Author Archives: Michael Froomkin

Zoopreme Court

Have a look at Zoopreme Court. Here’s a sample, Warren E. Bearger (Chief Justice 1969 – 1986):

Posted in Law: The Supremes | 2 Comments

Lessons Learned Too Well: The Evolution of Internet Regulation (2)

Read Part One.

In the US, the first wave of Internet law and regulation had three separate impulses, each a differently motivated reaction to the disruptive effects of a constellation of new technologies based on the communicative power of a network.

First, both logically and in time, was the legal instinct for categorization, often as a means to solve disputes. Was the Internet like a telephone network? Or was it more like television? Was computer-mediated speech more like radio or newspapers or private letters? Was e-commerce like mail-order? Is encryption more like speech or a widget? Where is an online transaction for jurisdictional purposes? Of course, as in any such exercise, which category an Internet-enabled activity would be placed in was often contestable, because there was debate about the true nature of the Internet-mediated activity, because analogies are imperfect, because parties dueled about the appropriate level of generality, or because category choice could determine outcomes.

A second type of first-wave regulation, usually legislative, sought to create new categories and in rare cases new institutions. Sometimes this was because the existing categories seemed inadequate; other times it was because the existence of a new technology promised new capabilities, or new solutions to old problems, or an opportunity to use the Internet as an excuse to achieve a regulatory goal that could not otherwise be justified.

Sometimes this impulse to create new categories went a bit wrong, as for example when the then rare breed of lawyer-technologists toiled to enable solutions that had not yet found their problems.

The best example of this phenomenon is the Utah Digital Signature Act of 1995, the first of its kind in the nation, and in many ways the model for the ABA guidelines that followed. The Utah law attempted to shape the future by defining transactional roles, rights, and responsibilities in a way that relied on particular technologies used in digital identification and authentication. Those technologies did not catch on in the marketplace nearly as quickly as the law’s backers had hoped, nor did the law succeed in kick-starting a new e-commerce industry based on new intermediaries. The Utah model more failed than succeeded. In contrast, digital signature laws that took a more modest and technology-neutral approach, and sought primarily to domesticate deployed technologies and fit them into known categories worked well. It helped to have a legislative rule making clear when an electronic or digital signature counted as a valid signature and when it did not – it saved a lot of needless court cases. (The most common answer, by the way, is that it is a signature for most things other than wills or conveyance of real property.) By the late ’90s there was (mostly light-weight) digital signature legislation in 49 US states, and in many countries.

A third set of legal and governmental responses unashamedly sought to return matters to the status quo ante, or were designed proactively to protect either business models or established governmental practices from Internet threats. And it is in this third category where our biggest future troubles lie.

Remember the equation, “Packet-switching + strong crypto = total communicative freedom”?

Excess communicative freedom was not just a concern of the US. The Canadian government unsuccessfully sought to block US sources from sending daily Internet accounts of ongoing Canadian trials – banned domestically on the grounds that it prejudices the defendant’s right to a fair trial. At some point more despotic regimes also began to take note and to wonder what they should do in response. In due course that would lead to the Great Firewall of China.

But it was the US government – or perhaps I should say the NSA, the people in charge of capturing and analyzing signals intelligence from around the world – who were first to recognize how that equation might make their lives more difficult. Similarly, domestic law enforcement agencies that relied on wiretaps to make and break cases faced the threat that if all communications were encrypted end-to-end, one of their most valuable law enforcement tools would go the way of the Dodo. It did not help that some cypherpunks had spec’ed out a model for a “Blacknet” – the philosophical if not in fact genetic ancestor of Wikileaks and its ilk – in which anonymous leakers could sell their secrets to anonymous buyers and both sides could be assured that their identities would remain unknown to all parties concerned including any intermediaries. Some law enforcement may have got excited about it, but as best we know “Blacknet” wasn’t real, just an online party piece intended pour épater les bourgeois. That said, crypographically powered anonymous remailers were real, and (when they were working properly) they allowed people to send untraceable messages, be they love notes or ransom notes.

Simply banning strong crypto did not seem to be a viable option. There was no statutory authority, and no political consensus for new legislation. Worse, there was a First Amendment case – unproven, perhaps, but fervently pushed by its adherents and potentially potent – that such a ban would be unconstitutional. The US government’s response was ingenious. Rather than seek new legal powers, the US government decided to leverage export control power it already had, and use that power to set technical standards in a way that would preserve the parts of the status quo it most valued. The government already prohibited the export of strong cryptography on the grounds that it was a dual-use good, a thing that could be used for military as well as civilian purposes, a category that included cryptographic software. Software companies were very concerned about speed getting to market, and about version control. They didn’t want to wait around for licenses, and they didn’t want to have to make a ‘lite’ version for export as that would depress foreign sales, and require them to maintain and update two versions of their product. Plus, crypto is hard to implement. Subtle mistakes can destroy a product’s security.

The US government’s clever ploy was to offer firms the use of an NSA-approved strong cryptographic algorithm embedded in a tamper-proof chip, with one little extra: the Clipper Chip would come with an extra method for decrypting messages known only to the US government, which it would promise to use only according to specified legal procedures. Win-win, said the government: strong crypto for everyone, we preserve our law enforcement and spy capabilities. In an effort to set a de facto technical standard, the US started to use the Pentagon’s buying power to acquire compliant smart cards, in the hope of creating economies of scale for Clipper-enabled devices and thus setting a market standard too. An important feature of this plan was that every private action – making the chips, selling the chips, using the devices – could be characterized as formally “voluntary,” thus evading or at least burying any Constitutional questions.

It almost worked. It failed, largely because of a determined effort by privacy activists who raised legal and technical questions about the plan, and because a globalizing marketplace rebelled at the thought of encryption optimized for US intelligence agencies.

Governments learned from these failures. Indeed, there is a risk that in time we may come to see them as having lost the battle but won the war because they learned – all too well – from their early failures.

One solution was simply to legislate more directly, and smarter.

Continued…

Posted in Law: Internet Law, Talks & Conferences | Comments Off on Lessons Learned Too Well: The Evolution of Internet Regulation (2)

Lessons Learned Too Well: The Evolution of Internet Regulation (1)

A week ago I gave a public address as part of my installation as the Laurie Silvers and Mitchell Rubenstein Endowed Distinguished Professorship, a rotating chair I’ll hold for a three year period.  Here’s part one of the prepared text, with the next three parts to follow daily. I plan to write a fuller version, with lots of footnotes, over the summer.

Laurie Silvers & Mitchell Rubenstein, the generous benefactors of this rotating chair, were instrumental in the creation of the SciFi network, but left it before it changed its spelling and got into wrestling matches and strange animal combinations like – I am not making this up – the Sharktopus.  Because of this SCI-FI connection, my friends have been asking me what sort of chair this is, and they seem awfully disappointed when I tell them that while it is a rotating chair, it isn’t a captain’s chair located in the center of a starship’s bridge, and doesn’t come with little panels you can manipulate to make exciting things happen.

But this virtual chair does come with an opportunity to talk to you about the evolution of internet regulation, and for that I would like to thank Laurie Silvers & Mitchell Rubenstein, and all of you for coming this afternoon.

***

Let me start by taking you back to the early 1990s, which by lucky coincidence is when I started writing about the law of the Internet. Before I do that, however, I should perhaps begin by explaining how it was that although I was hired by the University of Miami on the assumption, which I shared, that I would write about Administrative law and Constitutional Law, I instead turned into a law cyber-geek.

When I started at UM, it was possible to get an internet account, if you asked the people who ran the VAX over in the Unger building and then logged in via a modem. I got myself an account, and started playing with the Internet long into the night. One day – well, it was almost daybreak anyway – my wife, Caroline Bradley, came into my study and asked if I’d been up all night on the computer again. When I said that I had, she said the words that changed my career: “Either stop playing with it or start writing about it.” Fortunately for once I had the sense to listen.

The Morris worm of November 1988 had already foreshadowed the Internet’s coming loss of innocence, but it is interesting to note that the ordinary legal system found a way to deal with the MIT student who accidentally unleashed the first widely-deployed Internet pest. Robert T. Morris was convicted of violating the computer Fraud and Abuse Act, and sentenced to three years of probation, 400 hours of community service, a fine of $10,050, and the costs of his supervision. No new law was needed.

In 1992, when I arrived at UM, the Internet was already past its toddler years, and on the cusp of a precocious adolescence. Most of us used DOS, or Windows 3.1, or the Apple MacIntosh on the machines we used to get online. Most interactions were still text based; graphics tended to be attachments, files to download, or maybe ASCII art. The search for serious reference material sometimes required recourse to gopher space. There were many walled gardens like AOL. The first web server apparently dates to August 1991, the first web-based photo (an image of the European Organization for Nuclear Research (CERN) house band Les Horribles Cernettes) is said to date to 1992, but most of us who were online then primarily used email, mailing lists, or USENET or maybe a text-based web browser like Lynx. Some of the cooler folks – not me – were exploring text-based online virtual reality systems like MUDs (multiple user dungeons), or early social sites like the WELL.

Users of the internet tended to be academics, engineers, hobbyists and hackers. And I mean “hackers” in the nicest possible sense of the term “hackers” – they were people who played with tools, not people who broke things or even, in the main, broke into things.

If you wanted to learn how to get into this world, you bought (not downloaded) a book: The Whole Internet User’s Guide and Catalog (1992). In the ’90s a million people bought that book.

In 1990 there was basically no targeted Internet law as such, although there was of course a lot of law that could apply to people who used the Internet, just as it applies to people who use any other tool. Most Internet connections between computers ran over telephone lines, with the last mile connection starting with a modem or perhaps a very local area network. The Bell System’s monopoly on what could be connected to telephones had been broken, so the heavy hand of its contracts was as absent as the FCC. There was, however, a great deal of critical self-regulation not just at the protocol level in the form of the RFC’s issued by the Internet Engineering Task Force, the IETF, but also in the management of common user forums like USENET.

This extensive and generally effective self-regulation dovetailed with, and indeed fed, an ethos of empowerment and, at least in the minds of its adherents, optimism. (It would later feed into the anti-regulatory idea that the Internet should be treated as a legally autonomous area, but that never caught on, nor did it deserve to.)

The packet-switching that underlies the Internet famously decentralizes communication and makes censorship difficult. Thus the first part of the optimists’ credo, now almost a cliché, the ‘net treats censorship as damage and routes around it. Even worse from the censor’s point of view, strong cryptography was now available to the masses for the price of a download — that is, zero unless you had to pay for your phone connection.

Packet-switching + strong crypto seemed to herald total communicative freedom. And to the libertarian-leaning types (whether or not they styled themselves cypherpunks) who were greatly over-represented in the early online community, that sounded really good. Among the things this new freedom promised were decentralization, lower transaction costs, the empowerment of the periphery over center. Thus the optimistic enthusiasts predicted a number of goodies many of which did come to pass:

  • The replacement of the one-to-many model by a many-to-many model
  • A globalized, decentralized, subsidiarity-loving, empowered, mass culture, in which news and information flows would move chaotically around the network rather than down the narrow channels of mass media and centralized opinion formation.
  • New online communities, allowing widely scattered groups to coalesce ranging from the ‘World union of concerned butterfly fanciers’, to global diasporic communities
  • Enhancement of democracy via better citizen information, better communication with government, and especially via better organization of citizens groups and NGOs
  • Anti-censorship software, proxies, and the use of anonymizing browsers or cryptographically enhanced ‘tunneling’ software would mean that no government would be able to prevent information from entering. Thus, the catchphrase ‘information wants to be free‘. (To which the copyright owners would soon respond, ‘No, information wants to be paid for.‘)
  • Regulatory arbitrage: to the extent that things of value could be digitized (information, some services, stocks, and soon – it was confidently believed – currency), they could be traded an moved across borders to the regime with the most attractive regulatory climate. Thus the other catchphrase, Local laws are just speed bumps on the information superhighway.

For those who saw much more good than bad in these visions, these were heady days. We were going to change the world — make it freer, more efficient, more just and democratic.

Indeed, in the ’90s there were literally people – well at least one person, Patrick Ball of the AAAS – traveling around the world to teach democratic political movements in repressive societies how to use cryptography and the Internet to protect their organizing and communications. In the highest risk cases, the activists would not only be trained how to encrypt their records, but also how to store them in encrypted databases located abroad. Indeed, the people who put information into the databases did not have the codes to get it out again; thus membership lists were safe even from so-called ‘rubber hose cryptoanalysis’.

But not everyone saw the effects of this new technology as benign: some saw the prophesied erosion of state power as an invitation to anarchy, or as opening the door to the very evils that the state power was being deployed to prevent. And even some who might have weighed the overall balance as positive saw it as their duty to enforce the national rules that cyber-enthusiasts were happily undermining.

It was in the mid-1990s that the Internet really began to change as a result of multiple stresses. There was a flood of new users, and of new types of users, people for whom the internet was a tool, not a dissertation or a toy, and who due to their large numbers and disparate backgrounds and goals were not as easily socialized into the informal norms that had tended to keep things orderly. As the number of users grew, so too did the visible potential, and then the dollar value, of e-commerce. And a number of more proactive governments began to get excited about existing and imagined capabilities of this growing tide of Internet users.

Continued…

Posted in Law: Internet Law, Talks & Conferences | 1 Comment

Unofficial Final Results Coral Gables Election April 12, 2011

7917 ballots cast, including 3836 absentee. That’s 48.5% of the votes cast via absentee!

Mayor

Jim Cason 3056
Tom Korge 2087
Don Slesnick 2721

Group 4

Alvarez 485
Holmes 100
Martin 309
Quesada 3780
Rosenblatt 1775
Sanabria 1240

Group5

Kerdyk 5758
Naomon 1689

Source: Coral Gables TV live broadcast.

OK, back to my normal blogging starting tomorrow.

Posted in 2012 Election | 8 Comments

Absentee Ballots: Cason With Slim Lead, Quesada Crushing

Gables Home Page has the early results from 2,818 absentee ballots, which will be a significant fraction of the total ballots cast (“By 3 p.m. more than 3,000 residents had cast ballots, a little over 10 percent of the city’s 29,679 registered voters.”).

The absentee voters — thought by many to be significantly skewed to an older and more Hispanic vote — went Cason 40%, Slesnick 37%, and Korge only 23%. In Group 4, Quesada was crushing with 53%. Both Rosenblatt and Sanabria were far behind with 18% and 17%.

So presumably this means Quesada wins, because I think he’ll do well on the in-person vote too. Whether it means Cason wins is much harder to say without knowing how much of an absentee effort Slesnick made, and how different the in-person vote is from the absentee. Arguably, there might be more Slesnick voters turning up in person, maybe enough to turn the tide. The 3% gap between them, after all, is only 85 votes, not enough to rest comfortably on.

Polls closed over an hour ago. Where online do they report the results? There’s nothing evident at the Miami-Dade election results page, nor on the City of Coral Gables web page.

Update: I just read here that there were actually 4,683 absentee votes as of Monday, which would mean the numbers above are only partial even for the absentees. If correct, that also means that there could well be more absentee voters than in-person voters, in which case maybe these numbers will hold up after all?

Posted in Coral Gables | 3 Comments

Dropbox Is Much Less Private Than I Thought

Slight Paranoia has the story. It seems Dropbox tries to avoid storing duplicate files, and thus check (probably via a hash comparison) to see if any OTHER user has uploaded the same file. And there’s the rub:

As Ashkan Soltani was able to test in just a few minutes, it is possible to determine if any given file is already stored by one or more Dropbox users, simply by observing the amount of data transferred between your own computer and Dropbox’s servers. If the file isn’t already stored by Dropbox, the entire file will be uploaded. If Dropbox has the file already, just a few kb of communication will occur.

While this doesn’t tell you which other users have uploaded this file, presumably Dropbox can figure it out. I doubt they’d do it if asked by a random user, but when presented with a court order, they could be forced to.

What this means, is that from the comfort of their desks, law enforcement agencies or copyright trolls can upload contraband files to Dropbox, watch the amount of bandwidth consumed, and then obtain a court order if the amount of data transferred is smaller than the size of the file.

Last year, the New York Attorney General announced that Facebook, MySpace and IsoHunt had agreed to start comparing every image uploaded by a user to an AG supplied database of more than 8000 hashes of child pornography. It is easy to imagine a similar database of hashes for pirated movies and songs, ebooks stripped of DRM, or leaked US government diplomatic cables.

via slight paranoia: How Dropbox sacrifices user privacy for cost savings.

Ungood. Not actually something that I think has a large chance of impacting my life, but it’s bracing to discover that dropbox has easy access to cleartext of my files and has such a large security hole. I was misled by their description of how they encrypted things. The description is being corrected as a result of this discovery, but I’d rather they fixed the problem thank you very much.

Posted in Software | 4 Comments