Tuesday, 31 May 2011

Spreading ignorance or democracy through the web


If you were passing through Hoxton’s “silicon roundabout” last Friday and wondered why the traffic was a little easier than usual, it could have been because a good number of the folk that may well frequent such parts had cycled over to the Institute of Mechanical Engineers, Westminster, to attend a debate organised by those good folks at Demos and the Open Society Institute. Billed “Through a web darkly: does the internet spread democracy or ignorance?” the event was chaired by Ben Hammersley (Editor-at-large of Wired UK and founder of the Campus Party,) and featured Evgeny Morozov (author of “The Net Delusion: The Dark Side of Freedom and the Internet”), Dan Hind and Tom Chatfield.

All of these guys have got pretty extensive internet profiles, so I won’t comment on their credentials. Some of the points raised were very interesting, and ones which I need to think about in some depth. Evgeny made the simple point about behavioural advertising - that, thanks to algorithm techniques, the web becomes more a personalised, we are more frequently directed to information that we agree with, but is this leading to the politicisation of defaults?

He also remarked that the Government’s transparency agenda is somewhat flawed in that we will never be able to get all of the relevant information on the internet, but this is leading to a problem with rise of the conspiracy theorists, who will always be able to point to the absence of some information to establish a convincing narrative that they affirm too, but which may be well off the actual truth.

In terms of the technical ease with which rumours can be translated into fact, it’s now probably far cheaper to hire a team of 100 bloggers to create noise potential America presidential candidates can appear to be doing quite well among the electorate, despite their obvious lack of political gravitas.

Dan Hind supplied my favourite quote of the afternoon though, which was a chant that he had picked up being shouted by the protesters in Tahrir Square in Egypt during the recent civil uprising which led to the demise of former President Mubarak in February. A small group were heard to chant: We are the girls who chat to the boys on Facebook. For them, freedom was being able to admit an activity that was forbidden. The little things we take for granted in the UK, yet freedoms not yet properly won everywhere. And no, that's not them chanting that chant in the image. These girls are obviously protesting about something much more acceptable to whoever is reading this. So there's no need for members of the Egyptian army to arrest them and require them to undergo virginity checks.

Politics even entered sport and the football terraces. (Well, fancy that, I hear you exclaim). At one international match, the Tunisian football supporters were heard to tease their Egyptian counterparts for not getting rid of their dictator fast enough; We’ve got rid of ours, so why haven’t you got rid of yours? was the refrain.

Dan also made the point that the Egyptian authorities made the fatal mistake, during the uprising, of closing down the national broadcasting media - which resulted in people coming out into the streets for their news, and passing on news and current affairs stories in a way that could not be contained - so given similar circumstances in Blighty, I doubt that the BBC Trust will react by pulling the plug on Radio 4. We’ll be allowed to remain indoors to keep up with The Archers and Eastenders. No roaming the streets for us.

Tom Chatfield considered that, given that the internet really is only about 600 weekends old, we still have some way to travel before social mores have fully developed. But my, hasn’t it come far! Wiki leaks and Twitter may be bouncing around like stroppy adolescents, causing a bit of a rumble in the legal jungle, but time will tell. It may not be that long before someone (or something) tames these delinquents.

After all, getting down to the basics, what do we really need from Governments?

Most of us don’t need much more democracy (if that’s what you call it.)

Most of us would be perfectly happy with bread and circuses.

It was good enough for most of the Romans, and I’m sure it will be good enough for the most of us.

Well do Demos for such a thought-provoking session. There may be more in this series- and if so I’ll try and attend them.

Source:
Image credit - http://www.guardian.co.uk/world/2011/may/31/egypt-online-protest-virginity-tests

.

Spam update


Another text arrived last Friday afternoon from this Spam outfit (07591233106).

Perhaps they read the blog.

Anyway, it says: our records indicate you still have not claimed compensation for your accident. You may be entitled to claim up to £3650. To find out more reply “CLAIM” Thanks.

I’ll ignore them and see what happens next.

.

Thursday, 26 May 2011

I’m sick of spam aimed at corporate subscribers, too


If you’ve got a corporate mobile phone, you may recently have received an unsolicited text message from some really dodgy outfit. I don’t know who they are, but they use the number +447821142591 to send me their spam from. The first text, which I received a couple of weeks ago, advised me that: According to our records you may entitled to £3750 for the accident you had. For more info reply CLAIM to this message. To opt out text STOP.

I have not had an accident, nor have I ever told anyone that I have had an accident. However, I decided to play along by replying CLAIM to see what happened next. Within a few minutes an advisor phoned me to take my details. It was clear that the advisor did not know who he was calling, and when pressed he explained that he had been provided with my details from a third party. I told him that I was really unhappy about having received the text, I wanted future texts to stop, I wanted to know who had supplied him with my number, and that I would be complaining to his manager about the unsolicited call. Unsurprisingly, he immediately ended the call. I never got to speak to his manager. Nor did he tell me what outfit he worked for.

Today’s text was a bit blunter: You still have not claimed the compensation you are due for the accident you had. To claim then pls reply CLAIM. To opt out text STOP.

What can corporate subscribers do to stop this stuff being sent in the first place?

Well, I could log onto the Information Commissioner’s website, read and click on the stuff that’s on the banner at top of the page telling me something about cookies, and then navigate my way to their guidance. The ICO’s banner reads: On 26 May 2011, the rules about cookies on websites changed. This site uses cookies. One of the cookies we use is essential for parts of the site to operate and has already been set. You may delete and block all cookies from this site, but parts of the site will not work. To find out more about cookies on this website and how to delete cookies, see our privacy notice.

And then there’s a tick box which, once ticked, indicates that: I accept cookies from this site.

Phil Lee from Field Fisher Waterhouse has generously explained to a number of LinkedIn readers that : (i) if you don't consent to the ICO's banner, then it only drops a 'strictly necessary' session cookie (no other cookie); (ii) if you do consent, then it also drops a first party cookie to remember your consent and a third party analytics cookie; and (iii) if you later want to opt out, then I suppose you have to delete the first party consent cookie by clearing your browser cache.

I have not heard Phil comment on whether this is the best way of doing things - but full marks to the ICO for having possibly the first (and only) website in the European Union which tries to comply with the new cookie rules. That takes some courage.

Anyway, back to the plot.

The Commissioner’s guidance on such spam makes it clear that the relevant regulations are themselves defective, in that they only prohibit the sensing of unsolicited text messages to individuals, not to corporate subscribers. Some bitter irony this has turned out to be. I remember being one of those who were asked by the DTI (as it then was) to comment on what became The Privacy and Electronic Communications Regulations 2003. I pointed out this anomaly and explained that I was sure that all Service Providers would really prefer the regulations to prohibit the sending of unsolicited text messages to all subscribers, not just individual subscribers. However, the DTI disagreed. They weren’t in a goldplating mood, and probably didn’t think that business people needed to be protected like this. I do remember that the bright civil servant who was tasked with this issue didn’t have a corporate phone herself.

In terms of what can be done to reduce the likelihood of corporate phones receiving future unsolicited messages, there’s probably not much that can be done. We could try instructing staff to register their phone numbers with the Telephone Preference Service, but I’m not really sure how much good that would do.

I suspect that the telephone managers of some of the larger corporate subscribers would want their service provider to register corporate devices with the TPS as a matter of procedure rather than requesting their corporate to do it on an individual basis. But I’m not sure how easy this currently is. There must be a way though, if there’s a sufficient demand.

What I am sure of is that it’s not the service providers themselves who are providing the numbers to these grubby spam merchants. I just wish I knew who they were buying their databases from.

Source:
http://www.ico.gov.uk/for_the_public/topic_specific_guides/marketing/texts.aspx
http://www.legislation.gov.uk/uksi/2003/2426/contents/made

.

The improbability of spotting potential cybercriminals


Misha Glenny, the award-winning author and journalist, was on sparkling form last night as he briefed a select gathering of people in the private dining room of The Ivy in Soho last night. Big thanks to my friends at Detica for so generously inviting me to the event.

Misha’s spent the last couple of years investigating the rise of internet crime and how it is linked to the growth of industrial espionage on the web, and the broader issue of cyber warfare. And in doing so, he’s met some of the most notorious criminal hackers that the courts have managed to deal with. What he had to say was gripping – and his conclusions were bleak. To develop a mantra that former Prime Minister Tony Blair used to trot out, while our politicians and investigators can try to be tough on cybercrime, I’m not at all sure that anyone can be tough on the causes of cybercrime.

I don’t want to steal (too much) of Misha’s thunder, so I won’t report in too great a detail on what he had to say. But one theme really struck me, and I reflected on it as I returned home in the early hours of this morning. What can we do to spot these budding cybercriminals? And isn’t it a shame that we won’t be able to do very much about them until it’s too late?

What factors are common to the master cyber-criminals of the globe? Misha was extremely well qualified to discuss this issue, having had the opportunity to meet some of the finest criminal minds that have emerged from places as diverse as the Ukraine, Sri Lanka, Germany, Idaho USA, Nigeria, Turkey and of course the UK. Are there common behavioural traits that lead to a shared profile?

Well, yes there are. And as Misha reeled off the list, I began to think that people with these traits could turn out either to be very very good for society, or very very bad. But probably very very rich.

So, what should we look out for?

We should look out for nerds who are obsessive game players, people who are unusually good at maths or science, who might well have a traumatic experience in their early teens, whose moral compass makes them easy pray to more experienced cybercriminals, and who have poor communication skills in the real world, but who flourish in the virtual environment.

But how can we be tough on finding nerds like this, or of imposing behavioural change on them?

Should we “lock up all geeks”, and only allow emerging adults to engage with others once they’ve become properly house trained? It’s not going to happen. If they’re not on the aggressive or anti-social verge of society then they’re simply not going to be individuals of interest to the local police forces. These geeks will simply hone their criminal traits well away from the gaze of the law enforcers whose hands (and budgets) will be focused, for political reasons, on the local yobs who will be making life miserable for the more decent members of the community. Are we doomed?

I wouldn’t bet against it.

What’s the solution – a totalitarian surveillance state – but run by the “dear ruler” for benign purposes, rather than to oppress the populace? That’s not the flavour of the month. Not even in Africa, and the Middle East, as we are witnessing today. Can society ever be tough on such nerds, so that they develop into people with a different moral compass?

Well, I wouldn’t bet any of my own money on it.

But perhaps Misha has a solution. He didn’t mention it last night, but then again nobody asked him.

When it’s published, read Misha’s new book: Dark Market. Better still, pr-order it on Amazon today.

Source:
http://www.amazon.co.uk/DarkMarket-CyberThieves-CyberCops-Misha-Glenny/dp/1847921264


.

Tuesday, 24 May 2011

Cookies: “Keep calm and carry on”, advises our Minister


Wow.

In the space of just a few weeks, we’ve really been spoilt by those who have been appointed to rule us.

Not only have we been given the Statutory Instrument that implements the new cookie rules, and guidance from the Information Commissioner’s Office about the steps that need to be taken in order to comply with the rules, but our very own Minister has even just written us an open letter setting our minds at rest about some of the issues that were immediately raised by those who had digested the previous documents – and didn’t quite understand what was meant (or what should be inferred) from the text of the Statutory Instrument.

So, our compliance tool kit now comprises:
8 pages of regulations
2 pages of explanatory notes to the regulations
9 pages of ICO guidance
6 pages of DCMS guidance
1 "know your cookies" audit spreadsheet, prepared by our friends at Barclays
and, in a few weeks time , we can expect some more pages of ICO guidance on other matters covered by the Statutory Instrument.

Good going, well done.

A few of the usual data protection suspects huddled together after this evening's meeting of the Digital Economy Act All Party Parliamentary Group, which had actually met in Portcullis House to consider the future of mobile services, data roaming and spectrum. The general consensus was of considerable gratitude that Ed Vaizey, our Minister for Culture, Communications and Creative Industries had been so bold as to put his name to a document that has quite firmly established the Government’s direction of travel. The message to those who doubt the British pragmatic approach is, basically: get real. Or as Ed put it, much more elegantly in his open letter: we remain firmly convinced that the UK implementation is correct that it is good for business, good for consumers and addresses in a proportionate and pragmatic way the concerns of citizens with regard to their personal data online.

Whether the Article 29 Working Party, for example, shares his views on obtaining or expressing consent in the context of cookies, will be a debate that will rumble on for a long time. Webmasters don’t need to get prior consent for cookies, just consent. Wow. So a cookie can continue to be loaded onto a device as soon as the browser accesses the target website, just like today. Then the webmaster can seek consent. Thank goodness for that. Sanity prevails. Whether such sanity will prevail elsewhere in the EU is a matter that will only be resolved when the other Member States reveal their intentions as to how they will implement the rules. We Brits have found something that could work awfully well in practice, so let’s hope that others don’t complain too loudly that it doesn’t really work in theory.

There’s no need for me to comment on the other items covered in Ed’s letter. Plenty of others will be offering us a more detailed analysis in the comming days and weeks. Suffice to say, it’s great to realise that Ed's officials have recognised the real concern among some of those who are to be affected by the new rules. Those who wanted to comply needed some reassurance in how they should go about complying – and some of this reassurance has been forthcoming.

I doubt that Ed will continue issuing such letters, as Ministers don’t usually offer running commentaries on what their Statutory Instruments actually mean – they normally leave that up to the Judges to decide. However, I’m certain that a open letter such as the one published today will carry just as much judicial weight as a Ministerial statement in Parliament, and so for that I’m very grateful.

As an afterthought, given the ferocity with which the Judiciary have been challenged recently over the appropriateness of issuing injunctions to prevent the press from reporting what many thousands of people have already read on Twitter and other forms of social media, Ed may be realising that, actually, these days, Ministers could have more moral authority in privacy matters than Judges.


Source:
http://www.dcms.gov.uk/images/publications/cookies_open_letter.pdf


.

Sunday, 22 May 2011

Which cookies are really “strictly necessary” ?


The new cookie rules are almost upon us and there is more than a little interest in how the term strictly necessary will be interpreted by the regulators.

The Information Commissioner’s Offices’s first attempt seems a little harsh: The use of the phrase “strictly necessary” means its application has to be limited to a small range of activities and because your use of the cookie must be related to the service requested by the user. Indeed, the relevant recital in the Directive on which these Regulations are based refers to services “explicitly requested” by the user. As a result our interpretation of this exception therefore has to bear in mind the narrowing effect of the word “explicitly”. The exception would not apply, for example, just because you have decided that your website is more attractive if you remember users’ preferences or if you decide to use a cookie to collect statistical information about the use of your website.

The formal dictionary definitions suggest concepts that embrace exact or precise; not loose, vague, or broad, following or enforcing a rule or rules with great care; punctilious; closely enforced or rigidly maintained; disciplining rigorously or severely.

But all hope is not lost! The English language is a gloriously flexible language, and meanings of words can change pretty quickly. Even the meaning of words like strictly.

After all, who would have thought that the hit BBC competition “Strictly Come Dancing was actually judged on the quality of the dancing? Back in November 2008, John Sergeant reportedly pulled out of the competition over fears he may actually win the show. And how good a “dancer” was he? Well, in one of the funniest Strictly dances ever seen, he dragged his partner Kristina Rihanoff around the floor in his Paso Doble. Some dance that was.

So, let’s hope that the ICO has the same sense of pragmatism as the BBC executives evidently had, and that they will allow the participants themselves to decide what they feel is sufficiently strictly necessary when it comes to interpreting the new cookie rules.

My bet is that the definition of strictly will loosen up pretty quickly.


Side Note:
By the way, this is not the first time that the ICO has been asked to advise on a strictly issue. Our chums in Wilmslow were asked to rule on an Freedom of Information matter, not a Data Protection one, a little while ago. This was all about whether the public were allowed to know the actual numbers of votes that had been cast each week for the various contestants. Emails passed between BBC television centre and the ICO, and then the following information was published on the BBC’s website: We invite you to vote for the dancers that you liked best, based on their performance in each show and during the series. Releasing voting figures could affect the way that people vote, and also have an impact on the participants. We therefore do not disclose the exact voting figures. Although the BBC is subject to the Freedom of Information Act, information which is closely connected to our programme-making is not covered by the Act. The Information Commissioner, who regulates the Act, has confirmed that information about Strictly Come Dancing voting is not covered. We are therefore not required to disclose the voting figures under the Act.


Sources:
http://www.ico.gov.uk/for_organisations/privacy_and_electronic_communications/~/media/documents/library/Privacy_and_electronic/Practical_application/advice_on_the_new_cookies_regulations
http://www.yourdictionary.com/strictly ashx
http://www.bbc.co.uk/strictlycomedancing/about/voting.shtml

.

Compulsory breach notification: is anyone else heading in the wrong direction?


An extremely interesting debate was held at Australia House in Central London last Thursday. Hosted by Dtex, a company which assists organisations to control the flow of data via the delivery of a “Know Your Insiders” programme, the message was probably not one that those who are responsible for developing and enforcing the soon-to-some-into-force Electronic Privacy Regulations would have wanted to hear.

What do I mean?

Well, we all know that next week heralds the coming into force of new regulations which, among other things, change the rules around cookies. But I've said enough about cookies recently. This blog posting comments on the new rule changes to compulsory breach notification.

Regulation 5 relates to the notification of personal data breaches by Communication Service Providers. In all cases, the Information Commissioner must be notified. In some cases, the subscriber or user must also be notified where there is a risk that the breach would adversely affect the personal data or privacy of that user. Late breach notifications may result in the Information Commissioner imposing a fixed civil monetary penalty of £1,000 on the Service Provider.

There are two problems with this concept.

First, there is no list of Communication Service Providers in the UK, so it is not clear just how many organisations will be affected. I really don’t know how the Information Commissioner will take action against companies who fail to comply with the breach notification requirements, especially when his staff won't even know who he is expected to check up on. Of course, they will know all about the big Service Providers – but what about the smaller ones, whose security standards may well be those that are more suspect? Think, for example of the case of the firm that incurred the latest fine from the Commissioner. ACS Law were barely plankton in the legal ecosystem – yet the owner of the firm still managed to cause the liklihood of siginficant damage being inflicted on thousands of people!

Second, and more importantly, the regulations require Service Providers to devote more time to reporting the most minor of mistakes, which will inevitably divert precious resources from providing advice and support to business projects that really need greater attention. If we are not extremely careful, the debate will slip back into the “security zone”, rather than get focused on the most crucial part of the whole data protection problem.

Take a quick look a the definition of a “personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a public electronic communications service;.

So it’s a breach if a single encrypted laptop or a single encrypted data stick is lost? Despite the fact that no damage has been done to any “victim”? Or, in a retail environment, where a passer-by overhears a conversation between a sales advisor and the customer? Even where the only “unauthorised disclosure” is the customer’s name and telephone number?

Of course it’s far-fetched. But the explanatory notes to the Statutory Instrument do state that all breaches have to be reported to the ICO. (Just as users are apparently expected to have to consent to all cookies that are not strictly necessary on websites, but that’s another pet gripe of mine that is the focus of my next blog entry.)

In my view, this madness removes the focus on what I think is the most crucial part of the whole data protection problem. And this was the part which was the main subject of the speakers’ comments at Australia House last week.

If you are to believe the speakers, it’s not really about technical issues.

Obviously, technology can help – which was why the Australian Trade Commission were so keen to facilitate the session, which promoted the services of Dtex, an Australian company. They were also keen to ply us with some of the finest Australian wines and they most generously let us feast on Kangaroo canapés. (I kid you not!)

But, what we really need to concentrate on is people. It’s a behavioral issue, more than a technical issue. We have to focus on the human factor – but this is actually an extremely difficult thing to do.

One of the reasons it’s so hard to get board directors to focus on the importance of human behaviours is because the board members speak a language which can be alien to those who speak in terms of data protection. Board members exist to develop a strategic approach that will maximise shareholder returns – so they tend to speak in financial terms. When assessing risks to the company, they look to their Risk Steering Committees, and expect risks to be quantified in financial terms. What is the loss of “x” likely to be?

The trouble is that, in data protection terms, its really hard to quantify poor data protection standards in financial terms. How many customers really leave businesses that have had data breaches, for example? This is the sort of critical questioning that data protection managers face when they pay their concerns before the company. Where is the actual evidence that customers turn to other providers? While Larry Ponemon has done some amazing work in this area, some of his studies are getting quite depressing – a report published in March 2011, for example, predicted that: most privacy advocates and people in the data protection community believe that data breach costs will start coming down eventually because consumers will become somewhat immune to data breach news. The idea is that data breach notifications will become so commonplace that customers just won’t care anymore.

So, let’s all try and keep focused on the really important stuff – which is making sure that staff know what is expected of them, that they are properly trained and are really committed to the organization. That’s what I want to spend my time doing. Not wasting anyone’s time in Wilmslow having to report the loss of an encrypted data stick, simply because it was left in someone’s trouser pocket while went through the wash cycle at home.

Those folks in Wilmslow surely have better things to do,than wait for such relatively inconsequential reports to dribble through, too.

There was a time when regulators were expected to just waste their time on tedious details around purpose notification, as data controllers diligently kept their regstration entries up-to-date. Shortly they have something else to monitor - which could be equally wasteful of their scarce recources.


Sources:
http://www.legislation.gov.uk/uksi/2011/1208/made (The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011)
http://www.ponemon.org/blog/post/cost-of-a-data-breach-climbs-higher

Image credit:
This image is taken from the Monty Python comedy sketch: 100 Yards Dash for People with No Sense of Direction – part of the 27th Silly Olympiad. The starting gun goes off and everybody starts running, very fast. They run up to the high jump, disc throw, hamburger stand, and John Cleese goes powering out of the stadium and up a busy high street. As he’s running a reporter asks him about his progress. He shouts: “I’m getting there, getting there!” http://www.funnyordie.com/videos/284b7cef6e/monty-python-silly-olympiad-from-montypythonfan

.