Monday, March 01, 2010

Ryanair screenscraping: Irish court accepts jurisdiction, rules on enforceability of website terms of use

You might have noticed that Ryanair has an ongoing legal campaign to stop sites from scraping its content and then reselling flights. (Blogged previously by me: 1|2|3.)

Until now, however, Ryanair found itself stymied by jurisdictional problems, and in two separate decisions the Irish High Court held that it did not have jurisdiction to hear its claims. (The first decision saw Ryanair thwarted by its own terms of use which provided for the English courts to have jurisdiction; the second involved prior Swiss proceedings which caused the Irish court to decline jurisdiction in favour of the Swiss court.)

In the most recent development in this saga, Ryanair has now amended its terms of use to provide for the exclusive jurisdiction of the Irish courts, and has succeeded in establishing jurisdiction in Dublin in an action against Billigfluege and Ticket Point. According to the Irish Times Hanna J. held as follows:
The exclusive jurisdiction clause contained in [Ryanair’s] website’s terms of use was binding on [Billigfluege and Ticket Point] in circumstances where those terms were at all times available for inspection by [Billigfluege and Ticket Point] as users of or visitors to the website, [Ryanair] having taken appropriate steps to ensure that the terms were brought to the user’s attention through their inclusion on the website via a clearly visible hyperlink.

If you use the site, you agree not to breach its terms and if you do so, the exclusive jurisdiction clause set out in the Terms of Use makes it clear that Ireland is the appropriate jurisdiction for the purposes of litigating any disputes that may arise as a result.
The full decision isn't available online yet, but from this excerpt it may be very significant indeed.

This appears to be the first time an Irish court has ruled on whether site terms of use are enforceable, and the passage quoted seems to adopt a very wide browsewrap theory whereby visitors to a website will be bound by terms of use without any positive act on their part, provided that a hyperlink to the terms is "clearly visible". I'm not entirely sure that this result is correct - as Andres Guadamuz notes in a similar context, there are issues of acceptance and consideration in these cases - and it will be interesting to read the full decision to see whether and how these issues are considered.

The potential implications of this decision are also important. If the broad approach above is followed it would appear to have the potential to eliminate screenscraping entirely, and to enable site owners to assert exclusivity over information which is not protected by copyright or database right - in effect creating a new quasi intellectual property right and upsetting the balance created by statute. (Just witness the Dublin Bikes iPhone app case.) Hopefully if this case goes to a full hearing we will see these points raised and considered in detail.

Friday, February 19, 2010

Government departments not up in the clouds

After last week's story about the Department of Finance issuing warnings about the use of cloud computing, Sean Sherlock TD followed up by asking whether the warnings stemmed from any particular incident; whether government departments are already using cloud computing; and if so what safeguards are in place. The results are interesting: the Finance warnings don't appear to be the result of any mishap in central government as not one department is yet using cloud computing. (Though the Minister for Communications, Eamon Ryan, did say that his Department is actively promoting its use.)

Thursday, February 18, 2010

Alternative routes to identifying "anonymous" online users

David Robinson and Harlan Yu have posted a superb series of posts on Freedom to Tinker (1,2,3) about tactics which might be used to identify anonymous internet posters, even in cases where IP addresses might not have been logged by the site which hosts the comment. The key insight is that sites typically embed multiple external services (such as advertising, stats counters and video hosting) which may either individually or in combination enable the identity of particular users to be pinned down:
[P]laintiffs' lawyers in online defamation suits will typically issue a sequence of two "John Doe" subpoenas to try to unmask the identity of anonymous online speakers. The first subpoena goes to the website or content provider where the allegedly defamatory remarks were posted, and the second subpoena is sent to the speaker's ISP. Both entities—the content provider and the ISP—are natural targets for civil discovery. Their logs together will often contain enough information to trace the remarks back to the speaker's real identity. But when this isn't enough to identify the speaker, the discovery process traditionally fails.

Are plaintiffs in these cases out of luck? Not if their lawyers know where else to look.

There are numerous third party web services that may hold just enough clues to reidentify the speaker, even without the help of the content provider or the ISP. The vast majority of websites today depend on third parties to deliver valuable services that would otherwise be too expensive or time-consuming to develop in-house. Services such as online advertising, content distribution and web analytics are almost always handled by specialized servers from third party businesses. As such, a third party can embed its service into a wide variety of sites across the web, allowing it to track users across all the sites where it maintains a presence.
The traceability of any given site visitor will still depend on context: the number of third party services used by the site, the popularity of each third party service across the web, the types of identifying data that these parties collect and store, whether the speaker used any online anonymity tools, and many other site-specific factors.

Despite the variability in third party tracing capabilities, the nearly simultaneous connections to a few third party services means that the results of tracing can be combined. By sleuthing through information held in third party dossiers, logs and databases, plaintiffs in John Doe lawsuits will have many more discovery options than they had ever previously imagined.
Of course, these tactics are likely to be expensive. Also, in an Irish context the uncertainty as to whether a result will be achieved may mean that a court will be less willing to grant a Norwich Pharmacal order (which is a discretionary remedy (PDF) - not something which is available as of right). But nevertheless, the research is important - particularly as it illustrates that traditional methods of ensuring online anonymity (such as TOR routing) may be vulnerable to indirect attack.

Wednesday, February 10, 2010

Banned in Turkey: Turkish internet filtering and blocking

Banned in turkey






 Yaman Akdeniz has recently published a superb report for the OSCE on Turkey and Internet Censorship (press release | full text pdf).
 
Ironically, Yaman Akdeniz and his co-author Kerem Altıparmak have themselves been the subject of legal threats aiming to silence their criticism of Turkish internet censorship. Fortunately their book Restricted Access: A Critical Assessment of Internet Content Regulation and Censorship in Turkey (2008) is still available.

The image above is from Richard Dawkins' website, which has been blocked in Turkey since September 2008.

(Via Chris Marsden.)

Tuesday, February 09, 2010

Home Office terrorist material reporting site - some thoughts


The Home Office launched a new Directgov site last week, which "provides members of the public with information about what they can do if they come across violent extremist, terrorist and hate content online" (press release). The site takes reports and forwards them to a specialist unit within Association of Chief Police Officers (ACPO), which will take action if the material is illegal. Unsurprisingly there has been a good deal of media coverage (e.g. The Register | The Inquirer | BBC News).  So far, though, there doesn't seem to have been any assessment of how this fits into the broader matrix of internet regulation in the UK. This post asks what effect it might have.
  
Reducing the role of the IWF?

One of the more significant aspects of this story is that it appears to be the first time that the UK government has set up a specific site to which internet content can be reported. Until now, the government has effectively devolved that function to the Internet Watch Foundation (IWF). Although this is a private body, official policy has been to designate the IWF as the first port of call for online content. The Surrey Police website is typical:
If you come across offensive or illegal material, please DO NOT contact Surrey Police directly.
Instead, you can make a report on the Internet Watch Foundation (IWF) web site.
If they decide any action is needed, they will contact the ISP or the police, who can take appropriate action. (It's worth remembering that evidence of illegal or offensive material can be detected even after it has been deleted from a computer.)
The Internet Watch Foundation are qualified to judge the illegality of material and will report matters to the relevant police force. They are the only authorised organisation in the UK that provides an Internet hotline for the public to report their exposure to illegal content online.
Despite this, however, the IWF has never had a remit to receive complaints in relation to all illegal material online. For example, while there have been proposals from the Home Office that the IWF's remit should be extended to cover extremist websites, these have never come to fruition. Similarly, when the Terrorism Act 2006 created a system of notifying ISPs to take down terrorist material, that system bypassed the IWF entirely and required that notices be given via the police.

Consequently, the setting up of this site may be significant - does it indicate a trend which moves away from government reliance on the IWF and towards the use of separate (and public) reporting mechanisms?

Content control as a means of protecting vulnerable people?

The rhetoric used in announcing the site is also interesting. According to Lord West:
We want to protect people who may be vulnerable to violent extremist content and will seek to remove any unlawful material.
If this sounds familiar, that's because it echoes the justifications for introducing the Cleanfeed child abuse image blocking system and later for criminalising extreme pornography - in each case, a central component was the argument that harm would be caused to the viewer (by simply viewing the material, or by predisposing them to commit crimes). Is this approach - focusing on harm to the viewer - becoming more common in controlling content in the UK?

Using consumer pressure as a regulatory tool?

Quite apart from illegal content, the site also sets out to encourage users to challenge content which is  legal. According to Lord West:
This is also about empowering individuals to tell them how they can make a civic challenge against material that they find offensive, even if it is not illegal.

The internet is not a lawless forum and should reflect the legal and accepted boundaries of society.
Consequently, the site provides information on how to make complaints:
What you can do about online hate or violence that is not illegal

Most hateful or violent website content is not illegal. While you may come across a lot of things on the internet that offend you, very little of it is actually illegal.

UK laws are written to make sure that people can speak, and write, freely without being sent to prison for their views.

To be illegal, the content must match the descriptions at the top of this page.

Still, even if what you’ve seen does not seem to be illegal, you can take the steps below to have it removed if it upsets, scares or offends you.

Report it to the website administrator

Most websites have rules known as ‘acceptable use policies’ that set out what cannot be put on their website. Most do not allow comments, videos and photos that offend or hurt people...

If what you’ve seen is on a site with a good complaints system, you should report it to the website’s owners. Look out for their ‘contact us’ page, which should be clearly linked...

Report it to the hosting company


If the website itself is hateful or supports violence or terrorism let the website’s hosting company know. Hosting companies provide a place where the website sits, and often have rules about what they are willing to host.

Let the hosting company know they are hosting a website that breaks their rules, and ask them to stop.

You can find out which company hosts a website by entering their web address on the ‘Who is hosting this?’ website.
This approach - by encouraging community pressure to force ISPs to change their behaviour - matches policy in relation to blocking, where the Home Office has abandoned plans to legislate and has instead stated its intention to rely on public pressure instead:
For the first time the IWF will publish the list of ISPs who are certified as having implemented its blacklist. "Hopefully consumer and public pressure will encourage the ISPs who aren't on the list to comply," said Carr. A Home Office spokesman said: "We will continue to urge ISPs to implement blocking, and ask consumers to check with their suppliers that they have done so."
Does this mark the start of a trend towards greater use of consumer pressure by the UK government as a means of regulating what ISPs do?

Monday, February 08, 2010

Cloud computing complications

Not too long ago the Taoiseach and the Green Party were telling us that cloud computing is the way of the future for Irish business. Now it emerges that the Department of Finance has emailed government departments and public bodies warning about the risks of cloud computing. Is this a case (as some amused observers are saying) of the left hand not knowing what the right hand is doing? Or, as some sectors of the Irish technology industry are putting it, simple technical ignorance?
A Microsoft spokeswoman said that Ireland should "embrace the cloud across all aspects of public services".

"Microsoft’s software plus services offering provides enhanced security for data over and above what has traditionally been available for private and public organisations, and this is one of the primary reasons why so many public and private organisations across the globe are beginning to deploy solutions in the cloud."

Ed Byrne, general manager of Hosting 365, which provides cloud computing services, described the e-mail as "damaging" and showed a "lack of knowledge" of what the technology involves.

The technology is "mature and not nascent" said Philip Nolan, a partner in legal firm Mason Hayes + Curran. He said any contractual issues were surmountable, and he has large clients who use cloud computing for their core systems.
So are these criticisms justified? While it's understandable that providers might be defensive, these responses seem out of place given the very moderate tone of the original email, which is not a blanket ban on the use of cloud computing but simply a reminder to take legal advice before buying these services:
The Department of Finance has warned Government departments and public sector bodies that they should not purchase cloud computing services without obtaining legal advice.

The warning e-mail, which carries the subject "cloud computing warning", says that the Chief State Solicitor’s Office has "advised that issues such as data protection, confidentiality and security and liability are not necessarily dealt with in a manner that would be necessary for public sector responsibilities".
Far from being ignorant of the nature of cloud computing, this seems to show a good awareness of the challenges it can present. As Simon McGarr points out in today's Irish Times, unless properly thought out in advance cloud computing may result in the transfer of personal information outside the EU and in inadequate security measures being put in place by data processors. Suitable contracts can deal with these risks - but not all cloud computing providers (particularly those headquartered outside the EU) seem to be fully aware of their responsibilities under European data protection law, making detailed legal advice essential in all cases.

In addition, public sector storage of data presents further problems which are distinct from those faced in private sector use of cloud computing. For example, how will the public body ensure that data held in the cloud is available to meet a Freedom of Information Act request? How will departmental records held in the cloud be preserved and archived as required by the National Archives Act 1986? Will data in the cloud be sufficiently searchable as required by the Reuse of Public Sector Information Regulations? These and other complications make the advice from the Department of Finance seem eminently reasonable.

Update (27.02.10) - Microsoft's new secure cloud product for the US government shows some of the ways in which cloud computing products may have to be tailored for public sector use.

Friday, February 05, 2010

Please forgive the technical problems...

As you might have noticed, I'm changing the look and feel of the blog at the moment: something that requires migration from FTP to hosting with Google; updating the zone file for the domain; and all sorts of other technical shenanigans. Apologies in advance for the inevitable glitches. Normal service should be resumed shortly.

Sunday, January 31, 2010

Irish blogger agrees €100,000 settlement for libel

The Sunday Times has details of the settlement which was obliquely mentioned in Forbes last week:
A blogger has agreed a €100,000 settlement after libelling Niall Ó Donnchú, a senior civil servant, and his girlfriend Laura Barnes. It is the first time in Ireland that defamatory material on a blog has resulted in a pay-out.

Barnes, an American book dealer, made a profit of up to €800,000 in 2005 from selling a cache of James Joyce papers to the state. One year later she began a relationship with Ó Donnchú, an assistant secretary in the Department of Arts, Sports and Tourism.

In December 1, 2006, a blogger who styles himself as Ardmayle posted a comment about the couple and the sale of the Joycean manuscripts under the headline “Barnes and Noble”. Following a legal complaint, he took down the blog and in February 2007 he posted an apology which had been supplied by Ó Donnchú’s and Barnes’ lawyer, Ivor Fitzpatrick solicitors.

“I subsequently discovered that these remarks were inaccurate,” Ardmayle said. “I unreservedly apologise to both Laura Barnes and Niall Ó Donnchú in respect of this post.”

However, the pair subsequently issued separate proceedings. It is understood that the €100,000 settlement was agreed shortly before the case was due before the High Court. A full defamation trial before a jury can cost €700,000-€800,000 in legal costs for both parties.

The blog, still active at http://ardmayle.blogspot.com/, is in the form of a personal diary with observations on the arts, literature and sport. The author is not identified, and the litigants may have got his details through his internet server provider (ISP).

The settlement was subject to a confidentiality agreement, which forbids the blogger from speaking about it publicly. Neither Ó Donnchú nor Barnes responded to invitations to comment.
The Independent has more on the case from 2007 when proceedings were issued, and Sean Murphy has also produced a summary of the issues involved.

One interesting aspect of this case, as Mark points out, is the fact that the damages appeared to be quite high given that the blog in question was very low profile:
John Burns’s piece in today’s Sunday Times on the blogger who paid out €100,000 for libeling someone is interesting, and not just for bloggers. The blog which is the subject of the story is so obscure that Google finds zero – repeat zero – inward links. This is despite it having been operational since May 2005 (contrast that with TheStory; we’ve only been going since October or so, yet there are over 800 inward link results to the front-page alone). Additionally, the writer’s profile has only been viewed 3,000 times since the blog opened – or less than once per day.

So it’s a little-known, to say the least, blog.
Leaving aside the specifics of the case, perhaps this illustrates a more general point highlighting the importance of keeping good server logs.

The level of damages in defamation reflects the extent of publication – i.e. the extent to which the defamatory material was actually read. This is not (despite the best efforts of plaintiffs’ lawyers) the same as the extent to which it might have been read. Consequently (leaving aside other factors such as the gravity of the allegations) damages should be greatly reduced where the audience can be shown to be negligible. Potential readability worldwide notwithstanding.

Unfortunately, in the absence of server logs, it is going to be very difficult to rebut a plaintiff who claims that the material appeared quite high in search engine rankings, may have been read worldwide, etc. Consequently a defendant in that position is likely to be on the back foot, especially where a judge assumes that availability online automatically equals a mass audience.

Friday, January 29, 2010

Net Neutrality book now out

I've been looking forward to reading Chris Marsden's new book Net Neutrality and am glad to see that it's now been released by Bloomsbury - with a free download (PDF) under a CC licence being the icing on the cake. This passage gives a sense of the perspective he takes:
The network neutrality debate is only in part about economics and technology, despite what you might surmise from various pro-competitive statements by academics and the shape of the US and European debates. The extent to which even lawyers have been drawn into an open-ended debate regarding the merits of duopoly versus inset competition in telecoms, or the relative merits of open interoperable software environments versus proprietary property rights-based or corporate developments, or the benefits of end to end ‘dumb’ networks versus intelligent networks, displays the capture of the subject by economists and corporate technologists. The issues at stake are more fundamental to society than that. As a lawyer who has written for over a decade in favour of pro-competitive telecoms and media policy, I am not ashamed or abashed to state that I emphasize that communications policy is about fundamental rights of citizens as well as public welfare for consumers, and that it is about educated and informed users as well as optimally priced access networks. [Emphasis mine.]
Strongly recommended.

Saturday, January 16, 2010

Sexting and the law in Ireland

I was quoted in the Daily Mail recently in a story about a supposed increase in sexting by Irish children. The reporter was interested in the possible criminal liability of children who send and receive sexual images - something which featured only to a small extent in the story - and I thought it might be useful to jot down some more observations about the surprisingly complex law in this area.

(i) When will a "sext" amount to child pornography?

The most important legislation on this point is the Child Trafficking and Pornography Act 1998. Consequently, the first question we must ask is whether sexts will amount to child pornography prohibited under that Act.

In relation to particularly explicit images, section 2 makes it clear that images of a child "engaged in explicit sexual activity", or images which focus on the "genital or anal region" will constitute child pornography.

What about less explicit images? Might e.g. a topless photo constitute child pornography? Possibly. Under section 2, child pornography includes images relating to a child that "indicates or implies that the child is available to be used for the purpose of sexual exploitation". Sexual exploitation is in turn defined in section 3 to includes inducing a child to "participate in any sexual activity which is an offence under any enactment". Consequently, even a less explicit image might amount to child pornography if it implies that a child is available for (illegal) sexual activity.

(ii) Is there a "Romeo and Juliet" defence?


Suppose a 16 year old girl takes an explicit picture amounting to child pornography and texts it to her 16 year old boyfriend. Might the boyfriend be liable for the offence of possession of child pornography, contrary to section 6?

Yes. The 1998 Act (in common with other areas of Irish criminal law - consider this case involving a 15 year old boy and a 14 year old girl) doesn't recognise a so-called Romeo and Juliet defence in relation to sexual activities between children of similar ages. One might hope that in this scenario prosecutorial discretion would prevail and no prosecution would be brought - but on the face of it a crime would have been committed.

(iii) Can the person taking and sending the sext be prosecuted?

Maybe. Section 5 of the 1998 Act creates an offence of knowingly producing or distributing child pornography which on the face of it would seem to cover the actions of children who take photos of themselves and then send them to others. Children in other jurisdictions have been charged with offences in this situation.

The Act itself doesn't provide a defence for a child in this position, unlike other legislation dealing with child sexual offences. For example, Section 5 of the Criminal Law (Sexual Offences) Act 2006 provides that "A female child under the age of 17 years shall not be guilty of an offence under this Act by reason only of her engaging in an act of sexual intercourse."

Would it be possible to read such a defence into the law, arguing perhaps that the child is the person intended to be protected by the legislation and as such it would be inappropriate to criminalise their actions? Possibly - but at this point we might be entering uncharted waters.

The common law does recognise a general principle against criminalising the victim, a rule often traced to R v Tyrell (1894) 1 QB 710 where it was held that a girl could not be guilty of aiding and abetting a male to know her carnally. In that case, Lord Coleridge CJ famously said that an Act could not have "intended that the girls for whose protection it was passed, should be punished under it for the offences committed against themselves". This has since been accepted as a wider principle - see e.g. Hallevy's interesting article on this point.

The difficulty with that principle, however, is that it generally applies where there are two or more parties involved in the commission of the criminal act - but I'm not aware of any authority applying it to the case of a single perpetrator who is simultaneously the victim. It should certainly apply where A (a child) consents to B taking explicit pictures - but it may be more difficult to argue that it should apply where A takes and sends the pictures. In that situation, could it be said that A is the victim of their own activity, so that the Tyrell principle should apply?

Any answer to that question might also be influenced by policy considerations. It could be argued, for example, that it is desirable to impose possible criminal liability in order to deter children from doing something which may result in their being further victimised in the future; it might also be said that an effective exemption for "self-produced" child pornography could hamper criminal investigations.

These thoughts merely scratch the surface of this area. Mary Graw Leary has more on the difficult problem of sexting and "self-produced" child pornography in this nuanced article, while Radley Balko has a rather different (and to my mind more convincing) argument at Reason.

Tuesday, January 12, 2010

Why IP addresses are no longer enough to identify internet users

Richard Clayton has an excellent post explaining (in terms even a lawyer can understand) why the traditional formula of IP address plus timestamp is increasingly inadequate as a way of identifying internet users:
The basics are that you record an IP address and a timestamp; use the Regional Internet Registry records (RIPE, ARIN etc) to determine which ISP has been allocated the IP address; and then ask the ISP to use their internal records to determine which customer account was allocated the IP address at the relevant instant. All very simple in concept, but hung about — as the thesis explained — by considerable caveats as to whether the simple assumptions involved are actually true in a particular case.

One of the caveats concerned the use of Network Address Translation (NAT), whereby the IP addresses used by internal machines are mapped back and forth to external IP addresses that are visible on the global Internet. The most familiar NAT arrangement is that used by a great many home broadband users, who have one externally facing IP address, yet run multiple machines within the household.

Companies also use NAT. If they own sufficient IP addresses they may map one-to-one between internal and external addresses (usually for security reasons), or they may only have 4 or 8 external IP addresses, and will use some or all of them in parallel for dozens of internal machines.

Where NAT is in use, as my thesis explained, traceability becomes problematic because it is rare for the NAT equipment to generate logs to record the internal/external mapping, and even rarer for those logs to be preserved for any length of time. Without these logs, it is impossible to work out which internal user was responsible for the event being traced. However, in practice, all is not lost because law enforcement is usually able to use other clues to tell them which member of the household, or which employee, they wish to interview first.

Treating NAT with this degree of equanimity is no longer possible, and that’s because of the way in which the mobile telephone companies are providing Internet access.

The shortage of IPv4 addresses has meant that the mobile telcos have not been able to obtain huge blocks of address space to dish out one IP address per connected customer — the way in which ISPs have always worked. Instead, they are using relatively small address blocks and a NAT system, so that the same IP address is being simultaneously used by a large number of customers; often hundreds at a time.

This means that the only way in which they can offer a traceability service is if they are provided with an IP address and a timestamp AND ALSO with the TCP (or UDP) source port number. Without that source port value, the mobile firm can only narrow down the account being used to the extent that it must be one out of several hundred — and since those several hundred will have nothing in common, apart from their choice of phone company, law enforcement (or anyone else who cares) will be unable to go much further.
Edited to add (14.01.10):

In two follow up posts, Richard explains what this means for data retention rules (arguing that the IP address only approach of the Data Retention Directive is flawed) and considers the practicalities of identifying mobile internet users.

Sunday, January 10, 2010

Children's hospital lost data on 1m patients

In a follow up to his excellent story about Temple Street Children's Hospital storing DNA samples of over 1.5 million people without any legal basis, Mark Tighe has a piece in today's Sunday Times revealing that the hospital also lost two servers full of information about patients in 2007:
Two computer servers containing the records of almost 1m patients were stolen from the Children’s University hospital in Temple Street in 2007 and have never been recovered.

The data were far more than that lost on stolen bank laptops in recent years. The theft was investigated by the data protection commissioner (DPC) and the gardai after being reported by the Dublin hospital in February 2007. The organisations had decided that there was no need to inform the public, believing there was little chance of the thief being able to access the data.

Patients’ details, including names, date of birth and reason for admission are thought to have been included.
Interestingly, there's no mention of the servers having been encrypted, making it unclear on what basis it was decided that the data couldn't be accessed.

There's also an update indicating that there has already been some official interest in accessing the DNA records:
In Australia and New Zealand, hospital databases have been accessed by police using DNA in their investigations.

Asked if it had allowed gardai access to the database, Temple Street said it had “one tentative enquiry” by an agency but this was not followed up.

"Our patient confidentiality policy will continue to dictate the response and no access to samples will be granted," a spokeswoman said.

Tuesday, January 05, 2010

Revenue set up VIP unit (but don't the little people deserve privacy too?)

One recent story which didn't attract as much attention as it should have was the revelation that the Revenue have set up a special VIP unit to minimise leaks of confidential information about public figures. This emerged with the publication of an audit by the Data Protection Commissioner which found significant weaknesses in Revenue controls of data. (Weaknesses which still existed despite promised reforms after high profile scandals in 2005 and again in 2007.)

There's a lot of interesting material in that audit, but the VIP unit might well be the most significant. Although spun as a privacy friendly measure, it reflects a trend whereby in relation to privacy there is one law for them and one law for us. It would be unfortunate if this establishes a precedent for two tier protection in other departments also. Call me a cynic, but I suspect that effective privacy protection will only come about if the political classes find themselves exposed to the same risks as the rest of us.

Monday, December 28, 2009

Reform of search warrants must take electronic searches into account

The Law Reform Commission has just published a consultation paper on search warrants and bench warrants. In relation to search warrants it points out there is currently a bewildering array of statutory provisions (over 100 different Acts and Regulations) which deal with searches, with different procedures to be followed and different powers of search and seizure in each case. The consultation paper aims, amongst other things, to rationalise the law in this area, and seeks to put in place a single statutory framework.

Surprisingly, though, the consultation paper has almost nothing to say about searches of computers and data. In fairness, it does note that there are some existing (rather patchy) provisions which specifically deal with computer searches - such as the power to require passwords in s.48 of the Criminal Justice (Theft and Fraud Offences) Act 2001. It also makes a very brief reference to the need for specialist forensic examination of seized computers. However it fails to consider any of the difficulties which have emerged when traditional norms are applied to data, much less current proposals which would fundamentally rewrite the law in this area.

To take just a few examples: there is no recognition of the vast quantities of personal data which are often stored on computers, making searches particularly privacy invasive in a way which is not generally true elsewhere. On a similar note, the consultation paper fails to recognise that the effect of seizing a computer and data can often be to shut down a business or to seriously disrupt an individual's life, and that this can often be mitigated by returning a copy of the seized data. There's no analysis of how extensive searches of data should be - if, for example, a computer is seized on suspicion of fraud offences should it be permissible to automatically scan the hard drive to detect possible child pornography images? (These and many other issues have been extensively analysed by Orin Kerr in several excellent articles, including Search Warrants in an Era of Digital Evidence and Searches and Seizures in a Digital World.) Similarly, there's no mention of so-called remote searches (police hacking into computers at a distance), despite the fact that these have been the subject of recent EU proposals.

These and other issues will have to be addressed if the Law Reform Commission analysis is to deal with computer searches adequately in a way which protects privacy - if you're interested in bringing any of these issues to their attention, you can email them at info@lawreform.ie or make a submission via snail mail using the details on this page.

Sunday, December 27, 2009

Temple Street Hospital holding a de facto national DNA database?

Today's Sunday Times reports that the Temple Street Children's Hospital has kept blood samples of almost every newborn in the country since 1984 - without the consent or knowledge of their parents - and has kept those samples indefinitely. The details are remarkable:
A DUBLIN hospital has built a database containing the DNA of almost every person born in the country since 1984 without their knowledge in an apparent breach of data protection laws.

The Children’s University hospital in Temple Street is under investigation by the Data Protection Commissioner (DPC) since The Sunday Times discovered it has a policy of indefinitely keeping blood samples taken to screen newborn babies for diseases.

Unknown to the DPC, the hospital has amassed 1,548,300 blood samples from “heel prick tests” on newborns which are sent to it for screening, creating, in effect, a secret national DNA database. The majority of hospitals act on implied or verbal consent and do not inform parents what happens to their child’s sample.

The blood samples are stored at room temperature on cards with information including the baby’s name, address, date of birth, hospital of birth and test result. The DPC said it was shocked at the discovery.

On four occasions the hospital has allowed scientists from a university and other hospitals to access the Newborn Screening Cards (NSCs) for research purposes. This was done on the basis of anonymity but without the consent of parents and followed approval by the hospital’s ethics committee.

The DPC is now engaged in urgent discussions with the hospital, the Health Service Executive (HSE) and the Department of Health to force the hospital to comply with data protection legislation by January. The DPC could order the destruction of the records if it is not satisfied the hospital is taking the necessary actions.

“Clearly it is a matter of significant concern to us that holding data of this nature containing sensitive health details of such a significant portion of the population appears to have operated without taking account of data protection requirements,” said Billy Hawkes, the DPC commissioner.

“The issue of the justification for the holding of the blood samples for any period beyond that which is necessary to perform the initial blood test will have to be considered as part of this office’s investigation of this matter. At present the position would appear to be that there is no consent from parents for the information to be held at all.”
Similar de facto databases have been created in this accidental manner in other jurisdictions - in Australia and New Zealand for example - where they have been extremely controversial and have had safeguards imposed. In Western Australia, police began to use these databases without consent in criminal investigations, causing hospitals to destroy existing databases and to change medical practice to store samples for a two year period only. In New Zealand, meanwhile, the practice is that parents are fully informed as to the purpose for which samples are taken and stored, and have the right to have the sample returned to them once the testing is completed, and the privacy implications of this database are currently under review.

In light of these controversies elsewhere, the lack of informed consent and the fact that there is no legal basis for the heel prick tests (a point confirmed in North Western Health Board v. HW and CW) it's hard to see how Temple Street could have believed that it was entitled to hold onto these samples indefinitely - and it is remarkable that this point appears to have been missed by the ethics committee on four separate occasions.

Thursday, December 10, 2009

Consultation Paper on Electronic Evidence to be published today

The Law Reform Commission will be publishing a Consultation Paper on Documentary and Electronic Evidence today. The Irish Times has a summary of the contents:
The LRC states that in general there be no difference between the rules concerning manual or computer-generated documents and records; all business records, whether manual or computer-generated, should in general be presumed to be admissible and that the Bankers’ Books Evidence Act 1879, which allows banking records to be admitted as evidence in court, should be updated and extended to apply to records from all financial institutions.

For mechanically generated recordings, such as videos or CCTV, it should be clarified that any defects in their quality should not rule them inadmissible but should be simply a question of the weight given to the recording.

It also recommends that an expert group be established to develop standards and guidelines for the verification of electronic and digital signatures, and that the existing law which presumes that “public documents” are admissible should be updated, because much of the relevant legislation predates the foundation of the State.

Tuesday, December 08, 2009

Hosting defence applies to user comments: English High Court

In a significant decision, Karim v. Newsquest Media Group, Eady J. has accepted that online newspapers can rely on the E-Commerce Directive hosting defence in respect of user comments, meaning that they should generally be exempt from liability in respect of those comments provided that they take them down when notified that they are potentially defamatory.

The plaintiff in this case was a solicitor who had been struck off following mishandling of client funds. The defendant's websites reported the proceedings before the Disciplinary Tribunal in an article titled "Crooked solicitors spent client money on a Rolex, loose women and drink", and a number of users made further allegations about the plaintiff in the comments attached to the article. The defendant took exception to both the article itself and the user comments and issued proceedings against the defendant without prior notice. On receiving the proceedings, the defendant took down the articles and comments the same day.

The plaintiff's case comprised two components - the article and the attached user comments - and the defendant applied for summary judgment in respect of both.

As regards the article, the court had no difficulty in finding that it was covered by absolute privilege as a fair, accurate and contemporaneous report of legal proceedings under s.14 of the Defamation Act 1996, and that portion of the claim was struck out.

As regards the user comments, the defendant argued that it was protected by the hosting defence, as transposed into UK law by Regulation 19 of the Electronic Commerce (EC Directive) Regulations of 2002. This provides:
Where an information society service is provided which consists of the storage of information provided by a recipient of the service, the service provider (if he otherwise would) shall not be liable for damages or for any other pecuniary remedy or for any criminal sanction as a result of that storage where -

(a) the service provider -

(i) does not have actual knowledge of unlawful activity or information and, where a claim for damages is made, is not aware of facts or circumstances from which it would have been apparent to the service provider that the activity or information was unlawful; or

(ii) upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information, and

(b) the recipient of the service was not acting under the authority or the control of the service provider.
Although no authority was cited on this point, Eady J. stated that he was "quite satisfied" that the defendants could rely on this defence, going on to hold that the users were not acting under the "authority or control" of the defendant. This portion of the claim was therefore struck out also.

This appears to be the first time that an English court has dealt with this question, though it reaches the same result as the Irish decision in Mulvaney v. Betfair (t/a The Sporting Exchange).

As with that decision, it is good news for online publishers dealing with user-generated content, suggesting that the courts will adopt a wide interpretation of the hosting defence. But as with Mulvany v. Betfair, it might be unwise to celebrate yet. This is a first instance decision (albeit a decision of one of the most prominent judges in this field) and was based on the arguments of one side only. It does not consider the arguments which might be put forward to limit the hosting defence, and rather glosses over the question of whether posters in a moderated forum could be said to be acting under the authority or control of the host.

Experience from the US has shown that online immunities tend to be extensively challenged as plaintiffs seek to work around them. Section 230 of the Communications Decency Act has, in particular, been repeatedly litigated and occasionally evaded by plaintiffs. (Eric Goldman analyses some of the approaches taken by plaintiffs: 1|2|3.) It's safe to say that similar challenges to the hosting immunity are likely in Europe until such time as the European Court of Justice issues a definitive interpretation of its scope.

(Via The Register)

EU guidance on unfair commercial practices - confirms rules apply to social networking, blogs

The Commission has just published a lengthy working document (PDF) with guidance on the application of the Unfair Commercial Practices Directive. This confirms that the Directive applies to blogs and social networking sites and gives some examples of banned practices - such as the use of fake comments or "astroturfing":
Social media, which include blogs, social networking sites, have become important avenues for commercial practices, especially hidden ones. They are sometimes used by traders to promote and advertise their products.

For example, several Member States have reported that cosmetic companies have paid bloggers to promote and advertise their products on a blog aimed at teenagers, unbeknownst to other users. In such cases, the authorities considered that the bloggers concerned were engaging in hidden commercial practices.

Unfair commercial practices may also occur on price comparison websites. An obvious case is when an online price comparison service belongs or is linked to a trader and is used to advertise its products. For example, the site "quiestlemoinscher.com" (literally "whoisthecheapest.com"), a grocery price comparison service created by a French major supermarket company, was considered by French courts to be a trader's website and a tool for comparative advertising...

[T]he Directive tackles the particular situation of "hidden" traders or traders representing themselves as consumers. Under Annex I of the Directive (the "black list"), the following practice is prohibited in all circumstances: Falsely claiming or creating the impression that the trader is not acting for purposes relating to his trade, business, craft or profession, or falsely representing oneself as a consumer.

For example, "hidden" traders may be:
– a hotel website including flattering comments supposedly by consumers which are actually drafted by the hotel owner;
– a bookshop advertising its "customers' choice" books where customers have never been consulted and the choice is made by the bookseller.
Of course, none of this should come as any suprise to Irish readers. The Directive was implemented in Ireland by the Consumer Protection Act 2007, and both Daithi and Damien had good posts around that time pointing out that the Act would prohibit businesses from posing as consumers or (covertly) paying bloggers to post about them.

Responsibility for enforcing the Consumer Protection Act lies with the National Consumer Authority. Given how common fake comments have become, I'm surprised that they haven't put out any guidance on this topic. It may be that it will take a complaint from an annoyed blogger (is there any other type?) or forum moderator before they take any action in this area.

Incidentally, it must be said that the approach taken by the Directive and national law (which is limited to paid posts or "advertorials") is much more sensible than the approach which the FTC has taken in the United States, where it now requires bloggers and twitterers to post details of any supposed conflict of interest - even a review copy of a book! - on pain of a $11,000 fine. Jack Shafer has more on the FTC rules (PDF).

Monday, December 07, 2009

Time for national steps to tackle cybercrime

The Irish Times has a good report of the recent IRISS Conference on Cybercrime. The comments of Paul Gillen were particularly interesting:
Det Insp Paul Gillen, head of the Garda computer crime investigation unit, said he was very concerned about the possibility of distributed denial-of-service attacks against Irish sites.

"I’m scared that Ireland will suffer what Estonia suffered," he said, referring to incidents in April and May 2007 when many Estonian government websites and critical systems were taken offline. "Ireland’s capability to react to something like that would worry me," said Det Insp Gillen...

Despite newspaper reports and regular warnings from banks, the phishing problem has got worse, added Det Insp Gillen. "We still have people who are willing to sit down and give their user name and password and are willing to write 100 PIN numbers from a code card that the bank gave them – and then they’ll go back to check they’re the right ones," he said. "Somewhere along the way, we’re obviously failing at getting the information out to the general public to make them more aware of hi-tech crime."

According to Det Insp Gillen, phishing scams usually happen in four stages: the hack is performed to infiltrate a person’s PC and steal their login details, or else the victim is tricked into revealing their pass codes by an e-mail that seems to have been sent by their bank. Criminals then gain access to the person’s bank account over the internet and use the codes to transfer money to an account in another part of the country.

Gangs then use "money mules" – other people who withdraw funds from ATMs. "The money mule is the first person to raise their head above the trench to have the back of their collar grabbed,” said Det Insp Gillen, who said gardaí have had some success stopping this.

"Everyone in this structure receives a percentage of the take in the crime," he said. "We’re dealing with highly organised crime here. The only way we’re in a position to deal with it is if IT security professionals, academics, law enforcement and a Cert join into a community to develop a task force, because everyone has information that could be a piece of evidence."
So what is currently being done to deal with the problems identified at the conference?

One promising development took place in August when the Minister for Communications announced that a report outlining a national cyber security strategy would be in place by the end of the year. (According to the Press Office in Communications, the report is currently being finalised.)

On the legislative front, however, the picture is gloomier. Irish law still has no general offence to deal with denial of service attacks (PDF) or online interception and implementation of the Cybercrime Convention and the Framework Decision on Attacks Against Information Systems is long overdue.

There is a Criminal Justice (Cybercrime and Attacks against Information Systems) Bill on the legislative agenda - but there's no date given for when we might see a draft. Given that we were initially promised implementing legislation in 2003 (PDF, p.25) and again in 2006, one might be forgiven for being sceptical as to whether any reform of the law relating to cybercrime will take place in the lifetime of this Government.

Wednesday, December 02, 2009

Software development agreement did not transfer copyright

OUT-Law have a report of an interesting recent English case - Infection Control Enterprises Limited v Virrage Industries Limited and Aidan Cartwright [2009] EWHC 2602 (QB) - concerning ownership of commissioned software which was intended for resale by the client. As is increasingly the trend, the client didn't succeed in their claim that there was an implied term that they would acquire the copyright.

I discussed the legal issues involved in these types of cases in a 2007 article in the Journal of Intellectual Property Law & Practice - "Copyright in Custom Code: Who Owns Commissioned Software?" Fortunately this decision doesn't appear to have proved me wrong.

Thursday, November 19, 2009

Telenor Pirate Bay blocking decision - English translation

In an important (but surprisingly poorly publicised) decision two weeks ago a Norwegian court dealt a blow to music industry attempts to force ISPs to police their users, holding that Telenor was under no obligation to block access to The Pirate Bay. An English translation of that decision is now available (PDF link) and makes interesting reading. One particularly significant portion of the ruling stresses that it is not appropriate to assign a censorship function to private entities, and that if filtering is to be required then legislation would be necessary:
If the plaintiffs' claim is heard, this will, in the court's view, give a situation difficult to handle in practice. Reference is made to the fact that the content on The Pirate Bay, and also other websites, can be changed and is in fact constantly being changed. The court further states that Telenor as an Internet provider does not have a duty to monitor or investigate what Internet is used for, so that the Internet providers must be notified of alleged illegal actions. Thus, Telenor and other Internet providers, as private companies, must assess whether or not to stop a relevant website or service. This task normally belongs to public authorities, and the court finds that in the present situation, it is unnatural to assign such responsibility to private companies. If this solution is to be chosen, a closer study will be required. As we have been informed, the Ministry of Culture and Church Affairs has already initiated a legislation process on these matters.

Saturday, November 14, 2009

BT Ireland caves in on "three strikes" demands?

According to today's Irish Times the music industry's litigation against BT Ireland has been settled. Terms of the agreement weren't revealed, but my assumption would be that BT have agreed to implement a three strikes system for disconnecting users accused of filesharing, following the Eircom model. Surprisingly however there hasn't yet been a press release from IRMA or BT. Does anyone have more information?

Edited to add: Thanks to the anonymous commenter for pointing out that this simply follows BT's deal to move its consumer division to Vodafone.

Sunday, November 08, 2009

Irish law on hacking tools / dual-use software

In my last post I mentioned the iPhone dessid app which generates WEP keys from the SSIDs of Eircom routers - making life easier for individuals who wish to piggyback on the wifi of others.

What are the legal issues associated with using or providing this app? Unsurprisingly media coverage of the software has reported that unauthorised access to wifi may constitute a criminal offence, something Eoin O'Dell has previously teased out in a series of posts (1|2|3).

A more difficult question however - and one which hasn't yet been considered - is whether simply providing the app might itself constitute a criminal offence.

So called hacking tools have been specifically criminalised in some jurisdictions. In the UK for example section 37 of the Police and Justice Act 2006 (which was eventually brought into force in October 2008) amended the Computer Misuse Act 1990 to create a new offence of making, supplying or obtaining articles for use in computer misuse offences - an offence which would be committed where a person supplies a program "intending it to be used" or "believing that it is likely to be used" in an unauthorised access offence.

That offence is wide enough to capture dual-use tools - programs such as this one which have legitimate as well as criminal uses - and consequently the Crown Prosecution Service has issued guidelines to prosecutors in relation to when prosecutions should be brought, looking at factors such as whether software is "available on a wide scale commercial basis and sold through legitimate channels", is "widely used for legitimate purposes", is "circulated to a closed and vetted list of IT security professionals or [is] posted openly" or has been "developed primarily, deliberately and for the sole purpose of committing" an offence.

Unsatisfactory though the UK law and guidance might be (a point made by, amongst others, Richard Clayton) it does at least attempt to legislate specifically for computer crime. Irish law on the other hand has no offence specifically tailored for this situation, leaving us to wonder whether new situations might be forced within the confines of old offences. I wrote about this point recently for Reich (ed.), Cybercrime and Security, and here's a short excerpt:
While Irish law does not specifically deal with these matters, it may be possible to prosecute in individual cases using section 4 of the Criminal Damage Act 1991. That section provides:
“A person (in this section referred to as the possessor) who has any thing in his custody or under his control intending without lawful excuse to use it or cause or permit another to use it— (a) to damage any property belonging to some other person … shall be guilty of an offence.”
Bearing in mind that the definition of property under the 1991 Act includes data, this section would seem to be wide enough to criminalise possession of e.g. a virus or Trojan horse where accompanied by an intention to damage property. It should, however, be noted that this section does not criminalise creation, possession, sale or distribution per se – in every case it must be shown that the defendant had an intention to use the item to damage property. This appears to create two related problems for prosecutors. From an evidential point of view it is likely that they will face a difficulty in demonstrating that an accused person had the necessary intention. Moreover, the intention which must be shown is an intention to damage property – a mere intention to carry out an unauthorised access would not suffice. If, for example, A were found to be in possession of a username and password belonging to B, this would not be an offence under section 4 if A’s intention was merely to view B’s data.
Applying this analysis to the dessid app, it seems to me unlikely that distributing this or similar software would be an offence under section 4. First, that section requires an intention to cause or permit a person to use it to commit an offence. Mere foresight that an offence might be committed would not seem to be enough. Secondly, section 4 applies only to things to be used for the purpose of criminal damage - so that distribution of software for some other illegal purpose (such as unauthorised access) would not fall within its remit. (A further obstacle might lie in the narrow wording of section 4 - is software a "thing" within the meaning of that section?)

Friday, November 06, 2009

Unauthorised access? There's an app for that

APPLE IS benefiting from sales of a piece of software that provides free access to up to 250,000 home broadband networks without the owners’ knowledge.

The software for Apple iPhones, called “dessid”, which costs €1.59, exploits a flaw in the hardware Eircom provided to its broadband customers and which first came to light in September 2007.

The problem occurred because each Eircom customer’s wireless network broadcast a unique eight-digit code as its network name. The password was derived from these digits.
To my mind, the real issue behind this Irish Times story is not that you can buy an app which allows you to piggyback on the wifi of Eircom customers (there's a handy web page that will still work even if Apple pulls the program from the app store) - instead it's that Eircom have agreed to disconnect users accused of filesharing, despite knowing full well that their own wireless modems are insecure and that people will be wrongfully disconnected as a result.

Sunday, October 18, 2009

Data breach consultation paper now out

The Data Protection Review Group has now published a consultation paper (pdf) on reforming Irish law on notification of data breaches. Pages 33-38 on possible regulatory options are particularly useful, though the group is clearly hampered by the fact that any national reforms might soon be out of date as a result of changes at European level.

Garda databases still open to abuse?

From today's Sunday Business Post:
A garda undermined a series of major anti-crime surveillance operations by passing details of car registrations belonging to undercover detectives onto a gang of armed robbers.

The garda is the subject of an internal investigation which is looking into a number of officers who are suspected of being on the payroll of separate Dublin criminals. The garda was in regular contact with a crime figure who is facing charges related to serious criminal activity.

When the criminal gang suspected that they might be under surveillance, they supplied the garda with a list of car registrations they had encountered. The garda checked the car details on the force’s Pulse IT system and informed the gang if the cars were part of the Garda fleet.

In several cases, the garda was able to identify vehicles that were being used by an undercover Garda unit. To avoid detection, the officer got junior uniformed gardaí to log into the Pulse system using their own passwords - as the system records a digital imprint of every log-in by a member using their unique password, The Sunday Business Post understands.
Update (8.11.09) - The Sunday Independent has more on abuse of Garda databases.

Moriarty-Tribunal.ie v. MoriartyTribunal.com - Denis O'Brien takes the PR battle online

Today's Sunday Business Post has an interesting article about Denis O'Brien's latest salvo in his ongoing PR battle against the Moriarty Tribunal investigation into how he came to be awarded Ireland's second mobile phone licence.

The official website of the Tribunal is moriarty-tribunal.ie and O'Brien has now launched a full frontal attack on the findings of the tribunal at moriartytribunal.com, which bills itself as presenting "the true picture of the Moriarty Tribunal's 8 1/2 year inquiry into the awarding of the second mobile phone licence" - including confidential correspondence between the Tribunal and parties.

Is a UDRP claim on the cards? Probably not (though there has been one case where an Irish public body has unsuccessfully invoked the IEDRP). Nevertheless, I'll be interested to see whether the Tribunal will object to the use of such a similar domain name.

Friday, October 16, 2009

UK Government abandons plans for mandatory web filtering

Just over a month ago the Independent on Sunday reported that:
The Home Office is drawing up plans for what, in effect, would be the first form of state intervention in Britain in relation to the internet.

British ISPs would face heavy fines for failing to block sites containing images of child sexual abuse, according to the contents of a leaked Home Office document seen by The Independent on Sunday...

The leaked Home Office letter says a clause in the Police, Crime and Private Security Bill in the Queen's Speech would "compel domestic ISPs to implement the blocking of illegal images of child sexual abuse".
This was far from new policy - since 2006 the Home Office has consistently said that it would legislate for mandatory filters unless ISPs "voluntarily" filtered against the IWF blacklist. But according to The Register, it has now rather abruptly changed its position:
The government has abandoned its long-standing pledge to force 100 per cent of internet providers to block access to a list of child pornography websites.

The decision to drop the policy will be finalised at a meeting on Monday to be attended by internet industry representatives, children's charities and Alun Michael MP.

The former minister had aimed to pressurise small ISPs to implement the Internet Watch Foundation's (IWF) blacklist with the threat of legislation, but the Home Office has now backed down. A lobbying campaign argued costs were too high for small companies to bear and that the blocking technology can be easily circumvented by determined paedophiles.
Instead the Home Office will attempt to use consumer pressure to encourage the remaining ISPs to filter:
For the first time the IWF will publish the list of ISPs who are certified as having implemented its blacklist. "Hopefully consumer and public pressure will encourage the ISPs who aren't on the list to comply," said Carr. A Home Office spokesman said: "We will continue to urge ISPs to implement blocking, and ask consumers to check with their suppliers that they have done so. The Government recognises the work done by most of the internet industry to tackle this problem."
Why the about-face? One factor may have been that the Home Office didn't enjoy wide support for its plans even amongst official bodies. The Chief Executive of the Child Exploitation and Online Protection Centre (CEOP) recently said that he was not convinced of the need to introduce mandatory filtering, while apComms had come out strongly against mandatory web filters. Key to both views was the recognition (which was slow in dawning at the Home Office) that web filters are increasingly irrelevant to the wider problem. Or, as The Register put it:
One likely factor in the softening of stance of both the government and charities is the fact that on the frontline of online child protection, websites carrying images of abuse are no longer seen as a priority.

The Child Exploitation and Online Protection Centre is focussed on paedophile peer to peer networks as they are much more likely to carry recent images, potentially indicating ongoing abuse. The IWF's website blocking is seen as yesterday's issue.
Coincidentally, Germany is also having second thoughts about mandatory filtering, with post-election negotiations for a new coalition government featuring demands that the proposed filtering system be halted.

Thursday, October 15, 2009

apComms come out for worldwide IWF system; against mandatory internet filtering

apComms - the influential UK All Party Parliamentary Communications Group - have now issued the Report from their inquiry "Can we keep our hands off the net?". This inquiry commenced in April and focused on five questions:
#1 Can we distinguish circumstances when ISPs should be forced to act to deal with some type of bad traffic? When should we insist that ISPs should not be forced into dealing with a problem, and that the solution must be found elsewhere?
#2 Should the Government be intervening over behavioural advertising services, either to encourage or discourage their deployment; or is this entirely a matter for individual users, ISPs and websites?
#3 Is there a need for new initiatives to deal with online privacy, and if so, what should be done?
#4 Is the current global approach to dealing with child sexual abuse images working effectively? If not, then how should it be improved?
#5 Who should be paying for the transmission of Internet traffic? Would it be appropriate to enshrine any of the various notions of Network Neutrality in statute?
The full report is an interesting document, and is squarely at odds with current government policy in several areas. Here's what it has to say on filesharing, for example:
We do not believe that disconnecting end users is in the slightest bit consistent with policies that attempt to promote eGovernment, and we recommend that this approach to dealing with illegal file-sharing should not be further considered.
What interests me most is what apComms have to say about dealing with online child pornography. Here they've adopted what seems to be a sensible approach (no doubt influenced by their advisor, Richard Clayton) warning against over-reliance on filters, rejecting government policy to introduce mandatory filters and instead recommending an international extension of IWF-type voluntary cooperation on notice and take-down systems:
We recommend that the Government does not legislate to enforce the deployment of blocking systems based on the IWF lists. This has the potential to damage future attempts to fix problems through self-regulation, and will thus, in the long term, be counterproductive...

It seems quite clear from the evidence that we received that a great deal more could be done to promptly request ISPs to remove child sexual abuse image websites. The IWF are clearly doing a good job along these lines within the UK, but they tell us that they are unable to extend this activity to key countries such as the US and Russia.

In our view, this is an unacceptable situation. If the IWF are unable to perform this important function on a global basis, then some other organisation will need to be given the task. Although there is no particular reason why such a global body should be UK based, the long history of leadership in this area makes the UK a natural candidate to develop a new approach.

We recommend that the Government, in consultation with the EU Commission, establish whether the Internet Watch Foundation (IWF) should extend its “notice and take-down” mechanisms to the whole world, and if not, work to establish such a global system.
More from Andres and The Register.

Wednesday, October 14, 2009

Judgment in Irish Pirate Bay blocking case now available

The Courts.ie website now has the full text of the judgment by Charleton J. in EMI Records v. Eircom where an order was made against Eircom requiring them to block access to The Pirate Bay. This decision is of limited precedential value - it was made on the consent of Eircom and is an ex tempore judgment only. Nevertheless it's worth reading for an insight into how Irish judges will respond to claims that websites should be blocked.

The judgment itself doesn't refer to the terms of the order against Eircom, but I've previously put up the relevant portions of the order.

Tuesday, October 13, 2009

IRISS Conference on Cybercrime in Ireland

This promises to be a very interesting event:
IRISS Conference 2009

IRISS will hold its first annual conference on the 19th of November 2009 at the D4 Berkley Court hotel. This all day conference will focus on providing you with an overview of the current cyber threats facing businesses in Ireland and what you can do to help deal with those threats.

Experts on various aspects of cyber crime and cyber security will share their thoughts and experiences with you while a number of panel sessions will provide you with the opportunity to discuss the issues that matter to you most. There will be a number of expert speakers on cyber crime including representatives from;

* The Irish Reporting and Information Security Service
* An Garda Siochana,
* The Data Protection Commissioner's Office
* The European Network and Information Security Agency
* OWASP (The Open Web Application Security Project).

In parallel to the above speaking sessions Ireland's first Cyber Security Challenge, HackEire, will be held to identify Ireland's top cyber security experts. HackEire will see 10 teams, up to a maximum of four people per team, compete against each other in a controlled environment to see which team will be the first to exploit weaknesses in a number of systems and declare victory. The purpose of the HackEire competition is to demonstrate how attackers could gain access to your systems and allow you to learn from the event on how to prevent such attacks from impacting your network.

The conference will be open to anyone with the responsibility for securing their business information assets. There is no charge for those who wish to attend.
(via Michele)

Monday, October 12, 2009

Employment law issues that didn't exist when I was in law school

From OUT-LAW:
Employers must gain control of their employees' online behaviour and virtual attire according to business research firm Gartner. It said that companies should establish dress codes for employees' avatars.

Friday, September 25, 2009

JC Decaux should backpedal on iPhone app threat

I'm quoted in today's Irish Times on the threats made by JC Decaux against Fusio resulting in their taking down their Dublin Bikes App.

Leave aside for a moment the PR stupidity of this strategy.

Ignore if you will the dubious legal basis of their claim. (Without going into the finer points of copyright in facts, database rights, clickwrap agreements or possible passing off, the vague nature of their complaint - "Following our conversion, I confirm that you do not have the rights to use the information published on the web site http://www.dublinbikes.ie/. In particular the data concerning the stations is the property of JCDecaux and cannot be used without our prior authorisation" - makes it clear that they have little idea what they are talking about.)

Think instead about the issue of principle. A body which is operating in partnership with Dublin City Council is attempting to stop an Irish company from providing - free of charge - facts to the public about the service which they offer, without giving any justification for doing so, and without offering an alternative of their own. (I'm happy to see that at least some of our politicians understand the absurdity of this.)

I spoke to the press office in Dublin City Council today, who made it clear that they regard this matter as nothing to do with them. But why not? DCC were happy to work with Fusio to develop the app. Is there no provision in their contract with JCD establishing an obligation to provide information to the public about the service? Will they make sure that future contracts address this type of situation? (And - while I'm on the topic of the contract - why does JCD own the domain dublinbikes.ie? Is there any provision in the contract for the domain to revert to DCC on its expiry?)

Tuesday, September 15, 2009

Ryanair screen scraping: New litigation

I've blogged before about Ryanair's case against Travelfusion and Bravofly in respect of screen scraping. According to RTE News, this case has now been joined by a fresh set of proceedings in the High Court by Ryanair against Ticketpoint, Reisebuero and Billigfluege, alleging that they are using screen scraping to resell Ryanair tickets at higher prices.

According to the news report, Ryanair is complaining that the three companies are "applying a service charge and credit card charges to the prices". I wonder who they got that idea from?

Thursday, September 03, 2009

Lori Drew decision published - Breach of terms of use as a criminal offence

When Lori Drew was prosecuted for bullying via MySpace which led to the suicide of Megan Meier many people were worried about the prosecution theory of the case. The basis of the charge was not the bullying itself but rather that by failing to comply with MySpace's terms of use Lori Drew had committed an offence of unauthorised access to a computer. If accepted, this theory would have criminalised failure to abide by terms of use - terms which most users never read and which are often vague and imprecise in their scope - and effectively permitted site owners to provide that a breach of their rules would now be a crime. As Andy Grossman put it, the effect would be that "every site on the Internet gets to define the criminal law. That’s a radical change. What used to be small-stakes contracts become high-stakes criminal prohibitions."

Consequently there was some relief two months ago when the trial judge indicated that he would quash the jury's guilty verdict, but his short oral statement of reasons on that day didn't go into detail as to why the prosecution case was flawed. The full written judgment has now been published, and shows that the trial judge applied the void for vagueness doctrine to find that a prosecution based on simple breach of terms of use would not give fair warning to users as to what actions might be criminal and would criminalise vast numbers of users without providing even minimal guidelines to govern prosecutions.

Would a similar result be reached in Ireland? The position is complicated slightly by the peculiar wording of the relevant offence - which speaks of "access without lawful excuse" rather than "unauthorised access" - but the same underlying principles would apply. The domestic caselaw - in particular King v Attorney General [1981] IR 223 - has established the proposition that the ingredients of an offence must be set out with precision and clarity and this has since been reinforced by ECHR jurisprudence requiring accessibility and foreseeability in criminal offences (e.g. CR v. United Kingdom). In light of those principles, it seems likely that the Irish courts would follow the reasoning in the Lori Drew case.

Some key portions of that ruling are worth quoting:
If a website’s terms of service controls what is “authorized” and what is “exceeding authorization” - which in turn governs whether an individual’s accessing information or services on the website is criminal or not, section 1030(a)(2)(C) would be unacceptably vague because it is unclear whether any or all violations of terms of service will render the access unauthorized, or whether only certain ones will.

For example, in the present case, MySpace’s terms of service prohibits a member from engaging in a multitude of activities on the website, including such conduct as “criminal or tortious activity,” “gambling,” “advertising to . . . any Member to buy or sell any products,” “transmit[ting] any chain letters,” “covering or obscuring the banner advertisements on your personal profile page,” “disclosing your password to any third party,” etc... The MSTOS does not specify which precise terms of service, when breached, will result in a termination of MySpace’s authorization for the visitor/member to access the website.
By utilizing violations of the terms of service as the basis for the... crime, that approach makes the website owner - in essence - the party who ultimately defines the criminal conduct. This will lead to further vagueness problems. The owner’s description of a term of service might itself be so vague as to make the visitor or member reasonably unsure of what the term of service covers. For example, the MSTOS prohibits members from posting in “band and filmmaker profiles . . . sexually suggestive imagery or any other unfair . . . [c]ontent intended to draw traffic to the profile.”

Moreover, website owners can establish terms where either the scope or the application of the provision are to be decided by them ad hoc and/or pursuant to undelineated standards. For example, the MSTOS provides that what constitutes “prohibited content” on the website is determined “in the sole discretion of MySpace.com . . . .” Additionally, terms of service may allow the website owner to unilaterally amend and/or add to the terms with minimal notice to users.
Because terms of service are essentially a contractual means for setting the scope of authorized access, a level of indefiniteness arises from the necessary application of contract law in general and/or other contractual requirements within the applicable terms of service to any criminal prosecution.
Treating a violation of a website’s terms of service, without more, to be sufficient to constitute “intentionally access[ing] a computer without authorization or exceed[ing] authorized access” would result in transforming section 1030(a)(2)(C) into an overwhelmingly overbroad enactment that would convert a multitude of otherwise innocent Internet users into ... criminals... If any conscious breach of a website’s terms of service is held to be sufficient by itself to constitute intentionally accessing a computer without authorization or in excess of authorization, the result will be that section 1030(a)(2)(C) becomes a law “that affords too much discretion to the police and too little notice to citizens who wish to use the [Internet].”
Eric Goldman has analysis of the decision and its implications for legal responses to cyberbullying - suggesting that the decision is likely to encourage lawmakers to introduce new offences of online harassment.