Monday, October 17, 2011

Innovation, Information and the Internet: Modernising Copyright Law

I'm delighted to be chairing a conference on copyright reform this Friday (21st October) and would encourage anyone with an interest in the topic to attend. The event is free and you can register online at http://www.dublincopyrightconference.com/. Full details:
Innovation, Information and the Internet: Modernising Copyright Law

When: Friday 21st October 2011, 1.00pm - 5.00pm (a sandwich lunch will be served at 12.00)

Where: Presidents' Hall, Law Society of Ireland, Blackhall Place, Dublin 7, Ireland

The current review of copyright law in Ireland presents significant challenges for rightsholders, copyright users and the legal profession alike. This conference will consider areas where Irish law is in need of reform and in particular will look at the role of copyright in the digital economy, the development of fair dealing exceptions, the role which fair use plays in the United States, and the experience of reform in the United Kingdom.

Speakers will include prominent national and international experts from private practice, academia and government, including:

Prof Dr Martin Senftleben - Faculty of Law, Vrije Universiteit Amsterdam
Ms. Helen Sheehy, Commercial & Copyright Department, Sheehy Donnelly Solicitors
Prof Lionel Bently - Faculty of Law, University of Cambridge
Mr Stephen Rowan - Deputy Director, Copyright and IP Enforcement Directorate, UK Intellectual Property Office
Prof Peter Jaszi - College of Law, American University Washington
Ms. Linda Scales, Solicitor and co-founder of the Copyright Association of Ireland

Sunday, September 18, 2011

Internet blocking in schools: not such a good idea, it turns out

Despite being published in 2010, I somehow managed to miss until now these remarkably sensible research findings from Ofsted on internet blocking in schools:
Restricting pupils’ access to websites may actually impair their judgement, making them more “vulnerable” to paedophiles on-line, said Ofsted. The claims come despite an admission that teachers had problems stopping young people logging on to “inappropriate” websites at school. In a report, Ofsted said there were widespread incidents of pupils accessing social networking websites and instant chat rooms – where they can be targeted with abuse. But inspectors said "locked down" systems that barred access to websites were actually "less effective" in keeping children safe overall.
In a particularly good analogy, Ofsted also points out that:
Children who hold a parent’s hand every time they cross the road are safe. However, unless they are taught to cross the road by themselves, they might not learn to do this independently. A child whose use of the internet is closely monitored at school will not necessarily develop the level of understanding required to use new technologies responsibly in other contexts.
There's a lesson here in relation to internet blocking as applied to adults also.

Daily Telegraph story
Full text of Ofsted report

(h/t Joe McNamee, EDRI)

Monday, August 08, 2011

Data protection: subject access rights not affected by litigation

The Circuit Court recently gave a significant judgment in Dublin Bus v. Data Protection Commissioner, holding that subject access rights in Ireland are not affected by the fact that civil proceedings are contemplated or ongoing.

In this case Dublin Bus attempted to withhold CCTV footage of an accident from a subject access request, making a number of rather weak arguments which claimed alternatively that the footage was subject to legal professional privilege and/or that the access request constituted some form of interference by the DPC with pending litigation. In the Circuit Court Judge Linnane gave short shrift to these claims, holding that the footage was not privileged, the Data Protection Acts did not contain any exemption in respect of contemplated or pending legal proceedings, and (unlike UK law) the Irish legislation does not permit the court any discretion as to whether to order access.

None of these rulings are surprising (it would have been very surprising indeed if the court had found otherwise) but it is nevertheless useful to have a decision confirming these points. I've placed a copy of the full judgment on Scribd in the hope that it might prove useful for other subject access requests:Dublin Bus v. Data Protection Commissioner

Wednesday, August 03, 2011

Site Blocking: What the UK Government would prefer you not to see

It's well known that internet blocking is easy to circumvent. Ofcom in today's report "Site Blocking" to reduce online copyright infringement admits as much, saying that:
For all blocking methods circumvention by site operators and internet users is technically possible and would be relatively straightforward by determined users. (p.5)
Despite this, however, one branch of the UK Government still appears determined to keep its head in the sand, and according to that report:
The Department for Culture, Media and Sport has redacted some parts of this document where it refers to techniques that could be used to circumvent website blocks.
Unfortunately, the technical competence of the DCMS appears to be somewhat limited, and the redaction was (ironically?) also easily circumvented, by measures as simple as copy/paste. Needless to say, a department which is unable to censor a single PDF does not exactly inspire confidence when it proposes to introduce blocking for the entire UK internet, and it is just as well that the UK government has today announced plans to abandon the blocking provisions of the Digital Economy Act.

[Updated - 1.15pm]

The full, unredacted version now appears on Scribd. As can be seen from that document, the material which was redacted was all improperly removed. The tactics discussed to circumvent blocking are all well-known, even to a mere lawyer such as myself, and the redactions appear to be motivated more by considerations of security theatre than anything else.Ofcom Site Blocking Report With Redactions Removed

[Previously]

Here are the individual portions of the report which the DCMS attempted to quash. Text in italics was not redacted but appears for context:

pp.28-29
Robustness

Bypassing IP address blocking is technically straightforward for those who have an incentive to do so.
The blocked site operator may:

• change IP address but stay on the same network (i.e. on the same hosting provider);
• move to an entirely new network (to a previously unobserved IP address);
• offer encrypted network services which obscure the true network address/destination such as Virtual Private Networking;26,27 or
• server operators may institute a Fast Flux network (where users run software on behalf of blocked site which hides the true network address of the blocked site).

There are other methods available to site operators. When moving to a new IP address a site operator may register multiple IP addresses for a given site in order to maintain service in the event that some of those individual IP addresses are blocked. This approach has legitimate purposes also.28 Furthermore, by setting a low “Time to Live” (TTL) Domain Name System (DNS) record value, determining the length of time that the IP address for a particular domain (expressed in seconds) remains in remote name server caches, it is easier for a site operator to move IP addresses without end users losing access. Where a low TTL is expressed the ISP DNS name server resolution cache is purged quickly thereby ensuring that newly assigned site IP addresses are retrieved from the authoritative name server and site accessibility is maintained. Figure 13 below shows that the TTL value for "kickasstorrents" is one hour, demonstrating that any changes to IP address to DNS name are refreshed and propagated within ISP DNS servers in just over an hour.

Figure 13: Kickasstorrents DNS record Time to Live (1 hour) Name TTL Class Record Address
www.kickasstorrents.com. 3600 IN A 95.215.60.37
www.kickasstorrents.com. 3600 IN A 93.114.40.112
www.kickasstorrents.com. 3600 IN A 193.105.134.81
www.kickasstorrents.com. 3600 IN A 95.143.195.138
www.kickasstorrents.com. 3600 IN A 76.76.107.90

26 Ipredator - Surf anonymously with VPN and proxy https://www.ipredator.se/?lang=en
27 UK based VPN services facilitating access to copyright infringed material may be subject to site blocking injunctions. UK VPN operators may institute site blocking at the VPN egress point. NB: we are not aware of any UK based VPN service marketed or positioned for such activity. Such services are likely to be non-UK based.
pp.33-34
DNS blocking robustness

For site operators and end users with a sufficient incentive to engage in circumvention DNS blocking is technically relatively straightforward to bypass:


• the blocked site may offer services such as Virtual Private Networking, which is where encryption and other security measures are deployed to ensure that the data cannot be viewed by third parties (DNS name resolution may occur within the VPN providers network thereby bypassing the ISP based DNS site-blocking);
• the end-user can change their DNS name servers to 3rd party DNS name servers;32,33
• users may use anonymous web proxy or other anonymising services which are not reliant on the ISP DNS servers; or
• name resolution may be performed locally by adding an entry to a hosts file (IP address resolution information can be obtained from websites running a web-enabled equivalent of “nslookup” command).

32 Google Public DNS - http://code.google.com/speed/public-dns/
33 OpenDNS Store > Sign up for OpenDNS Basic: - https://store.opendns.com/get/basic/

For end users who want to bypass blocks there are several options. For instance, there are many legitimate alternative DNS providers to ISP DNS registries. Examples include OpenDNS and Google DNS. We consider the changing of DNS servers to alternative providers to require low technical skills, as the providers offer clear instructions using plain English. For instance, switching to Google DNS requires 11 steps for Windows users and only 8 for those using MAC OS.

With a modest understanding of internet technologies it is possible to access a site by entering the site IP address (if multiple websites are hosted at the same IP address the user will be displayed the default web site or page for that web server/IP address). Site operators can draw attention to online web based and alternative sources of DNS name resolution within emails to their user base or via online forums.

Other channels that site operators could use to widely distribute advice on how best to circumvent DNS blocking could include posting to online forums, Really Simple Syndication (RSS) or updates via micro blogging sites such as Twitter ®. The advice could include changing to unblocked DNS name servers, Virtual Private Networks and proxy services or other anonymising systems. Similarly, site operators may quickly mirror or make copies of a blocked site on new top level or country code domains pointing towards new IP addresses e.g. www.blockedsite.cc; www.blockedsite.ru; www.blockedsite.vn; www.blockedsite.net.
p.38
Techniques that may undermine URL blocking include:

• web site operators providing encrypted access to their web sites via Secure Sockets Layer/ Transport Layer Security i.e. https connectivity https://www.example.com/downloads/pirate.zip;
• a site operator may run a website on a network port other than port 80;
• the site operator changing the IP address and bypassing the network routing announcements;
• a site operator registering a new domain name e.g. www.example.net or www.example.org;
• the blocked site offering services such as Virtual Private Networking;
• the use of anonymous web proxy or other anonymising services;
• the site operator reorganising the site structure if the blocking is conducted against specific URLs; and
• the site operator or end user encoding URLs to bypass blocking.
p.40
Packet inspection blocking robustness

Both shallow and deep packet inspection can be bypassed by site operators using the following means:


• changing the IP address but staying on the same network;
• moving to an entirely new network (to a previously unobserved IP address);
• the site may use network encryption techniques such as Virtual Private Networking to render scrutiny of the IP packet‟s payload or real IP address destination impossible, given the technology available today; or
• the site operator may add or remove site IP addresses from a pool of IP addresses.

End users who wish to circumvent packet inspection may opt to use anonymous web proxies or other anonymsing services.
p.41
As with the deployment of any of the single primary techniques, the hybrid approach is also susceptible to circumvention by the use of anonymising tools such as The Onion Router, VPNs or anonymous proxy services.
p.44 (Column marked "Difficulty of circumvention" originally redacted)


p.45 (Column marked "Difficulty of circumvention" originally redacted)




p.52
Technical Glossary

Anonymous Web Proxy Service that allows users to place web requests via an intermediary server. The proxy server makes the connection on behalf of the user thereby hiding originating IP address and bypassing blocking network techniques.

The Onion Router (ToR) Anonymity network originally developed by the United States Navy. Used in many countries to bypass state censorship.

Monday, August 01, 2011

Judicial committee to consider internet use by juries and live tweeting of trials

According to Kieron Wood in the Sunday Business Post Mr Justice John Murray is to chair a committee to consider the contempt risks posed by jurors' use of the internet and social media, and which may also consider the issues associated with courtroom reporting via twitter or liveblogging. There doesn't seem to be anything on the Courts Service website about this yet, but hopefully the committee will follow the UK practice by holding a full public consultation and (if there is a need for urgent action) issuing interim guidance only in the meantime. Given the importance of the constitutional guarantee of open justice it would be wrong to make any final decision without giving those affected the opportunity to be heard.

Kieron Wood also writes about the wider problems the internet poses for the justice system in a longer piece in the Business of Law supplement.

Friday, July 29, 2011

Newzbin2: Did BT shoot itself in the foot - and will Irish ISPs do the same?

Yesterday's decision in Twentieth Century Fox v. BT (PDF) introduces mandatory web blocking for the first time in the UK and unsurprisingly has already received a great deal of attention (BBC|Guardian|IPKat).

Lilian Edwards has provided a comprehensive legal analysis, while Richard Clayton tackles the technical implications of the judgment, so I won't attempt to duplicate their work. But a separate blog post might be useful on one point which has received less attention - the significance of the fact that BT had already voluntarily adopted a system - Cleanfeed - to block child abuse images.

In 2004 - when BT initially adopted Cleanfeed - it was even then obvious that there was a risk of function creep and in particular that copyright holders would seek to use the system. In a briefing to LINX at the time (link now broken), however, BT appeared to believe that it was unlikely to be sued and could mitigate this risk by discontinuing the use of Cleanfeed if scope creep became a reality. According to the then Director of Internet Services for BT Retail: "if the pressure to extend the scope of Cleanfeed became too great [BT] would simply cancel the project" and "BT is unlikely to be the defendent of choice for a copyright holder or other party attempting to hold an ISP legally responsible for Internet traffic".

Yesterday's ruling has shown the limits of this reasoning. Once Cleanfeed provided a proof of concept then function creep was inevitable and the idea that BT could unilaterally turn off the blocking system unrealistic. Instead, it painted a target on its back. According to a representative for the movie industry "BT was chosen because it's the largest and already has the technology in place, through its Cleanfeed system, to block the site".

The use of Cleanfeed also prevented BT from asserting two defences that might otherwise have applied - that there was no clear legal basis for imposing a blocking system and that their obligations would be unclear. Instead, according to the High Court:
the order sought by the Studios is clear and precise; it merely requires BT to implement an existing technical solution which BT already employs for a different purpose; implementing that solution is accepted by BT to be technically feasible; the cost is not suggested by BT to be excessive. (para. 177)
In light of this, therefore, it's hard not to conclude that BT shot itself in the foot by adopting a blocking system which could easily be repurposed for the benefit of Hollywood.

"No good deed goes unpunished" - this case proves the truth of this statement, and will undermine other voluntary initiatives to block child pornography by showing how easily those initiatives can be coopted by the movie industry or music industry. There's also a lesson here for Irish ISPs who are coming under police pressure to introduce similar blocking systems. Will they now do so, knowing that these systems will make them a happy hunting ground for the content companies, defamation plaintiffs, and others who may wish to block access to the web in Ireland?

Sunday, July 24, 2011

Irish mobile phone companies act on voicemail hacking - but why the delay and have they gone far enough?

Yesterday's Irish Times has a story detailing what Irish mobile providers are doing about voicemail security, in light of the UK phone-hacking scandal. There is more detail on the Data Protection Commissioner's website, which indicates that the DPC has abandoned earlier plans to make remote access to voicemail a user option. Instead, according to the DPC:
[The networks] have now all put in place or have committed to put in place in the coming days additional measures to assist their customers to protect the data on their phones. It is now important that the public follow the advice of their mobile provider and where they have not already done so take steps to either secure their voicemail and phones generally or improve upon the measures they may have already taken. At the end of this process it will no longer be possible to access a person’s voicemail using a default password.
The state of play is now as follows:
Meteor and eMobile
No default security PIN is applied and every customer is required to choose their own secure PIN when enabling voicemail. In an effort to encourage customers to take proactive steps to secure their voicemail service they have enhanced the information contained on both websites (www.eMobile.ie or www.meteor.ie) with additional details and guidance on how to secure voicemail services. Additionally, an educational SMS will be sent to all voicemail users in the coming days. Customers can strengthen their password today by dialing 171 (both Meteor and eMobile) and follow the instructions.

O2
O2 has commenced a programme of communications with customers to advise on how they can keep access to their voicemail secure at all times. The communications will include text messages to customers and a pre-recorded advisory when customers dial in to their voicemail service to retrieve messages. O2 has also updated its website with a range of security tips, available at www.o2.ie in the "Can we help you today?" section on the homepage. Customers can change their password today by dialling 173 from their handset and follow the instructions.

Three
Three is communicating to its customers the importance of securing their voice mail with a unique PIN known only to the customer. The communications will include text messages to customers with advice on setting up a voicemail PIN. There will also be an Online Help & Support update to the section on Voicemail to advise customers on the level of security they should use when setting up their PIN. Customers can change their password today by dialling 171 (in Ireland) or +353 83 333 3171 from abroad from their handset and follow the instructions.

Vodafone
From tomorrow Vodafone Ireland customers will hear information when they dial 171 on how they can change their voicemail password at any time. Voicemail and password information is also available today on Vodafone.ie. Vodafone will continue to inform its customers in the coming weeks on new enhanced security options available to its customers. Customers can change their password today by dialling 173 from their handset and follow the instructions.
At first glance this might seem like a step forward, but it leaves many questions unanswered.

First - why has it taken the Irish networks so long to act? Wrongful access to voicemail messages was well known long before now - and I blogged about it here back in 2006. There is simply no excuse for the delay that most networks have shown.

Second - will the networks continue to issue new phones with default voicemail passcodes? Credit must go to Meteor/eMobile who don't do so, but it isn't clear from the DPC's statement - "At the end of this process it will no longer be possible to access a person’s voicemail using a default password" - whether the other networks will be required to abandon their ongoing use of default passcodes. If not, however, then it's hard to see how they would not be in breach of Regulation 4 of the new ePrivacy Regulations, which provides that:
(1) With respect to network security and, in particular, the requirements of paragraph (2), an undertaking providing a publicly available electronic communications network or service shall take appropriate technical and organisational measures to safeguard the security of its services, if necessary, in conjunction with undertakings upon whose networks such services are transmitted. These measures shall ensure the level of security appropriate to the risk
presented having regard to the state of the art and the cost of their implementation.
(2) Without prejudice to the Data Protection Acts, the measures referred to in paragraph (1) shall at least—
(a) ensure that personal data can be accessed only by authorised personnel for legally authorised purposes,
(b) protect personal data stored or transmitted against accidental or unlawful destruction, accidental loss or alteration, and unauthorised or unlawful storage, processing, access or disclosure, and
(c) ensure the implementation of a security policy with respect to the processing of personal data.

(Daragh O'Brien has more on the ePrivacy Regulations and their impact on voicemail hacking.)

Third - have the Irish networks taken steps to secure against other methods of voicemail hacking such as Caller ID spoofing? This is a well known problem in the US and at least some European countries - as Brian Krebs puts it:
For years, it has been a poorly-kept secret that some of the world’s largest wireless providers rely on caller ID information to verify that a call to check voicemail is made from the account holder’s mobile phone. Unfortunately, this means that... your messages may be vulnerable to snooping by anyone who has access to caller ID "spoofing" technology. Several companies offer caller ID spoofing services, and the tools needed to start your own spoofing operation are freely available online.
The recent statement from the DPC doesn't address this particular attack, and the track record of most Irish networks doesn't fill me with confidence that they are on top of this issue either.

Tuesday, July 19, 2011

The Internet of Elsewhere

I've just finished reading a review copy of Cyrus Farivar's impressive new book The Internet of Elsewhere. Like many books, it traces the development and mass takeup of the internet - unlike most, however, it is not US-centric and instead gives equal space to case studies from four countries: South Korea, Senegal, Estonia and Iran. In doing so, it provides a wealth of detail for many developments (the 2003 Iranian crackdown on bloggers, the Seoul "Dog Poop Girl", the Estonian takeup of wifi) which are often cited but seldom put into their wider social context. The author makes a particular point of describing the factors such as demographics, literacy and cost which have driven the use of the internet in each country - or, in the case of Senegal, have kept much of the population offline. A particular highlight for anyone interested in civil liberties online is the description of Iranian control of the internet, which goes back to early measures in 2000 and describes the various state tactics since then which have resulted in many prominent bloggers being forced to leave the country. The book also succeeds in being an easy read - while it is well researched and sourced it is also journalistic in its tone and describes each country through the stories of individuals. I would recommend this to anyone with an interest in the takeup of the internet and the social changes it prompts.

Tuesday, July 05, 2011

Virtual execution of documents under Irish law

There's been quite a bit written about the electronic signature of contracts, and under Irish law there are specific statutory rules in place under Part 2 of the Electronic Commerce Act 2000 which allow such signatures to be used. Curiously, however, there's been much less attention paid to a more traditional form of "virtual signing" - where one or more parties to a transaction are not physically present at the meeting where a particular document is executed.

In these situations the practice had developed of either executing signature pages in advance or signing a document remotely and subsequently distributing signature pages by fax or email. This practice, however, hit a road bump with the decision of the High Court of England and Wales in Mercury Tax Group v. HMRC which held that a signature given in respect of an incomplete draft deed could not be transferred to an amended final deed, as s. 1(3) of the Law of Property (Miscellaneous Provisions) Act 1989 requires that "the signature and attestation must form part of the same physical document... which constitutes the deed".

Although obiter, this finding had obvious wider implications for virtual signatures generally in any situation where statutory requirements for signatures must be met. Consequently, it was followed by a practice note from the Law Society of England and Wales (January 2010) and now by a practice note from the Law Society of Ireland (June 2011, PDF, pp. 52-53).

The whole Law Society guidance note is very useful and must be read, but it helpfully summarises the options as follows:
Option
Steps
Documents
Option 1 (return the entire PDF/ Word document and a PDF of the signed signature page)
• Once the documents have been agreed, final execution versions are emailed to the parties and/or their lawyers.
• For convenience, a separate extracted signature page may also be attached to the email, but this is not necessary.
• Each authorised signatory prints and signs the signature page. If appropriate, the signing may need to take place in the presence of a witness.
 • The signature page is then scanned and returned by email together with the whole document previously emailed to the signatory. (For a deed, make it clear when delivery is to occur.)
• See suggested wording for covering email (panel, p53)
Option 1 may be used for any document or deed, i.e. including:
• A deed,
• A real estate contract,
• A guarantee (whether a deed or in simple contract form),
• A simple contract.
Option 2 (return the entire PDF/ Word document and a PDF of the signed signature page)
• Once the documents have been agreed, final execution versions are emailed to the parties and/or their lawyers.
• For convenience, a separate extracted signature page may also be attached to the email, but this is not necessary.
 • Each authorised signatory prints and signs the signature page.
• The signature page is then scanned and returned by email, together with authority for it to be attached to the final approved version of the document. (The degree of formality required for this authority will depend on the circumstances.)
Option 2 may be used for:
• A guarantee (in simple contract form only),
• A simple contract
 • A real estate contract.

Option 2 may not be used for a deed (of any type).
Option 3 (return the entire PDF/ Word document and a PDF of the signed signature page)
• Once the documents have been agreed, final execution versions are emailed to the parties and/or their lawyers.
• For convenience, a separate extracted signature page may also be attached to the email, but this is not necessary.
 • Each authorised signatory prints and signs the signature page.
• The signature page is then scanned and returned by email, together with authority for it to be attached to the final approved version of the document. (The degree of formality required for this authority will depend on the circumstances.)
Option 3 may be used for:
• A guarantee (in simple contract form only),
• A simple contract,
• A real estate contract.

Option 3 may not be used for a deed (of any type).

There is also an important caveat that for registration purposes "wet ink" versions of all signatures may be required - if so, the guidance note points out that appropriate undertakings must be included that these will be provided following execution.

Friday, June 24, 2011

Irish documents on interception of communications and surveillance

I've uploaded a few documents recently which might be useful to anyone interested in issues of surveillance and interception of communications in Ireland.

First is the 2009/10 report of the Designated Judge responsible for monitoring the interception of communications and data retention:
Interception and Data Retention Annual Report 2009/10

Second is the 2009/10 report of the (different) Designated Judge responsible for monitoring covert surveillance:
Covert Surveillance Report 2009-10

Third is the Revenue manual setting out their understanding of their powers and duties in relation to covert surveillance, following the enactment of the Criminal Justice (Surveillance) Act 2009:
Revenue Surveillance Manual

(Many thanks to Mark Tighe for copies of the two judges' reports.)

Monday, June 13, 2011

Ireland to extradite "Boards.ie hacker"?

Continuing our series of "interesting stories lost behind the Sunday Times paywall", John Mooney and Mark Tighe reveal that the DPP has directed the extradition of a Latvian man suspected of involvement in the January 2010 hacking of Boards.ie [subscription only].

According to that article:
Gardai from the force's computer crimes unit quickly traced the hacker to Latvia but it is only in recent weeks that the Director of Public Prosecutions (DPP) has ordered the suspect to be extradited. The DPP has directed that there is enough evidence to secure a conviction...

Legal sources said it may be possible for the boards.ie suspect to be charged with theft or fraud: some of the passwords obtained in the hack appear to have been used to steal money from people's Paypal accounts... The hacker is suspected of downloading a number of databases to order.
Background on the attack on Boards.ie: 1|2.

Sunday, June 12, 2011

The first Irish case on defamation via autocomplete

Another story lost behind the Sunday Times paywall last week was Mark Tighe's piece on what seems to be the first Irish case alleging defamation via Google's autocomplete system:
Hotel Fury over Google

A FAMILY-OWNED hotel in Louth is suing Google because it says the search engine giant gives web surfers the mistaken impression it is bust. The four-star Ballymascanlon House hotel, located outside Dundalk, has applied for a High Court injunction to prevent the Google search engine from suggesting it is in receivership.

Ballymascanlon is not in receivership and the Quinn family, who have run the hotel for 70 years, say it is trading successfully.

Google declined to comment on the legal action.

When search engine users type the first seven letters of the hotel's name into Google, the website's automatic prompting service, Google Instant, throws up the suggestion "Ballymascanlon hotel receivership".

The hotel, one of the most popular wedding venues in the northeast, says it has been contacted by brides who had booked weddings there and were "in tears" after seeing the Google prompt.
Mark Collier has an excellent post setting out the background to this case and more details, from which I've borrowed the following image showing the offending search terms:

This isn't the first time Google has been sued over autocomplete suggestions - it recently lost similar cases in France and Italy - and the case raises a fundamental issue as to whether Google should be treated as responsible for the suggestions which it claims merely reflect the most popular user queries. Undoubtedly (if the case makes it to trial) Google will rely heavily on the recent English judgment in Metropolitan International Schools v. Designtechnica, in which it was found not to be the publisher of defamatory snippets in search results on the basis that:
When a snippet is thrown up on the user's screen in response to his search, it points him in the direction of an entry somewhere on the web that corresponds, to a greater or lesser extent, to the search terms he has typed in ... it is for him to access or not, as he chooses. [Google] has merely, by the provision of its search service, played the role of a facilitator.
In this case, however, it may be that Google will face difficulties in running that defence. Looking at both Metropolitan International Schools and the recent Italian judgment, three factors seem likely to be important. First, unlike the case of search results, autocomplete suggestions do not merely reflect what is elsewhere on the web but are created by Google (albeit by algorithm). Second, as Google actively censors the autocomplete system it makes it harder to argue that there is no "human input" into the results - a factor which was critical in Metropolitan International Schools. Third (although the judgment isn't entirely clear on this point) the court in Metropolitan International Schools found it signficant that Google could not block all searches against particular terms without also blocking a great deal of unrelated material. In this case, however, it would seem quite simple to remove a particular autocomplete result for this hotel, ruling out any argument based on practicability or collateral damage.

Incidentally, I see from the High Court search that the action is listed as QUINN [SENIOR] & ORS -V- GOOGLE IRELAND LIMITED 2011/4784 P. I was surprised to see Google Ireland named as a defendant, as I understand that Google's search functions are run by Google Inc., California - a distinction which tripped up the Red Cross in their action seeking to identify a blogger hosted on Google's blogspot. In that case the Red Cross eventually had to seek the permission of the court to substitute Google Inc. as the defendant, and I'll be interested to see whether this happens in this case also.

Saturday, June 11, 2011

Data Protection Commissioner investigating Eircom's "three strikes" system

Between the bank holiday weekend and the Sunday Times paywall Mark Tighe's story last week revealing that the Data Protection Commissioner is investigating the Eircom / IRMA three strikes system didn't receive the attention it deserved. However the investigation has the potential to entirely derail the system and needs to be considered further.

First, the background. I'm disappointed but not surprised to find that my 2009 prediction - that Eircom would end up falsely accusing innocent users - has come to pass in relation to 300 users:
THE "three strikes" scheme to prevent music piracy, which is operated by Eircom at the behest of record companies, is being investigated by the data protection commissioner (DPC) after customers said they were sent warning letters in error. The investigation began after an Eircom customer complained that he had wrongly received a "first strike" letter. The company has admitted it incorrectly issued such warnings to a "limited number" of customers.
So why did Eircom falsely accuse users?
This was due to a software failure caused when the clocks went back last October, it said.
Far from being a technical sounding "software failure", this appears to show up ineptitude in relation to a very basic aspect of network management - i.e. making sure that the server clock reflects daylight savings time. As a result, it seems that users found themselves being accused on the basis of what somebody else did from the same IP address either an hour earlier or an hour later. Consequently, the users who were wrongfully accused should consider themselves lucky that this incompetence did not lead to their being accused of a serious crime - for example, being arrested and having their homes searched due to the wrong time being used (as happened to these Indian users).

The significance of this case goes beyond simple technical failings, however, as the complaint to the Data Protection Commissioner has triggered a wider investigation of the legality of the entire three strikes system:
The DPC said it was investigating the complaint "including whether the subject matter gives rise to any questions as to the proportionality of the graduated response system operated by Eircom and the music industry".
This is unsurprising - when the Eircom / IRMA three strikes settlement was being agreed the Data Protection Commissioner identified significant data protection problems with it. These problems remain, notwithstanding the deeply flawed High Court judgment which approved of the system - a judgment which, for example, decided on the question of whether or not IP addresses are personal data without once considering the views of the Article 29 Working Party. It is not surprising that the Data Protection Commissioner was not convinced by that judgment (the judgment was problematic at least in part because the Commissioner was not represented - the only parties before the court had a vested interest in the system being implemented). However, until a concrete complaint arose no further action could be taken.

The complaint in this case has now triggered that action, and it seems likely that the Commissioner will reach a decision reflecting his previous views that using IP addresses to cut off customers' internet connections is disproportionate and does not constitute "fair use" of personal information. If so, the Commissioner has the power and indeed the duty to issue an enforcement notice which would prevent Eircom from using personal data for this purpose - which would ultimately seem likely to put the matter back before the courts. Watch this space.

Saturday, May 14, 2011

Impact of the Criminal Justice Bill on the investigation of cybercrime

The Minister for Justice yesterday published the Criminal Justice Bill 2011 (pdf) which is primarily aimed at white collar crime and unsurprisingly aims to facilitate the investigation of banking and financial crimes in particular (press release | Irish Times). It will, however, also have a significant impact on the investigation and prosecution of cybercrime.

Under section 3, the Bill applies to “relevant offences” which, as set out in Schedule 2, includes the offence of dishonest use of a computer. In addition, the Bill allows the Minister to add crimes to the list of "relevant offences" including "criminal acts involving the use of electronic communications networks and information systems or against such networks or systems or both". Consequently, assuming the Minister uses this power, the majority of computer crimes are likely to be subject to the provisions of this Bill.

As summarised in the press release, the key parts of the Bill are:
• A new system to make more effective use of detention periods. This will allow persons arrested and detained for questioning by the Gardaí to be released and their detention suspended so that further investigations can be conducted during the suspension period.

• New powers for the Garda Síochána to apply to court for an order to require any person with relevant information to produce documents, answer questions and provide information for the purposes of the investigation of relevant offences. Failure to comply with such an order will be an offence.

• Measures relating to how documents are to be produced to the Gardaí. These measures are aimed at reducing the delays associated with the production of large volumes of poorly ordered and uncategorised documents to the Gardaí in the course of their investigations.

• Measures to prevent unnecessary delays in investigations arising from claims of legal privilege.

• The creation of a new offence, similar to the former misprision of felony offence, which relates to the failure to report information to the Gardaí.
Also, though not mentioned in the press release, s.18 of the Bill will make the admission of documentary and electronic evidence in criminal trials significantly easier by establishing new presumptions regarding the creation, ownership and receipt of documents.

These provisions would dramatically change the rules governing the investigation and prosecution of computer crime in Ireland. Take two examples. The proposed offence of failing to report information would create a positive duty to report computer crimes to the Gardaí - with failure to do so carrying a term of imprisonment of up to five years. One wonders whether this is workable and what effect it might have on the work of computer security researchers. Similarly, the new power to order the production of documents includes a requirement that such documents be provided in decrypted form or that a password be provided (s.15(6)), which appears to address the gap in the law revealed by the encrypted Anglo Irish Bank files.

This is certainly one to watch for anyone with an interest in cybercrime in Ireland, and I'll be coming back to it as it progresses through the Oireachtas.

Thursday, May 12, 2011

ALAI comes to Dublin

There's a very good IPR conference coming up in Dublin shortly as the Association littéraire et artistique internationale will hold its bi-annual Study Days on the 30th June and 1st July, hosted by the Copyright Association of Ireland. Readers of this blog may be particularly interested to see that speakers include the president of HADOPI, solicitor Helen Sheehy (who has represented the Plaintiffs in all Irish filesharing litigation) and Judge Peter Charleton (who heard both the Eircom and UPC filesharing cases). Full details at www.alaidublin2011.org.

Monday, April 11, 2011

The curious case of internet filtering in Ireland

[Reblogged from the new website MediaLaws.eu, where I will be contributing updates from Ireland.]

One of the most important developments for freedom of expression online has been the growth of internet filtering systems, which have rapidly been adopted by national governments as the “solution” to various forms of internet wrongdoing. Ireland is no exception to this trend, and last month it was revealed that the Garda Síochána (the national police force) is now attempting to introduce a system whereby ISPs would block access to websites alleged to host child abuse images.

It is somewhat ironic that this news becomes public just as both Germany and the Netherlands have decided to abandon similar systems, having found that they are ineffective as a means of tackling child abuse images. Even leaving aside considerations of effectiveness, however, the proposed Irish system still presents a number of significant concerns.

A fundamental principle under Article 10 of the European Convention on Human Rights is that measures which have the effect of restricting freedom of expression must be “prescribed by law”. In this case, however, the Irish system would not have any legal basis whatsoever, much less any judicial oversight or control. Instead, it would involve the police in telling ISPs what domains to block on a “self-regulatory” basis. Consequently, it would seem on the face of it that the proposed system would violate Article 10. The European Commission recently reached the same conclusion about self-regulatory blocking systems (p.30) as did a government study which was decisive in causing the Dutch blocking system to be abandoned.

A further problem relates to the secret manner in which the government and the police have attempted to introduce this system. There has been no public consultation or debate of any kind regarding blocking – instead, information has only dripped out in response to freedom of information requests and leaks from ISPs. This is particularly worrying given that (as Lessig points out) internet filtering is an inherently opaque process, which is prone to operating in an unaccountable way and to being extended beyond its original purposes. In the Irish context, the secrecy surrounding the introduction of filtering doesn’t bode well for the future.

The nature of the proposed blocking is also worrying. What Irish police have suggested is based on the CIRCAMP model, which attempts to block material by using DNS tampering. In short, the police would notify ISPs to block http://example.com or http://subdomain.example.com and the ISP would then configure their DNS servers to redirect all attempts to visit any material hosted on those (sub)domains. The effect would be massive overblocking, where users would be unable to visit any page hosted on a particular domain, irrespective of whether it had any connection whatsoever with the blocked material. Last February, a similar approach in the United States saw over 84,000 innocent websites being wrongfully blocked, and there is no reason to think that the Irish approach would be any more precise.

Finally, one particularly unusual aspect of the proposals is the way in which police seek to introduce monitoring of users. According to the proposals, where a user attempts to view a blocked domain name, police would “obtain details of other websites visited by the user, along with other technical details, in order that [they] can identify any new websites that require blocking”. This in effect seeks the full browsing history of users – whether or not there has been any attempt on their part to view child pornography! (Bearing in mind that DNS tampering results in massive overblocking, it is quite likely that a user may have their browsing history disclosed due to an attempt to visit http://example.com/innocent_content when the entirety of example.com has been blocked due to a single image or page elsewhere in the site.) This raises fundamental privacy and data protection concerns, particularly given that a user can often be identified by viewing their browsing history (e.g.), and has therefore been referred to the Data Protection Commissioner for investigation.

Given these problems, it must be hoped that these proposals are abandoned. But quite apart from these particular proposals, it is now also time to look at the other systems of internet filtering in Ireland that have developed on an ad hoc basis. In particular, Irish mobile phone companies have been engaged in self-regulatory blocking for some time (1|2), in a manner which often affects innocent users due to crude DNS systems. Similarly, the largest Irish broadband provider Eircom recently settled an action brought by the music industry by (amongst other things) agreeing to block access to The Pirate Bay and “related domain names”. These systems have developed without any real public scrutiny or oversight and it is time to consider the effect which they have on users, whether they are subject to adequate transparency and oversight mechanisms and whether or not they are effective at achieving their goals.

Thursday, April 07, 2011

Data breach law in Ireland - the current state of play

I had a very interesting morning at McCann Fitzgerald who were kind enough to invite me in to give a legal update on data breaches - here's a copy of the handout I provided:Lessons from laptop loss: Legal consequences where organisations lose personal data

Saturday, April 02, 2011

Irish Press Council now taking online only sites as members

The Press Council published its annual report for 2010 yesterday. It details some interesting cases (1|2) involving reporting which reuses material from social networking sites and blogs, but more importantly for Irish websites the launch also revealed that the Press Council is now taking online only media as members.

From the Irish Times:
With the increase in news gathering and reporting increasing on the internet, chairman of the Press Council Daithí Ó Ceallaigh said web-based organisations or publications could benefit by joining its independent regulatory regime.

“When this happens – and at least one new web-based organisation has already been accepted as one of the recent new members of the council – we are ready to play a positive role in light of our own experience in support of the highest possible journalistic standards.”
This is a significant development. Membership of the Press Council and adherence to its Code of Practice offers periodicals a significant benefit in establishing a defence of fair and reasonable publication on a matter of public interest. The narrow definition of "periodical" in the Defamation Act 2009, however, created doubt as to whether an online-only publication would qualify for membership.

Eoin O'Dell took the view that it wouldn't (a view which I shared) though the last Minister for Justice later took a contrary view, claiming that:
The question of whether publications existing "on-line" only, either now or in the future, wish to come under the umbrella of the Press Council - and abide by its code of practice - is a matter for those publications. Nothing in the Defamation Act precludes this. Neither have I noticed any express limitation of jurisdiction in the Articles of Association of the Press Council on membership by on-line publications. Some recent commentary from media experts seems to have missed this point.
The Press Council itself has now clearly taken the position that online-only periodicals are eligible for membership, which will certainly cause a number of Irish websites to consider joining.

One note of caution, however: it will ultimately be for a court to determine whether an online-only site is a "periodical" for the purposes of the defence of fair and reasonable publication. The views of the Press Council on this point will be relevant but certainly not conclusive.

Monday, March 28, 2011

Consultation on implementation of Telecoms Reform Package

There are just a few days left if you wish to comment on the Department of Communications proposals for implementation of the Telecoms Reform Package.

While there's quite a lot contained in the five sets of proposed regulations, the portions of most interest to me are the proposals regarding the revised E-Privacy Directive (.doc) which will implement a requirement for data breach notification along with new rules regarding cookies.

Curiously enough, there hasn't been much public debate in Ireland about the impact of the new rules regarding cookies - unlike the UK, where a similar implementation (which essentially copies and pastes text directly from the Directive) has been particularly controversial. This may be because the proposed Irish text is more business friendly in explicitly stating that browser settings can be used to show that users consent to cookies. However, it's still not entirely clear from the draft regulations whether this means that the technically unsavvy user will be taken to have consented where they fail to adjust their browser settings from what is (usually) the default "accept all cookies" option. (The Article 29 Working Party, for example, have taken the view that failure to adjust default settings does not amount to an affirmative consent.)

Update: The Department has now confirmed that it has extended the deadline for submissions to 15 April.