138 posts • joined 27 Jul 2007
NebuAd rise from the ashes in the UK
NebuAd may have shut down in the US but in the UK they have rebranded and are about to relaunch as Insight Ready Ltd.
This looks to have been planned for some time as NebuAd first registered insightready.co.uk last summer and were promoting the Insight brand last autumn. Paul Goad appears to be the CEO of Insight Ready Ltd. (NebuAd's former UK Managing Director) and it looks like NebuAd's Commercial Director, Tony Evans, seems also to be involved.
See https://nodpi.org/2009/05/19/nebuad-pull-a-fast-one/ for more details.
No it isn't, it is trying to force companies to behave ethically and respect the rights of individuals. Another reason why this is not suitable to try and enforce on browsers is because a browser cannot possibly tell people what the cookies for each site are for so how is a customer supposed to give or deny informed consent on a per site basis?
It makes far more sense for web sites to filter based on geofilters (given they are making money out of the data) than it does to try and force browsers to do it (which make no direct revenue out of the data, they merely give people the means to access web sites).
This is -not- a browser issue, it is a commercial behaviour issue which needs to be addressed at the core level as I stated before. And what about LSO's (flash cookies) are they supposed to be controlled by the browser too?
Because browsers are not limited to an EU market, in fact most of them are developed outside of the EU. A browser company is unlikely to want to be forced into something by foreign laws.
Plus it leaves a lot of holes in the net for rogue companies to manipulate. If people get annoyed with clicking an option in their browser to allow cookies by default, it will apply for -all- cookies even though it is unlikely that people will be happy to have all cookies allowed. The legislation needs to impact the source of the problem, which is the web sites themselves instead of passing responsibilities off to 3rd parties which are certainly not the responsible parties.
Privacy is a right not a convenience (or inconvenience depending on your view) so if companies have to throw a couple of hours work at becoming privacy compliant that is their problem to resolve not the browsers.
@ Eddie Edwards
There is no proposal to have a ban on cookies, maybe you should re-read the article?
@ Eddie Edwards
Furthermore, when was the last time a large company wanted to know what a law means so they could comply with it? In the real world, companies only want to know what the laws mean so they can find loopholes which allow them to circumvent compliance.
In principle the arguments regarding cookies in the Directive are very good, they give weight to consumer choice over commercial interests, that is a very positive step. Defining what is essential and what is not would be useful but it certainly doesn't warrant a knee jerk reaction against the spirit of the directive.
I should have typed all these in 1 comment but never mind.
Your reference to IR35 in the last part of your comment is incoherent. Quite obviously it is very easy to determine whether or not you are compliant on the cookie issue, simply don't set any cookies until the user indicates consent, problem solved.
I suspect that definitions of essential cookies will be either included in notes for the directive or will be left to member states to define within their own legislation.
The answer from my side of the fence (pro privacy) is that essential cookies might include login and site preference cookies (including compliance with the Disability Discrimination Act). Whereas advertising/marketing, 3rd party and tracking cookies are not essential.
Do I think people should be asked permission before Google Analytics, Audience Science, Shopping Cart deletion (as per examples in the article) are permitted? Yes of course I do.
Instead of whining
Mind you I don't know why you are concerned, given the level of regulatory capture which currently exists in the UK and the historical evidence illustrating a complete lack of enforcement by the relevant bodies; it is highly unlikely any such changes or interpretations of EU Directives will impact the technology industry in the UK, which is rapidly becoming a safe haven for unethical business practices. And let's face it, many of the organisations responsible for such disgusting behaviour probably have Pinsent Masons (yes Out-Law.com) on retainer.
Anyone who can't see an obvious conflict of interests with this article would have to be incredibly short sighted.
Registered with ICO under DPA?
Anyone else managed to find a registration as a data controller for SEOne Club?
I have searched by name, address and postcode, but so far I have not managed to find a registration in ICOs database. Are SEOne Club owned by another company or something?
Of course if one doesn't exist, then SEOne Club have broken the law and personally it is my opinion that the law police should be seen as complicit.
excellent investigative journalism
Chris, this was an exceptional piece, thanks.
You might also want to look into the situation regarding the recording of minutes in meetings between the public sector and commercial agents which I have highlighted here:
How can the public sector be held accountable if they keep no records? They are keen to keep records of everything we do but not so keen to have the same rules applied to them.
NoDPI's Response to today's news
Obviously we are in high spirits, read the response here:
Lets clarify this
1. The only reason the ICO were able to take enforcement action is because the company running the database was not registered with the ICO as controlling personal data. That is the only criminal offense which took place here - if they had registered themselves with ICO at a cost of £35 a year then they would have avoided this prosecution.
2. David Smith, deputy Information Commissioner himself stated last Saturday on a panel at the Convention on Modern Liberty that ICO have NO enforcement powers under DPA when it comes to registered institutions/corporations.
3. David Smith, deputy Information Commissioner himself stated last Saturday on a panel at the Convention on Modern Liberty that the ICO registration fee was a TAX on businesses and contributes to the ICO's annual budget.
So there you have it, for a fee of £35 per year any company or organisation can basically do whatever the hell they like with personal data. They might get told off by the ICO if they break the DPA but they certainly won't be prosecuted.
With reference to points 2 and 3 above watch the video yourself to see him saying those things, it is available here:
It is the second video (the Q&A panel) which contains the relevant statements - readers might also be interested in the deputy information commissioner's statement that ICO don't need to take action against Phorm because the public are doing such a good job of it. Oh and also that people in the UK don't have a right to privacy, only a right that others respect their privacy....the guy is a complete idiot in my book.
Petition now closed
The final count displayed on the petition page is 21,358.
Signatures soar on the last day
So far today the number of signatures has increased by approx. 1% which is pretty impressive considering it is the last day in a year long petition.
Thanks John for posting the article and I am sure I echo the sentiments of many in thanking The Register generally for their coverage of this issue over the past 12 months.
To my knowledge the only case law in England which covers child consent is Gillick's Competence and is only applicable to medical treatment. My understanding is that in other cases not relating to medical treatment age of consent should be accepted as being 16 or above.
I am sure someone will be along to correct me if I am wrong.
Charged under the DPA?
So exactly how is this Dr being charged under the DPA? For the past year the ICO have been telling members of the public that they have no powers to take DPA breaches to court and that the only option for court is a private civil prosecution where "damage" must be proved in order for a case to stand a chance.
So it is interesting to see that when the rich and famous get their data abused suddenly the ICO are taking criminal action?
Thereis not enough info in the article to determine exactly what action is being taken and how - I would be very interested to find out.
The outside lane of a motorway is NOT the "fast lane" go read your highway code.
Secondly, if the peer had been paying DUE CARE AND ATTENTION to the road he should have been able to avoid hitting the stationary vehicle - it is not like the incident happened right in front of him and of course this is why we have SAFE STOPPING DISTANCES so even if it had happened right in front of him he would still have no excuse.
If people stopped speeding and stopped driving up each others arses the vast majority of RTAs would never happen - I have seen some appalling behaviour by other drivers both on the motorway and off (including the police and other public sector workers).
When I worked on the development of National Unemployment Benefit System 2 back in the early 90s (a project run and delivered by ITSA - Information Technology Service Agency which was a government department not an external corporation) backup and redundancy were paramount. The entire system had 4 sites around the country for redundancy and it would require all 4 of the sites to go down at once for the system to fail.
Sadly the site where I used to work is now occupied by EDS and it seems redundancy has become a thing of the past for government IT systems. NUBS2 was by no means perfect and was replaced by Jobs Seekers Allowance, but it seems to me that things back then (when they were run by civil servants) made a lot more sense from a development perspective than they do now.
Surely this would fall under horror and not in the "public good" so they are all going to banned right? How ironic that Big Brother could kill Big Brother ;)
Murder - The Musical
♫♪ How does the accused plead today, speak clearly before the court ♫♪
♫♪ How can I be guilty m'Lord? My brain just had a short ♫♪
♫♪ For 16 days and 16 nights I hear the same old ditty ♫♪
♫♪ I could not work I could not sleep - please bestow on me your pity ♫♪
♫♪ I loved my wife with all my heart 'til SongSmith was installed ♫♪
♫♪ But now she's gone because of song; the court should be appalled! ♫♪
♫♪ Show mercy Sir, please let me be! Blame Redmond for this crime ... ♫♪
♫♪ Just stop right there, now hold your tongue; sing not another line ♫♪
♫♪ Case dismissed, you're not to blame it's Redmond who'll do time! ♫♪
They must have got the idea from Morrisey as all his songs sound the same too...
WORSE THAN FAIL
OMG WTF WERE THEY THINKING!
If people start that sh*t on the train there is going to be murder committed I expect. First we had mobile phones - now we have SongShit^H^H^Hmith
"Eurovision Song Contest - Sponsored by Microsoft SongSmith"
Wonder what odds William Hill will give me for that?
Question is will the software be "going for a song"?
Mine's the one with bad jokes in the pocket...
One would have thought MS would like to try and recapture some of the Linux/Mac market share so it is a little odd they would require you to use IE7 + 3rd Party ActiveX control to download the beta.
Even more fail
Windows Defender doesn't like the ActiveX Control
Phorm legal team
In other news it would appear that Phorm have also replaced their legal team. David Pester is no longer listed as Legal Counsel on Phorm’s web site and appears to have been replaced by Sharon O’Leary and furthermore Teresa Marrero (who used to be listed as VP Commercial Law on Phorm’s web site) has apparently disappeared too.
Phorm have done a good job of keeping the news about their legal team quiet (presumably they are not required to announce such changes under AIM rules) and I am not one to speculate (OK maybe a little) but one can only assume that things are not as rosy as recent press articles may lead you to believe.
Anyone who has further evidence (re: Due Dilligence)
Anyone who has further evidence or would like to write a letter supporting the call for a prosecution please see the following article on my blog:
Thanks again to Chris for his exemplary work on this issue.
From my research of the relevant laws, the penalties should this go to trial and BT/Phorm are found guilty are custodial and a fine; if each count is penalised according to the legislation then we are looking at literally millions of years in jail with unlimited fines.
Of course it would be naive to believe that the court would impose maximum penalties for all counts, but I would expect at least the fine to be substantial and there would be no justification for not issuing a custodial sentence for the 5 years in accordance to the same legislation.
I made complaints under Computer Misuse Act (custodial and fines), RIPA (custodial and fines) and criminal Copyright violations under Copyright, Designs and Patents Act. So really the only acceptable outcome is for who ever was responsible for letting this happen either goes to jail or at least gets a suspended sentence. The fines should this be tried at the Crown Court or higher, is unlimited according to the law.
@MIchaelG - What are you smoking?
RIPA does NOT only apply to public authorities, it also applies to private individuals and companies; I suggest you actually read RIPA before commenting about it and maybe look at the existing case law.
Don't use the exclusion email address you are playing into their hands
The law states that the system has to be Opt In and the exclusion email address is Opt Out. Do NOT use the email address. Add the terms and conditions which have been drafted by Nicholas Bohm and can be found on https://nodpi.org
The Home Office stated that there MIGHT be a case of implied consent ONLY IF there are not explicit terms denying consent. By adding the terms you are complying with the Home Office's advice (even though they state that their advice is not legal advice and just an opinion.)
BBC ignores invasion of privacy
I have a telephone interview with the BBC tomorrow.
What we need to remember
The case was handed to a Detective Inspector in CID who confessed having little to no understanding of technology and who originally stated that only Public Authorities fall under the jurisdiction of RIPA.
I am considering filing for a Judicial Review on the grounds that the officer in charge of the case was not "qualified" to manage it by his own admission and that the case should have been dealt with by a team of technical experts.
The fact that I handed the police a very comprehensive complaint outlining which laws I felt had been broken, citing the relevant sections of those laws, directly referencing which sections of the BT internal report provided evidence of the breaches; yet still DS Murray asked me to come up with some questions he could ask BT at the meeting he had with them on Sept. 2nd.
As Mr Nicholas Bohm has been quoted in Chris' article I fail to understand how no criminal intent existed since the intent of the trials was specifically to intercept and modify their customers communications; which is a criminal act. They did not accidentally intercept and modify those communications - the entire purpose of the trials was to do exactly that.
Anyway you can read the full email from DS Murray and my response on:
For more info...
For more information on the CoL situation, read the emails and listen to the phonecalls here:
Member of the European Commission
Get out your pens
Could everyone please put pen to paper (not fingers to keyboard) and write Commissioner Vivian Reding a letter applauding the news and reiterating your concerns over the Phorm issues (including the trials and future deployments of the technology). It is critical that we now make sure Commissioner Reding discovers just how much of a public issue this is, and that it is not just a few geeks complaining.
If everyone writes to her office, she will have no reason to doubt the seriousness of this case and will hopefully pursue the issue accordingly. This is a great opportunity to bypass the regulatory capture currently being demonstrated by ICO.
Thanks for going to the effort of chasing this up Chris, it is very good news and confirms the statements the Commissioner recently sent to members of the public.
NoDPI Web Site
http://www.nodpi.org is now up with some information on it.
The look of the site is likely to change over the next week once a more suitable theme has been developed.
Shameless Digg request
If people would like to help publicise the event, please Digg it on the following URL. If we can make front page on Digg the news should go viral in just a few hours.
I can't deny having a bit of a laugh on reading that comment. Please make yourself known when you come out, it would be interesting to hear how the AGM went.
The AGM is 16th July starting at 10:30am. We plan to start the protest around 10am so we can catch some of the shareholders on their way in.
Call to Action
I would like to take this opportunity to encourage everyone to attend the protest, it is set to be a very interesting day. I am in the process of organising guest speakers to give presentations during the lunch time period outside the Barbican.
We plan to start at 10am to catch shareholders on their way into the AGM, then after the speeches we are heading down to BT's HQ where the protest will continue.
Throughout the day a petition calling for action from the Metropolitan Police with regards to the covert trials in 2006/2007, will be available for people to sign and will be presented to the Met at the end of the day along with the case file.
This is a very important issue not just because of the illegal trials of 2006/2007 but also in light of the current Net Neutrality debate, the mission creep possible with this DPI technology is very sinister in light of that debate as well as regards to privacy issues.
Finally, I would like to thank Chris once again for his dedication to this issue over the past 3 months.
So they have admitted to breaking the law then? Ageism is illegal in the UK as far as I recall.
Do TalkTalk fall under "Airtime Reselling"?
If so then it seems we have a new player in the Phorm game and people need to start writing letters to the Best Buy board expressing their concerns about Phorm.
I wonder if Chris Williams can possibly manage to get a comment out of the Best Buy executives re: Phorm?
New alternative to P2P?
I guess someone couldn't find the songs on a P2P service and wanted them so badly they stole the servers.
Just goes to show that P2P decreases crime.
And Kent thought I was paranoid?
re: Since when
Nooo you are wrong. Kent says "everyone wants this" surely he is right?
You seem to be forgetting one important fact here. The UK are already the 4th most monitored country int he world. They are doing a fine job in building a surveillance society they have no need of Phorm.
Can the rampant crazies please stop the nonsense about "The government want Phorm so they can spy on us", believe me, if the government want to spy on you they don't need Phorm and never will, so stop being so bloody stupid.
Secondly, Kent (my vowels almost get mixed up every time I utter that name). My personal experience with him after attending a recording session for BBC "Click" with him is that he behaves like a spoilt child. He was rude to the BBC (turned up 30 minutes late and then refused to answer their questions with anything other than his usual rubbish about "Google is evil blah blah blah" irrespective of the question being asked) and he was way beyond rude to me resorting to personal attacks and insults.
It doesn't surprise me in the slightest that he has now made a personal attack on FIPR as the man simply has no class. I would be worried too if my share price had dropped over 60% in 2 months and government advisory groups were calling my business model illegal.
Incidentally, you can see the BBC "Click" episode on 3rd/4th May at 11:30am on BBC News 24.
What about the risk to search engines?
Re: Interception of Communications Commissioner!
No but the Tribunal can be used to issue a complaint against both the Information Commissioner and the Home Office for failing to enforce the law.
- Fee fie Firefox: Mozilla's lawyers probe Dell over browser install charge
- 20 Freescale staff on vanished Malaysia Airlines flight MH370
- Neil Young touts MP3 player that's no Piece of Crap
- Review Distro diaspora: Four flavours of Ubuntu unpacked
- Sysadmins and devs: Do these job descriptions make any sense?