24 January 2012

Coptalk

The Canberra Times reports that Warren Allistair Tamplin has pleaded guilty in the ACT Magistrates Court after accessing "secret information from the national police database while working for the Australian Federal Police".

Tamplin worked as a protective services officer; according to a statement of facts tendered in court he "repeatedly accessed records from the database over three years from 2007 to 2010, using his AFP email address to send the information to a personal email account". He pleaded guilty to charges of recording proscribed information in breach of police regulations.

The CT notes that Tamplin committed one of the offences on the same day that he completed an AFP online security course, in which participants learned it was illegal to distribute police information.

Details of the accessed information were suppressed. He reportedly had emailed some of the information, classed as protected or highly protected, to other people outside the police force.
He was eventually discovered after a fellow staffer received an email purporting to be from the New York Police Department, which included a link to Tamplin's website and an invitation to join an email list.

Investigators audited Tamplin's official AFP email account and found that he had been sending information from the police database to himself and others. Tamplin told investigators that he had set up a security industry website as a personal project with a view to starting his own business after he left the federal police.

He said the website was based on news and information about terrorism, mostly obtained from the search engine Google or news sites.

He had also created an email distribution list to share information with other law enforcement workers.

Tamplin told investigators there was ''no truth in the news and he needed to 'get out what really happened'''. But he also said he did not make any money from the records he sent out and believed the information was ''open source'' and ''as good as gossip''.

He conceded that management would take a ''pretty dim'' view of his behaviour and acknowledged that he did not have the authority to copy the information.

21 January 2012

Losses

The UK Information Commissioner (ICO) has highlighted responses to three data breaches.

In the first former health worker Juliah Kechil has pleaded guilty to unlawfully obtaining patient information by accessing the medical records of five members of her ex-husband’s family in order to obtain their new telephone numbers. She had been a Health Care Assistant in the Royal Liverpool University Hospital's outpatients department. She was fined £500 and ordered to pay £1,000 towards prosecution costs, along with a £15 victim surcharge following conviction under s 55 of the Data Protection Act at Liverpool City Magistrates Court. The Commissioner notes that -
Royal Liverpool University Hospital began an investigation in November 2009 when the defendant’s father-in-law contacted the hospital after receiving nuisance calls which he suspected had been made by his former daughter-in-law. Having changed his phone number in July 2009 following unwanted calls from Ms Kechil, he was immediately concerned that there had been a breach of patient confidentially.

Checks by the hospital revealed that all of the patients whose details had been compromised were not at any time under the medical care of Ms Kechil and she had no work-related reasons to access their records. She accessed the information for her own personal gain without the consent of her employer. The accesses were traced through audit trails which were linked to the defendant’s smartcard ID.
The Commissioner noted that the ICO - somewhat more positive than the Australian OAIC - "continues to call for more effective deterrent sentences, including the threat of prison, to be available to the courts to stop the unlawful use of personal information".

In the second response Praxis Care Limited, a care provider with offices in the Isle of Man and Northern Ireland, has "taken action to improve its data protection practices" following a joint ruling by the ICO and the Office of the Data Protection Supervisor (ODPS) for the Isle of Man.

Praxis Care Limited breached both the UK Data Protection Act and the Isle of Man Data Protection Act by failing to keep peoples’ data secure. An unencrypted memory stick, containing personal information relating to 107 Isle of Man residents and 53 individuals from Northern Ireland, was lost on the Isle of Man in August last year. Some of the data was sensitive and related to individuals’ care and mental health. The stick has not been recovered.

Praxis has "now committed to making sure that all portable devices used to store personal data are encrypted", with personal information that is no longer needed being disposed of securely in line with the company’s updated data security guidance. The Commissioner commented that -
Carrying people’s personal information around on an unencrypted memory stick is clearly unacceptable. The fact that some of the personal details stored on the device were out of date and so surplus to requirements makes this breach all the more concerning.

The ICO will continue to work closely with other data protection regulators where it is clear that a data breach extends across national boundaries.
A separate undertaking has been signed by the Chartered Institute of Public Relations (CIPR), the organisation whose practitioners tend to advise on the thing to say when clients let personal information go feral.

The CIPR has made a formal undertaking with the ICO over the loss of up to 30 membership forms on a train in May last year. The Institute - nothing like looking ahead, given the frequency of data breaches - did not have a policy in place for handling personal data outside of the office. It has agreed to review its data protection policy and "make sure that it is communicated to staff" by the end of February.

Blundr

Another day, another data breach.

This time it's a warning from the Australian Securities & Investment Commission (ASIC) and exposure of a weakness in the Grindr and Blendr social network services, with claims in the SMH that -
A popular "meat-market" smartphone app that spawned a sexual revolution in Australia's gay community has been compromised by a Sydney hacker, potentially exposing intimate personal chats, explicit photos and private information of users.
Grindr, with a reported 100,000 Australian users in mid 2011, and the straight Blendr, combine geospatial awareness with personal profiles. In essence participants can use a mobile phone or other wireless device to view the profiles of other participants within a particular proximity and exchange information.

 It's discussed in studies such as 'There’s an App for that: The Uses and Gratifications of Online Social Networks for Gay Men' by David Gudelunas in 16 Sexuality & Culture (2012), Gaydar culture: gay men, technology and embodiment in the digital age (Ashgate 2010) by Sharif Mowlabocus and 'Queer theory, cyber-ethnographies and researching online sex environments' by Chris Ashford in 18(3) Information & Communications Technology Law (2009).

The SMH reports that -
The hacker discovered a way to log in as another user, impersonate that user, chat and send photos on their behalf.

The vulnerabilities are also present in Blendr, the straight version of the app, according to a security expert who said both apps had "no real security" and were "poorly designed". Fairfax Media is not aware that Blendr has been hacked but the potential was there, according to the security expert.

The founder of the apps, Joel Simkhai, conceded both were vulnerable and he was rushing to release a patch to address the issues. He said he had originally been waiting until new architecture was built "within weeks" but was now releasing an update to both apps "over the next few days".

In a telephone interview about the vulnerabilities last Friday he said it was news to him about the potential for text chats to be monitored and claimed the company had never experienced a "major breach" in which a large portion of users were affected.
"We [do] get people trying to hack into our servers," he said. "That's something that I am aware of and we certainly have a team in place that are working to prevent that."

But by Tuesday Mr Simkhai admitted that he was "aware of some vulnerabilities" but he would not talk about them in detail to avoid a hacker exploiting them.

"We are certainly aware of a lot of these vulnerabilities and ... they will be fixed as fast as humanly possible," he said.

He could not say how many people had attempted to take advantage of the vulnerabilities but said a website created by the hacker had exploited some of the flaws in Grindr. That website was shut down after Friday's interview with Fairfax Media after he sought legal action.

The website, registered on July 14 last year, allowed the hacker to search for any Grindr user regardless of their location, and capitalised on the vulnerabilities to offer other services not designed by the apps. ...

At one point, according to sources who saw the website before it was taken down, it listed users' Grindr pseudonyms, passwords, their personal favourites (bookmarked friends) and allowed them to be impersonated, and thus have messages sent and received without their knowledge. At one point, the website also allowed users' profile pictures to be replaced.

It is understood the hacker changed the profile picture of numerous Sydney Grindr users to explicit images. One user who was targeted confirmed they had been banned due to a perceived terms of service violation.

It is understood the hacker took advantage of the fact the apps used a personalised string of numbers known as a hash, instead of a user name and password, to log in. The hash is exchanged between users' smartphones so they can communicate with each other but the hacker discovered it could be replaced with another users' hash to enable the hacker to:
• Log in as any user
• See the user's favourites
• Change their profile information and profile picture
• Talk to others as the user
• Access pictures sent to the user
• Impersonate a user's "favourite" and talk to them as a friend
A security expert - who did not wish to be named because he didn't have Mr Simkhai's permission to analyse his systems - said that the Grindr and Blendr apps "had no real security".

They are "very poorly designed ... [with] poor session security and authentication", the expert said. "It wouldn't be too hard to secure this."

The security expert demonstrated with permission of a user how he could log in as them and take over the app.

In a statement Mr Simkhai said keeping his platform secure from hackers was a "number one priority".
What are consumer expectations about privacy and data protection in such services? What are service operator responsibilities? I'm reminded of the iBill data breach several years ago.

In 2006 it was revealed that personal information for over 17 million customers of the online payment service iBill (the dominant payment intermediary in the online adult content industry) was available on the net, being used by spammers and identity theft criminals. The data included consumer names, phone numbers, addresses, email addresses, IP addresses, credit-card types and purchase amounts. It appears to have been taken by an iBill employee. I've noted elsewhere that the iBill data breach was not disclosed by the company. Given that the data did not include Social Security, credit-card or driver's-license numbers, no US laws required iBill (or the adult content companies for which they provided payment services) to warn people. A year after the FBI first learned of the loss they had also failed to issue any public warnings.

ASIC has meanwhile "advised clients of online stockbroking firms to urgently review their account security". Its media release states that -
During regular surveillance of the Australian financial markets, ASIC has become aware of several stockbroking account intrusions involving unauthorised access and trading.

ASIC recommends that as soon as possible users of online stockbroking accounts:
• ensure their computer virus software is up-to-date;
• change their passwords; and
• check their transaction history.
ASIC also recommends users do this regularly, as with bank accounts.

If you become aware of any unauthorised trading on your account, you should contact your stockbroker immediately. This will help to ensure that any further unauthorised activity can be prevented.

ASIC is working with online stockbroking firms to help those clients who have been impacted.

ASIC is also working with other authorities to identify the source of the intrusions and pursuing a line of enquiry consistent with similar incidents in overseas markets.

Seduction

'Marriage as Punishment' by Melissa E. Murray in 100(2) Columbia Law Review ( 2012) 101-168 comments that -
Popular discourse portrays marriage as a source of innumerable public and private benefits, happiness, companionship, financial security, and even good health. Complementing this view, our legal discourse frames the right to marry as a right of access, the exercise of which is an act of autonomy and free will. However, a closer look at marriage’s past reveals a more complicated portrait. Marriage has been used - and importantly, continues to be used - as state-imposed sexual discipline.

Until the mid-twentieth century, marriage played an important role in the crime of seduction. Enacted in a majority of U.S. jurisdictions in the nineteenth century, seduction statutes punished those who 'seduced and had sexual intercourse with an unmarried female of previously chaste character' under a 'promise of marriage.' Seduction statutes routinely prescribed a bar to prosecution for the offense: marriage. The defendant could simply marry the victim and avoid liability for the crime. However, marriage did more than serve as a bar to prosecution. It also was understood as a punishment for the crime. Just as incarceration promoted the internalization of discipline and reform of the inmate, marriage’s attendant legal and social obligations imposed upon defendant and victim a new disciplined identity, transforming them from sexual outlaws into in-laws.

The history of marriage as punishment offers important insights for contemporary discussions of marriage. It reveals the way in which our current discourses of marriage are naïve and incomplete, emphasizing marriage’s many attributes while downplaying its role as a vehicle of state-imposed sexual discipline. In view of this history, our contemporary jurisprudence on the right to marry can be reread to reveal the disciplinary strains that continue to undergird marriage and the right to marry. Most importantly, this history reveals that state regulation of sex and sexuality has been a totalizing endeavor, relying on marriage and criminal law as two essential domains for disciplining and regulating sexuality.

With this in mind, the recent struggle for marriage equality seems unduly narrow. While achieving marriage equality is important, this history underscores an equally important interest in defining and preserving spaces for sexual liberty that exist beyond the disciplining domains of the state.
Murray concludes that -
In January 2010, Theodore Olson, one of the lawyers litigating Perry v. Schwarzenegger, outlined “The Conservative Case for Gay Marriage.” Speaking to social conservatives who have resisted efforts to expand civil marriage to LGBT individuals and those who are undecided about marriage equality, Olson argued that “same-sex unions promote the values conservatives prize,” including accountability, social stability, and economic partnership. For Olson, the allure of marriage equality is obvious: Marriage is a disciplinary institution and its expansion to include same-sex couples would necessarily include more people within the ambit of the state’s disciplinary reach.

Olson’s account of marriage’s disciplinary possibilities accords with marriage’s history. As this Article recounts, from the mid- nineteenth century to the mid-twentieth century, marriage played an integral role in the enforcement and administration of criminal seduction statutes. Recovering this history of marriage and seduction not only reveals the complicated relationship between criminal law and family law, it also makes clear that family law, through the institution of marriage, was, no less than criminal law, an important disciplinary force in the lives of men and women.

The history of criminal seduction offers useful lessons for the contemporary practice of marriage. Though the popular discourse of marriage focuses on the institution’s many salutary benefits, it elides more substantive discussion of its disciplinary content and punitive history. As this Article argues, marriage, like the criminal law, continues to be one of the technologies of discipline that is deployed by the state in the project of constructing and replicating a disciplined citizenry.

Recognizing and acknowledging marriage’s disciplinary qualities complicates the extant jurisprudence of rights that, most recently, has focused on the right to marry. As this Article has argued, marriage’s role as a technology of discipline requires us to reconsider the marriage right as more than simply a right of access, but rather a right of access to the disciplinary force of the state.

Reframing the right to marry and the institution of marriage along these lines would allow a more accurate depiction of marriage—one that is transparent and forthright about marriage’s disciplinary character. Greater transparency and accuracy in our discourses of marriage is important for those who seek marriage, and for those who would avoid it. Transparency not only helps illuminate what marriage is — it prompts us to think seriously about alternatives for those who would prefer to live their lives outside of the state’s disciplinary domains. Accordingly, this Article strives not only toward a more accurate understanding of marriage, but toward the possibility of sexual liberty untethered to marriage.

Upstairs

Posts in this blog over the past two years have noted the misadventures of self-described "eerily accurate, profound clairvoyant" and witch Eilish De Avalon, a person whose supposed ability to see the future didn't save her from a traffic dispute with the police and whose claim that a Victorian court had no jurisdiction over witches was - quelle horreur - not accepted by that court.

The Northern Star reports that -
A mother and daughter told a court only God had the authority to order them to pull down an illegal extension to their South Golden Beach property, but the magistrate took a different view.
So far God apparently hasn't endorsed the statement by afflicting the magistrate with boils, a plague of toads and scorpions, or other indications of His displeasure.

The item indicates that
In a hearing at Mullumbimby Local Court on Thursday, Byron Shire Council argued the downstairs area of the property was not approved to live in as part of the original development consent and it should be demolished.

The council's governance manager, Ralph James, said despite several requests over the past two years, the property owner had not taken any reasonable steps to get the downstairs development approved or cease use of the area.

"Of concern was the fact that the house was located in an area that is subject to flooding," he said.
It's unclear whether the property owners are unfussed about inundation, welcoming floods as a God working in the same mysterious ways that include affliction with cancer, freckles, a taste for Elvis or ability to make cheap gibes in a blog.

The NS goes on to note that -
The council was originally notified of the illegal extensions by a community member and the matter was listed for December 1, 2011 but the defendants failed to attend.

When the matter was heard, the women submitted a written argument stating they did not have to submit to the jurisdiction of the court, or the council

God was only jurisdiction they recognised, she told the court.
No sign, alas, of whether non-recognition of Australian jurisdictions purportedly obviates the need to pay tax, observe the road rules, refrain from the keeping of slaves or burning witches, and other niceties.

Ms De Avalon's meanwhile out of custody, after two months in prison, and delighting the mass media with headlines such as "Witch ritual in church incites Father's fury". The Herald Sun - where would we be without it - reports that -
A witch who went to jail for dragging a policeman 190m with her car has hijacked a wedding ceremony being performed by the reverend Father Bob Maguire.

Father Maguire said he felt like the "devil took over me" when Eilish De Avalon conducted a Pagan Handfasting Ceremony at a Brighton Catholic church.

Father Maguire said he had warned the woman to tone back her scripts for the January 7 wedding but was "taken for a ride" on the day.

Ms Avalon, who was jailed for two months last June after pleading guilty to recklessly causing serious injury, dangerous driving, driving while suspended and using a mobile phone while driving, yesterday confirmed to the Herald Sun it was the first time she had performed the ceremony in a church, but declined to speak further.

Handfasting ceremonies are performed for same-sex couples, opposite gender couples and for multiple partners.

The bride and groom's hands are tied during the ceremony and vows are usually taken for a year and a day.

At the end of some services, the couple jump over a broomstick. ...

Fr Maguire said: "She is using me as an endorsement to blow her own trumpet. She took an opportunistic advantage of the parish.

"I was taken for a ride and blindsided. Once in the saddle she took over the place. It was like the devil got a hold of me.

20 January 2012

Cybertravel

'The Future of Cybertravel: Legal Implications of the Evasion of Geolocation' by Marketa Trimble in 22 Fordham Intellectual Property, Media & Entertainment Law Journal (2012) considers geolocation questions.

Marketa comments that -
Although the Internet is valued by many of its supporters particularly because it both defies and defeats physical borders, these important attributes are now being exposed to attempts by both governments and private entities to impose territorial limits through blocking or permitting access to content by Internet users based on their geographical location – a territorial partitioning of the Internet. This article, as opposed to earlier literature on the topic discussing the possible virtues and methods of raising borders in cyberspace, focuses on an Internet activity that is designed to bypass the territorial partitioning of cyberspace and render any partitioning attempts ineffective. The activity – cybertravel – permits users to access content on the Internet that is normally not available when they connect to the Internet from their geographical location. By utilizing an Internet protocol address that does not correspond to their physical location, but to a location from which access to the content is permitted, users can view or use content that is otherwise unavailable to them. Although cybertravel is not novel (some cybertravel tools have been available for a number of years), recently the tools allowing it have proliferated and become sufficiently user-friendly to allow even average Internet users to utilize them. Indeed, there is an increasing interest in cybertravel among the general Internet public as more and more website operators employ geolocation tools to limit access to content on their websites from certain countries or regions.

This paper analyzes the current legal status of cybertravel and explores how the law may treat cybertravel in the future. The analysis of the current legal framework covers copyright as well as other legal doctrines and the laws of multiple countries, with a special emphasis on U.S. law. The future of the legal status of cybertravel will be strongly affected by the desire of countries and many Internet actors to erect borders on the Internet to facilitate compliance with territorially defined regulation and enjoy the advantages of a territorially partitioned cyberspace. This paper makes an attempt to identify arguments for making or keeping certain types of cybertravel legal, and suggests legal, technical, and business solutions for any cybertravel that may be permitted.
She suggests that -
If we accept the premise that cybertravel, or the capability of a user to use the Internet as if he were located in a location other than where he is physically located, is socially valuable and worth permitting in some form, the question turns to the conditions under which cybertravel could be legal. ... the existence of this capability does not depend on permitting anonymity on the Internet; anonymization and cybertravel need not go hand in hand.

Thinking about the possible future of cybertravel requires a consideration of all the various policies and business motives that lead website operators to limit access to their content on the Internet. First, website operators design content limitations to enhance user convenience by localizing accessible content, for example by showing advertisements for local businesses. Second, website operators may have contractual obligations with content providers, for example to limit access to video programs that a provider has licensed only for certain countries or regions. Third, the operators may limit access to content to comply with laws that prohibit certain types of content in certain countries, for example by blocking gambling when it is outlawed by some countries; prohibitions may also apply, however, for less-maligned content that may be made inaccessible because of countries’ legal requirements – for instance, countries’ consumer protection laws may require certain products to be offered only if they have been certified for use in the country. Fourth, website operators may decide voluntarily to limit access to content to avoid being exposed to personal jurisdiction and liability in certain countries where they wish to avoid litigation, taxes, regulation or some other type of obligation. Finally, website operators may implement access limitations for security reasons; for example, a bank will not allow a user from outside the account holder’s country of residence to log into the account holder’s account because the bank assumes that such a login is a fraudulent attempt to access the account.

The first type of restriction – content localized for advertising or for user convenience – should cause the least difficulty. There should be no reason for prohibiting users from viewing this type of content as if they were sitting in another country. In fact, website operators such as Google and Lufthansa offer links to allow users to switch easily among different country versions. This switching may not be completely without cost to the website operator, however; if users regularly escape the “convenience” of localized content and use other country versions in lieu of their own local versions, it may diminish website operators’ advertising revenues because they lose some of the advantage that a partitioned cyberspace provides in allowing them to charge premium advertising rates for advertisements that target local consumers.

Cybertravel that is used to evade the other types of access limitations listed above is problematic. It is unrealistic to expect countries to allow users connecting to the Internet from their territory to bypass any prohibitions against certain content or activities by cybertraveling to another country where such content or activities are expressly or implicitly permitted. Allowing cybertravel for these purposes would defeat the public policies behind the prohibitions and undermine national sovereignty. Similarly, it is difficult to defend cybertravel that is used for the purpose of bypassing geolocation tools employed by website operators who are complying with contractual obligations, seeking to avoid personal jurisdiction and liability, or protecting themselves and others against criminal activities. The question is whether there is a way to permit cybertravel when it is conducted to avoid these types of limitations but the conduct has a legitimate goal, such as accessing one’s own bank account from a foreign country. The method of cybertravel is not important, because the tools for its implementation will change; what is important is that travel to another portion of cyberspace be possible.

There are three perspectives from which possible solutions for the future of cybertravel will arise: legal, technical and business. As has been shown by other examples in the Internet environment, a combination of solutions from all three perspectives seems most likely to succeed. For example, laws that prohibit copyright infringement have not stopped online music piracy, and neither have filters that have been imposed by Internet service providers or automatic warnings that are generated by college campus service providers. Although these measures and laws addressing piracy have probably slowed online music and film piracy, the solutions had to be assisted by business solutions, such as iTunes and Netflix, to offer a legal and viable alternative to piracy.

As discussed earlier ... a number of legal doctrines cover issues potentially associated with cybertravel; however, because these doctrines were neither created for nor shaped with cybertravel in mind, court interpretation will be required to determine to what extent the doctrines may make illegal all or some instances of cybertravel. Whatever the status of cybertravel will be, it will be beneficial to clarify the applicability of existing laws to cybertravel and possibly draft specific regulations to govern cybertravel further. If IPv6 makes IPv4 obsolete and a transition actually occurs to permanently assigned or embedded IP addresses, the transition could provide momentum for the creation of cybertravel-specific legislation, and perhaps even for an agreement on a legislative solution at the international level.

Within some permitted extent, cybertravel, as an equivalent to physical international travel, could be subject to reasonable limitations; traditionally, the obligation to carry a passport is considered one such limitation, and a digital passport could serve this purpose for cybertravel. The passport could either be a virtual equivalent to a physical passport and carry the same personally identifiable data of the holder/Internet user, or be a document with only limited information, such as the user’s location. The location identified in either type of passport could be either the current physical location of the user or the place of residence or domicile of the user, depending on the criterion that was set as the factor determining the accessibility of the Internet content.

Although intuition seems to dictate the selection of the user’s current physical location as the determining factor, the other option – place of residence or domicile – should not be excluded summarily. The prevailing principle of territoriality of law suggests that current physical location be the correct solution; under the principle, laws apply territorially, or alternatively stated, the prescriptive jurisdiction of a country extends only to the country’s borders – and outside its borders only to the extent that the country’s jurisdiction covers acts that have effects within its borders. Another principle, the principle of personality of law, exists as well, but with less applicability because the principle of territoriality of law applies to the vast majority of the legislative activities of a country. The use of residence or domicile as the determinative factor for access to Internet content would present a remarkable opportunity to introduce the principle of personality of law for activity on the Internet. Under this principle countries legislate for their own nationals and permanent residents and the laws follow those persons wherever they travel. An analysis of the issues surrounding personality of law on the Internet is beyond the scope of this paper and deserves a separate study, but is worth mentioning.

A law for digital passports cannot exist without a technical implementation. It is not difficult to imagine such a system if the IPv6-related vision of permanently assigned or embedded IP addresses that would identify specific devices (or even persons if the devices were embedded in human bodies) becomes a reality; the law could make it illegal to change or reroute an IP address because that act would be equivalent to forging a physical passport. The digital passport would inform each website operator about the location of the user, or the user’s residence or domicile, depending on the information in the passport.

Knowing exactly how many cybertravelers are connecting to a website and from what locations could assist intellectual property owners, for example, in the creation of tailored licensing schemes; if information about cybertravelers were to include personal identifiers, the system could become what Paul Goldstein described in 1994 as the “celestial jukebox” – a service that would allow on-demand access to copyrighted works from anywhere in the world for a fee. The digital environment is perfectly equipped to implement this system; in such a world, each user could access copyrighted works from anywhere in the world and be charged only for works that the user accessed. This is where a technical solution would prompt the need for a business solution.

What hampers progress towards a celestial jukebox are the significant transaction costs associated with the identification and location of right holders and the negotiation of licenses with multiple right holders. The magnitude of these costs must be addressed in order for global licensing to be feasible, and there are initiatives being developed in this area to pave the way for this type of solution; for example, experts have proposed that the World Intellectual Property Organization create and administer an international repertoire database, and other experts are exploring possibilities for cross-border collective management of rights in the digital environment.

Even without a celestial jukebox solution that would cover all works globally, and even without digital passports, there is clearly space for smaller-scale business solutions to meet the challenges of cybertravel. If content is limited because of the contractual obligations of website operators, cybertravel could be enabled by global or regional licensing schemes that would allow operators to offer selected content either worldwide or in selected countries. Instead of paying cybertravel providers to facilitate cybertravel, users would pay for access directly to website operators, who would then bear any licensing costs and any other costs associated with the content, such as a public television licensing fee.

Of course, these solutions are directed only towards access to content that is restricted because of contractual limitations; any content that is illegal in a country will continue to be inaccessible to users accessing the Internet from that country, and potentially to nationals or permanent residents of that country even when they are temporarily present in another country, if digital passports are used. For certain types of content – and the instances of these types of content are likely to be limited – countries may reconsider the legal status of content in light of the possibilities afforded by digital passports. For example, some countries might reconsider their stance on online gambling if they have the ability to tax users located in their country who use foreign online gambling sites.

The solutions also fail to address cases in which access to content is limited by a website operator’s or content provider’s choice; these cases arise because of issues of jurisdiction, taxation or online security. When website operators or content providers decide sua sponte to restrict their content to certain viewers, users have minimal recourse; only in rare circumstances will a government direct private entities to make content more widely available than it already is. Here a system of digital passports could prove useful; for example, if access to content were based on a user’s permanent residence, content could be made available to a qualified user while he was temporarily located in another country, without exposing the website operator to jurisdiction or taxation in that country.

Finally, knowledge of the numbers and physical locations of cybertravelers could make possible not only sophisticated licensing arrangements but also agreements – either private (meaning between individual content providers and website operators) or international (meaning among countries) on an acceptable level of free spillover. In the physical world, it is accepted that due to international travel, some content limited to a certain country will be available to those who travel to that country. For example, when distribution rights under copyright are licensed for one country, it is understood that some of the copyrighted works will land in the hands of persons who are present in the country only temporarily and those persons may carry the work with them to other countries; laws provide exceptions for individual users to do this because it is considered natural spillover. Exceptions for a similar reasonable spillover could be permitted for cybertravel. However, without information about the extent of cybertravel, it is impossible to find arguments to support the exceptions for the spillover; a passport system would allow the collection of such information.

Abuse

The Australian Institute of Health & Welfare has released its 150 page Child Protection Australia 2010-11 report [PDF], indicating that the number of notifications of child abuse or neglect to state/territory child welfare departments continued to fall in 2010–11, although the number and rate of children in substantiated cases remained stable.

There was a 13% fall in the number of children subject to notifications of possible child abuse or neglect compared with the previous year. During the same period, the number of children in substantiated cases (ie where a govt agency "concluded that the child has been, is being, or is likely to be abused, neglected, or otherwise harmed") was stable - rising by less than 1%.

In 2010–11, there were 237,273 notifications of potential child abuse or neglect involving 163,767 children. Of these notifications, over half were investigated and just over a third were substantiated.

There were 31,527 children involved in substantiated cases during 2010–11, ie 6.1 for every 1,000 Australian children aged 0–17. The report notes that -
Children aged under 12 months were most likely to be the subject of a substantiation of child abuse or neglect. However, over the past five years we have seen a large fall in reported rates of abuse and neglect for those under 12 months of age, from 17 to 12 per 1,000 children
The number of children on care and protection orders at 30 June 2011 rose by 4% from the previous year. The number of children in out-of-home care at 30 June 2011 rose by 5%. Although the total number of children on care and protection orders and in out-of-home care has increased, the number of new admissions into out-of-home care per year has fallen, suggesting that children on existing orders may be staying longer in out-of-home care.

As in previous years, the vast majority of children in out-of-home care lived in home-based care, primarily in foster care (45%) or with relative/kinship carers (46%).

The report states that -
Aboriginal and Torres Strait Islander children continue to be over-represented within the child protection system. Aboriginal and Torres Strait Islander children were 7.6 times as likely as non-Indigenous children to be the subject of a child protection substantiation, and 10 times as likely to be in out-of-home care.

The most common type of substantiated abuse for Indigenous children was neglect, which made up 38% of all substantiated cases, compared with 23% for non-Indigenous children.