Week 6 Feb 21, 2007 Start reading chapter 3: BIG libel (see also mcspotlight.org) Hit Man Corporate Cybersmear Cyberhoax (see also gatt.org) p 102 #7,8: Batzel v Cremers Paper 1: I read them, the grader read them, independently. Both our comments are here. I occasionally adjusted a score up a point (never down) based on the grader's perception. It is important to STAY ON TOPIC. It is important, IF you are going to make Fair Use a topic, to address the four parts of the test. See Jane Ginsburg's scenario in H&I on the fictitious Prof Donna Prima, very much like Prof Ulrich. Except: Prima's site has cartoons, music, stuff unrelated to her topic. Charles Joseph Minard's chart on Napoleon's 1812 invasion of Russia. done in 1869 Overall you are rather conservative re copyrights. But Ulrich's problem is very real. Suppose the issue were exposing some serious injustice? See copyright-as-speech-suppression. Opening paragraph is important! So is conclusion. Fair Use arguments Important not to misstate these! differences between types of material This is important: facts v images v whole v partial articles alternatives to reproduction discussion of editing is a plus Public Domain is NOT an issue; orphaned works *is* an issue; gov't is looking into it! But they will doubtless muck it up. =============================================================================== =============================================================================== Get to cyberspeech? copyright and suppression of speech lawsuits & suppression: McDonalds case ISP protections against libel Batzel case jurisdictions web hoaxing =============================================================================== =============================================================================== Another look at Smyth v Pillsbury: Did Pillsbury announce the no-firing-due-to-email policy, and then did someone get mad and decide to ignore it? Or did they just not think it through ahead of time? Electronic Communications Privacy Act, 1986: The ECPA has three exceptions that serve to limit its applicability to employer monitoring 1. The provider exception; 2. The ordinary course of business exception 3. The consent exception. Generally, most employer monitoring falls under one of these. Phone surveillance in the workplace Keystroke monitoring Location monitoring Do computers empower workers, or shackle them? =============================================================================== =============================================================================== Overarching privacy question: is your personal privacy really being eroded? Does junk mail *really* matter? =============================================================================== Case 3: Westin General social justifications for privacy Autonomy: control of info about oneself Keeping our roles straight: we all play many roles in our lives: Safety valve to allow complaints & expressions of frustration near-universal deviations from social norms: driving too fast padding expense accounts income tax drugs sexual mores setting limits on our communication with others Implicit issue: do we *care* if gov't or anonymous marketers know about us? We do like to regulate what our associates know about u s, though. Need to "not be onstage" sometimes: we need privacy (physical isolation) to reflect on our experiences, and reconsider our moral choices. Havoc done to interpersonal relations by those who are too candid Need to discuss partially formed ideas with a trusted listener friends doctors, lawyers, therapists, pastors What of Westin's issues have to do with electronic monitoring??? =========================================================================== Transparent society / David Brin 1. If you invade privacy, you have to reveal your own personal info. Does this make any sense at all? This is sort of "reciprocity". Tradeoff between provacy and accountability: pseudonymity v anonymity how DO we handle genetic info? Sending "juries" in to listen to the FBI? GOVERNMENT privacy ================== Case 4: Patriot II OMIT Patriot 1: allows gov't to search everyone's financial records Patriot 2: DNA database, 15-day warrant-free wiretaps, immunity to businesses providing false information permits spying on american citizens, Old (2001) & new (2006) patriot acts New changes: "Section 215" requests for business/medical records [inc libraries]: must be approved by fbi director or other high-level official also by FISA court must include Statement of Facts Showing Relevance requires minimization procedures for this data adds judicial challenge (by records provider, not subject!) More on National Security Letters: judicial challenge option, etc. Sneak-and-Peek warrants may be issued by Foreign Intelligence Surveillance Court; these warrants are non-public even to the subject. What is "search"? Old-fashioned examples of privacy issues, now kind of quaint: "matching" of names in federal programs: tax records v welfare recipients students v selective service tax & immigration records No-fly list, and corrections Other criminal databases; problem of how corrections are made library records - threatened by Patriot I caller ID PATRIOT act: bank records, ISP logs are all things gov't can now demand without a warrant What are our "effects"??? ======================================================================= Govt data collection: what does this really have to do with computing? Govt has resources to keep records on "suspects" even with pencil and paper. Government and e-privacy: * matching between government databases * eavesdropping on internet communications * eavesdropping on the phone (including VOIP) * obtaining commercial records (bank, credit, grocery) * getting search-engine records (google) * transponders: I-Pass, cellphone, RFID * facial recognition * databases of suspicions (Terrorist Information Agency) What if facial recognition were to really take off? What would be the consequences? Do we really have a right to engage in mild rule-breaking? =================================================================== Commercial privacy: How much could merchandisers really DO with lots of info? * people who have recently bought expensive things? * dietary habits, from grocery info * political leanings, based on magazine subscriptions Oscar Gandy and the "panoptic sort": is this really an issue? Web cookies - do they matter? E-bay privacy This one is quite remarkable. What do you think? Fast-food purchases Alcohol purchases Grocery tags To what extent do we really care about any of this? Is it really just about "a few more pieces of junk mail"? Use of databases: credit bureaus for insurance for hiring for apartment leasing apartment-legal-complaints ======================================================= Odlyzko and price discrimination: real goal behind all this commercial info? Odlyzko: price discrimination basic supply/demand. You set price P, user X has threshold Px P <= Px: user X buys it P > Px: user X does not buy it But what you really want is to charge user X the price Px. Example: Alice & Bob each want a report. Alice will pay 1000, bob will pay 500. You will only do it for $1300. Charge Alice 900, bob 400: both think they are getting a deal. But is this FAIR to alice? In one sense, absolutely yes. But what would Alice say when she finds out bob paid less than half, for the same thing? Possible ways to improve the perception of value: give it to Alice earlier give her bonus tracks too delete some features from Bob's copy, or disable them What do computers have to do with this? Airline pricing: horrendously complicated, to try to maximize revenue for each seat. Online stores certainly *could* present different pricing models to different consumers. Might this happen? What about grocery stores? Dell: different prices to business, education academic subscriptions and price discrimination two roundtrip tickets including weekends are less than one Minneapolis -> Newark Wed-Fri: 772.50 Minneapolis -> Newark Wed-nextweek: 226.50 Newark-> Minneapolis Fri-nextweek: 246.50 issue isn't online shopping so much as store shopping versioning ======================================================================= RFID tags all your clothing displays where you bought it "Hello. My underwear comes from Wal*Mart" RFID tags on expensive goods, signaling that I have them Loyola RFID cards RFID v barcodes: unique id for each item, not each type readable remotely without your consent "Kill" function Active and passive tags Are there ways to make us feel better about RFID?? Serious applications: Inventory management Store checkout Access control (eg of people into Lewis Tower, or of cars into a lot) Personnel tracking (knowing where people are) Computer interface to real world Tracking exposure to viral illness embedded in currency as anti-counterfeiting measure [!] Getting devices to detect each other, and interoperate Self-guided museum tours Smart refrigerator: keeps track of dates Smart laundry Where are my keys? Where is my copy of _War and Peace_ consumer recalls compliance monitoring for medications Technological elite: those with access to simple RFID readers? Sort of like those with technical understanding of how networks work? 2003 boycott against Benetton Is the real issue a perception of control? Guenther & Spiekerman Sept 2005 CACM article, p 73 Models: User-control. User implements, in effect, a password Agent model: you delegate access decisions to a software package that understands your privacy preferences Is there a "killer app"? Smart refrigerators don't seem to be it I-Pass is maybe a candidate, despite privacy issues (police-related) Speedpass is another example What about cell phones? They allow us to be tracked, too! What about existing anti-theft tags? They are subject to some of the same misuses. Papers: Eckfeldt: focuses on benefits RFID can bring. Airplane luggage, security [?], casinos, museum visitors Gunther & Spiekermann: it's really about control. We don't want to be broadcasting information about ourselves that we cannot control. But if we *could* control it, perceptions might change. But their actual study doesn't back this up: neither Privacy-Enhancing Technology helped a lot. Fig 2: more interesting RFID applications Ohkubo, et al: leaking information about possessions revealing shopping patterns some technological fixes: eg smart tags if you don't understand these, who will? Stajano: readable only by owner Supports PRICE DISCRIMINATION ======================================================== Workplace privacy Is there any reasonable expectation? Web browsing: certainly it uses up time ======================================================== PERSONAL privacy ================ CallerID again Commercial databases accessed by Private Eyes? Background checks? Nosy people? All that commercial info: does our view change if it turns out that our neighbors are also getting all this data? Anonymity as a way of achieving privacy: anon.penet.fi was run by julf helsingius; closed in august 1996 Question: anon.penet.fi *might* help child pornographers & terrorists. Should that be a deciding factor? Anonymity gets replaced by pseudonymity: Your screen name isn't obviously traceable to you, but the authorities can find you. Maybe even creditors, or irritated other participants deja view: searching old newsgroups when people used their real names (go to google groups and use advanced-search feature) Could the same happen to facebook users? Some legit uses of pseudonymity (eg in online forums) Discussing addiction asking about medical issues asking about products we're considering purchasing RIAA v Verizon: It looks like Verizon ultimately lost. (this case seems to be largely about anonymity) ============================================== MEDICAL privacy Etzioni on privacy of medical records HIPPA has lots of rules about this # Health information is to be used only for health purposes. Without your consent, it can't be used to help banks decide whether to give you a loan, or by potential employers to decide whether to give you a job. # When your health information gets shared, only the minimum necessary amount of information should be disclosed. ============================================================== ============================================================== Cyberspeech What does it have to do with computers? Usenet personal websites blogs email: harassment & stalking Legal basis of free speech: we have a very fundamental right to it. Most legal theory tends to be utilitarian (how will this affect the most people), but the right to free speech is ALMOST a fundamental principle in the deontological sense. Limitations on speech: Libel Copyright (not patent) Trademark Obscentity Indecency (less severe) Threats Endangerment (Yelling "theater" at a crowded fire) incitement to immediate crime State secrets (but cf _The Pentagon Papers_, leaked by Daniel Ellsberg) fraud (although *commercial* speech has always been more tightly regulated) Subversive speech (cf Holmes opinion in Abrahms v US) stock price manipulation Weapon/bomb information? CDA - Communications Decency Act Usenet history on worries about libel/copyright. Case studies: 1. Mcspotlight.org 2. _Hit Man_ - Smolla 3. Corporate cybersmear - Reder 4. WTO - Feder. gatt.org ============================== Copyright and suppression of speech Case 1: anon.penet.fi Run by Julf Helsingius 1993-1996 rationale for internet anonymity terrorists, child pornographers, drug smugglers rationale & function of anonymous remailer 1996: scientologists ask for records because someone posted secret scientology documents using anon.penet.fi. Finnish police get a search warrant. Helsingius decides that he can't protect identities & it's not worth it. Case 2: Diebold Appeal case: Diebold had attempted to enforce "takedown" notices based on the theory that the leaked documents were covered by copyright; defendants argued fair use. The court: The purpose, character, nature of the use, and the effect of the use upon the potential market for or value of the copyrighted work all indicate that at least part of the email archive is not protected by copyright law. The email archive was posted or hyperlinked to for the purpose of informing the public about the problems associated with Diebold’s electronic voting machines. It is hard to imagine a subject the discussion of which could be more in the public interest.... Even if it is true that portions of the email archive have commercial value, there is no evidence that Plaintiffs have attempted or intended to sell copies of the email archive for profit.... At most, Plaintiffs’ activity might have reduced Diebold’s profits because it helped inform potential customers of problems with the machines. However, copyright law is not designed to prevent such an outcome. ... Rather, the goal of copyright law is to protect creative works in order to promote their creation.... Finally, Plaintiffs’ and IndyMedia’s use was transformative: they used the email archive to support criticism that is in the public interest, not to develop electronic voting technology. Accordingly, there is no genuine issue of material fact that Diebold, through its use of the DMCA, sought to and did in fact suppress publication of content that is not subject to copyright protection.