27 April 2018

Hacking

'Is Tricking a Robot Hacking? ( University of Washington School of Law Research Paper No. 2018-05) by Ryan Calo, Ivan Evtimov, Earlence Fernandes, Tadayoshi Kohno and David O'Hair comments 
The term “hacking” has come to signify breaking into a computer system. A number of local, national, and international laws seek to hold hackers accountable for breaking into computer systems to steal information or disrupt their operation. Other laws and standards incentivize private firms to use best practices in securing computers against attack. 
A new set of techniques, aimed not at breaking into computers but at manipulating the increasingly intelligent machine learning models that control them, may force law and legal institutions to reevaluate the very nature of hacking. Three of the authors have shown, for example, that it is possible to use one’s knowledge of a system to fool a driverless car into perceiving a stop sign as a speed limit. Other techniques build secret blind spots into machine learning systems or seek to reconstruct the private data that went into their training. 
The unfolding renaissance in artificial intelligence (AI), coupled with an almost parallel discovery of its vulnerabilities, requires a reexamination of what it means to “hack,” i.e., to compromise a computer system. The stakes are significant. Unless legal and societal frameworks adjust, the consequences of misalignment between law and practice include inadequate coverage of crime, missing or skewed security incentives, and the prospect of chilling critical security research. This last one is particularly dangerous in light of the important role researchers can play in revealing the biases, safety limitations, and opportunities for mischief that the mainstreaming of artificial intelligence appears to present. 
The authors of this essay represent an interdisciplinary team of experts in machine learning, computer security, and law. Our aim is to introduce the law and policy community within and beyond academia to the ways adversarial machine learning (ML) alter the nature of hacking and with it the cybersecurity landscape. Using the Computer Fraud and Abuse Act of 1986 — the paradigmatic federal anti-hacking law — as a case study, we mean to evidence the burgeoning disconnect between law and technical practice. And we hope to explain what is at stake should we fail to address the uncertainty that flows from the prospect that hacking now includes tricking.

Cheating

'Contract cheating: a survey of Australian university students' by Tracey Bretag, Rowena Harper, Michael Burton, Cath Ellis, Philip Newton, Pearl Rozenberg, Sonia Saddiqui & Karen van Haeringen in (2018) Studies in Higher Education comments
Recent Australian media scandals suggest that university students are increasingly outsourcing their assessments to third parties – a behaviour known as ‘contract cheating’. This paper reports on findings from a large survey of students from eight Australian universities (n=14,086) which sought to explore students’ experiences with and attitudes towards contract cheating, and the contextual factors that may influence this behaviour. A spectrum of seven outsourcing behaviours were investigated, and three significant variables were found to be associated with contract cheating: dissatisfaction with the teaching and learning environment, a perception that there are ‘lots of opportunities to cheat’, and speaking a Language Other than English (LOTE) at home. To minimise contract cheating, our evidence suggests that universities need to support the development of teaching and learning environments which nurture strong student–teacher relationships, reduce opportunities to cheat through curriculum and assessment design, and address the well-recognised language and learning needs of LOTE students.
The authors write
In 2015, a series of higher education cheating scandals were reported by the Australian media (ABC Radio National 2015; Chung 2015; Visentin 2015a, 2015b). These reports suggested that there was a potentially large and unaddressed problem of Australian university students outsourcing their assessment to third parties – a behaviour known as ‘contract cheating’. The purported escalation in students’ use of online essay mills, file-sharing sites, and online contracting platforms sparked public and sector concerns, and led to direct involvement from Australian national regulator, the Tertiary Education Quality and Standards Agency (TEQSA), which asked the universities implicated to provide reports on their investigations and responses. Concerns about contract cheating can be situated within a broader context of global higher education disruption, one in which the social, political and economic role of universities is undergoing unprecedented change. The massification and internationalisation of higher education have led to larger and increasingly diverse student cohorts, often without corresponding growth in institutional funding. As a result, universities have progressively come to operate as commercial enterprises, with all operations – from student recruitment, retention and graduate outcomes, to research funding, outputs and university rankings – driven by competitive strategies. Job opportunities for graduates are increasingly uncertain, threatened by disruptive technologies and fluctuating job markets, which contributes to a rise in ‘credentialism’ (Brown 2001) and more transactional and disengaged approaches to learning. A booming ‘sharing economy’, which facilitates the exchange of goods and services via online platforms, allows individuals to outsource almost any task, large or small, creating a shift from ‘you are what you own’ to ‘you are what you can access’ (Richardson 2015). This context represents a ‘perfect storm’ in which contract cheating can perhaps be seen as an unsurprising symptom of an ecosystem under extreme stress. ... 
This paper reports on key findings from the survey of university students, which sought to answer the following four research questions:
(1) How prevalent is contract cheating in Australian universities? 
(2) Is there a relationship between cheating behaviours and sharing behaviours? 
(3) What are university students’ experiences with and attitudes towards contract cheating and other forms of outsourcing? 
(4) What are the individual, contextual and institutional factors that are correlated with contract cheating and other forms of outsourcing?
Findings are
Responses were obtained from 14,086 students, representing 4.38% of the total student population at the eight universities surveyed. Response rates to each question varied slightly throughout the survey, so for accuracy of reporting, findings include the response rate for each question. 
How prevalent is contract cheating in Australian universities? 
Table 1 shows the prevalence of the seven outsourcing behaviours among Australian university students. The two sharing behaviours were the most commonly reported. Buying, trading or selling notes was reported by 15.3% of respondents, while 27.2% reported providing completed assignments to other students. A total of 814 students (5.78% of all respondents) reported engaging in one or more of the five behaviours classified as ‘contract cheating’. The most common contract cheating behaviour was providing examination assistance (3.1%), although it should be noted that ‘exam assistance’ is a very broad term which may include a relatively minor breach such as assistance with a single question through to providing an examinee with extensive assistance to complete the whole exam. The least reported contract cheating behaviour was arranging for someone else to take an exam (0.2%). The responses from the 814 students who reported engaging in one or more of the five contract cheating behaviours were extracted so they could be analysed as a subset, and compared to the responses of the remaining students. This subset is referred to as the ‘Cheating Group’, while the remaining responses (from students who did not engage in these behaviours) are classified as belonging to the ‘Non-Cheating Group’. 
Is there a relationship between cheating behaviours and sharing behaviours? 
The sharing behaviours of the Cheating Group and the Non-Cheating Group were compared, as shown in Table 2. The overall pattern was that the Cheating group were more likely to engage in ‘sharing Is there a relationship between cheating behaviours and sharing behaviours? The sharing behaviours of the Cheating Group and the Non-Cheating Group were compared, as shown in Table 2. The overall pattern was that the Cheating group were more likely to engage in ‘sharing behaviours’ than the Non-Cheating Group, as indicated in the shaded cells. The Cheating Group was twice as likely as the Non-Cheating Group to buy, trade or sell notes. They were more likely than the Non-Cheating Group to use a file-sharing website for this purpose, and more than twice as likely to use a professional service for this purpose. The Cheating Group was also twice as likely as the Non-Cheating Group to provide others with a completed assignment. They were more likely than the Non-Cheating Group to provide it to some kind of professional service, and they were four times more likely to have been paid money for an assignment. For both the Cheating and the Non-Cheating Groups, completed assignments were more commonly shared than notes (almost two times more). 
What are university students’ experiences with contract cheating and other forms of outsourcing? 
As shown in Table 2, the most commonly reported cheating behaviour among the Cheating Group was providing exam assistance (53.2% of the Cheating Group), followed by receiving exam assistance (41%). The next most common cheating behaviour was obtaining a completed assignment to submit (37%). Of the 301 students who reported this behaviour, 68.5% reported going on to submit that work for assessment. Exam impersonation, either taking an exam for another or arranging for another to take an exam, was relatively uncommon, although still worthy of note, particularly in the case of taking an exam for someone else (7.9%). For each cheating behaviour, a majority of the Cheating Group reported engaging in the behaviour 1–2 times (from 58% to 81.7%). A small proportion reported frequently engaging (10 or more times) in the contract cheating behaviours (from 2.9% to 9.4%). For the most commonly reported cheating behaviour (providing exam assistance), 42% of students reported engaging in this behaviour three or more times. Students were asked to identify who had provided the assistance for each of the outsourcing behaviours, choosing from a range of options and selecting all that applied. For both of the sharing behaviours, the Cheating and Non-Cheating Groups reported sharing most often with a student or former student, or a friend or family member. When buying, selling or trading notes, both groups are more likely to share with a website or professional service than a partner or girl/boyfriend. This is reversed for providing a completed assignment, with students more likely to report providing to a partner or girl/boyfriend than a website or professional service. For each cheating behaviour, a majority of the Cheating Group reported engaging in unauthorised assistance with current/former students (from 40% to 78.9%), and friends or family members (from 51.2% to 71.6%). A small proportion of the Cheating Group reporting using/providing a professional service. Professional services were most commonly used by students who arranged for someone to take their exam for them (18.8% of that group), and by students obtaining a completed assignment for the purpose of submitting it as their own (10.4% of that group). Students reported the exchange of money in a relatively small number of cases across the five cheating behaviours (from 2.8% to 16.7%), with payment most common in cases where students took an exam for someone else. 
What are students’ attitudes towards contract cheating and other forms of outsourcing? 
Students were asked to report their levels of agreement on a 5 point Likert scale regarding the ‘wrongness’ of the seven behaviours investigated. Figure 2 shows that the Non-Cheating Group reported higher levels of agreement than the Cheating Group on all behaviours. The largest difference was in relation to providing assistance in an exam (98.3% vs. 70.6% agreement, respectively), and the smallest difference was in relation to arranging for someone to take an exam (98.3% vs. 94.6% agreement, respectively). Although most Non-Cheating and Cheating students agreed that providing an assignment (for any reason) was ‘wrong’, both groups agreed much less strongly that buying, selling or trading notes is ‘wrong’. We then compared the attitudes of Language Other than English (LOTE)/English-speaking Cheating Group students and International/Domestic Cheating Group students. As shown in Figure 3, LOTE and English-speaking students reported comparable attitudes on six of the seven behaviours, with the only exception being buying, selling or trading notes, where 6.9% more LOTE students agreed that this behaviour was wrong. As shown in Figure 4, International and Domestic students reported comparable attitudes on six of the seven behaviours, with the only exception being buying, selling or trading notes, where 8.1% more International students agreed that this behaviour was wrong. 
What are the individual, contextual and institutional factors that are correlated with contract cheating and other forms of outsourcing? 
Table 3 shows a preliminary demographic ‘profile’ of the Cheating Group. It compares key descriptive statistics of the Cheating Group with all survey respondents to signal an over- or under-representation of certain variables in the Cheating Group. Males are over-represented in the Cheating Group by a ratio of 1:1.3; LOTE students are over-represented by a ratio of 1:1.9; International students are over-represented by a ratio of 1:2.1, and Engineering students are over-represented by a ratio of 1:1.8. In contrast, students who study externally (online only) are under-represented in the Cheating Group by a ratio of 1:0.46.  The Cheating and Non-Cheating Groups were also compared for their perceptions of the teaching and learning environment, as shown in Figure 5. Students were asked to report their levels of agreement on a 5 point Likert scale regarding the following 10 items:
  • I have opportunities to approach my lecturers and tutors for assistance when needed 
  • My lecturers and tutors ensure that I understand what is required in assignments
  • There are lots of opportunities to cheat in my subjects 
  • My lecturers and tutors have explained my institution’s academic integrity policy, and the consequences for breaching it 
  • My lecturers and tutors spend class time teaching me how to reference (including how to quote, paraphrase and summarise with acknowledgement). 
  • My lecturers and tutors spend class time talking about ‘contract cheating’ and its consequences. 
  • My lecturers and tutors spend class time teaching me how to engage in scholarship in my discipline (i.e. research, read, critically analyse and discuss discipline material). 
  • My lecturers and tutors consistently monitor and penalise academic integrity breaches in line with my institution’s policy. 
  • My lecturers and tutors are consistent with each other in grading assignments. 
  • I receive sufficient feedback to ensure that I learn from the work I do.
Figure 5 shows the responses to these items, with items where the Cheating Group indicated the lowest levels of agreement relative to the Non-Cheating Group shown first. As shown in Figure 5, in descending order of difference, the Cheating Group reported markedly lower levels of agreement than the Non-Cheating Group on four items: understanding assignment requirements (item 2), receiving sufficient feedback (item 10), opportunities to approach educators (item 1), and the teaching of scholarly practice (item 7). Both groups reported comparable levels of agreement (approximately 5% difference or less) on 5 of the 10 items – explaining academic integrity policy, monitoring and penalising breaches, teaching referencing, consistent grading and explaining contract cheating. Both groups of students indicated the lowest levels of agreement that educators explain contract cheating. The Cheating Group reported higher levels of agreement on only two items: educators explain contract cheating (item 6), and lots of opportunities to cheat (item 3). An issue with the analysis of individual effects is that it cannot control for other underlying variables (i.e. the number of LOTE students varies significantly between disciplines). A multivariate analysis was therefore undertaken to examine the extent to which the demographic variables and perceptions of the teaching and learning environment influenced outsourcing behaviours, including the sharing behaviours not captured by preliminary analyses of the Cheating and Non-Cheating Groups. The multivariate analysis is reported in Appendix 1, with the dependent variable for each behaviour being whether the student admitted doing the behaviour (1) or not (0), and employing a random effects logit model. ... 
Of the seven outsourcing behaviours, sharing and cheating behaviours were each influenced by different variables. Although Engineering students were over-represented in the Cheating Group by a ratio of 1:1.8, the multivariate analysis (see Appendix 1) indicated no discipline effects on cheating behaviours. Rather, cheating behaviours were primarily explained by students’ International or LOTE status, higher levels of dissatisfaction with the teaching and learning environment, and perceptions that there are lots of opportunities to cheat. 
Findings for each behaviour outlined in Appendix 1 are detailed below. For the 15.3% of students who engaged in buying, selling or trading notes, the following groups of students were more likely to engage in that behaviour: students enrolled at a Group of Eight university,  younger students, students who had been enrolled longer at university, students in Commerce and Law, and students who reported higher levels of dissatisfaction with the teaching and learning environment. For the 27.2% of students who reported providing a completed assignment, the following groups of students were more likely to engage in that behaviour: younger students, students who had been enrolled longer at university, students who were working either part or full-time, students in Engineering, Education, Commerce and Health Sciences, and students who identified lots of opportunities to cheat in their subjects. For the 2.2% of students who obtained a completed assignment to submit as their own, the following groups of students were more likely to engage in that behaviour: males, students who reported higher levels of dissatisfaction with the teaching and learning environment, and students who identified lots of opportunities to cheat in their subjects. For the 3.1% of students who provided exam assistance, no demographic descriptors had a significant effect on that behaviour. However for the 2.4% who reported receiving exam assistance, the following groups of students were more likely to engage in that behaviour: LOTE students and those students who identified lots of opportunities to cheat in their subjects. For the 0.5% of students who reporting taking an exam for another, the following groups of students were more likely to engage in that behaviour: International students, students who reported higher levels of dissatisfaction with the teaching and learning environment, and students who identified lots of opportunities to cheat in their subjects. For the 0.2% of students who reported arranging for another person to take an exam for them, the following groups of students were more likely to engage in that behaviour: LOTE students, international students, students who reported higher levels of dissatisfaction with the teaching and learning environment, and students who identified lots of opportunities to cheat in their subjects. ... 
Despite the widespread availability of file-sharing websites and commercial services that support cheating, students still primarily engage in outsourcing behaviours with people they know: other students, friends and family. Students reported using professional services relatively rarely, and more commonly in cases of exam impersonation than for other cheating behaviours. Money was also exchanged infrequently, most commonly in relation to ‘taking an exam for someone else’. Perhaps this explains why cheating rates were not higher among fully online, external students; although their relative anonymity and remoteness spark concerns they could more easily get away with cheating, their disconnection from typical, campus-based networks of peers limits their access to the most commonly used sources of outsourced material. Although contract cheating rates remain relatively low, sharing academic work is a common part of the learning experience for many Australian students. Moreover, students more frequently provide others with completed assignments than they do with notes. It remains unclear whether students are altruistically providing their completed assignments to others in order to assist with their learning, to serve as a ‘model’ for comparison, or recklessly providing their work to other students, knowing full well that the assignment will be submitted by that student as their own work. The survey did not ask students to specify, and so did not classify this behaviour as cheating for the purpose of this analysis. It is reasonable to assume, however, that some of the students who have provided others with a completed assignment did so knowing that the student would misuse it in some way, and so engaged in a behaviour that would likely be considered cheating at their institution. While this question certainly warrants further investigation, the fact that such a large proportion of students are engaging in this behaviour, as well as buying, selling and trading notes is indicative of a ‘sharing economy’ in which everyday tasks are routinely shared or outsourced .... 
Furthermore, our data also indicated a possible relationship between these ‘sharing’ behaviours and more egregious forms of cheating. The Cheating Group were twice as likely as the Non-Cheating Group to engage in both of these sharing behaviours, more likely to use a file-sharing website or professional service to do so, and more likely to exchange money in the process. This evidence indicates the possible adoption of more instrumental, transactional approaches to learning among the Cheating Group. It is unclear whether one behaviour precedes the other. For example, perhaps students begin with sharing notes, prompting disengagement from components of the learning process, which in turn starts them on a ‘slippery slope’ towards disengagement from other aspects of learning, including the completion of assessment. Or it may be that students in the Cheating Group are more generally disengaged, and therefore more likely to outsource all aspects of their learning, including note-taking. Perhaps the most important contribution of this study is the identification of particular individual, contextual and institutional variables that influence outsourcing behaviours. Despite a significant amount of academic integrity research, variables relating to cheating behaviour have typically been examined in isolation, thereby risking the conflation of measured variables with other underlying factors. Much of the research has previously concluded that males are more likely than females to cheat ... Studies have also pointed to higher cheating rates among particular student cohorts, including International students ..., Business students ... and Engineering students .... 
The preliminary analysis of the descriptive statistics did indicate an over-representation in the Cheating group of students from certain groups: specifically, males, International students, Engineering students and students from more ‘elite’ Group of Eight universities. However, in the multivariate analysis (Appendix 1) many of these seemingly significant variables fell away due to their conflation with the key contributing variables. Contract cheating was primarily influenced by dissatisfaction with the teaching and learning environment, and perceptions that there were lots of opportunities to cheat in subjects, with the teaching and learning environment having the strongest effect (odds ratios ranging from 1.27 to 1.63, with opportunities to cheat ranging from 0.6 to 0.85). For two of the cheating behaviours (receiving exam assistance and arranging for another to take an exam), the LOTE variable also had a particularly strong effect (odds ratios of 4.41 and 2.10). ... 
For the two exam impersonation behaviours, when compared to international students, domestic students had much-reduced probabilities of undertaking this behaviour (OR of 0.41 and 0.33). The perception among the Cheating Group that there are ‘lots of opportunities to cheat’ could be interpreted in a range of ways. One hypothesis is that students who are engaging in cheating are looking for opportunities to cheat, and so see opportunities where more engaged learners do not. Or it may be that some students are exposed to opportunities (such as sharing work with peers) that other students are not. It appears, then, that while the Engineering discipline contains around one-quarter of all the students in the Cheating group, it is not Engineering per se that influences cheating behaviour. It is rather that students who are LOTE, and/or particularly dissatisfied with the teaching and learning environment, and perceive there to be ‘lots of opportunities to cheat’ are concentrated within the discipline of Engineering. Most studies have previously concluded that international students are particularly vulnerable to engaging in breaches of academic integrity. .... Our findings, while not disputing the critical role of students’ previous educational and learning experiences, contradict the simplistic view that International students cheat more due to culturally based values and attitudes towards cheating. This research suggests that the categories of LOTE and International should not be conflated. Although LOTE and International status both increase the probability of having others take an exam, this is the only overlap of influence: LOTE increases the probability of receiving exam assistance, while International status increases the probability of taking an exam for others. Nor did the cultural and linguistic diversity of our sample lead to a diversity of attitudes towards outsourcing behaviours... The only difference here was that both International and LOTE students were more likely to report that buying, selling or trading notes are ‘wrong’, which perhaps indicates that among these groups, there is greater confusion and a tendency to err on the side of caution with regard to the boundaries between acceptable and unacceptable academic practice. It appears to be the case, then, that both Domestic and LOTE students may engage in cheating behaviours despite thinking that they are wrong, not because they believe these practices are acceptable. Understanding what leads students to cheat requires the examination of a range of complex, and overlapping factors, but ‘culture’ alone does not explain the phenomenon. The sharing behaviours were influenced by a variety of variables, but for both, younger students were more likely to be involved. This perhaps indicates that engagement in a ‘sharing economy’ is to some extent related to generational factors. The sharing behaviours were also more prevalent in certain discipline areas, indicating the presence of certain discipline-based cultures of sharing, collaboration and possibly collusion. ... Although Group of Eight students were more likely to engage in buying, selling and trading notes, they were no more or less likely to engage in other outsourcing behaviours. This finding is at odds with a prevailing assumption that contract cheating is more likely to occur in higher education providers of ‘lower quality’. .
They conclude
 In the context of widespread concerns about the proliferation of online file-sharing sites and commercial assignment writing services, this large-scale study of Australian students sought to investigate the prevalence and nature of contract cheating and other outsourcing behaviours, and understand the individual, contextual and institutional factors that may influence these behaviours. Contract cheating behaviours were primarily influenced by high levels of dissatisfaction with the teaching and learning environment, perceptions that there are lots of opportunities to cheat in subjects, and students’ LOTE status. Sharing behaviours were influenced by a range of variables, but particularly age (students 25 and younger), and discipline of study. 
It is of particular concern that LOTE students continue to be over-represented in cheating surveys, and that despite two decades of research which has pointed to the need to direct resources toward more systematic approaches to students’ language and learning development, little progress appears to have been made . The long-held myth that International students have different, culturally based attitudes towards cheating has perhaps contributed to the general failure of universities to take responsibility for this issue. Our findings contribute to debunking that myth. Perhaps more important is the finding that outsourcing behaviours – including serious forms of cheating – are more commonly influenced by dissatisfaction with the teaching and learning environment, and a perception that there are lots of opportunities to cheat in subjects. This places responsibility squarely with universities, and should prompt serious considerations of approaches to curriculum and assessment design. We concur with other researchers ... that simplistic remedies, such as a return to high-stakes, invigilated examinations, are likely to be counter-productive in addressing a problem as complex as contract cheating. If indeed contract cheating is symptomatic of a ‘perfect storm’ of global and local factors, it demands a multi-pronged and holistic approach. Teaching and learning environments that focus on developing strong student–teacher relationships should be a key component of any institutional approach. Such environments reduce opportunities for students to cheat, because educators are more familiar with each student’s capabilities. They also allow for the early identification of students who may be vulnerable to cheating. As a starting point, we recommend that universities focus on two aspects of the teaching and learning environment where students who have engaged in cheating report a markedly more negative experience than other students: ensuring that students understand what is required in assignments, and that they receive sufficient feedback to learn from that work. 
It is also important that universities respond to the ways in which the ‘sharing economy’ is shaping students’ approaches to life and learning. Curriculum and pedagogy could better reflect the realities of working in a highly connected and networked world, in which sharing and collaboration are an increasing part of professional practice. Educators need to support students in learning to navigate this world, both as learners who must demonstrate their own individual capabilities through assessment, and as emerging professionals who need to learn to work ethically.

Metes

'The Forgotten History of Metes and Bounds' by Maureen (Molly) Brady  in Yale Law Journal (forthcoming) comments 
Since the settling of the American colonies, property boundaries have been described by the “metes and bounds” method, which is a highly customized system dependent on localized knowledge of movable stones, impermanent trees, and transient neighbors. The metes and bounds system has long been the subject of ridicule, and a recent wave of law-and-economics scholarship has argued that land must be easily standardized to facilitate market transactions and yield economic development. However, historians have not yet explored the social and legal context surrounding the metes and bounds system—obscuring the important role that highly customized property played in stimulating growth. 
Using new archival research from the American colonial period, this Article reconstructs the forgotten history of metes and bounds within recording practice. Importantly, the benefits of metes and bounds were greater—and the associated costs lower—than ahistorical examination of these records would indicate. The rich descriptions of the metes and bounds system transmitted valuable information to American settlers and could be tailored to different types of property interests, permitting simple compliance with recording laws. While standardization is critical for enabling property to be understood by a larger and more distant set of buyers and creditors, customized property practices built upon localized knowledge serve other important social functions that likewise encourage development.

Difference

'Buggery and Parliament, 1533-2017' by Paul Johnson comments 
Over nearly five centuries the UK Parliament, and its earlier incarnations, frequently legislated to ensure the regulation and punishment of buggery, a form of sexual conduct once generally accepted to constitute one of the most serious criminal offences known to law. In the early twenty-first century, Parliament abolished the offence of buggery and, subsequently, granted pardons to certain individuals previously convicted of it. Whilst some aspects of the history of Parliament’s approach to buggery are well known – particularly in respect of homosexual law reform – much of this history remains obscure. This article provides an in-depth consideration of the making of statute law in Parliament relating to buggery that reveals the dramatically changing attitudes of legislators towards this aspect of sexual conduct and highlights the significance and importance of the pardons granted to those convicted of the offence.
Johnson provides a cogent discussion of disregards and pardons, before going on to conclude that
Whilst the criminal offence of buggery has been abolished in English and Northern Irish law references to buggery continue to endure in a range of statutes which, for example, make provision for granting anonymity to people who allege they are victims of the offence, ensure the continuity of sexual offences law in respect of criminal justice proceedings, and regulate what information a person must provide when making an application for a licence to provide gambling facilities. Buggery also forms one of the offences for which a person can become subject to the notification requirements of the ‘sex offenders register’. In due course, when those who were victims of buggery and those who committed the offence are deceased, all of these statutory provisions will become superfluous and, along with the legislation making provision for the disregarding of offences, will likely be repealed. At such time, the only references to buggery that will endure in UK statute law will be in the legislation that provides pardons for past offences (which, as discussed above, will hopefully be expanded in the future in respect of armed forces personnel). Buggery will not, however, disappear from parliamentary debate but will continue to be discussed in relation to those jurisdictions to which Britain ‘exported’ the offence and where it, or some version of it, continues to endure in criminal law. A concern with buggery will remain an inherent aspect of the ‘common enterprise’ that has recently developed amongst legislators committed to challenging and abolishing ‘oppressive discriminatory laws’ affecting LGBT people around the world in Commonwealth nations, as well as in the Crown Dependencies and British Overseas Territories.

Obscurity

The Chance 'to Melt into the Shadows of Obscurity': Developing a Right to Be Forgotten in the United States' by Patrick O'Callaghan in A. Cudd and M. Navin (eds) Privacy: Core Concepts and Contemporary Issues (Springer, 2018) comments 
This chapter argues that there is some (limited) evidence of a right to be forgotten in the jurisprudence of U.S. courts. For the purposes of this argument, the right exists whenever interests in being forgotten and/or forgetting are understood as weighty enough to impose a duty on government and/or fellow citizens to respect those interests. Most of the relevant cases belong to the pre-digital era but nevertheless provide some doctrinal support for a right to be forgotten in the digital era. In particular, the chapter pays close attention to the privacy challenges associated with search engines and argues that it may be possible to implement a Google Spain-inspired right to be forgotten (in the sense of delisting or deindexing search results) in the United States.

20 April 2018

UK Artificial Intelligence

The House of Lords has released a report on artificial intelligence in the UK, titled AI in the UK: Reading, Willing and Able?.

The report features a useful discussion of concerns regarding provision by the  Royal Free London Hospital Trust (ie a NHS unit) of bulk patient data to Alphabet (Google's parent).

The summary states
Our inquiry has concluded that the UK is in a strong position to be among the world leaders in the development of artificial intelligence during the twentyfirst century. Britain contains leading AI companies, a dynamic academic research culture, a vigorous start-up ecosystem and a constellation of legal, ethical, financial and linguistic strengths located in close proximity to each other. Artificial intelligence, handled carefully, could be a great opportunity for the British economy. In addition, AI presents a significant opportunity to solve complex problems and potentially improve productivity, which the UK is right to embrace. Our recommendations are designed to support the Government and the UK in realising the potential of AI for our society and our economy, and to protect society from potential threats and risks.
Artificial intelligence has been developing for years, but it is entering a crucial stage in its development and adoption. The last decade has seen a confluence of factors—in particular, improved techniques such as deep learning, and the growth in available data and computer processing power—enable this technology to be deployed far more extensively. This brings with it a host of opportunities, but also risks and challenges, and how the UK chooses to respond to these, will have widespread implications for many years to come. The Government has already made welcome advances in tackling these challenges, and our conclusions and recommendations are aimed at strengthening and extending this work.
AI is a tool which is already deeply embedded in our lives. The prejudices of the past must not be unwittingly built into automated systems, and such systems must be carefully designed from the beginning. Access to large quantities of data is one of the factors fuelling the current AI boom. We have heard considerable evidence that the ways in which data is gathered and accessed needs to change, so that innovative companies, big and small, as well as academia, have fair and reasonable access to data, while citizens and consumers can protect their privacy and personal agency in this rapidly evolving world.
To do this means not only using established concepts, such as open data and data protection legislation, but also the development of new frameworks and mechanisms, such as data portability and data trusts. Large companies which have control over vast quantities of data must be prevented from becoming overly powerful within this landscape. We call on the Government, with the Competition and Markets Authority, to review proactively the use and potential monopolisation of data by big technology companies operating in the UK.
Companies and organisations need to improve the intelligibility of their AI systems. Without this, regulators may need to step in and prohibit the use of opaque technology in significant and sensitive areas of life and society. To ensure that our use of AI does not inadvertently prejudice the treatment of particular groups in society, we call for the Government to incentivise the development of new approaches to the auditing of datasets used in AI, and to encourage greater diversity in the training and recruitment of AI specialists.
The UK currently enjoys a position as one of the best countries in the world in which to develop artificial intelligence, but this should not be taken for granted. We recommend the creation of a growth fund for UK SMEs working with AI to help them scale their businesses; a PhD matching scheme with the costs shared between the private sector; and the standardisation of mechanisms for spinning out AI start-ups from the excellent research being done within UK universities. We also recognise the importance of overseas workers to the UK’s AI success, and recommend an increase in visas for those with valuable skills in AI-related areas. We are also clear that the UK needs to look beyond the current dataintensive focus on deep learning, and ensure that investment is made in less researched areas of AI in order to maintain innovation.
Many of the hopes and the fears presently associated with AI are out of kilter with reality. While we have discussed the possibilities of a world without work, and the prospects of superintelligent machines which far surpass our own cognitive abilities, we believe the real opportunities and risks of AI are of a far more mundane, yet still pressing, nature. The public and policymakers alike have a responsibility to understand the capabilities and limitations of this technology as it becomes an increasing part of our daily lives. This will require an awareness of when and where this technology is being deployed. We recommend that industry, via the AI Council, establish a voluntary mechanism to inform consumers when artificial intelligence is being used to make significant or sensitive decisions.
AI will have significant implications for the ways in which society lives and works. AI may accelerate the digital disruption in the jobs market. Many jobs will be enhanced by AI, many will disappear and many new, as yet unknown jobs, will be created. A significant Government investment in skills and training is imperative if this disruption is to be navigated successfully and to the benefit of the working population and national productivity growth. This growth is not guaranteed: more work needs to be done to consider how AI can be used to raise productivity, and it should not be viewed as a general panacea for the UK’s wider economic issues.
As AI decreases demand for some jobs but creates demand for others, retraining will become a lifelong necessity and pilot initiatives, like the Government’s National Retraining Scheme, could become a vital part of our economy. This will need to be developed in partnership with industry, and lessons must be learned from the apprenticeships scheme. At earlier stages of education, children need to be adequately prepared for working with, and using, AI. For a proportion, this will mean a thorough education in AI-related subjects, requiring adequate resourcing of the computing curriculum and support for teachers. For all children, the basic knowledge and understanding necessary to navigate an AIdriven world will be essential. In particular, we recommend that the ethical design and use of technology becomes an integral part of the curriculum.
In order to encourage adoption across the UK, the public sector should use targeted procurement to provide a boost to AI development and deployment In particular, given the impressive advances of AI in healthcare, and its potential, we considered the health sector as a case study. The NHS should look to capitalise on AI for the public good, and we outline steps to overcome the barriers and mitigate the risks around widespread use of this technology in medicine.
Within the optimism about the potential of AI to benefit the UK, we received evidence of some distinct areas of uncertainty. There is no consensus regarding the adequacy of existing legislation should AI systems malfunction, underperform or otherwise make erroneous decisions which cause harm. We ask the Law Commission to provide clarity. We also urge AI researchers and developers to be alive to the potential ethical implications of their work and the risk of their work being used for malicious purposes. We recommend that the bodies providing grants and funding to AI researchers insist that applications for such funding demonstrate an awareness of the implications of their research and how it might be misused. We also recommend that the Cabinet Office’s final Cyber Security & Technology Strategy consider the risks and opportunities of using AI in cybersecurity applications, and conduct further research as how to protect datasets from any attempts at data sabotage.
The UK must seek to actively shape AI’s development and utilisation, or risk passively acquiescing to its many likely consequences. There is already a welcome and lively debate between the Government, industry and the research community about how best to achieve this. But for the time being, there is still a lack of clarity as to how AI can best be used to benefit individuals and society. We propose five principles that could become the basis for a shared ethical AI framework. While AI-specific regulation is not appropriate at this stage, such a framework provides clarity in the short term, and could underpin regulation, should it prove to be necessary, in the future. Existing regulators are best placed to regulate AI in their respective sectors. They must be provided with adequate resources and powers to do so.
By establishing these principles, the UK can lead by example in the international community. There is an opportunity for the UK to shape the development and use of AI worldwide, and we recommend that the Government work with Government-sponsored AI organisations in other leading AI countries to convene a global summit to establish international norms for the design, development, regulation and deployment of artificial intelligence.

18 April 2018

Reforming auDA and the dot au ccTLD

As a member of several auDA working parties in a past life I expressed concerns regarding regulatory capture. Those substantive nature of those concerns is evident in the Commonwealth government's Review of the .au Domain Administration report released today.

The report states
On 19 October 2017, the Minister for Communications, Senator the Hon Mitch Fifield, announced a review of Australia’s management of the .au domain (the Review). The not-for-profit .au Domain Administration (auDA) oversees the operation and management framework of the .au domain of the internet. auDA is endorsed by the Australian Government as the appropriate entity to administer Australia’s country code Top-Level Domain (ccTLD)—the .au domain—on behalf of Australian internet users.
The digital landscape has changed significantly since auDA was endorsed by the Australian Government in 2000. The internet has become all-pervasive and a critical enabler of the digital economy. The .au namespace plays an important role in supporting the digital economy, allowing entities and organisations to register domain names. As of late September 2017, over 3 million .au domain names had been registered in Australia.
While internet usage continues to grow, the overall communications environment is changing. Australians are accessing the internet in different ways and cyber security threats are increasingly prevalent. Future trends may have an impact on the domain space and it is important Australia has an effective .au administrator that is able to ensure the ongoing availability of .au domains while navigating future uncertainty.
auDA’s governance arrangements have not changed significantly since it was first established, with its structure and approach to governance set at a point in time when the internet and the domain industry was still in its infancy. The Review has found that reforms to auDA’s governance arrangements are necessary if the company is to perform effectively and meet the needs of Australia’s internet community.
In undertaking the Review, the Department has reflected on three principles:
• The Australian Government is committed to strengthening multi-stakeholder mechanisms for internet governance, noting the diversity of auDA’s stakeholders. 
• The .au namespace is a public asset given its increasing importance to the daily lives of Australians and should be governed with community interests in mind. 
• auDA has a monopoly position in administering the .au namespace and should be subject to stringent oversight requirements.
Importantly, the review acknowledges that auDA has overseen a significant ramp up in the number of domain names and has introduced many important policy and security initiatives. auDA has contributed to .au being seen globally as a secure and trusted namespace.
The government's Findings are -
The central finding of the Review is the current management and governance framework for auDA is no longer fit-for-purpose and that reform is necessary if the company is to perform effectively and meet the needs of Australia’s internet community.
In particular, the current membership model, and its relationship to corporate governance, is impeding auDA’s decision making and is contributing to ongoing organisational instability. The membership class structure is not reflective of Australia’s internet community nor auDA’s stakeholders. The current process where the majority of directors are appointed from the membership does not support effective governance outcomes.
Further, directors can be elected to the board with little regard to the skills required to effectively govern a modern domain administrator. Directors are also not required to meet probity, security or conflict of interest checks.
Ultimately, current governance and management framework arrangements are not satisfactory given the importance of the .au namespace to the Australian community. In considering stakeholder feedback and better practice guidelines, the Review identifies a range of reforms to improve stakeholder engagement, transparency and accountability, and mechanisms to promote trust and confidence in the .au domain name.
The Review considers that significant and urgent reforms are necessary to ensure that the .au namespace is administered in line with community and the Australian Government’s expectations.
To achieve this, the Review has made recommendations focusing on:
• clarifying the role of the .au domain administrator to ensure its activities are aligned with its responsibilities 
• reforming the management framework to support improved transparency, consultation and accountability by providing greater guidance on performance and reporting requirements 
• supporting effective stakeholder engagement and better representation of the Australian internet community, by acknowledging the .au DNS as a public asset and the multi-stakeholder approach to internet governance 
• outlining the role and expectations of the Australian Government 
• fostering greater trust and confidence in the .au namespace by enhancing security best practice and coordination of DNS administration.
... Reforming auDA will be a substantial process. Changes to its governance and membership arrangements involves significant constitutional reform, which requires the support of the membership base. The extent to which the membership supports reform is unclear.
The Review proposes two options to implement recommendations. The first option would see the Minister for Communications issuing revised terms of endorsement to auDA supported by an implementation plan with clearly identified milestones for reform. This plan would see a clear pathway for reform in place by three months, significant progress by 12 months, and the full reform package implemented within 24 months.
Alternatively, the Government could consider issuing an expression of interest to assess whether an alternative provider is able to perform the .au domain administration function in line with the revised terms of endorsement. This option may identify a viable alternative provider for the administration of the .au namespace mitigating the risk that constitutional reform of auDA cannot be achieved.
The stability, resilience and security of the .au namespace is paramount to the Government. The review recommends that auDA be given the opportunity to conduct the necessary reforms. However, the Government is committed to implementation of timely reform and will take action to ensure that Australia’s domain name is administered effectively and in the interest of all Australians. This includes transitioning the delegation for management of .au to another provider if auDA is unable to achieve necessary outcomes.
On that basis the report features the following recommendations
Purpose of the .au domain administrator
1. While auDA has an ongoing role in the security and stability of the .au space including as part of the critical infrastructure sector, this should not in the foreseeable future alter auDA’s role and purpose. 
2. That auDA continue to operate as a not-for-profit entity and does not seek to maximise profit. 
3. Consideration of commercial strategies relevant to the sustainability of the domain administrator should not detract from the domain administrator’s core function as described in the terms of endorsement and core purpose.
Management framework
4. That auDA provide an annual Strategic Plan covering at least a four-year-period and with the Strategic Plan reflecting company purpose and terms of endorsement. The auDA Board and management should present progress against the organisation’s purpose and its strategic objectives at auDA’s Annual General Meeting and in its Annual Report. 
5. That auDA develop a KPI framework to: a. measure its performance against its stated objectives in its terms of endorsement b. report against in its Annual Report and at its Annual General Meeting. 
6. As part of its Strategic Plan, that auDA outline how it intends to discharge its functions as a not-for-profit company and report on its effectiveness in its Annual Report and at its Annual General Meeting.
Transparency and consultation
7. That auDA reform its governance arrangements to ensure: 
a. that the nomination of all Board positions is undertaken by a Nomination Committee comprised of representatives from industry, the business sector, consumers, an auDA member representative, and the Commonwealth, represented by the Department
i. in establishing the Nomination Committee, the auDA Board will undertake a consultative merit-based process to identify members, with a Department representative as a panellist, and the Department to select the committee members from this process 
ii. the Nomination Committee will undertake probity and disclosure assessments and develop a skills matrix to ensure new directors have an appropriate mix of technical and corporate skills and industry experience 
iii. the Nomination Committee will shortlist: member candidates to stand for election by members; and independent candidates to stand for election by the Board 
iv. however, the first Board, following the reform of auDA’s governance arrangements will be selected according to the skills mix identified by the Nomination Committee with shortlisted nominees agreed with the Department 
b. length of terms directors can serve is capped at three years with directors appointed for no more than two consecutive terms 
c. the Board is structured so that the majority of the Board is independent of auDA’s membership 
d. that within 12 months the Board is reconstituted to ensure all appointments meet this criteria.
8. That auDA establish a Board Charter:
a. to set out the respective roles and responsibilities of the Board, Chair and CEO 
b. to set out the basis for appointment of the Chair 
c. that requires the Board to report on an annual basis to stakeholders publicly on its performance against this charter. 
9. That auDA:
a. formalise its transparency and accountability framework, consistent with recommendations in the Westlake review 
b. report annually on its performance against the framework in its Annual Report and at its Annual General Meeting.
Membership
10. That auDA reforms its existing membership model by creating a single member class or a functional constituency model and that membership reform is non-discriminatory and supported with transparent membership guidelines. 
11. That auDA diversify its member base in the short-term with a focus on extending membership to stakeholders that are underrepresented. 
12. That auDA report annually on its initiatives for growing its membership, and their effectiveness at diversifying the membership in its Annual Report and at its Annual General Meeting. 
13. That auDA review its assessment process for new members, in conjunction with the implementation of Recommendations 10, 11 and 12. 
Expectations and role of the Government 
14. That the Minister for Communications issue new terms of endorsement, setting out the Government’s expectations for .au domain administration and that auDA respond by publishing a statement on how it will deliver on these expectations. 
15. That the Government review these terms of endorsement within two years from when they are issued to ensure they remain fit-for-purpose, with reviews scheduled every three years going forward. 
16. That the Department of Communications and the Arts adopts a more formal oversight role of auDA, including that:
a. auDA report quarterly to the Department on its implementation of reforms, work agenda and key work priorities 
b. the Department conducts independent verification of some or all of auDA’s reporting provided through its Annual Report, including those requirements identified as part of the review 
c. a senior executive officer from the Department continue as a non-voting observer at auDA Board meetings and is present for all decisions taken by the Board. 
17. That the oversight role of the Department of Communications and the Arts is reviewed periodically by Government to ensure it is fit-for-purpose. 
Stakeholder engagement 
18. That auDA develops a public stakeholder engagement strategy and implementation plan to articulate how it will engage with stakeholders in all levels of operation and decision making. 
19. Through its Annual Report and at its Annual General Meeting, auDA should report on its performance against its stakeholder engagement strategy. 
20. That auDA publish conclusions from its review on its community activities and publish an implementation plan on future community activities. 
21. That auDA continue to engage with ICANN and other international bodies to represent Australian interests. 
22. That auDA’s stakeholder engagement strategy (Recommendation 18) include ICANN and other relevant international fora and bodies. 
23. As part of its Strategic Plan (Recommendation 4), auDA publishes a forward-looking international travel schedule and describes in its Annual Report the effectiveness of its international activity.
Trust and confidence in .au
24. As part of its international engagement (Recommendations 21, 22 and 23), auDA engage with key international security fora including ICANN’s Security and Stability Advisory Committee to ensure that it is kept updated on international security developments. 
25. That auDA develop and implements an enterprise security strategy based on domestic and international best practice in consultation with all relevant stakeholders. 
26. That auDA publishes a public facing version of its enterprise security strategy, having regard to relevant sensitivities. 
27. As part of its stakeholder engagement plan (Recommendation 18), that auDA maps its relationship with Australian Government security agencies and the internet industry and community on security of the .au namespace. 
28. That the Department of Communications and the Arts facilitate partnerships between auDA and relevant cyber security agencies. 
29. As part of its quarterly reports to Government (Recommendation 16) that auDA report on its security activities.
The report identifies  new terms of endorsement
Preamble
Australia’s country-code Top Level Domain (ccTLD) is an important resource, given the growing reliance of Australians on the .au namespace for economic and social activities. Noting there is a diversity of stakeholders in this namespace, the management of the .au domain must support multi-stakeholder engagement and be administered in the public interest. Responsibility for the administration of .au is ultimately derived from, and is subject to, the authority of the Commonwealth. The Australian Government can delegate the responsibility for managing the .au namespace to an appropriate entity or organisation. However, endorsement from Government is contingent on the entity satisfying a number of conditions. The Government provides the following terms of endorsement to auDA, as the .au domain administrator.
Core functions
The .au domain administrator will undertake the following core functions: • ensure stable, secure and reliable operation of the .au domain space • respond quickly to matters that compromise DNS security • promote principles of competition, fair trading and consumer protection • operate as a fully self-funding and not-for-profit organisation • actively participate in national and international technical and policy namespace fora to ensure that Australia’s interests are represented and to identify trends and developments relevant to the administration of the .au namespace • establish appropriate dispute resolution mechanisms.
Emerging domain issues such as commercial opportunities should not detract from the domain administrator performing its core functions.
Conditional requirements
In undertaking these functions, the .au domain administrator will uphold the following requirements and conditions: Effective governance arrangements for the .au namespace Good governance practices provide the foundation for the effective management of the .au ccTLD. The .au domain administrator must implement a governance structure that supports effective decision-making and represents the interests of stakeholders in a transparent and accountable manner.
Conditions:
That the .au domain administrator has:
• a governance structure which includes the following characteristics: 
• an independent process that can provide assurances of the suitability of candidates considered for board appointments, such as a Nomination Committee 
• a board that has the collective mix of technical and corporate skills, and industry experience, to effectively administer the .au namespace 
• a board that appoints a majority of directors who are independent of the organisation, including the Chair 
• appointment terms that support ongoing board renewal 
• a Board Charter that outlines the roles and responsibilities of the board, Chair and CEO and the basis for appointment of the Chair.
Facilitate effective stakeholder engagement
Noting that the .au namespace has a diversity of stakeholders, the .au domain administrator must engage and consult widely to ensure it can effectively represent the views of its stakeholders.
Conditions: 
That the .au domain administrator:
• consults with stakeholders on deliberations and decisions that will impact on the Australian internet community 
• develop a comprehensive stakeholder engagement plan, including how it will engage with key stakeholders such as industry, members of the community, Government and relevant international bodies and organisations  
• consistent with this stakeholder engagement plan, participate in international fora and relevant community activities 
• has a clearly defined membership structure that can represent the views of the Australian internet community 
• initiate activities that engage the internet community and support the diversification of its member base 
• establish an effective process for assessing and processing new members.
Support accountability and transparency
In managing a public asset, the .au domain administrator will be accountable to its stakeholders, including the Australian Government. Improved transparency and accountability is necessary to provide the assurance that the .au namespace is being managed consistent with Government and community expectations.
Conditions:
That the .au domain administrator has:
• an annual strategic plan that reflects these Terms of Endorsement and the company’s purpose with reference to how it will discharge its functions as a not-for-profit entity 
• a transparency and accountability framework 
• an effective reporting framework which would include reporting through its Annual Report and at its Annual General Meeting on performance against: 
• these terms of endorsement, supported by a key performance indicator framework • board performance against its charter 
• its strategic plan • the transparency and accountability framework 
• stakeholder engagement activities including international and community activities and initiatives that aim to expand the member base.
Engagement with the Australian Government
In providing its endorsement for an entity to administer what is a public asset, the Government has a strong interest in the management of Australia’s ccTLD. 
Conditions: 
That the .au domain administrator:
• provide quarterly updates on performance and work priorities to the Department 
• acknowledge that the Government reserves the right to independently review auDA’s reporting and reporting processes at any time 
• ensure that a senior officer from the Department is included in all relevant auDA governance processes, including, but not limited to, non-voting observer status at board meetings for all decisions 
• develop a strategy to enable an orderly transition to an alternative domain administrator in the event that endorsement is withdrawn by the Government.
Support trust and confidence in .au
Confidence in the .au namespace will be critical to the growth of Australia’s economy. In addition to the Department of Communications and the Arts, there are a number of other Australian Government agencies that have a role in supporting the security and stability of .au.
Conditions:
That the .au domain administrator:
• engage with key international security fora to ensure it is aware of international security developments and best practice 
• develop, maintain and, to the greatest extent possible, publish an enterprise security strategy which is informed by domestic and international best practice 
• work with the Department of Communications and the Arts to facilitate partnerships between auDA and relevant cyber security agencies
Commencement of these terms of endorsement
In agreeing to the terms of endorsement, the .au domain administrator is required to respond in writing within three months, providing an implementation plan on how it will meet these terms. The Australian Government will conduct a review within two years to assess the performance of the .au domain administrator and consider whether these terms of endorsement remain fit-for-purpose.