Category: Internet Law

Everything related to the world of law online.

  • The ‘Right to be Forgotten’ is not a Bad Thing

    There has been much said in the past week about the ‘right to be forgotten’ principle being developed in European Law, after the decision by the European Court of Justice in the case of Google Spain v AEPD and Mario Costeja González.

     

    new-google-logo-knockoff

    Why this decision isn’t a good thing

    The decision of the ECJ has been subject to swathes of criticism for a variety of reasons. However, one of the biggest issues to raise its head is the ideological discussion of Data Protection v. Freedom of Expression.

    Originally, data protection was intended to help protect individuals from organisations collecting and storing information on them erroneously. In general, data protection is a good thing. Infact, it’s bloody awesome. It means that when any company or other body collects ‘personal data’ on you, recording it in a filing system, you have the right not only to see it, but to have inaccurate data modified, as well as to prevent the processing of it for marketing purposes.* Sounds good, right? Oh, and this also applies to organised filing systems that are stored on paper, not just electronically.

    In reaching its decision in the Google Spain case, the ECJ has applied the established approach to data protection, whilst at the same time injecting the relatively new principle of the ‘right to be forgotten’. The problem with this is that the circumstances are fundamentally different to those in which the protections were introduced to be applicable to.

    In the Google Spain case, the information was held to be legally published on the site of the newspaper in question, and so is not required to be removed. However, because Google collected, stored, and processed the links to the information, it was then considered a ‘data collector’ under the data protection definitions, and so obliged to consider, and give effect to the removal request.

    This is DUMB.

    This is not the same as a situation where an organisation is keeping detailed personal records on an individual (such as their medical details, telephone number, or address, for example), that would not otherwise necessarily be found elsewhere. In this situation, the information is already in the public domain, published lawfully. The fact that Google collects the locations of this data, stores it, and then offers up the hyperlinks in search results should not bring it under the gambit of The Directive in its current form. I won’t even begin to think too much about the baffling way in which this seems to fly in the face of the general approach to hyperlinking that was laid out in the Svensson case, earlier this year.

    In any event, these removals only apply to the EU – not to Google sites (or those of any other ‘search engine operator’) that lie outside. Clearly the ECJ must not have heard of a proxy before. At the root of it, this is bad law because in the context of a global Internet, it is meaningless.

    Why the right to be forgotten isn’t a bad thing

    When the right to be forgotten was first being discussed, it was in relation to something far more sensible – something which had very little to do with freedom of expression at all. It was to do with the right of users to have online service providers remove the personal information held on them when they chose to delete their account. Ever tried to delete your Facebook account completely? It’s not exactly a walk in the park. It wasn’t about trying to hide past transgressions that have already received media attention, and it wasn’t about curtailing the basic architecture of the web – it was about being able to tell Zuckerberg that when you want to leave, they should honour that.

    The problem with the ECJ’s decision is the way in which they have applied the principles of data protection, rather than data protection itself. Whether or not the Court wilfully misunderstood, in order to crowbar the right to be forgotten into the judgement in this case is one thing, but that doesn’t mean the entire principle should be dismissed.

    Sadly, a lot of the commentary has focussed on the specific facts of this case, and applied them broadly to support a wider theoretical gap between the supposed American principle of freedom of expression, and the European importance on privacy. Whilst that is a whole separate discussion, I do not believe that this should be reduced to some sort of absolute Transatlantic ideological difference. Instead, it should be seen for what it is: a bad application of principles that are fundamentally designed to protect individuals.

    The right to be forgotten is valuable, but it should never have come close to impinging on the freedom to ‘receive and impart information‘ on that which is already lawfully published.

    * This interpretation is based on the UK Data Protection Act of 1998, which gave effect to Directive 95/46/EC – the EU Data Protection Directive.

    More reading:

    You can read the full text of the original application, the opinion, and the judgement of the ECJ over on Curia.

    The relevant (English) press release from the ECJ on the Google decision is here.

    Here is a helpful description of how Google’s new form dealing with right to be forgotten requests will operate.

    Stanford Law Review article on the Right to be Forgotten here.

    Article on the decision and censorship from Index here.

    ‘What you need to know about the ‘Right to be Forgotten’ – here.

  • Automattic/WordPress.com fight back against Censorship

    WordPress LogoAutomattic – the company behind WordPress.com, have taken a decisive step in the fight against bogus DMCA claims.

    Under the Digital Millennium Copyright Act, people can submit a takedown notice to web service providers where their intellectual property is being used without permission. This is the legislative attempt to protect hosts like Google, WordPress, Tumblr, etc from being held responsible for the content that their users post – provided that they swiftly restrict access.

    However, whilst this system is designed to give a balance between protection and enforcement, the reality is that many times it is abused by those who wish to silence critics, or to censor views with which they disagree. The Church of Scientology infamously issued thousands of DMCA takedown notices to stop the spread of anti-Scientology views on Youtube, for example. This tactic is highly effective, as the content is almost always restricted (at its peak moment of attention), and the process to challenge the notices (a ‘counter notice’) isn’t something that creators are, or arguably should be, familiar with. In effect, it becomes a virtual game of ping-pong, with the burden of proof shifting to the ‘author’ of the content to prove that they actually have the rights to publish. Sites themselves can take action, but with the sheer volume of notices that they receive, it is often impractical, and rarely a route that businesses want to go down.

    I’m both pleased and proud to see that WordPress are fighting back against two such bogus DMCA claims, as announced in this latest blog post, where you can find all the details of the two cases in question.

    For the full text of the original post from Oliver Hotham – one of those that fell victim to the misrepresentative DMCA, continue reading below, where it is republished with permission.

    (more…)

  • No, It’s Not Just About Porn

    No, It’s Not Just About Porn

    Glasgow Guardian NewspaperThe Glasgow Guardian is the student newspaper from the University of Glasgow, and is generally better than most of the publications of this type that I’ve come across – I’m not just saying that because they used to use my pictures.

    I was surprised to come across an article in the last issue entitled ‘The day the porn was still there‘, which spoke about the proposed Internet filtering that the Government were seeking to impose on ISPs in the UK.

    It wasn’t great. Have a read for yourself.

    I wrote a response, which has been published in the current issue, on page 11.

    For those of you that aren’t fond of viewing content online in a format suitable for print (and why would you be?) the text is below:

    I write in response to the article entitled ‘The day the porn was still there’, published on the 16th of September 2013, by Imants Latkovskis.

    In the interests of full disclosure, I am a member of the Open Rights Group Supporters’ Council – the ‘London based NGO’ whose views were criticised in the original piece. However, the purpose of this response is not to rise to defend the content of the organisation’s claims; that job is for somebody else – and not what I signed up for.

    Aside from the over-use of emotive language, and massively reductive statements (“ticking the ‘I want porn’ box is unlikely to be the start of a dystopian future.”), Latkovskis has managed to miss the point completely; the thrust of the article seeming to be that ‘illegal porn is bad, so it’s good that they want to block it’.

    Latkovskis states that in justifying the proposed filter, David Cameron was ‘referring to child pornography, which seems to be forgotten about quote after quote.’ However, he himself is guilty of confusing two quite distinct issues. This isn’t something that he should feel too bad about though, as the proposals have been deliberately designed to have this effect.

    We have to separate out whether the purpose of an on-by-default Internet filter is either to:

    1. Prevent access to illegal material, e.g. child pornography

    or

    2. Prevent people (ostensibly children) from accessing any pornography

    These are two very different aims, and require equally different approaches.

    It’s a moot point for the purposes of this article that none of these type of filtering systems actually work effectively in any regard. If you aren’t sure about that, just ask yourself when the last time was that you or a ‘friend’ used a VPN to get onto American Netflix, or a proxy to peruse certain eye-patch clad torrent websites. Never, I’m sure!

    The concern that any sort of default Internet filter will inevitably also block access to other content is not an unfounded one. Mobile operators such as Orange and T-Mobile have already blocked sites under categories headed ‘Chat’ and ‘Forums’ from their service without an explicit indication that you want to gain access – something that you often cannot obtain until you have been a customer for 6 months or longer. Nobody should have to submit their name to a database with tick-boxes against the categories of content they have chosen to view, or what information they want to exchange, and that is a realistic consequence of these proposals.

    This fundamentally isn’t about pornography, and to suggest that those who question a blanket, State-mandated Internet filter are advocating free and unfettered access to ‘material depicting rape and child abuse’ is at best disingenuous, and dangerously mis-informed.

    Yet another badly thought out, technologically incompetent piece of legislation (if ISPs are not pressured into this ‘voluntarily’) will do nothing to protect children, nothing to stop the spread of illegal material, and only serve to further squeeze the freedom to communicate and disseminate information online.

     

  • Response from John Mason MSP and Anas Sarwar MP on NSA/GCHQ Surveillance

    After the revelations last week concerning the active weakening of encryption technologies by the NSA and GCHQ, I used writetothem.com to get in touch with my local MSP John Mason, and MP Anas Sarwar.

    The message I sent to John is below, with a similar variant used for Anas Sarwar:

    Dear John Mason,

    Yesterday a number of major media outlets published revelations that GCHQ, in partnership with the American NSA, have been systematically working to defeat encryption systems used on the Internet. Despite a move many years ago to have vulnerabilities inserted into encryption software being defeated, these agencies have clandestinely used their considerable resources to do this extra-legally.

    In actively reducing the integrity of secure communications, GCHQ has also weakened the protection of consumers online. With un-named vulnerabilities being implemented into systems that we have been led to believe are safe, such as online banking, and e-commerce, these have been opened up to exploitation by third party hackers. The Internet is a more dangerous place because of these actions.

    Much is still unclear about the capabilities possessed by GCHQ and the NSA, such as what technologies that are now vulnerable. Answers need to be provided, as these agencies have far over-stepped their remit, effectively engaging in mass surveillance of their own citizens, in breach of the right to privacy afforded by the various International conventions.

    Whilst I understand that this can arguably be classed as a reserved matter, I believe that it is so important that the actions of GCHQ cannot be left un-challenged. I ask that you would publicly challenge GCHQ for details of the technologies that they have exploited; to cease the invasion of the privacy of those in Scotland; and to demand that the UK Government explains why this has been allowed to happen.

    I look forward to your response,

    Yours sincerely,

    Stephen Blythe

    secure email

    I have always found John Mason to be helpful, and determined to stand up for his constituents. His response is below:

    Dear Stephen

    Thanks for your email.

    In the first place I am happy to agree with your main points that GCHQ or whoever should not be spying on their own citizens.  You can quote me publically[sic] on that if you want.

    However, how to deal with it is more difficult.  In the first place I think there is wide public support for spying by the state on suspected terrorists and in fact when we do see terrorist acts we often have a public reaction as to why the state had not been more proactive in clamping down sooner.  The film ‘Minority Report’ (I think) raised some of these questions in how far the state goes in preventing crimes happening.

    Secondly, I believe GCHQ has the full support of the UK government/establishment.  They see it as their job to do all this kind of thing.  So asking them not to do it is a bit like asking a cat to stop being a cat.

    Thirdly, my guess is that the UK establishment is also spying on the Scottish government.

    On a personal basis, I tend to work on the assumption that my phone calls may be tapped, my emails and texts are likely tobe read by people who should not be doing so.  Can we change all this?  I’m not sure.  I would certainly likely to and am happy to support any campaign on this.  Whistle blowers are certainly part of the answer.  Unless we can get insiders to go public, I doubt we will find out much information that the establishment does not want us to have.

    I am happy to discuss any of this with you face to face if that would be easier.  I guess I am a bit sceptical but I am open to persuasion that things can be made better.

    Regards

    John Mason

    The response from Anas Sarwar is below:

    Dear Mr Blythe,

    Anas Sarwar MP has asked me to thank you for your email below regarding allegations about data collection and sharing by UK intelligence agencies.

    These are, of course, extremely serious allegations and it is vital that they are thoroughly investigated and that we ensure there is effective oversight and a clear legal framework to oversee our intelligence operations.

    Mr Sarwar appreciates that our intelligence and security services undertake vital, often unrecognised, work to protect our security and to counter the threats we face. Given the global nature of their work it is also crucial that our intelligence agencies are able to share information across international borders with our allies, including the USA.

    However, he also believes there needs to be public confidence that our intelligence agencies are themselves law-abiding and accountable, and that any intelligence information received from the USA or any other country has been obtained legally.

    These recent allegations have caused real public concern and underline once again the need for effective Parliamentary and Ministerial oversight of all three of our intelligence organisations. The Government have been asked a number of questions about these allegations in the House of Commons and by the Intelligence and Security Committee. The Committee was set up in 1994 to examine the expenditure, administration and policy of the country’s intelligence agencies, and is currently looking into the issues around GCHQ that have been raised by recent events.

    Mr Sarwar has asked me to assure you that he will continue to monitor this important issue closely and will try to raise some of the points you mentioned with Government Ministers in Parliament ducharlotte.methuen@glasgow.ac.ukring Ministerial question time. [sic]

    Thank you once again for writing to Mr Sarwar and sharing your views with him.

    Yours sincerely,

    Yassar Abbas
    Office of Anas Sarwar MP
    Deputy Leader of the Scottish Labour Party
    Member of Parliament for Glasgow Central

    Rm 221-223 Portcullis,
    House of Commons,
    Westminster,
    London,
    SW1A 0AA.

    I since have invited John Mason to come and meet with the Glasgow Open Rights Group members to discuss the issues involved.

  • The NSA, GCHQ, and Encryption. What’s Going On?

    encryptionIn the past few days, more details have emerged about the sheer extent of the surveillance being carried out by both the NSA in America, and GCHQ in the UK.

    Whilst the initial news that these intelligence agencies have been intercepting massive amounts of data was a shock, the latest round of news is perhaps the most alarming of all. PRISM had an apparent budget of $25 Million. ‘Bullrun’ has a value of closer to $250 Million.

    A surge of web users have reportedly moved to increase the amount of encryption they use on a daily basis after discovering the extent to which their unsecured communications were being monitored. Now, it turns out that that much of that encryption could well have little effect on the ability for Government bodies to snoop.

    This is a development that has massive implications for our use of, and dependency on, the Internet itself… yet because of the subject matter, has not garnered as much coverage as it should have. The articles from the Guardian et. al give an insight into what is going on, but do not go into specific details of the technologies at risk, and can be inaccessible to somebody who is not already familiar with issues relating to encryption.

    What’s the problem?

    • When encryption first was introduced online, there was a concerted effort by Governments to require systems to have in-built weaknesses to ensure they retained an ability to access it; the ultimate master key. This was defeated after a hard-fought, cross-political campaign. However, the NSA and GCHQ have gone ahead and achieved the same result, without legislation, by utilising their considerable resources.
    • The intelligence agencies have deployed multiple tactics to ensure they have access to data – whether it is encrypted or not.
    • One of the tactics includes the weakening of encryption systems by implementing vulnerabilities into their architecture. This means that even the most theoretically secure encryption services can be exploited to reveal the information.
    • Encryption is not just a tool for political activists or paranoid geeks. Every day we rely on encryption to securely log in to our bank accounts; buy things online; save usernames and passwords; and keep the likes of our Facebook accounts from interference.
    • By systematically targeting encryption to weaken its protections, the NSA and GCHQ are also undermining the integrity of all of our communications online; the basis of the global ‘information economy’.

    How can I protect myself?

    At the moment, it isn’t clear exactly what services have been manipulated, and what have not. Speculation is rife over whether actual protocols used (such as HTTPS for secure web browsing) have been compromised, or whether it is simply specific companies that have been coerced into providing covert ways into their services. SSL for example – indicated by the presence of the padlock in the address bar – has been shown to be extremely vulnerable given the way that the ‘certificate authorities’ who sign off on the transmission are susceptible to attack. As Orwell Upgraded puts it: ‘Who looks after the keys?’ Even the much lauded article by security expert Bruce Schneier on this topic seems contradictory and unclear in places. (“The NSA has huge capabilities – and if it wants in to your computer, it’s in. With that in mind, here are five ways to stay safe” – Eh?!)

    However, this technology is not available to everybody, yet. Your local police force will not have access to this technology, nor your employer, nor the opportunist hacker. It wasn’t too long ago that even Scotland Yard were reporting that the use of TrueCrypt encryption on David Miranda’s laptop rendered the data ‘extremely difficult to access’. The NSA is still reportedly deploying many of the bread-and-butter tactics used by hackers for decades, including brute-force attempts to access accounts by mathematically ‘guessing’ passwords. If they did indeed have a golden bullet to decrypt all secure material, then there would be no need for this. Edward Snowden himself, the exiled NSA contractor who leaked the documents in the first place, has confirmed that ‘properly implemented crypto systems‘ work; the issue being the lack of security that surrounds those systems in the first place.

    There are still steps that can be taken to make it more difficult for your data to be accessed. Whilst not ideal, for the everyday web user, taking a few extra steps can mean that your data is less likely to be intercepted than somebody who takes no steps at all. There’s that well-worn tale of the man who, when faced with a lion, puts on trainers. When someone points out that he’ll never be able to out-run such a powerful beast, he simply replies that he only has to out-run everybody else.

    No, we don’t know who to trust just now, but you can still take steps to improve your security:

    • Make use of high entropy passwords. Never use the same password for more than one service. LastPass is one of the best ways to manage this. Whilst stored in ‘the cloud’, it makes use of end-to-end encryption, which means only you should theoretically be able to decrypt its contents.
    • Encrypt your data with 4096 bit encryption where possible.
    • Use open source software that can be scrutinised by the online community for weaknesses. Avoid commercial, ‘closed’ software from a vendor that can be more easily manipulated. TrueCrypt is one of the most widely used and respected. Whilst we currently don’t know about its status in this whole affair, it’s one of the best bets.
    • Encrypt your Internet traffic with a VPN, or use Tor.
    • Use extensions such as HTTPS Everywhere to ensure you are always using the most secure version of a website where available.

    Make your data as difficult to access as possible. Don’t just leave the door wide open.

    What now?

    Good question.

    • People need to know about this and why it’s important, not just be blinded by the technical speak. Spread the word, explain to people, and get them to act as well. – (Share This on Twitter)
    • Sign the Electronic Frontier Foundation’s petition to demand answers to what is going on. (US link hereUK/International link here).
    • Write to your local MP and demand that they challenge the UK Government to give answers on this. Write to your MSP and do the same with the Scottish Parliament; it might be a reserved issue, but they still have the power to speak. Cause a fuss until they listen.

    This is a dark time for the Internet, but it doesn’t have to stay that way.

  • Do we need a ‘Cyber Fire Department’?

    Yesterday I attended the ScotSoft 2013 technology forum hosted by ScotlandIS in the Sheraton ‘Grand Hotel and Spa’ through in Edinburgh. The event – followed afterwards by an awards dinner (which I did not attend!) – had a number of speakers that covered issues across the software business lifecycle, from acquiring initial financial backing to long-term development plans.

    ScotlandIS LogoThe keynote was on the future of the Internet, and came from none other than Google’s ‘Chief Internet Evangelist’, Vint Cerf. It only took a few minutes to realise why he rightfully deserves what is probably the coolest job title that any self-respecting geek could ever have. Whilst the rest of the day had been very much focussed on those involved in the business side of the tech industry, Vint spoke with a natural and pervasive authority on everything from the implementation of IPv6 (‘Go ask your ISPs what their roll-out plan is’), to the distributed and often chaotic nature of Internet Governance. It should perhaps have been obvious that this would be the case from one of the ‘founding fathers’ of the Internet, but it is a rare thing indeed to find someone who is not only so formidably technically able, but who also has the charm and charisma to communicate that passion and ability to others so effectively. In many ways, it brings into question the existence of the much fabled, so-called ‘digital native’, and whether or not such a thing can or should be defined by reference to any particular generation.

    Vint covered many topics in the short time he was allocated – from the crude beginnings of ARPANET, all the way through to using TCP/IP in space – but there was one fleeting reflection in particular that really captured my imagination: the idea of a ‘Cyber Fire Department’. This wasn’t something that there was too much time spent expanding upon, but he explained by giving the example of somebody trying to single handedly stop their house from burning down with a bucket of water; eventually, they would need other people to assist with bigger hoses and more water than they could supply on their own. With people increasingly concerned about the issue of safety online, the notion of a service that responded to people experiencing overwhelming technological difficulties was something that he suggested ‘we should be thinking about’.

    It’s this idea I’d like to think about.

    Binary Hose PipeWhy on earth would we need or want such a thing?

    At first, it might seem a ludicrous proposition, especially to those who still instinctively perceive the Internet as some sort of glorified playground for teenagers to frivolously socialise. To many, the web simply isn’t serious business, despite all of the evidence to the contrary. Truth is, it may well be easier to simply be dismissive rather than to face the difficult challenges that will inevitably need to be tackled as the result of the increasing permeation of the Internet into our everyday lives.

    We now have a globally interconnected network which has transformed the way we communicate, and become incorporated into the very foundation of our economies. This is not a phenomenon that is going to be reversed, and if anything, is set to increase rapidly as mobile devices proliferate, and more and more objects get the ability to share information on the net (the latest hot phrase being the ‘Internet of things’).

    Just as fire spreads quickly from adjoining buildings due to carelessness or lack of education, the same is true of the Internet; weaknesses in one system potentially having a devastating knock-on effect on others that are connected either directly or indirectly. In order to ensure the integrity of such an important asset, it appears that to contemplate the proposition of an emergency cyber response brigade seems eminently sensible.

    What would a ‘Cyber Fire Department’ look like? What would it involve?

    Let us assume that such a service was run separately from region to region, rather than some centralised, global endeavour. Aside from simply flying in the face of the distributed nature of the web in principle, I’m sure that all of us can imagine the bureaucratic nightmare that such an international entity would inevitably end up finding itself embroiled in (ICANN, anyone?).

    The gut reaction to the suggestion of such a service may be to query the merit of a 999/911 type response to issues that do not fundamentally involve crimes relating to the person, but this model doesn’t necessarily have to be the one that is adopted. If brought into existence, the thing would not be required to have the same status as the major emergency services, nor indeed have to be publicly funded. One needs only to look at the myriad of examples that are out there already, such as the Royal National Lifeboat Institution (RNLI) to see how such a service can be both publicly available and independent.

    …but would the market swallow this? There are already commercial offerings from the likes of the ‘Geek Squad’ marketed as emergency technical support. It seems unlikely that there would be any philanthropic provision from a non-profit organisation with substantial enough backing to effectively take on the private actors, which would seem to indicate the inevitability of some sort of central Government involvement.

    Perhaps a bigger hurdle to be overcome would not be the financial element of the funding, but the ideological implications of the origin. Already, creeping state involvement in the regulation of the Internet is being pushed back by advocates of the ‘open web’, and the introduction of such a significant step could be easily seen as too much interference in a sphere that by its very nature transcends the boundaries of nation states.

    How far do we take this?

    If we accept the premise that the Internet is a precious enough asset that we should adopt some sort of cyber fire department, then there are other interesting questions that become raised as a consequence. Off the top of my head, some of these might include:

    • Ageing computer systems and equipment pose some of the most significant security risks. Should we implement an MOT style check to ensure that the equipment people are using is of an adequate standard to help ensure safety online?
    • Do we grant the cyber fire department statutory powers to ensure that ‘cyber safety’ regulations are enforced, much as their equivalents in the actual fire service have?
    • Viruses are often spread by those who are unfamiliar with how to properly navigate online. Does this mean that we should implement a driver’s license style test before they are granted access to the Internet?

    Some of this sounds preposterous, and would (rightly) be considered a massive encroachment into online freedom, but it wasn’t so long ago that the idea of state-wide Internet filters blocking access to content including message boards seemed completely out of the question too.

    Thinking about it

    The question about whether we should adopt an emergency cyber response service in the style of a cyber fire brigade may seem like being a long way off from any serious implementation, and it probably is. However, the discussion does spark off a whole slew of related considerations that we should be taking seriously. As the UK Government comes under criticism for its ‘digital by default’ strategy for not taking into account those without either the access or training to get online, the issue of digital engagement and education seems to go hand-in-hand with a lot of the concerns relating to online safety.

    Whatever the outcome, we are at a point of transition, and the policy issues that are involved are as fascinating as they are complex. Like Vint said yesterday, it’s something we should be thinking about.

  • The Ask.FM saga continues

    The illustrious Mark Leiser has quoted yours truly in his latest post on the ask.fm/Twitter abuse saga over on the Drum. I’ve got an article on the same topic lined up for this week on the Open Rights Group Zine, so keep an eye out.