party dossiers, logs and databases, plaintiffs in John Doe lawsuits will have many more discovery options than they had ever previously imagined.
Wednesday, February 10, 2010
Banned in Turkey: Turkish internet filtering and blocking
Yaman Akdeniz has recently published a superb report for the OSCE on Turkey and Internet Censorship (press release | full text pdf).
Ironically, Yaman Akdeniz and his co-author Kerem Altıparmak have themselves been the subject of legal threats aiming to silence their criticism of Turkish internet censorship. Fortunately their book Restricted Access: A Critical Assessment of Internet Content Regulation and Censorship in Turkey (2008) is still available.
The image above is from Richard Dawkins' website, which has been blocked in Turkey since September 2008.
(Via Chris Marsden.)
Tuesday, February 09, 2010
Home Office terrorist material reporting site - some thoughts
The Home Office launched a new Directgov site last week, which "provides members of the public with information about what they can do if they come across violent extremist, terrorist and hate content online" (press release). The site takes reports and forwards them to a specialist unit within Association of Chief Police Officers (ACPO), which will take action if the material is illegal. Unsurprisingly there has been a good deal of media coverage (e.g. The Register | The Inquirer | BBC News). So far, though, there doesn't seem to have been any assessment of how this fits into the broader matrix of internet regulation in the UK. This post asks what effect it might have.
Reducing the role of the IWF?
One of the more significant aspects of this story is that it appears to be the first time that the UK government has set up a specific site to which internet content can be reported. Until now, the government has effectively devolved that function to the Internet Watch Foundation (IWF). Although this is a private body, official policy has been to designate the IWF as the first port of call for online content. The Surrey Police website is typical:
If you come across offensive or illegal material, please DO NOT contact Surrey Police directly.
Instead, you can make a report on the Internet Watch Foundation (IWF) web site.
If they decide any action is needed, they will contact the ISP or the police, who can take appropriate action. (It's worth remembering that evidence of illegal or offensive material can be detected even after it has been deleted from a computer.)
The Internet Watch Foundation are qualified to judge the illegality of material and will report matters to the relevant police force. They are the only authorised organisation in the UK that provides an Internet hotline for the public to report their exposure to illegal content online.Despite this, however, the IWF has never had a remit to receive complaints in relation to all illegal material online. For example, while there have been proposals from the Home Office that the IWF's remit should be extended to cover extremist websites, these have never come to fruition. Similarly, when the Terrorism Act 2006 created a system of notifying ISPs to take down terrorist material, that system bypassed the IWF entirely and required that notices be given via the police.
Consequently, the setting up of this site may be significant - does it indicate a trend which moves away from government reliance on the IWF and towards the use of separate (and public) reporting mechanisms?
Content control as a means of protecting vulnerable people?
The rhetoric used in announcing the site is also interesting. According to Lord West:
We want to protect people who may be vulnerable to violent extremist content and will seek to remove any unlawful material.If this sounds familiar, that's because it echoes the justifications for introducing the Cleanfeed child abuse image blocking system and later for criminalising extreme pornography - in each case, a central component was the argument that harm would be caused to the viewer (by simply viewing the material, or by predisposing them to commit crimes). Is this approach - focusing on harm to the viewer - becoming more common in controlling content in the UK?
Using consumer pressure as a regulatory tool?
Quite apart from illegal content, the site also sets out to encourage users to challenge content which is legal. According to Lord West:
This is also about empowering individuals to tell them how they can make a civic challenge against material that they find offensive, even if it is not illegal.Consequently, the site provides information on how to make complaints:
The internet is not a lawless forum and should reflect the legal and accepted boundaries of society.
What you can do about online hate or violence that is not illegalThis approach - by encouraging community pressure to force ISPs to change their behaviour - matches policy in relation to blocking, where the Home Office has abandoned plans to legislate and has instead stated its intention to rely on public pressure instead:
Most hateful or violent website content is not illegal. While you may come across a lot of things on the internet that offend you, very little of it is actually illegal.
UK laws are written to make sure that people can speak, and write, freely without being sent to prison for their views.
To be illegal, the content must match the descriptions at the top of this page.
Still, even if what you’ve seen does not seem to be illegal, you can take the steps below to have it removed if it upsets, scares or offends you.
Report it to the website administrator
Most websites have rules known as ‘acceptable use policies’ that set out what cannot be put on their website. Most do not allow comments, videos and photos that offend or hurt people...
If what you’ve seen is on a site with a good complaints system, you should report it to the website’s owners. Look out for their ‘contact us’ page, which should be clearly linked...
Report it to the hosting company
If the website itself is hateful or supports violence or terrorism let the website’s hosting company know. Hosting companies provide a place where the website sits, and often have rules about what they are willing to host.
Let the hosting company know they are hosting a website that breaks their rules, and ask them to stop.
You can find out which company hosts a website by entering their web address on the ‘Who is hosting this?’ website.
For the first time the IWF will publish the list of ISPs who are certified as having implemented its blacklist. "Hopefully consumer and public pressure will encourage the ISPs who aren't on the list to comply," said Carr. A Home Office spokesman said: "We will continue to urge ISPs to implement blocking, and ask consumers to check with their suppliers that they have done so."Does this mark the start of a trend towards greater use of consumer pressure by the UK government as a means of regulating what ISPs do?
Subscribe to:
Posts (Atom)


