<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Developments</title>
	<atom:link href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/feed/" rel="self" type="application/rss+xml" />
	<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments</link>
	<description></description>
	<lastBuildDate>Sat, 12 May 2012 10:27:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New Defamation Bill &#8211; first thoughts</title>
		<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/11/new-defamation-bill-first-thoughts/</link>
		<comments>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/11/new-defamation-bill-first-thoughts/#comments</comments>
		<pubDate>Fri, 11 May 2012 13:31:23 +0000</pubDate>
		<dc:creator>Andrew Cormack</dc:creator>
				<category><![CDATA[Role of ISPs]]></category>
		<category><![CDATA[Defamation]]></category>

		<guid isPermaLink="false">http://webmedia.company.ja.net/edlabblogs/regulatory-developments/?p=1129</guid>
		<description><![CDATA[The new Defamation Bill promised in the Queen’s Speech has now been published. Although it also contains changes to what statements can give rise to liability for defamation, the most interesting part for network operators is likely to be the new provisions on liability for those who host third party content on web sites and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F11%2Fnew-defamation-bill-first-thoughts%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F11%2Fnew-defamation-bill-first-thoughts%2F" height="61" width="51" /></a></div><p>The new <a href="http://services.parliament.uk/bills/2012-13/defamation.html">Defamation Bill</a> promised in the Queen’s Speech has now been published. Although it also contains changes to what statements can give rise to liability for defamation, the most interesting part for network operators is likely to be the new provisions on liability for those who host third party content on web sites and blogs.</p>
<p>Section 1 of the current <a href="http://www.legislation.gov.uk/ukpga/1996/31/crossheading/responsibility-for-publication"><em>Defamation Act 1996</em></a> essentially gives hosts two options when they receive a complaint that a statement on their site is defamatory:</p>
<ul>
<li>remove or modify the statement promptly, and be sure that they cannot incur liability for the defamation;</li>
<li>leave the statement untouched and risk being found liable for publication if it is subsequently found to be defamatory.</li>
</ul>
<p>Paragraph 5 of the Bill would create two more options:</p>
<ul>
<li>If it is possible for the claimant to identify the person who posted the statement, then the host is protected from liability and does not need to do anything;</li>
<li>If it is not possible for the claimant to identify the poster, then the host is protected from liability so long as they follow a process or processes that will be specified in a subsequent Statutory Instrument.</li>
</ul>
<p>While the new options are welcome, the current wording creates three obvious questions:</p>
<ul>
<li>What is included within the scope of “website”? And how will this affect future publication technologies that haven’t yet been invented?</li>
<li>Is the “operator” of a website the person that runs the server, the website software, the main author of a blog, etc.? I would hope that at least those three are covered.</li>
<li>What is meant by “identifying” the person who posted the statement? This posting says that it was written by “Andrew Cormack”, but searching the web reveals several individuals with that name. Or is it sufficient that a complainant could request a Norwich Pharmacal Order against the operator of this site and discover which of them it is? I would imagine that a website operator would want to be very sure  that the poster was indeed sufficiently &#8220;identifiable&#8221; before they left an allegedly defamatory statement untouched.</li>
</ul>
<p>Section 5(4) of the Bill also specifies what needs to be in a notice in order to trigger this process: a welcome clarification.</p>
<p>During the <a href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/03/05/government-response-on-draft-defamation-bill/">consultation process that led to this Bill</a>, it was also suggested by the Joint Parliamentary Committee that it might change the current legal position that encourages a website operator to wait for complaints rather than proactively checking for defamatory statements. <span style="text-decoration: line-through">This Bill doesn’t seem to do that.</span> [UPDATE: I've a feeling that the double negatives in the Bill do actually have that effect, but I need to study them a bit more to be sure. If so, as noted below, this would only apply to proactive checking for <strong>defamatory </strong>statements, not to other types of unlawful publication].</p>
<p>The consultation also suggested that there might be a process to allow a website operator to ask for a judicial ruling on whether an anonymous posting was defamatory, if it felt that there was good reason not to remove it (for example because of the statutory duty on universities and colleges to promote free speech). That doesn’t seem to be in the Bill, but it could still be included in the Regulations.</p>
<p>And, of course, this Bill only affects liability for defamation, not for other types of civil or criminal illegality, such as copyright breach. Those will continue to be covered (by default) by the notice and takedown procedures in the eCommerce Directive.</p>
<img src="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-content/plugins/pixelstats/trackingpixel.php?post_id=1129&amp;ts=1337180112" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/11/new-defamation-bill-first-thoughts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dutch law requires network neutrality</title>
		<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/dutch-law-requires-network-neutrality/</link>
		<comments>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/dutch-law-requires-network-neutrality/#comments</comments>
		<pubDate>Thu, 10 May 2012 14:21:50 +0000</pubDate>
		<dc:creator>Andrew Cormack</dc:creator>
				<category><![CDATA[Network Neutrality]]></category>
		<category><![CDATA[Role of ISPs]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[NetworkNeutrality]]></category>

		<guid isPermaLink="false">http://webmedia.company.ja.net/edlabblogs/regulatory-developments/?p=1124</guid>
		<description><![CDATA[According to the Dutch digital rights organisation, Bits of Freedom, the Netherlands has just passed a new Network Neutrality law. Their unofficial translation into English suggests that Public Electronic Communications Service Providers will only be permitted to throttle or block traffic on their networks if this is necessary:
a. to minimize the effects of congestion, whereby [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F10%2Fdutch-law-requires-network-neutrality%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F10%2Fdutch-law-requires-network-neutrality%2F" height="61" width="51" /></a></div><p>According to the Dutch digital rights organisation, Bits of Freedom, the Netherlands has just <a href="https://www.bof.nl/2012/05/08/netherlands-first-country-in-europe-with-net-neutrality/">passed a new Network Neutrality law</a>. Their unofficial <a href="https://www.bof.nl/2011/06/27/translations-of-key-dutch-internet-freedom-provisions/">translation into English</a> suggests that Public Electronic Communications Service Providers will only be permitted to throttle or block traffic on their networks if this is necessary:</p>
<blockquote><p>a. to minimize the effects of congestion, whereby equal types of traffic should be treated equally; [or]</p>
<p>b. to preserve the integrity and security of the network and service of the provider in question or the terminal of the enduser; [or]</p>
<p>c. to restrict the transmission to an enduser of unsolicited communication as refered to in Article 11.7, first paragraph, provided that the enduser has given its prior consent; [or]</p>
<p>d. to give effect to a legislative provision or court order.”</p></blockquote>
<p>Items B and D on that list seem relatively uncontroversial, but it seems to me possible that C and A may prohibit desirable services. C appears to allow an ISP to offer a spam-blocking service to users, but to prohibit offering services (either opt-in or opt-out) that filter any other kinds of unwanted material. The effect of A seems to depend on what is meant by “equal types of traffic should be treated equally”. If it means that a network operator can only apply controls at the level of an IP address or range then it seems to prohibit treating time-critical services (such as audio and video) differently from other things like e-mail; but if that sort of discrimination in favour of real-time services (which may be necessary to deliver acceptable performance even on uncongested networks) is permitted then it may also allow the <a href="http://berec.europa.eu/doc/2012/TMI_press_release.pdf">discrimination against peer-to-peer and VoIP traffic</a> that was recently identified by European regulators.</p>
<p>It will be interesting to see how those issues are resolved, particularly as the Netherlands appears to be the first country in the world to try this approach. I understand that the Dutch telecoms regulator has indicated that ISPs will be given an opportunity to develop practical implementations before the law is enforced.</p>
<img src="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-content/plugins/pixelstats/trackingpixel.php?post_id=1124&amp;ts=1337180112" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/dutch-law-requires-network-neutrality/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Queen&#8217;s Speech 2012</title>
		<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/queens-speech-2012/</link>
		<comments>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/queens-speech-2012/#comments</comments>
		<pubDate>Thu, 10 May 2012 08:13:15 +0000</pubDate>
		<dc:creator>Andrew Cormack</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Role of ISPs]]></category>
		<category><![CDATA[Defamation]]></category>
		<category><![CDATA[RIPA]]></category>

		<guid isPermaLink="false">http://webmedia.company.ja.net/edlabblogs/regulatory-developments/?p=1120</guid>
		<description><![CDATA[Yesterday at the State Opening of Parliament the Queen&#8217;s Speech announced the Government&#8217;s plan for legislation in the next year. A couple of the proposed Bills seem likely to affect network operators.
First is a Defamation Bill, which was the subject of a consultation last year. Although the Internet isn&#8217;t the main focus of the legislation, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F10%2Fqueens-speech-2012%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F10%2Fqueens-speech-2012%2F" height="61" width="51" /></a></div><p>Yesterday at the State Opening of Parliament the Queen&#8217;s Speech announced the Government&#8217;s plan for legislation in the next year. A couple of the proposed Bills seem likely to affect network operators.</p>
<p>First is a <a href="http://www.bbc.co.uk/news/uk-18005317">Defamation Bill</a>, which was the subject of a <a href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/03/05/government-response-on-draft-defamation-bill/">consultation</a> last year. Although the Internet isn&#8217;t the main focus of the legislation, the consultation did recognise that there were problems with the current system of liability for hosting providers, which encourages them to remove any comment that is the subject of a complaint, without considering whether the complaint is justified. A <a href="http://www.libdemvoice.org/julian-huppert-mp-writes-what-does-the-queens-speech-mean-for-civil-liberties-28456.html">posting by Julian Huppert MP</a> on the Liberal Democrat Voice blog suggests that the draft legislation may be published as soon as tomorrow.</p>
<p>[UPDATE: he was right, see <a href="http://services.parliament.uk/bills/2012-13/defamation.html">http://services.parliament.uk/bills/2012-13/defamation.html</a> - more when I've had a chance to study it]</p>
<p>Second is the <a href="http://www.bbc.co.uk/news/uk-politics-18003315">Communications Bill</a>, in which the Government intends &#8220;to maintain the ability of law enforcement and intelligence agencies to  access vital communications data under strict safeguards&#8221;. At the moment ISPs are required by the <a href="http://www.legislation.gov.uk/uksi/2009/859/contents/made"><em>Data Retention Regulations 2009</em></a> to keep information about e-mails and phone calls sent using their services; law enforcement agencies can then use powers in <a href="http://www.legislation.gov.uk/ukpga/2000/23/part/I/chapter/II">Part 1 Chapter 2 of the <em>Regulation of Investigatory Powers Act 2000</em></a> to access that information. The Government doesn&#8217;t seem to have published any information about this, so it&#8217;s not clear whether one or both of these Acts will be changed by the new Bill. Julian Huppert&#8217;s blog suggests that a draft bill will be published for consultation before a final version is considered by Parliament.</p>
<img src="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-content/plugins/pixelstats/trackingpixel.php?post_id=1120&amp;ts=1337180112" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/10/queens-speech-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking and Anti-blocking</title>
		<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/blocking-and-anti-blocking/</link>
		<comments>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/blocking-and-anti-blocking/#comments</comments>
		<pubDate>Fri, 04 May 2012 10:57:19 +0000</pubDate>
		<dc:creator>Andrew Cormack</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Illegal Content]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[BotNets]]></category>
		<category><![CDATA[Copyright]]></category>
		<category><![CDATA[DataProtection]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[IllegalMaterial]]></category>
		<category><![CDATA[IWF]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Role of ISPs]]></category>

		<guid isPermaLink="false">http://webmedia.company.ja.net/edlabblogs/regulatory-developments/?p=1100</guid>
		<description><![CDATA[Given the outcome of previous hearings on copyright infringement, the court’s conclusion this week that the UK’s major ISPs should be ordered to block access to The Pirate Bay was no surprise. However the judgment raises an interesting technical issue. In a previous hearing, it had been pointed out that there was a way to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F04%2Fblocking-and-anti-blocking%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F04%2Fblocking-and-anti-blocking%2F" height="61" width="51" /></a></div><p>Given the outcome of previous hearings on copyright infringement, the court’s conclusion this week that the UK’s major ISPs should be ordered to block access to The Pirate Bay was no surprise. However the<a href="http://www.bailii.org/ew/cases/EWHC/Ch/2012/1152.html"> judgment</a> raises an interesting technical issue. In a previous hearing, it had been pointed out that there was a way to get around blocks on individual web pages that would not be possible if the block instead referred to the IP address of the website as a whole. IP address blocking is recognised as carrying the highest risk of blocking legitimate material (“overblocking”) but it seems that the current IP address of The Pirate Bay is only used by the site, so the judge was prepared in this case to permit blocking of all access to those addresses.</p>
<p>However there are many other evasion techniques that get around both URL and IP blocks and the legal action against The Pirate Bay has been accompanied by a lot of publicity for those. According to a BBC report, there has been <a href="http://www.bbc.com/news/technology-17922214">a significant increase in their use by young people</a> in recent years. Unfortunately such techniques don’t just open up access to sites blocked for copyright reasons, they inevitably evade all other filters implemented by ISPs as well. So those using them may well increase their risk of exposure to images listed by the <a href="http://www.iwf.org.uk/">Internet Watch Foundation</a> (earlier orders explicitly required ISPs to use the same systems to block copyright and IWF material), malicious code, and phishing sites that steal banking and other passwords. ISPs can no longer protect these users by filtering: all that will be left is any protection that may be implemented on the individual’s computer, smartphone, etc. Techniques such as the Virtual Private Networks described by the BBC also mean that the VPN operator can see all the user’s Internet traffic, creating a significant privacy threat if the operator, or their country, doesn’t protect that information as the user expects.</p>
<p>Such a significant risk to individuals, their computers and – by hindering <a href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/ietf-on-botnet-detection/">attempts to control the spread of malicious code</a> – the rest of the Internet seem a high price to pay for free music <img src='http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<img src="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-content/plugins/pixelstats/trackingpixel.php?post_id=1100&amp;ts=1337180112" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/blocking-and-anti-blocking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IETF on Botnet Detection</title>
		<link>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/ietf-on-botnet-detection/</link>
		<comments>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/ietf-on-botnet-detection/#comments</comments>
		<pubDate>Fri, 04 May 2012 08:46:24 +0000</pubDate>
		<dc:creator>Andrew Cormack</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Role of ISPs]]></category>

		<guid isPermaLink="false">http://webmedia.company.ja.net/edlabblogs/regulatory-developments/?p=1096</guid>
		<description><![CDATA[A bot is a program, maliciously installed on a computer, that allows that computer and thousands of others to be controlled by attackers. Bots are one of the major problems on the Internet, involved in many spam campaigns and distributed denial of service attacks, as well as allowing attackers to read private information from the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;"><a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F04%2Fietf-on-botnet-detection%2F"><img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwebmedia.company.ja.net%2Fedlabblogs%2Fregulatory-developments%2F2012%2F05%2F04%2Fietf-on-botnet-detection%2F" height="61" width="51" /></a></div><p>A bot is a program, maliciously installed on a computer, that allows that computer and thousands of others to be controlled by attackers. Bots are one of the major problems on the Internet, involved in many spam campaigns and distributed denial of service attacks, as well as allowing attackers to read private information from the computer’s disk and keyboard. Some bots even allow cameras and microphones to be monitored by the attacker. Detecting and removing bots is therefore in the interests of both individuals and internet providers. <a href="http://www.rfc-editor.org/rfc/rfc6561.txt">RFC6561</a> describes the technical issues around detecting and notifying Internet users whose computers may have been infected by a bot, and also highlights the need to take account of legal, economic and reputational issues when doing so.</p>
<p>One of the main problems with bots is that they are now very good at concealing themselves alongside legitimate programs and internet traffic. The RFC notes that</p>
<blockquote><p>With the introduction of peer-to-peer (P2P) architectures and associated protocols, the use of HTTP and other resilient communication protocols, and the widespread adoption of encryption, bots are considerably more difficult to identify and isolate from typical network usage.  As a result, increased reliance is being placed on anomaly detection and behavioral analysis, both locally and remotely, to identify bots.</p></blockquote>
<p>Unfortunately neither anomaly detection nor behavioural analysis can be perfect: both may be triggered by legitimate Internet activity that happens to generate patterns that look like those of a bot. This means that any detection and notification process must be aware that some of the computers “detected” will not be in fact be infected. Even for computers that are infected, removing the bot may require more than the average level of technical skill, or involve actions such as deleting and re-installing the operating system that users are not willing or able to do. As an increasing number of devices are connected to the Internet, it seems likely that bots will infect equipment that the user simply cannot disinfect, such as games consoles, set-top boxes or smart meters.</p>
<p>Detecting infected systems also raises significant legal and technical concerns. Since Internet Service Providers know who their customers are, examining their traffic to identify devices that may be infected will involve processing of personal data; detailed inspection of traffic may even come within the scope of Interception law. Such laws may have exemptions for particular actions by network operators, but these are likely to be tightly constrained and require additional privacy protection. Even if the action is lawful, attempts to protect users in this way can be mis-understood &#8211; either as unjustified “snooping” or as an attempt to sell security services &#8211; resulting in end-users rejecting them.</p>
<p>There are some examples of <a href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/01/16/botnet-cleanup-efforts-by-german-isps/">successful botnet mitigation schemes</a>, and a <a href="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/02/06/commons-committee-awareness-raising-to-deal-with-malware/">UK Parliamentary committee</a> has recently called for ISPs to do more in this area. However it’s clear that any scheme needs to be very carefully designed, with input from technical, legal <strong>and </strong>communications experts.</p>
<img src="http://webmedia.company.ja.net/edlabblogs/regulatory-developments/wp-content/plugins/pixelstats/trackingpixel.php?post_id=1096&amp;ts=1337180113" style="display:none;" alt="pixelstats trackingpixel"/>]]></content:encoded>
			<wfw:commentRss>http://webmedia.company.ja.net/edlabblogs/regulatory-developments/2012/05/04/ietf-on-botnet-detection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

