Tuesday, December 14, 2010

What is happening to Intellectual Property law in this country?

The last couple of months have seen interesting developments in Intellectual Property (IP) law. The Combatting Online Infringement and Counterfeits Act (COICA) made it through Committee in the Senate. The Department of Homeland Security (DHS) is being used to enforce IP law by the Department of Justice (DOJ). Internet domains are taken down with no warning to disrupt the sale of counterfeit goods. According to the press release from the DOJ:

The coordinated federal law enforcement operation targeted online retailers of a diverse array of counterfeit goods, including sports equipment, shoes, handbags, athletic apparel and sunglasses as well as illegal copies of copyrighted DVD boxed sets, music and software.

Makes sense and seems reasonable. But they seized at least one search engine that never hosted torrents or knock-off items. That is disturbing. What would happen if DHS suddenly decided to seize Google? Bing? You can find torrents and knock-offs on those sites, too. Shutting down a search engine because you can find pirated movies is like shutting down a library because you can find the formula for TNT.

Historically IP crimes have been civil matters. But recently they have begun to be pressed as criminal offenses. Take a case reported by Wired.com, the case of Matthew Crippen. Crippen is charged with two counts of circumventing DRM on XBox video consoles by installing mod chips that allowed people to run homegrown software, RIPped DVD's, and other 'unofficial' content, although he could have been charged with many more counts. His lawyers are trying to use the recent decision granting jail-breaking the iPhone an exemption under fair use as part of their defense strategy. If they lose he's facing 3 years in jail, although it could have been as long as 10 years.

Why is the Department of Homeland security enforcing copyright law? Why are IP cases being tried as criminal cases? Why are we changing our IP suspects guilty until proven innocent? How can we fix these problems?

ICE takes down 77 Internet domains without warning

According to Mashablecom,  Friday the Immigrations and Customs Enforcement (ICE)  division of the Department of Homeland Security seized approximately 77 domains for copyright infringement. The seizures were made without any warning and without going through the hosting ISP's.

CBSnews.com reports a Torrent of Gov't Seizures in Online Piracy War, and tells us that ICE is taking down domains that host pirated movies and music in a move to combat piracy. They are supposedly getting court orders based on complaints received.

The reports also tell you that not everyone agrees with this move. I know I don't. It's not that I condone piracy. I disagree with the current copyright law for several reasons. One reason is that it makes it illegal for me to exercise my fair use right to make a backup copy of a movie, software, ebook, etc. It's wrong to rip a movie and put make copies for my friends or put it online for anyone to copy. But making a single copy for personal backup is allowable according to the fair use provisions of U.S. copyright law.

The big problem with ICE taking down infringing domains is that entire domains are being taken down without warning - possibly without recourse - regardless of whether or not the entire domain is involved or even aware of the alleged infringements. What information was used to determine the domains should be taken down? What kind of checking was done to verify infringement took place?

The U.S. (and other) government(s) have the right and duty to enforce their laws. Sharing copyrighted movies without permission of the copyright holder is immoral and illegal. So taking down sites who exist to make it easy to share illegal copies is proper. But doing so in a manner that takes down that are not involved in illegal activity is not. It is very likely that there were legitimate sites taken down by this action. Possibly even legitimate businesses. That is not just wrong, it's irresponsible.

The government has a responsibility to enforce it's laws, but it also has a responsibility to enforce them in a fashion that causes the least pain and suffering possible to the law abiding citizens. The very nature of file sharing sites makes it possible for cease and desist letters to be sent and/or investigation into the suspect domain to determine exactly which sites are guilty to be done without risking the case. Taking down entire domains without considering that a domain can contain many different totally unrelated sites could result in more harm than the illegal file sharing.

The government has a responsibility to enforce the laws, but please don't trample on law abiding citizens to do it.

Happy Thanksgiving!

Next blog Monday, Nov. 29.

Cookie Monster imitates Betty White

Cookie Monster has decided that what worked for Betty should work for him, too. so has a Facebook page, and is looking or supporters to get him a hosting gig. Go show your support.

PS: If you're flying this Thanksgiving, remember, the poor shmuck "touching your junk" probably doesn't like it any more than you do, so try to take it easy on him (or her).

Bullies video beating, post on Facebook

Another case of Facebook being used by bullies is being investigated, this time in Schenectady, NY. But instead of using the site to bully other students, the bullies made a video of the beating they gave another student and posted it on Facebook.

Other students visiting the Facebook page said they would like to see the girl in the video beat up at school. The police are investigating, and given the schools history, I don't think they'll go lightly on the bullies. In the 2008-09 school year four girls committed suicide, and two of them were probably being bullied when they did it.

This case is different than the usual Facebook bullying you hear about. The girl wasn't abused by messaging and wall posts, she was beat up, video'd, and more students said they would like to see her hurt at school. While it's easy to create an anonymous Facebook page, most camera's today put identifying information on the video, so the students who beat her may get a surprise visit from the police, even if none of the students who visited the page used their real names on their accounts. And I'm glad. This is one time that I wouldn't mind if Facebook was even more dismissive of users privacy than it already is.

The terrorists are winning

I got a kick out of this cartoon by Mike Keefe on the Cagle Political Cartoon blog. I thought it was pretty close to right, but amusing.

Then I read about Thomas Sawyer, a survivor of bladder cancer who was humiliated by thoughtless TSA employees. He was chosen for an enhanced pat down after going through the full body scanner. He tried to warn them about his urostomy bag, but they ignored him and broke the seal, leaving him wet and smelling of urine. The TSA employees acted as though nothing had happened despite the wet spot on his clothes. And I realized that the changes we're enduring because of terrorism are no laughing matter.

Next I read a headline, "Qaeda Branch Aimed for Broad Damage at Low Cost," referring to the failed (or not) parcel bomb last month. The terrorists claim the operation may not have blown up a plane, but it had the desired effect of causing the U.S. to revamp security again, a time consuming and expensive prospect. In fact they've shifted emphasis from flashy attacks to simple, low grade attacks that cause maximum return in things like expanded security procedures.

The terrorists have won. They control our airport security. We need to turn things around and come up with reasonable procedures for airport security that respect human dignity and treat airline passengers like customers, not suspects.

Combating Online Infringement and Counterfeits Act makes it out of committee

Public Knowledge reports that the Senate Judiciary Committee has approved COICA. COICA is a nasty piece of legislation that allows a person to get a website taken down by complaining that it is infringing on someone's intellectual property. No hearings, no trials, no investigation necessary. Complain to the ISP of the allegedly offending site, and down it comes. It won't work the way it's intended, and will have little effect on criminals, but it could have a profound effect on legitimate businesses who deal with file storage and encryption. I blogged about some of the problems last month.

Write your senators and representatives. This is important, and could change the face of the internet completely if left unchecked. It's made it out of committee, but it can be stopped short of passing the Senate and be kept out of the House entirely. Find your senator's physical and email addresses here Find your representative's physical and email addresses here.

TSA procedures fail most important test: Effectiveness

The Transportation Security Administration (TSA) is coming under a lot of fire lately. Privacy advocates and groups are attacking full body scanners and "enhanced" pat downs while overzealous, poorly trained or just plain drunk with power employees do things that are fueling the fires of citizen backlash against the ridiculous procedures.

From the (over)reaction to Johnny Edge's refusal to get either full body scanned or an enhanced pat down to a three year old girl terrorized by a too literal interpretation of the rules by a TSA employee, it has become obvious that the TSA and our government have forgotten who the enemy is. And I think even the low level employees know how ineffective their procedures are. The frustration, and maybe even fear that they will be the one that let's a bomber through cause them to react to any resistance, even a tired, scared three year old, as if it's a serious threat.

Of course, not everyone thinks the TSA is wrong. Even though there are experts who refute the TSA claims that the full body scanners are harmless. Even though there is doubt that the scanners would detect explosives of the type used by the crotchbomber. Even though no one knows if the scanners will detect or scan through artificial flesh. Even though the GAO recommended more testing before buying or deploying any more of the scanners earlier this year. Even though there is so much doubt about the real usefulness of the scanners The Christian Science Monitor supports the TSA, as does Alex Altman at the Time Swampland political blog. Mr. Altman cites a CBS poll showing that 81% of Americans are ok with the TSA procedures. But the problems with TSA procedures will persist even if 100% of the citizens are ok with them.

You can say that any security can be breached by someone clever and determined enough. And you wouldn't be lying. But it doesn't even take a particularly clever or determined terrorist to get through the body scanners and pat downs.

But that's not the worst. The way airport security works now, all you have to do is get into the airport and approach the people lined up at the checkpoints. Not as spectacular as the flaming remnants of a passenger jet falling from the sky, but possibly even more effective as a terror tactic. Maybe as effective psychologically as hitting the Twin Towers on 9/11.

Could Israel's system scale to work with our aviation system? Can any part of it? Has anybody checked? If it can, then leaving the system we have in place unaltered is criminally negligent.

Dept. Of Transportation launches "Faces of Distracted Driving" site

Phone calls, text messages, screens in the dash. There was a time when it was kids and the radio. Now there's an army of driving distractions to pull our attention from the road. Transportation Secretary Ray LaHood announced on his official blog today the launch of "Faces of Distracted Driving, a site devoted to the danger of driving while distracted.

There is a lot of information on the site, including a summary of state laws, a FAQ and statistics. There are also three stories of people killed by distracted driving with more to be added. It's sobering, and thought provoking. Just a few days ago I received a text on the way home and started to reply when I realized I was veering to the ditch. I straightened out and put away the phone, but I was seconds from being a statistic. I resolved not to text while driving, and these stories reinforced that resolve.

We often don't think about the consequences of our actions, and when we do, we think the worst won't happen to us. But it can. I don't know which scares me more, the thought of leaving my family without a husband and father or taking someone elses loved one away forever because I couldn't be bothered to pull over or get where I'm going before talking or texting.

Facebook messages - We want to license to the rest of your life.

Facebook is beginning a "slow rollout" of a new service, Facebook Messages. Messages will combine chats, sms messaging, and email. Eventually it may include VOIP messages. It's pretty cool. If you want you can have an @facebook.com email address, or if you want to keep your current address you can. It keeps a history of all of your conversations. You can even add friends that aren't on Facebook and keep records of your conversations with them. The only tradeoff is that Facebook now has license to make use of all of that content per the statement of rights and responsibilities, section 2:

You own all of the content and information you post on Facebook, and you can control how it is shared through your privacy and application settings. In addition: For content that is covered by intellectual property rights, like photos and videos ("IP content"), you specifically give us the following permission, subject to your privacy and application settings: you grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook ("IP License"). This IP License ends when you delete your IP content or your account unless your content has been shared with others, and they have not deleted it. (emphasis mine) When you delete IP content, it is deleted in a manner similar to emptying the recycle bin on a computer. However, you understand that removed content may persist in backup copies for a reasonable period of time (but will not be available to others). When you use an application, your content and information is shared with the application. We require applications to respect your privacy, and your agreement with that application will control how the application can use, store, and transfer that content and information. (To learn more about Platform, read our Privacy Policy and About Platform page.) When you publish content or information using the "everyone" setting, it means that you are allowing everyone, including people off of Facebook, to access and use that information, and to associate it with you (i.e., your name and profile picture). We always appreciate your feedback or other suggestions about Facebook, but you understand that we may use them without any obligation to compensate you for them (just as you have no obligation to offer them) (emphasis mine).

The provisions giving Facebook a license to all of my data doesn't seem too bad since it's subject to my privacy and application settings. If only I could know that my settings would not change without my wanting them too. It would also help if my privacy settings wouldn't be set to wide open every time Facebook decides to make changes to their privacy settings.

Facebook's new Messages is a really good idea. But there are few companies I would trust less with my private messages.

In Palestine, impersonating God could be bad for your health

Eric Berry on Allfacebook.com reports that Walid Husayin of Qalqilya in Palestine is facing possible life in prison for claiming to be God in several Facebook groups he created. He also criticized the Islamic faith and created mock Quran verses that encouraged people to smoke marijuana.

It's somewhat risky to criticize Islam over the internet while in an Islamic country. It's a little riskier to claim to be God in an Islamic country. To do both from an internet cafe in a small conservative town in an Islamic country is asking for trouble.

Walid Husayin spent 7 hours a day on one computer of the local internet cafe. The owner became suspicious and had employee take screenshots while Walid was on the computer. He turned them over to the police, who arrested Walid while he was at the cafe blogging. The maximum sentence by law is life in prison, but people in Qalqilya - people he has known his entire life - want him executed by burning.

I guess we should count our blessings. In the U.S. we can say what we want about our government or any religion without fear of arrest. But as our government continues to monitor as many of the countries phone calls as it can and law enforcement seeks the power to decrypt any and all private encrypted communication, can we be sure that will always be the case?

Not if we don't make sure it is.

The lighter side of airport security

After seeing stories like "Pregnant Traveller: TSA Screeners bullied me into a full body scan it's nice to see people aren't letting the idiocy break their spirit. Here are a few links to sites that take the TSA with a grain of salt:

A (fake) children's book to help you're kids understand the security process.

Here are T-Shirts that I could wear through airport security. And because those weren't enough, the stop groping me T.

Thursday, November 11, 2010

National Labor board: Can't fire employees for Facebook comments

Monika Plocienniczak reports on CNN.com that the National Labor Relations Board (NRLRB) issued a complaint against American Medical Response, an Ambulance company that fired one of their employees after she had made some negative comments about her job on Facebook.


AMR, of course, denies that the woman was fired for her Facebook comments. They say that she was fired because of multiple complaints about job performance and her treatment of patients.


In some ways it doesn't matter why she was fired. It does matter what the final decision is. If a court agrees with the NLRB, then venting about your boss on Facebook becomes protected speech under the National Labor Act. That is very important. Right now employers can monitor Facebook and determine who is hired, who is promoted, who is demoted using what they find there. If Facebook comments fall under the National Labor Act then the won't be able to do that. It may not prevent employers from using social media to look at prospective employees, but it will make it illegal for social media to be used to determine who to fire, promote or give raises.


One of the biggest problems with social media is that it makes parts of our lives that used to (and still should) remain private are public. Now those private things are being used to determine whether persons would make good employees. We know things now about past Presidents that might have, had they been generally known at the time, been major scandals. Maybe even have derailed their presidency. John Kennedy was a womanizer. So was Clinton. Whatever you may think of his womanizing (and his politics), Clinton was one of the most astute statesmen the U.S. has had in the Oval Office.


Much of what is on Facebook is "not safe for work" and much isn't safe for your career (current or future) either. The bad thing is, much of that isn't really a good indicator of what kind of employee a person will be. Employers shouldn't be allowed to use it for that purpose.

Using stolen Social Security number isn't identity theft

The Colorado Supreme Court has overturned the identity theft conviction of Felix Montes-Rodriguez. This case is important because according to the courts decision, the fact that he used a stolen Social Security number did not make his action identity theft:

Montes-Rodriguez admitted to using the false social security number. However, he contested the criminal impersonation charge. He argued that he did not assume a false identity or capacity under the statute because he applied for the loan using his proper name, birth date, address, and other identifying information.

and further down:

We reverse. Consistent with previous Colorado case law, we hold that one assumes a false or fictitious capacity in violation of the statute when he or she assumes a false legal qualification, power, fitness, or role. We also reaffirm our earlier holding that one assumes a false identity by holding one’s self out to a third party as being another person.

When I first saw this decision I thought, "No Way! How could they say that?!"

But after rereading, I realized that the court was right. This particular criminal didn't steal anyones identity, he just committed fraud. He never claimed to be someone else. He used all of his own identifying information except for his Social Security number. By the definition of identity theft in Colorado law, he didn't steal anyone's identity.

That doesn't make his crime less serious. It should make it easier to get any bad marks on credit report removed, since it's fairly easy to prove they were the result of fraud by a third party. It should. In practice it may not be so easy. If a car dealer or bank was willing to accept a Social Security number that was not connected in any way to any of the other identifying information given, and approve a loan based in part upon that number, then the financial reputation and identity of the rightful holder of the number has been stolen. It doesn't matter that the name, address, phone number and everything else on the application belongs to the actual applicant. The credit score(s) attached to the Social Security number is a, possibly the, major factor in the approval of the loan.

Forty years ago the idea that a Social Security number isn't tied to identity might have worked. Today it is so entwined with our identities that it can be difficult to do anything without one. The law needs to catch up to that reality and recognize that sometimes the financial history attached to a Social Security number can be more important than the name - as evidenced by this case.

Tuesday, November 9, 2010

Using stolen Social Security number isn't identity theft

The Colorado Supreme Court has overturned the identity theft conviction of Felix Montes-Rodriguez. This case is important because according to the courts decision, the fact that he used a stolen Social Security number did not make his action identity theft:


Montes-Rodriguez admitted to using the false social security number. However, he contested the criminal impersonation charge. He argued that he did not assume a false identity or capacity under the statute because he applied for the loan using his proper name, birth date, address, and other identifying information.

and further down:


We reverse. Consistent with previous Colorado case law, we hold that one assumes a false or fictitious capacity in violation of the statute when he or she assumes a false legal qualification, power, fitness, or role. We also reaffirm our earlier holding that one assumes a false identity by holding one’s self out to a third party as being another person.

When I first saw this decision I thought, "No Way! How could they say that?!"


But after rereading, I realized that the court was right. This particular criminal didn't steal anyones identity, he just committed fraud. He never claimed to be someone else. He used all of his own identifying information except for his Social Security number. By the definition of identity theft in Colorado law, he didn't steal anyone's identity.


That doesn't make his crime less serious. It should make it easier to get any bad marks on credit report removed, since it's fairly easy to prove they were the result of fraud by a third party. It should. In practice it may not be so easy. If a car dealer or bank was willing to accept a Social Security number that was not connected in any way to any of the other identifying information given, and approve a loan based in part upon that number, then the financial reputation and identity of the rightful holder of the number has been stolen. It doesn't matter that the name, address, phone number and everything else on the application belongs to the actual applicant. The credit score(s) attached to the Social Security number is a, possibly the, major factor in the approval of the loan.


Forty years ago the idea that a Social Security number isn't tied to identity might have worked. Today it is so entwined with our identities that it can be difficult to do anything without one. The law needs to catch up to that reality and recognize that sometimes the financial history attached to a Social Security number can be more important than the name - as evidenced by this case.

Monday, November 8, 2010

You've probably never heard of Oliver Drage

I hadn't until I checked the "Conspicuous Chatter" blog and saw the latest entry about enforcement of Britians Regulations of Investigatory Powers Act 2000(RIPA).


Mr. Drage has been convicted of not giving his encryption key to investigators when they requested it, which is a violation of RIPA. He's been convicted of that crime and sentenced to 16 weeks in jail. Conspicuous Chatter is very clearly on the side of Mr. Drage and not happy with the way the BBC reports the story so I checked out what the BBC said.


The BBC reports that Oliver Drage was arrested by police investigating "Child Sexual Exploitation." Apparently they had enough evidence to arrest him and confiscate his computer, but not enough to charge him. His 50 character encryption key had them stumped, so they asked him for it. He refused. They charged him with violating RIPA and convicted him. The police reaction to the conviction and 16 week sentence:


Det Sgt Neil Fowler, of Lancashire police, said: "Drage was previously of good character so the immediate custodial sentence handed down by the judge in this case shows just how seriously the courts take this kind of offence.

I don't know British law, but I have to assume that 16 weeks is the stiffest sentence allowed for failing to surrender your password. Otherwise I can't imagine a judge not giving a longer sentence when the purpose is to get a man accused of sexually abusing children to give up the encryption key to his computer.


I don't know if he is guilty, and it's important to remember that although it looks incriminating, he could have perfectly legitimate reasons for not giving police the key. It could be principle. He could have some other type of incriminating evidence on his computer but be innocent of child sexual exploitation. It could be some other reason.


This is a question that is still being decided in the U.S. Is your encryption key protected by the Fifth Amendment? Should it be? I think the answer to both questions is yes. But cases like this one raise questions, I admit.


What do you think?

Friday, November 5, 2010

The first free anti-virus for OS X

On November 2nd PCMag.com reported that Sophos is releasing a free antivirus for the Mac. Other security companies are releasing software for the Mac, but Sophos is the only one to release free AV software.


The recent release of Koobface for Mac is only the latest malware designed for Mac. It was dead on arrival, but that was most likely a coding error, so a virulent version could show up any time. Sophos free software is available now and offers protection against Koobface and the other known Mac malware. There is a forum for discussing the software here and you can download it here


There are still people who argue that anti-virus on a Mac is unnecessary. Well, that may be true for now, but that will soon change as Koobface Mac was a hairs breadth from being the real deal. Mac users can't afford to keep being complacent about malware.

Thursday, November 4, 2010

Britian proposes allowing site takedowns with just complaint

http://www.ispreview.co.uk/story/2010/10/30/uk-government-make-isps-responsible-for-third-party-content-published-online.html

The U.S. wants to wiretap the internet. The UK wants to make it easy to get 3rd party content removed. MarkJ reports on ISPreview.com that:


The UK governments Minister for Culture, Communications and Creative Industries, Ed Vaizey, has ominously proposed that broadband ISPs could introduce a new Mediation Service that would allow them the freedom to censor third party content on the internet, without court intervention, in response to little more than a public complaint.

The proposal is supposed to be for the benefit of regular citizens, but it is easy to imagine the abuse by corporations and organizations (RIAA, MPAA, et al) who would use it as a club to attempt to force consumers to conform to industry ideas of how things should be.


It is sad that proposals to help protect citizens must be either be so carefully crafted and limited almost to the point of uselessness or risk abuse that does more harm than not having legislation would have.

Tuesday, November 2, 2010

Do us all a favor. Vote.

It's election day, and every eligible citizen should go vote. I'd say I don't care how you vote, but that would be a lie. I'd prefer you vote for conservative candidates who believe in citizens and states rights.


But regardless of my preferences, for our government to work the way it's supposed to every eligible voter needs to vote. We get the government we deserve, whether it's because we don't make our will known, or because we do. If you vote you are making your opinion known. Even if your candidate loses, how much or how little he (or she) loses by sends a message. That message can be more important than winning, if it tells other politicians they need to pay attention to what their constituents want.


So whatever your politics, go vote.

Monday, November 1, 2010

Predicting employee behavior available now

In a column titled, "'Pre-crime' Comes to the HR Dept.", Mike Elgin talked about a new industry, fortune telling.

Ok, he's not actually talking about fortune telling in the traditional sense. He is talking about predicting how people and companies will act in the future based on how they've acted in the past. He talks about two companies. The first is Social Intelligence, a company that scours social networks to provide information on prospective employees to companies. The idea is that information found on social networks is a better indicator of what kind of employee you will be than your resume.

The second company he talks about is Recorded Future. Recorded Future also scours the web to predict the future actions of people and companies. It attempts to find logical links that make it possible to make those predictions.

These are two companies, but how long before this type of algorithm is common in HR departments? What happens when hiring, firing and promotions are determined by predictions of future performance rather than past performance? What happens when software predicts that you will leave within 6 months? Will the company fire you preemptively?

For many of us, having an online presence is unavoidable, or even necessary. What does our online presence say about us? What kind of impression are we giving, and what kind of predictions can be made from it? As new and better predictive algorithms are developed the tidbits we leave online will become more important. Having control over as many as those tidbits as possible is the only way to have any control over our own lives. As things are now, we are at the mercy of the data miners who build profiles to predict what we like, what we don't like and how to convince us we need things. In the near future they will also be determining whether and how much money we have by telling our employers whether we should be given a raise, a promotion, or even a job.