20120708

Music: The Internet’s Original Sin

Cory Doctorow

In a recent Search Engine podcast, host Jesse Brown wondered about music’s ongoing centrality to the debate over file-sharing and freedom. After all, the music industry has all but abandoned lawsuits against fans, and services from Last.fm to the Amazon MP3 store present a robust set of legit ways of hearing and acquiring music. The labels have even abandoned DRM. So why is the music industry the enduring bogeyman of Internet policy fights? Brown called downloading music ‘‘the Internet’s original sin,’’ and posited that we’ll go on talking for music for a long time yet.

I think he’s right. Music exists in a sweet spot between commerce and culture, individual and collective effort, identity and industry, and digital and analog – it is the perfect art-form to create an infinite Internet controversy.

Let’s start with music’s age. Movies are still in their infancy. Books are in their middle age. Stories themselves are ancient. But music is primal. Books may predate commerce, but music predates language. Our relationship with music, and our social contracts around it, are woven into many other parts of our culture, parts that are considered more important than mere laws or businesses. The idea that music is something that you hear and then sing may even be inherent to our biology. I know that when I hear a catchy tune, I find myself humming it or singing it, and it takes a serious effort of will to stop myself. It doesn’t really matter what the law says about whether I am ‘‘authorized’’ to ‘‘perform’’ a song. Once it’s in my head, I’m singing it, and often singing it with my friends. If my friends and I sing together by means of video-sharing on YouTube, well, you’re going to have a hard time convincing us that this is somehow wrong.

Music is also contingent. The part of a song that is ‘‘musical’’ is totally up for grabs, and changes from society to society and age to age. The European tradition has tended to elevate melody, so we think of ‘‘writing a song’’ as ‘‘writing the melody.’’ Afro-Caribbean traditions stress rhythms, especially complex polyrhythms. To grossly oversimplify, a traditional European song with a different beat (but the same melody) can still be the same song. A traditional Afro-Caribbean song with a different melody (but the same rhythm) can still be the same song. The law of music – written by Europeans and people of European descent – recognizes strong claims to authorship for the melodist, but not the drummer. Conveniently (for businesses run in large part by Europeans and people of European descent), this has meant that the part of the music that Europeans value can’t be legally sampled or re-used without permission, but the part of the music characteristic of Afro-Caribbean performers can be treated as mere infrastructure by ‘‘white’’ acts. To be more blunt: the Beatles can take black American music’s rock-n-roll rhythms without permission, but DJ Danger Mouse can’t take the Beatles’ melodies from the White Album to make the illegal hiphop classic The Grey Album.

The reality is that all music takes from all other music, anyway. They called Brahms’s first symphony ‘‘Beethoven’s Tenth’’ for reasons that are immediately apparent to anyone familiar with both composers. The parts of music that can be used under the banner of ‘‘inspiration’’ and the parts that constitute ‘‘infringement’’ or ‘‘plagiarism’’ or some other frowned-upon taking are arbitrary, and there is an enormous gap between how the law treats music production, how music producers describe what they do, and what scholars who study music see happening.

Meanwhile, the recording industry has always had a well-deserved reputation for corruption and maltreatment of artists. From the recurring payola scandals that crop up every decade or so to the never-ending stream of stories about the bad deal musicians get, the industry has never been able to credibly claim that buying artists’ creations from their labels will end up enriching the artists themselves. No fan cares much about the commercial fortunes of labels themselves – if we care about anyone, it’s the musicians. When you learn that – to pick just one example – the labels only recently ended the practice of running secret ‘‘third-shift’’ pressings in the dead of night, CDs that were not on the books and that were sold without generating royalties for the artists, it’s hard to credit the idea that taking music without paying for it always harms artists. Incidentally, the thing that stopped third-shift pressings wasn’t ethics or artists’ rights movements – it was the provision in Sarbanes-Oxley that made executives personally, criminally liable for balance-sheet frauds.

Maltreatment of the talent isn’t unique to music, of course. But movies don’t have obvious ‘‘creators’’ to sympathize with. Rather, they have directors (who tend to be either totally unknown or incredibly rich and famous), and actors (ditto). Even screenwriters have a reputation for being awfully well-off when compared to other kinds of writers, especially novelists. And while novelists are obviously the creators of the books we love, the standard novel publishing deal is much better than the standard recording deal – a licensed work rather than a work for hire, no expenses charged back against the creator, more transparent royalty reporting, etc.

I think even the record industry recognizes that appealing to the innate justice of its survival and profit is a nonstarter. That’s the only explanation I can think of for their campaigns in the past decade that have focused on the risk to young peoples’ moral character as a result of file-sharing. This is a pretty poor argument, of course: when the record industry spends half a century telling would-be censors that it is not in the business of safeguarding the morals of young listeners, it’s pretty rich for the same industry to turn around and announce that it is only suing and threatening kids to save them from a life of sin and degradation.

Music production is also in the sweet spot between movies and books when it comes to technological advances. It’s true that word processors, desktop publishing, and e-books have increasingly led to a credible notion of a truly independent author who does it all for herself, but the one-man music studio is a more advanced than the one-writer publishing house. Meanwhile, movies are still generally viewed as enormous collaborations requiring big, complex companies behind them to coordinate all the big, complex tasks that go into making a feature. There is a widespread sense that almost everything a record label does can be done by the musicians themselves, using the same equipment that the rest of us use to play Minesweeper and watch YouTube. The reality is that there are many musicians who can write or perform a song, but can’t arrange or edit or master or market or bookkeep that song, but it’s still pretty easy to imagine a world in which all the current record labels die, but recorded music continues to thrive.

Back at the beginning of the file-sharing wars, during the delirious 18 months during which Napster went from zero to 52 million users, much of the focus was on the novelty of getting music for free – but there was also a lot of buzz about getting some of that music at all. Prior to Napster, more than 80 percent of recorded music wasn’t for sale (except as uncatalogued, obscure used LPs). The record industry had always enjoyed both the savings from not having to warehouse and manage all those physical products, and the increased profits that arose from limiting choice. Napster, the original long tail marketplace, showed that audiences hungered for abundance of choice.

Twelve years later, abundance is the signal characteristic of all media. The media choices available to us are staggering in their variety and depth. As I write this in mid-2012, there’s an hour of new video appearing on YouTube every second. Video-on-demand services like Netflix present libraries that make the biggest Blockbuster store of yore seem like a single shelf at the back of the corner shop. Amazon’s self-publishing platform is attracting thousands of new books, from marginal titles of extreme specialist interest to algorithmically generated spam titles that repurpose Wikipedia entries and random scraped Internet text. There’s also plenty of fiction, some of which is brilliant and much of which is in the ‘‘90 percent of everything is shit’’ region predicted by Sturgeon’s Law. Curation is the watchword for the coming century: some process by which you are able to outsource some of the reviewing and ranking of all this material to communities, algorithms, or individuals.

But the accelerating growth of media in the online world means that no matter how carefully you choose your curators to ensure that you’re getting just enough media and not being overwhelmed, you will still end up overwhelmed. Everyone feels like there’s more media than they can handle coming in through the narrow, select channels they opted into, from Facebook and Twitter to a favorite blog or podcast. It’s not enough to choose one’s channels carefully; you also have to be able to skim what comes through those channels and make snap decisions about what you will experience in depth. Blog posts and quick YouTube clips are easy enough to glance at and decide whether they’re for you or not.

But novels and feature films are damned hard to ‘‘skim.’’ Figuring out whether you like a novel enough to read it through requires a substantial investment of time and attention. Deciding whether to watch a feature film, likewise.

A lot of music reveals itself well and quickly. Sign up for a predictive personal radio station like the ones provided by Last.fm, and you’ll find that it only takes a few bars’ worth of sound before you know whether you’re going to keep listening or hit the skip button.

What’s more, music is well-suited to multitasking, that characteristic survival activity of the 21st century. It’s not easy to read a novel while doing something else – notwithstanding the comedy cliché of a bookworm proceeding down a public road with his nose in a book – and movies also want you to switch off everything else while you watch them.

Music is much less jealous of your attention, perfectly comfortable with fading into the background. If you’re one of those people who works with music on all the time, you want your music to come out of your device like water coming out of a faucet. It’s natural that music that ‘‘feels free’’ fits right into our lives.

It’s also customary – and simple – to reference music. Whistle the Jeopardy! theme when a friend dithers over the menu at a restaurant; ‘‘Whistle While You Work’’ when you want to get your roommates to pitch in and pick up after themselves; ‘‘Blue Skies Smiling at Me’’ when spring has finally sprung where you are (and ‘‘April Showers’’ when the rain comes back). Sure, we quote iconic movie-lines at each other, and everyone knows a few literary quotes, but music is quoted much more widely in our daily lives – and in music itself, which is chock full of snatches from other music – than other media. When it comes to learning to be a musician, re-use, copying,­ and performance are central: you learn to play music by playing other peoples’ compositions, period. Budding filmmakers may try to re-create their favorite scenes, or work in ways that are obviously inspired by their predecessors; young authors may copy out a favorite passage to see how it works. But music is a field in which it is considered central and normal to reproduce others’ creations for years, commercially and privately, as a means of earning your chops.

All these factors – music’s suitability to a world of abundance, music’s ubiquity in our culture, music’s freight in our history, and the industry’s tarnished reputation – mean that the Internet and music businesses will continue to collide for the foreseeable future. There’s no end in sight to this controversy.

20120707

That's Not in the Constitution! Basic Rights Not Spelled Out in the Constitution

By Austin Cline

Innocent until Proven Guilty:

American courts treat accused criminals as innocent until proven guilty; this ensures that they are accorded all the rights they are due. There is nothing in the Constitution about a right to be treated innocent until proven guilty, though. The concept comes from English common law, and several parts of the Constitution, such as the right to remain silent and the right to a jury trial, only make sense in light of a presumption of innocence; without this presumption, what’s the point?

The Right to a Fair Trial:

There is nothing in the Constitution about a “right to a fair trial.” The Constitution lists several trial-related rights, such as the right to a jury trial and that a trial should be held where the crime occurred; yet if the state could give you a trial that is unfair without violating those explicit rights, then the letter of the Constitution would not be violated. Once again, though, the rights which are listed make no sense unless trials are supposed to be fair in the first place.

Right to a Jury of Your Peers:

Many people imagine that they have a right to tried in front of a jury of their peers, but there is nothing in the Constitution about that. As with “innocent until proven guilty,” this concept comes from English common law. The Constitution only guarantees a trial before an impartial jury in criminal cases, not that the jury you’re tried before has anything to do with you. It would be too difficult to even define who your peers are, much less get a jury of peers for every individual defendant.

The Right to Vote:

How can a country be democratic if there is no right to vote? The Constitution lists no such explicit right, as it does with speech or assembly. It only lists reasons why you can’t be denied the ability to vote — for example, because of race and sex. It also lists some basic requirements, such as being 18 or older. Voting qualifications are set by the states, which can come up with all sorts of ways to deny people the ability to vote without violating anything stated in the Constitution.

The Right to Travel:

Many think that they have a basic right to travel where they want, when they want — but there is nothing in the Constitution about a right to travel. This was no oversight because the Articles of Confederation did list such a right. Several Supreme Court cases have ruled that this basic right exists and that the state can’t interfere with travel. Perhaps the authors of the Constitution thought that the right to travel was so obvious that it didn’t need to be mentioned. Then again, perhaps not.

Judicial Review:

The idea that the courts have the authority to review the constitutionality of laws passed by legislatures is firmly entrenched in American law and politics. However, the Constitution does not mention “Judicial Review” and does not explicitly establish the concept. The idea that the judicial branch could be any kind of check on the power of the other two branches is baseless without this power, though, which is why Marbury v. Madison (1803) established it. Or were these just activist judges?

The Right to Marriage:

Heterosexuals seem to take it for granted that they have a right to marry whom they want; there is no such right in the Constitution, however. The Constitution says nothing at all about marriage and the regulation of marriage is left to the states. In theory, a state could ban all marriages, or all interfaith marriages, without violating anything explicitly stated in the Constitution. Equal protection of the laws must be maintained; otherwise, marriage can be restricted in lots of ways.

The Right to Procreate:

People may also assume that as with marriage, they have a right to have children. Also as with marriage, there is nothing in the Constitution about procreation. If a state banned procreation, required licenses for procreation, or selectively banned procreation for people with mental disabilities, physical disabilities, or other problems, nothing in the Constitution would automatically be violated. You have no explicit Constitutional right to procreate.

The Right to Privacy:

Whenever people complain about courts creating new rights that aren’t in the Constitution, they are usually talking about the right to privacy. Although the Constitution doesn’t mention any right to privacy, several passages imply such a right and many court decisions have found a right to privacy in different aspects of human life, such as contraception the education of children. Critics complain that courts have invented this right for political purposes.

Reading and Interpreting the Constitution:

Debates about whether some particular right is “in” the Constitution or not are really debates about how to read and interpret the Constitution. Those who claim that the Constitution doesn’t say “right to privacy” or “separation of church and state” are relying upon the assumption that unless a particular phrase or specific words actually appears in the document, then the right doesn’t exist — either because the interpreters are drawing invalid implications or because it’s illegitimate to go beyond the exact text at all.

Given how rare it is for the same people to argue that the implications being drawn are not valid, the latter of the two options is almost always the case. These same people who reject interpreting the text beyond its literal, specific language are also often the ones who resist interpreting the Bible beyond its literal language. They are literalists when it comes to their religious scriptures, so it’s not a surprise that they are literalists when it comes to legal documents.

The validity of this approach to the Bible is debatable; it’s not, however, an appropriate approach to dealing with the Constitution. Interpretation of laws should generally be limited to the plain text, but the Constitution isn’t a law or a set of laws. Instead, it’s a framework for the structure and the authority of the government. The main body of the Constitution explains how the government is set up; the rest explains the limitations on what the government is permitted to do. It can’t be read without being interpreted.

The people who sincerely believe that constitutional rights are limited solely to those spelled out in the text of the Constitution must be able to defend not just the absence of a right to privacy, but also the absence of constitutional rights to travel, a fair trial, marriage, procreation, voting, and more — not every right which people take for granted has been discussed here. I don’t think it can be done.

20120704

Free Software Foundation recommendations for free operating system distributions considering Secure Boot

by John Sullivan

Introduction

This paper is also available as a PDF.

We have been working hard the last several months to stop Restricted Boot, a major threat to user freedom, free software ideals, and free software adoption. Under the guise of security, a computer afflicted with Restricted Boot refuses to boot any operating systems other than the ones the computer distributor has approved in advance. Restricted Boot takes control of the computer away from the user and puts it in the hands of someone else.

To respect user freedom and truly protect user security, computer makers must either provide users a way of disabling such boot restrictions, or provide a sure-fire way that allows the computer user to install a free software operating system of her choice.

Distributors of restricted systems usually appeal to security concerns. They claim that if unapproved software can be used on the machines they sell, malware will run amok. By only allowing software they approve to run, they can protect us.

This claim ignores the fact that we need protection from them. We don't want a machine that only runs software approved by them -- our computers should always run only software approved by us. We may choose to trust someone else to help us make those approval decisions, but we should never be locked into that relationship by force of technological restriction or law. Software that enforces such restrictions is malware. Companies like Microsoft that push these restrictions also have a terrible track record when it comes to security, which makes their platitudes about restricting us for our own good both hollow and deceitful.

The GNU General Public License (GPLv3) shields our freedom against such restrictions. When you buy or rent a computer containing GPLv3-covered software, the license protects your freedom to use modified versions of that software in your computer. GPLv2 always required that users be able to do this, but one of the improvements in GPLv3 ensures that the freedoms all GPL versions are meant to provide can't be taken away by hardware that refuses to run modified software.

When it comes to security measures governing a computer's boot process, GPLv3's terms lead to one simple requirement: Provide clear instructions and functionality for users to disable or fully modify any boot restrictions, so that they will be able to install and run a modified version of any GPLv3-covered software on the system.

Secure Boot is one such measure, defined by a UEFI standard, but discussion about it has primarily revolved around the rules established by Microsoft in its Windows 8 Logo program. These rules say what computer distributors have to do in order to have their systems be Microsoft-approved. Part of this includes implementing Secure Boot in specific ways.

In order to comply with Microsoft's rules as currently published, distributors of x86 computers will have to provide users both the option to customize Secure Boot by using their own security keys, and the option to disable it completely.

Secure Boot, done right, embodies the free software view of security, because it puts users -- whether individuals, government agencies, or organizations -- in control of their machines. Our thought experiment to demonstrate this is simple: Microsoft may be worried about malware written to take over Windows machines, but we view Windows itself as malware and want to keep it away from our machines. Does Secure Boot enable us to keep Windows from booting on a machine? It does: We can remove Microsoft's key from the boot firmware, and add our own key or other keys belonging to free software developers whose software we wish to trust.
So what's the problem?

In theory, there should be no problem. In practice, the situation is more complicated. As currently proposed, Secure Boot impedes free software adoption. It is already bad enough that nearly all computers sold come with Microsoft Windows pre-installed. In order to convince users to try free software, we must convince them to remove the operating system that came on their computers (or to divide their hard drives and make room for a new system, perceptually risking their data in the process).

With Secure Boot, new free software users must take an additional step to install free software operating systems. Because these operating systems do not have keys stored in every computer's firmware by default like Microsoft does, users will have to disable Secure Boot before booting the new system's installer. Proprietary software companies may present this requirement under the guise of "disable security on your computer," which will mislead new users into thinking free software is insecure.

Without a doubt, this is an obstacle we don't need right now, and it is highly questionable that the security gains realized from Secure Boot outweigh the difficulties it will cause in practice for users trying to actually provide for their own security by escaping Microsoft Windows.

It's also a problem because the Windows 8 Logo program currently mandates Restricted Boot on all ARM systems, which includes popular computer types like tablets and phones. It says that users must not be able to disable the boot restrictions or use their own signing keys. In addition to being unacceptable in its own right, this requirement was a reversal from Microsoft's initial public position, which claimed that the Windows 8 program would not block other operating systems from being installed. With this deception, Microsoft has demonstrated that they can't be trusted. While we are interpreting their current guidelines, we must keep in mind that they could change their mind again in the future and expand the ARM restrictions to more kinds of systems.

The best way out of all of this (other than having all computers come pre-installed with free software) would be for free software operating systems to also be installable by default on any computer, without needing to disable Secure Boot. In the last few weeks, we've seen two major GNU/Linux distributions, Fedora and Ubuntu, sketch out two different paths in an attempt to achieve this goal.
Fedora's approach

Fedora's default approach to official distribution has the project joining a Microsoft and Verisign developer program which will give them a key that can then be used to sign a "shim" bootloader. This shim loads GRUB 2, the GPLv3-covered GNU program whose job it is to boot the operating system kernel, in this case Linux. Because Fedora's key will be "vouched" by Microsoft, it will be recognized by the firmware on the vast majority of desktops and laptops available.

Fedora also suggests that others use this option for unofficial distribution of modified Fedora software, or any other free software operating system. Anyone can pay $99 and get their own Microsoft-backed key which they can then use to sign the software they wish to run and/or share.

Fedora is not requiring users to join the Microsoft program. Users can also create and use their own keys, with a little more work. The Microsoft program is the route they chose for official Fedora distributions, but they will also provide utilities and support for users wishing to work with their own self-generated keys.

There is much to like about Fedora's thinking, as explained by Matthew Garrett. Their process of deliberation evinced concern for user freedom; it's clear that the Fedora team sought a solution that would work not just for their own GNU/Linux distribution, but for as many free software users and distributions as possible. Their discussion was also mindful of the desirability of empowering users to sign and run their own modified software without being treated as second-class citizens. Unsurprisingly, with those concerns guiding their thinking, they have ended on a proposal which as described is compliant with GPLv3.

Unfortunately, while it is compliant with the license of GRUB 2 and any other GPLv3-covered software, we see two serious problems with the Microsoft program approach.

1) Users wishing to run in a Secure Boot environment will have to trust Microsoft in order to boot official Fedora. The Secure Boot signing format currently allows only one signature on a binary -- so Fedora's shim bootloader can be signed only by the Microsoft-vouched key. If a user removes Microsoft's key, official Fedora will no longer boot, as long as Secure Boot is on.

2) We reject the recommendation that others join the Microsoft developer program. In addition to the $99 expense being a barrier for many people around the world, the process for joining this program is objectionable. A nonexhaustive list of the problems includes: restrictive terms in multiple of the half-dozen contracts that must be signed, a forced commitment "to receive targeted advertisements and periodic member email messages from Microsoft," and a requirement to provide notarized proof of government-issued identification and a credit card.

These are not acceptable conditions for modifying or using your operating system. For the time being, we should instead rely on the approach Fedora will support for unofficial distribution -- providing tools and materials for users who want to install and use their own keys.

Software signed with self-generated keys has the downside of not working on the majority of computers right off the shelf, without the user taking some extra steps. We acknowledge that this is an issue, but in addition to insisting on (and contributing to) documentation to make the necessary process easy to follow, we will strive to solve this problem through political action against manufacturers and proprietary software companies who impede free software adoption. Encouraging free software distributors and users to trust Microsoft or any other proprietary software company as a precondition to exercising their freedoms is simply not an acceptable solution.
Ubuntu's approach

Ubuntu has also announced a plan which is further described in a message to the Ubuntu developers' mailing list. Their plan addresses software distributed through three different channels:

1) Machines sold as "Ubuntu Certified," preinstalled with Ubuntu, will have an Ubuntu-specific key, generated by Canonical, in their firmware. Additionally, they will be required by the certification guidelines to have the Microsoft key installed.

2) Ubuntu CDs, distributed separately from hardware, will also depend on the presence of Microsoft's key in the machine's firmware to boot, when Secure Boot is active.

3) Ubuntu bootloader images distributed online from the official Ubuntu archive will be signed by Ubuntu's own key.

In the first two situations, because of the requirement to have the Microsoft key, their approach has the same issue as Fedora's official method. Users have to trust Microsoft in order to boot official Ubuntu CDs. Their certification program amplifies this problem, because it means no one can sell certified Ubuntu machines without trusting Microsoft.

As with Fedora, on a system with Secure Boot properly implemented, Ubuntu users will be able to add their own keys, or Ubuntu's key.

Our main concern with the Ubuntu plan is that because they are afraid of falling out of compliance with GPLv3, they plan to drop GRUB 2 on Secure Boot systems, in favor of another bootloader with a different license that lacks GPLv3's protections for user freedom. Their stated concern is that someone might ship an Ubuntu Certified machine with Restricted Boot (where the user cannot disable it). In order to comply with GPLv3, Ubuntu thinks it would then have to divulge its private key so that users could sign and install modified software on the restricted system.

This fear is unfounded and based on a misunderstanding of GPLv3. We have not been able to come up with any scenario where Ubuntu would be forced to divulge a private signing key because a third-party computer manufacturer or distributor shipped Ubuntu on a Restricted Boot machine. In such situations, the computer distributor -- not Canonical or Ubuntu -- would be the one responsible for providing the information necessary for users to run modified versions of the software.

Furthermore, addressing the threat of Restricted Boot by weakening the license of the bootloader is backwards. With a weaker license, companies will now have a form of advance permission to obstruct the user's ability to run modified software. Rather than work to make sure this situation does not happen -- for example by enforcing the proper Secure Boot implementation they say they "strongly support in [their] own firmware guidelines" -- Ubuntu has chosen a path which explicitly allows Restricted Boot.

No representative from Canonical contacted the FSF about these issues prior to announcing the policy. This is unfortunate because the FSF, in addition to being the primary interpreter of the license in question, is the copyright holder of GRUB 2, the main piece of GPLv3-covered software at issue.

It is not too late to change. We urge Ubuntu and Canonical to reverse this decision, and we offer our help in working through any licensing concerns. We also hope that Ubuntu, like Fedora, will actively support users generating and using their own signing keys to run and share any versions of the software, and not require users to install a key from Canonical to get the full benefit of their operating system.
What's the FSF doing to help solve these problems?

Secure Boot raises many issues for protecting user freedom, promoting free software ideals, and encouraging free software adoption. Addressing it requires a multifaceted approach. Assessing the solutions popular GNU/Linux distributions have proposed is one aspect, but we will also take proactive measures of our own.


We will continue to build public support around our statement against Restricted Boot. Over 31,000 people and 25 organizations have signed this statement, pledging not to buy any computer that they cannot install a free operating system on, and to advise others to do the same. We were pleased last week to add Debian GNU/Linux as an official organizational supporter of the statement. Subsequently, Trisquel and gNewSense have also added their signatures. When further actions need to be taken to stand up for this freedom as Secure Boot and Restricted Boot are rolled out, we will call upon this base of support. If you haven't yet signed, please do.


We will fight Microsoft's attempt at enforcing Restricted Boot on ARM devices like smartphones and tablets. Like any other computer, users must be able to install free software operating systems on these devices. We will monitor Microsoft's behavior to make sure they do not deceive the public again by expanding these restrictions to other kinds of systems.


We will work with (and when necessary, pressure) manufacturers and distributors to make the user instructions for working with Secure Boot on all systems extremely clear, so that users will be able to disable it and modify the approved keys with little difficulty and no bias. We will also work to make sure that users can change all of the software running on their machine, including the boot firmware itself.


We will offer our licensing and compliance resources to any free software developers to help them make sure they are complying with the GPL and other licenses as they implement Secure Boot. We will monitor distributions of signed GPLv3 software to ensure that they respect the necessary user freedoms, including providing installation instructions and materials.


We have already started exploring ways in which the FSF can work with manufacturers on behalf of the entire free software community to make free software operating systems installable with default Secure Boot hardware settings.


We will continue to work with companies like Lemote, Freedom Included, ZaReason, ThinkPenguin, Los Alamos Computers, Garlach44, and InaTux to make computers available that are preinstalled with fully free GNU/Linux distributions.


We will help provide information about which computers and components are most compatible with free software, including making people aware of which machines have Restricted Boot. Much of this information will be found at http://h-node.org.
Conclusion and recommendations

What we've offered here is our position based on the details published by all parties involved so far -- we will continue to assess the situation as these plans are actually put into practice, or changes are announced.

Our focus is to evaluate proposed solutions to the issues posed by Secure Boot on the basis of how well they protect user freedom, to recommend the solutions that do the best job of that, and to stop attempts to turn Secure Boot into Restricted Boot.

The best solution currently available for operating system distributions includes:

1) fully supporting user-generated keys, including providing tools and full documentation for booting and installing both modified and official versions of the distribution using this method;

2) using a GPLv3-covered bootloader to help protect users against the dangers of Restricted Boot;

3) avoiding requiring or encouraging users to trust Microsoft or any company which makes proprietary software; and

4) joining the FSF and the broader free software movement in pressuring computer distributors to facilitate easy and independent installation of free software operating systems on any computer.

We will do what we can to help all free software operating system distributions follow this path, and we will work on a political level to reduce the practical difficulties that adhering to these principles might pose for expedient installation of free software. The FSF does want everyone to be able to easily install a free operating system -- our ultimate goal is for everyone to do so, and the experience of trying out free software is a powerful way to communicate the importance of free software ideals to new people. But we cannot in the name of expediency or simplicity accept systems that direct users to put their trust in entities whose goal it is to extinguish free software. If that's the tradeoff, we better just turn Secure Boot off.

Please support the FSF's work in this area by joining as a member or making a one-time donation.

20120703

Top EU court upholds right to resell downloaded software

First-sale rights stronger in the EU than in the US.

by Timothy B. Lee

The European Court of Justice has ruled that customers have a right to resell software they purchase regardless of whether the software was originally distributed on a physical medium or downloaded over the Internet. The ruling is a defeat for Oracle, which had argued that the court should uphold provisions in its license agreement prohibiting such transfers.

Software vendors have long argued that software is "licensed, not sold." This claim is in tension with the doctrine of copyright exhaustion (called the first sale doctrine in the United States), which holds that copyright law does not give rightsholders control over used copies of their work. And the principle has gotten even more murky as software is increasingly distributed directly over digital networks, meaning that there's no physical copy of the work to resell.

Oracle distributes its software online. Once a customer has signed a licensing agreement, they have an unlimited right to download copies of the database software from Oracle's website, and to install as many copies of the software as specified in the licensing agreement. A company called UsedSoft acted as a broker for used Oracle licenses, allowing Oracle customers who no longer need their licenses to resell them to another firm that could put them to better use.

Oracle sued UsedSoft, arguing that UsedSoft was merely facilitating piracy of its software. The database giant noted that its license agreements specifically state that licenses are nontransferable. And it argued that the exhaustion doctrine only applied to physical copies, like CDs or DVDs, not to copies downloaded from a website.

On Wednesday, the European Court of Justice, the EU's highest court, decisively rejected Oracle's arguments.

"It makes no difference whether the copy of the computer program was made available by means of a download from the rightholder’s website or by means of a material medium such as a CD-ROM or DVD," the court ruled. "Even if the rightholder formally separates the customer’s right to use the copy of the program supplied from the operation of transferring the copy of the program to the customer on a material medium, the operation of downloading from that medium a copy of the computer program and that of concluding a license agreement remain inseparable from the point of view of the acquirer."

The court noted that if it accepted Oracle's argument, then "suppliers would merely have to call the contract a ‘license’ rather than a ‘sale’ in order to circumvent the rule of exhaustion and divest it of all scope."

"From an economic point of view, the sale of a computer program on CD-ROM or DVD and the sale of a program by downloading from the internet are similar," the court ruled. "The on-line transmission method is the functional equivalent of the supply of a material medium."

The court also rejected Oracle's contention that even if the original software license was transferable, the new owner was not entitled to use the free updates Oracle supplied with the software.

But the court did place some important limits on customers' rights to resell used software licenses. First, if a customer purchases a multiseat license, it is not allowed to split the license up into parts and sell them separately.

The court also held that after reselling the software, the previous owner must render his own copy of the software inoperable. Oracle had argued that this would be impossible to enforce in practice. But the court noted that this difficulty isn't unique to online software sales—the same problem arises when a customer resells a CD or DVD after using it to install software on his own computer.

European software purchasers now enjoy substantially stronger first-sale rights than their American counterparts. While the United States Court of Appeals for the Ninth Circuit has upheld the right to resell used CDs, the same court has been more deferential to software vendors, ruling that no-resale clauses in licensing agreements are enforceable. And since software companies invariably insert such clauses into their EULAs, the Ninth Circuit's ruling places used software sales under a legal cloud.

20120701

EU Weighs in on Privacy in Face Recognition Apps

Photo Tag Suggest, Tag My Face, Klik, FaceLook, Age Meter, FaceLock, and Visidon AppLock—the list grows by the day. These recent online and mobile applications apply face recognition technology to photos of individuals to identify or categorize them or to verify their identities. While often fun and convenient for users, these applications also raise privacy concerns for the individuals whose data is collected and used in the process. Face recognition in online applications is particularly problematic as personal data in these applications is sometimes used out of context by employers and law enforcement. Therefore, European privacy officials’ opinion recommending various privacy practices for these applications could not have come at a better time.

Last summer, the Article 29 Working Party—an advisory body formed under the EU Data Protection Directive—initiated an investigation into this issue in response to Facebook’s European launch of its face recognition technology. Given the many new face recognition applications subsequently launched, the opinion wisely does not focus on Facebook and instead provides general recommendations on how the EU Data Protection Directive applies to automatic face recognition in online and mobile applications.

The Directive requires EU countries to adopt privacy protections for the automatic processing of personal data, which according to the opinion includes both photos from which individuals can be identified and the measurements of their facial features. As face recognition technology automatically processes photos and measurements to identify or categorize individuals, it is subject to the Directive. A provider using automatic face recognition in its online service or mobile application must therefore notify the individuals that they will be identified with this technology and seek their permission.

The opinion clarifies that “informed consent” cannot be obtained simply by providing opt-out settings, although those settings are still important to ensure that individuals can easily retract their consent. Terms and conditions that discuss the face recognition process are also insufficient except if the main purpose of the application is face recognition. But a face recognition app may still need to get specific permission from the individuals in the photos if it uses photos or facial measurements from another application, such as a general-purpose social network. Notably, a person cannot consent to face recognition by simply uploading a photo to an application because the person may not anticipate that the photo will be used for this purpose and the photo could contain personal data of other individuals.

But the opinion also recognizes that strictly requiring informed consent would downright prohibit many novel uses of the technology. For example, a social network provider may not know whether an individual in a photo has consented to the automatic recognition until it identifies her. In that situation, the provider may initially process the photo to determine whether the individual has consented, but must delete all the resulting data if it turns out that there was no consent from that individual. The provider may also have to encrypt its data if that is necessary for its security.

While clarifying how the Directive applies to the novel uses of face recognition in online and mobile applications, the opinion seeks to provide some flexibility to avoid banning certain applications. As it does not focus on any particular application, it may potentially also provide guidance for future innovation in this area. Stay tuned as EFF continues covering this issue!

20120626

Netflix may have to provide closed captions online

Bob Egelko

A federal judge has taken a step toward requiring Netflix to provide closed-captioning for the deaf on its video-streaming website, ruling that federal disability laws cover businesses that serve their customers online.

Netflix, headquartered in Los Gatos, is the dominant provider of movies and TV programs on the Internet, with more than 20 million subscribers. The National Association for the Deaf accused the company of violating the law by withholding closed-captioning from most of the videos on its "Watch Instantly" on-demand website.

Netflix sought to dismiss the suit, arguing that the Americans with Disabilities Act requires accommodations for the disabled only in stores and other physical structures - an argument accepted in the past by some courts, including the Ninth U.S. Circuit Court of Appeals in San Francisco.

On Tuesday, however, U.S. District Judge Michael Ponsor of Springfield, Mass., said the law prohibits discrimination in any venue, including the Internet.

The legislative history of the 1990 law "makes clear that Congress intended the ADA to adapt to changes in technology," Ponsor said. "In a society in which business is increasingly conducted online," he said, the law's goal of equal access would be frustrated by "excluding businesses that sell services through the Internet."

The ruling allows the suit to proceed on behalf of groups representing the deaf and hard-of-hearing, who still must prove that the ADA requires Netflix to provide closed-captioning. Their advocates nonetheless called it a significant victory.

"By recognizing that websites are covered by the ADA, the court has ensured that the ADA stays relevant as much of our society moves from Main Street to the Internet," said Arlene Mayerson of the Disability Rights Education and Defense Fund in Berkeley, a lawyer for the plaintiffs.

Netflix could appeal the ruling to a federal appeals court in Boston. Spokesman Joris Evers said the company had no comment.

A 1996 federal law required closed-captioning for television programs but did not address online videos. Federal Communication Commission regulations will require captioning on Internet videos of all U.S.-produced, post-1996 programs by March 2014.

Netflix argued that the FCC rules took precedence over the more generally worded Americans with Disabilities Act. But Ponsor said that the FCC's timeline "reflects only minimum compliance standards" and that a court could invoke the ADA to order closed captioning at an earlier date on all videos.

Supreme Court 'papers please' ruling hits Arizona H-1B workers

Immigration attorneys advise holders of H-1B visas to carry paperwork at all times in Arizona

By Patrick Thibodeau

Computerworld - WASHINGTON -- Monday's U.S. Supreme Court decision that allows Arizona police to check peoples' immigration status means that H-1B workers in the state should have their visa documents available at all times, immigration attorneys say.

The court struck down several parts of Arizona's immigration law but nonetheless left in place a core provision -- the so-called "show me your papers" clause -- that allows police officers to check the immigration status of people in the state at specific times.

If police stop or arrest someone that they also suspect may be an illegal immigrant, they can under the law check that person's immigration status, the court ruled.

The Supreme Court ruled that police can't simply stop an individual and ask for his immigration papers simply because of his race, color or national origin.

However, a traffic stop, for instance, could be the trigger for an inquiry.

How complicated this gets may depend on the training of the police officer on the scene, his knowledge of work visas, and whether an H-1B worker in the state has an Arizona driver's license.

An Arizona state driver's license provides the presumption of legal residency.

Nonetheless, H-1B workers carrying the proper documents might face difficulties because of the immigration law, potentially experiencing delays or even detention, especially if they're dealing with officers and departments that are unfamiliar with immigration documentation, say attorneys.

It's believed that most H-1B workers do not routinely carry visa paperwork at all times because they're concerned that it could be lost. It can take months to replace lost documents, immigration attorneys noted.

Michael Wildes, managing partner at Wildes & Weinberg, an immigration law firm in New York, says his firm is advising clients -- "especially those in the Arizona corridor of the nation" -- to carry proper documentation of their legal status.

Wildes & Weinberg has always recommended that people from other countries make a habit of carrying the proper paperwork, but he said "it's particularly crucial" to do so in light of the recent Supreme Court ruling.

Foreign workers should always carry their visas and passports, their I-797 approval forms, and their I-94 arrival-departure records, said Wildes.

The practical advice for work visa holders as a result of this decision is to carry documentation, said Marko Maglich, an immigration attorney at White & Case in New York. H-1B workers who haven't been in the habit of carrying their documents "better do it now," he said.

It's uncertain how this law will play out in the state over the long term.

If an H-1B worker who carries, say, a California driver's license is pulled over in Arizona, there's no presumption of legal status -- that is only conferred by an Arizona driver's license, said Jorge Lopez, an attorney in the Miami office of Littler Mendelson who co-chairs the law firm's immigration and global migration practice group.

Lopez said visa holders should at least carry copies of their pertinent documents.

Eleanor Pelta, the president of the American Immigration Lawyers Association, said temporary visa holders are not required to carry their documents in Arizona, but they "may feel more comfortable carrying paperwork showing their legal status" because of the ruling.

The Supreme Court's decision "leaves a door open to challenge the 'show me your papers' provision as applied in a particular instance," said Pelta, an immigration attorney in the Washington office of Morgan, Lewis & Bockius. "It is possible that [the law] may still be challenged and struck down in another suit."

Court: No automatic life without parole for juveniles

By Raju Chebium

WASHINGTON - Juveniles convicted of murder can't be automatically sentenced to life in prison without parole, a divided U.S. Supreme Court ruled Monday.

The nation's highest court has previously invoked the Eighth Amendment in banning the death penalty for juveniles.

The 5-4 ruling, involving two 14-year-olds convicted in separate robberies in Alabama and Arkansas, struck down 29 state laws that impose mandatory life-without-parole sentences on juvenile murder defendants.

Forcing judges and juries to give life without parole, regardless of mitigating circumstances, violates Supreme Court rulings requiring "individualized sentencing for defendants facing the most serious penalties," Justice Elena Kagan wrote for the majority.

"We therefore hold that mandatory life without parole for those under the age of 18 at the time of their crimes violates the Eighth Amendment's prohibition on 'cruel and unusual punishments,' " she wrote.

The court didn't issue a blanket ban on life without parole for juvenile murder defendants. Judges and juries can still impose that sentence as long as all factors such as the juvenile's upbringing are taken into account, although the ruling would make such sentences extremely rare.

The nation's highest court has invoked the Eighth Amendment in banning the death penalty for juveniles. Also banned are life-without-parole terms for juveniles who commit crimes other than murder. Now juveniles convicted of murder are also included under the Eighth Amendment umbrella, though the court didn't shut the door entirely on that sentence.

Joining Kagan in the majority were Justices Stephen Breyer, Anthony Kennedy, Sonia Sotomayor and Ruth Bader Ginsburg.

The dissenters were Chief Justice John Roberts and Justices Antonin Scalia, Samuel Alito and Clarence Thomas, who argued that it's not the court's job to decide the appropriate punishment for juveniles convicted of murder.

"Neither the text of the Constitution nor our precedent prohibits legislatures from requiring that juvenile murderers be sentenced to life without parole," Roberts wrote in the dissenting opinion.

Evan Miller of Alabama was 14 when he and an accomplice robbed a neighbor, bludgeoned him with a baseball bat and burned his trailer in 2003. A Lawrence County, Ala., jury convicted him of murder for killing Cole Cannon, 52.

In the Arkansas case, Kuntrell Jackson was 14 when he took part in a 1999 video-store robbery in which the clerk was shot and killed by someone else.

Equal Justice Initiative, a Montgomery legal-rights group that represented Miller and Jackson, lauded the ruling as "an important win for children."

"The court took a significant step forward by recognizing the fundamental unfairness of mandatory death-in-prison sentences that don't allow sentencers to consider the unique status of children and their potential for change," said Bryan Stevenson, executive director of the Equal Justice Initiative.

About 2,500 prisoners nationwide are serving life-without-parole sentences for murders committed before they turned 18, according to Roberts. A majority of them are serving mandatory life terms with no chance of getting out of prison. Some or all of them may ask to be sentenced again.

Alabama Solicitor General John Neiman said the ruling clearly requires states to revise sentencing guidelines for juveniles who commit murder if life without parole is the only punishment allowed.

In light of the ruling, Miller and Jackson will seek to be sentenced again. But it's unclear if the ruling applies to others convicted of murder as juveniles who are serving mandatory life-without-parole sentences, Neiman cautioned.

"The actual impact of the decision in terms of practical reality is going to be a question that's going to be litigated," he said. "The opinion did not define … whether this new rule of sentencing, under the Constitution, will apply to defendants whose convictions are already final."

Stand Up for Owners' Rights

If you buy something, you can do with it—and do away with it—as you want. Right? The digital age is challenging this most basic of expectations in a few ways, and EFF and its allies are on the lookout. The Supreme Court will soon review a court decision that, if upheld, could put handcuffs on our ability to sell digital goods, or even physical goods with copyrighted logos or artwork, simply because the goods were manufactured outside the U.S. This case is important, but its also just a small piece of a larger assault on ownership rights. Over the past decade, courts and copyright owners have quietly been creating a world in which digital goods are never truly owned, but only licensed. And those licenses inevitably contain a plethora of legal restrictions on your ability to fully use the goods you "buy."

EFF has signed on to the Citizens' Petition for Ownership Rights, urging the U.S. government and the courts to protect our basic assumption that if you buy it, you own it, and can dispose of it as you please. You, too, can sign.

The petition was prompted by Kirtsaeng v. John Wiley & Sons, which is on its way to the Supreme Court. As we explained earlier this year, Kirtsaeng is a challenge to the "first sale" doctrine of copyright law. First sale says that once a given copy of a copyrighted work has been sold or given away, the copyright owner has no more legal control over that copy. That means the copyright owner can't ban resale, set a minimum resale price, or prohibit tinkering and modification. First sale is what makes used bookstores, libraries and video rentals possible.

In Kirtsaeng, the U.S. Court of Appeals for the Second Circuit said that first sale doesn't apply to copies made outside the United States, even if they were sold or given away legally and then imported into the U.S. Effectively, copies manufactured abroad—whether books, software, or physical goods with copyrighted labels or logos on them—could never be fully owned in the U.S. You could buy these goods, but you could never sell them or give them away without permission. Strange result, right? First sale is part of our intuitive understanding of what it means to buy and own something. If you've paid good money for a book, or a DVD, or whatever, or received it as a gift, it's fundamentally weird to be told that you can't lend it, or resell it as used, or give it away.

This decision gives copyright owners the ability to shut off markets for used copies, just by moving physical manufacturing abroad. It would also give manufacturers an incentive to move jobs out of the U.S. to create these legally handcuffed, non-resellable goods.

The defendant (and EFF) asked the Supreme Court to review the case, and the Court agreed. Now, we are asking the Obama administration to weigh in and protect the common-sense understanding of what it means to own something.

Kirtsaeng is not the only threat to owners' rights, though. Sellers of digital goods like software, e-books, movies, and music often try to opt out of the first sale doctrine using contracts - the shrink-wrap, clickwrap, and other forms of fine print agreements that we're inevitably presented with (and seldom read) whenever we buy digital goods. Often, those agreements say something like "this digital widget is licensed to you, not sold." The implication is that because the copyright owner hasn't "sold" you a copy, you can't lend it, or resell it, or give it away. Worse yet, you can't tinker with or modify it. Never mind that you paid for a permanent copy and the seller doesn't really expect that you'll ever give it back - the fine print claims to transform a sale into something else.

Unfortunately, several courts have ruled that this trick works. In Vernor v. Autodesk, Inc., the Ninth Circuit appeals court ruled that software licenses that "significantly restrict the user’s ability to transfer the software" and "impose notable use restrictions" turn what looks and feels like a purchase into something less.

Let's tell the courts and Congress that if it looks like a sale and feels like a sale, it's a sale. Let's sign the Citizens' Petition for Ownership Rights, to tell the Obama administration and the Attorney General to stand up for first sale at the Supreme Court. And beyond that, digital goods providers should not be able to opt out of first sale using magic words in the fine print of user agreements. Watch this space for more info on ownership rights and how you can help defend them!

20120625

How American fundamentalist schools are using Nessie to disprove evolution

Rachel Loxton

IT sounds like a plot dreamed up by the creators of Southpark, but it's all true: schoolchildren in Louisiana are to be taught that the Loch Ness monster is real in a bid by religious educators to disprove Darwin's theory of evolution.

Thousands of children in the southern state will receive publicly-funded vouchers for the next school year to attend private schools where Scotland's most famous mythological beast will be taught as a real living creature.

These private schools follow a fundamentalist curriculum including the Accelerated Christian Education (ACE) programme to teach controversial religious beliefs aimed at disproving evolution and proving creationism.

One tenet has it that if it can be proved that dinosaurs walked the earth at the same time as man then Darwinism is fatally flawed.

Critics have damned the content of the course books, calling them "bizarre" and accusing them of promoting radical religious and political ideologies.

The textbooks in the series are alleged to teach young earth creationism; are hostile towards other religions and other sectors of Christianity, including Roman Catholicism; and present a biased version of history that is often factually incorrect.

One ACE textbook – Biology 1099, Accelerated Christian Education Inc – reads: "Are dinosaurs alive today? Scientists are becoming more convinced of their existence. Have you heard of the 'Loch Ness Monster' in Scotland? 'Nessie' for short has been recorded on sonar from a small submarine, described by eyewitnesses, and photographed by others. Nessie appears to be a plesiosaur."

Another claim taught is that a Japanese whaling boat once caught a dinosaur. It's unclear if the movie Godzilla was the inspiration for this lesson.

Jonny Scaramanga, 27, who went through the ACE programme as a child, but now campaigns against Christian fundamentalism, said the Nessie claim was presented as "evidence that evolution couldn't have happened. The reason for that is they're saying if Noah's flood only happened 4000 years ago, which they believe literally happened, then possibly a sea monster survived.

"If it was millions of years ago then that would be ridiculous. That's their logic. It's a common thing among creationists to believe in sea monsters."

Private religious schools, including the Eternity Christian Academy in Westlake, Louisiana, which follows the ACE curriculum, have already been cleared to receive the state voucher money transferred from public school funding, thanks to a bill pushed through by state Governor Bobby Jindal.

Boston-based researcher and writer Bruce Wilson, who specialises in the American political religious right, compares the curriculum to Islamic fundamentalist teaching.

"They are being brought up to believe that they're at war with secular society. The only valid government would be a Christian fundamentalist government. Obviously some comparisons could be made to Islamic Fundamentalists in schools.

"One of these texts from Bob Jones University Press claims that dinosaurs were fire-breathing dragons. It has little to do with science as we currently understand. It's more like medieval scholasticism."

Wilson believes that such teaching is going on in at least 13 American states.

"There's a lot of public funding going to private schools, probably around 200,000 pupils are receiving this education," he And the majority of parents now home schooling their kids are Christian fundamentalists too. I don't believe they should be publicly funded, I don't believe the schools who use these texts should be publicly funded."

Daniel Govender, managing director of Christian Education Europe, which is part of ACE, said the organisation would not comment to the press on what is contained in the texts.

Of course, the Scottish tourist industry might well reap a dividend from the craziness of the American education system. Nessie expert Tony Drummond, who leads tours as part of Cruise Loch Ness, has a few words of advice to the US schools in question: come to the loch and try to find the monster.

"They need to come and investigate the loch for themselves," says the 47-year-old. "We've got some hi-tech equipment. They could come out on the boat and do a whole chunk of the loch.

"We do get regular sonar contacts which are pretty much unexplainable. More research has to be done, but it's not way along the realms of possibility."

But he's not convinced that the legend of the Loch Ness Monster is being taught the right way. "That's Christian propaganda," he says. "And ridiculous."

Textbooks of some state-funded Christian schools praise the Ku Klux Klan.

The violent, racist organisation, which still exists in the US, advocates white supremacy, white nationalism and anti-immigration.

One excerpt from Bob Jones University Press American history textbook has been reported as saying: "the [Ku Klux] Klan in some areas of the country tried to be a means of reform, fighting the decline in morality and using the symbol of the cross ... In some communities it achieved a certain respectability as it worked with politicians."

Other views taught include claims that being gay is a learned behaviour.

It isn't just America where the bizarre Christian Nessie myth is being taught as a reality. The UK has similar religious schools but they do not receive cash from the state. Nevertheless, the Evangelical Christian curriculum they follow has been approved by UK Government agency, the National Recognition Information Centre (Naric) which guides universities and employers on the validity of different qualifications.

Naric judged the International Certificate of Christian Education (ICCE) as officially comparable to qualifications offered by the Cambridge International exam board.

It is estimated around 2000 pupils study at more than 50 private Christian schools in Britain for the certificates as well as several home-educated students.

The courses are based around the Accelerated Christian Education (ACE) programme, which originated in Texas in the 1970s.

Pupils study a range of subjects, including science and English, but spend half their studies learning from Bible-influenced US textbooks.

It costs just $1.36 to charge an iPad for a year

The annual charging cost of an iPad is just $1.36, according to the Electric Power Research Institute. The group, known as EPRI, saw Apple Inc.'s big iPad sales numbers and decided to study the tablet computer's power use to determine what effect the devices might have on the nation's electricity consumption. / Lai Seng Sin

Written by Jonathan Fahey

NEW YORK — That coffee you're drinking while gazing at your iPad? It cost more than all the electricity needed to run those games, emails, videos and news stories for a year.

The annual cost to charge an iPad is just $1.36, according to the Electric Power Research Institute, a non-profit research and development group funded by electric utilities.

By comparison, a 60-watt compact fluorescent bulb costs $1.61, a desktop PC adds up to $28.21 and a refrigerator runs you $65.72.

The group, known as EPRI, studied the power consumption of Apple Inc.'s iPad to determine the effect that the newly popular devices might have on the nation's electricity use.

The answer: not much.

If the number of iPads triples from the current 67 million, they would need the electricity from one small power plant operating at full strength.

But if people are using iPads instead of televisions to play video games, or ditching their desktop computers for iPads, the shift to tablets could mean lower overall power consumption. A desktop computer uses 20 times more power than an iPad.

Baskar Vairmohan, the EPRI researcher who conducted the iPad test, said the group is now studying usage to understand whether the explosion of tablets is adding to power consumption, or reducing it.

Residential power demand is on track to fall for the third straight year, according to the government. A weak economy is keeping people in smaller houses and shacked up with others. At the same time, efficiency programs are pushing more efficient light bulbs, air conditioners and other devices into homes. Refrigerators use a quarter of the power they used a generation ago, according to EPRI.

For the iPad test, Vairmohan measured the amount of power used to charge up an iPad with a drained battery. He assumed that users would charge up every other day. Over a year, the latest version of the iPad consumed 11.86 kilowatt-hours of electricity. (Older versions consume somewhat less power.)

The juice would cost $1.36 at the U.S. average residential price of 11.49 cents per kilowatt-hour.

But there's an even cheaper way to go than the iPad. EPRI calculated the cost of power needed to fuel an iPhone 4 for year: just 38 cents.

20120624

Richard O'Dwyer and the new internet war

Join my petition to defend TVShack entrepreneur Richard O'Dwyer's battle against extradition

By Jimmy Wales


British student Richard O'Dwyer with his mother Julia leaving Westminster magistrates court in London on January 13, 2012.

I think that copyright matters, and is important. Creators ought to be legally able to give their work away freely, as so many do for the betterment of humankind, and to set certain conditions on how their work is used. And I think creators ought to be able to release their work under traditional copyright and have legal recourse against those who are illegally profiting from it.

It's important to say this up front, because much of what you will hear about the case of Richard O'Dwyer will be misleading propaganda designed to persuade you that people who defend him are defending copyright violation or "piracy". At least in my case, nothing could be further from the truth.

O'Dwyer created a website, called tvshack.net, that acted as a search engine for people to find out where they could watch and in some cases download popular TV shows, typically programmes not yet available outside the US. Some of the links led to legal sources, others to unauthorised sites. In that respect his site was no different from hundreds of thousands of services where the general public gathers to talk.

O'Dwyer respected the rules – deleting content when he received properly formatted take-down notifications. Given the state of US internet law, it is extremely difficult to see how he can be convicted of copyright violation. But that is what he is now threatened with, a conviction that could carry a sentence of 10 years in a US prison, after the British home secretary, Theresa May, signed an extradition order in March.

US authorities claim that O'Dwyer illegally made around £147,000 from advertising displayed on the site over three years. His lawyers contend that linking to other content is not illegal under UK law, and point out that Britain's Crown Prosecution Service did not pursue charges against him.

Copyright is an important institution, serving a beneficial moral and economic purpose. But that does not mean it can or should be unlimited. It does not mean that we should abandon time-honoured moral and legal principles to allow endless encroachments on our civil liberties in the interests of the moguls of Hollywood.

One of the important moral principles that has made everything we relish about the internet possible, from Wikipedia to YouTube, is that internet service providers need to have a safe harbour from what their users do. There are and should be some limits to this. Under US copyright law, there are notice and take-down provisions requiring service providers to remove content under a properly formatted notification. And there is a distinction between hosting copyrighted material and telling people where it is. The latter is protected under the first amendment.

When I met Richard (along with his mother), he struck me as a clean-cut, geeky kid. Still a university student, he is precisely the kind of person one can imagine launching the next big thing on the internet. Enthusiastic, with a sharp mind and a quick wit, he reminds me of many great entrepreneurs. He tried to follow the law, and I would argue that he very likely succeeded in doing so.

Given the thin case against him, it is an outrage that he is being extradited to the US to face felony charges. No US citizen has ever been brought to the UK for alleged criminal activity on US soil. There is a disparity here that ought to raise concerns at the highest levels of government in both the US and UK.

From the beginning of the internet, we have seen a struggle between the interests of the "content industry" and the general public. Due to heavy lobbying and much money lavished on politicians, until very recently the content industry has won every battle. Internet users handed the industry its first major defeat earlier this year with the epic Sopa-Pipa protests over planned copyright laws that culminated in a widespread internet blackout and 10 million people contacting the US Congress to voice their opposition.

O'Dwyer is the human face of that battle, and if he's extradited and convicted, he will bear the human cost. That's why I've launched a petition on change.org to ask the home secretary to stop his extradition – and why I hope you will sign it. Together, we won the battle against Sopa and Pipa. Together, we can win this one too.

Jail For File-Sharing Not Enough, Labels Want ISP-Level Spying Regime

From October, knowingly uploading or simply downloading copyrighted material from the Internet will be a criminal offense subject to jail sentences in Japan. But despite now having the ultimate deterrent, it’s still not enough for the Recording Industry Association of Japan. The group is now pressing for ISPs to install spying technologies that will automatically block unauthorized uploads.

Earlier this week, Japan approved an amendment to its Copyright Law that will soon give the authorities the power to jail Internet users for up to two years for simply downloading copyright material.

Uploading copyright material has been illegal for some time, but the criminalization of downloading has caused some to worry whether simply viewing a pirate music video on YouTube could render people liable to prosecution.

Understandably this kind of talk has the potential to lead to a climate of fear among Internet media consumers, but if that leads to increased sales at authorized outlets rightsholders won’t be too disappointed. In fact, after lobbying hard for this tough copyright law amendment, that will be very much “mission accomplished.”

Not surprisingly though, even the toughest of sanctions aren’t going to stop the big recording labels coming back for more mechanisms to protect their interests. And that they have.

Several music rights groups including the Recording Industry Association of Japan say they have developed a system capable of automatically detecting unauthorized music uploads before they even hit the Internet. In order to do that though, Internet service providers are being asked to integrate the system into their networks.

The system works by spying on the connections of users and comparing data being uploaded to the Internet with digital fingerprints held in an external database. As can be seen from the diagram, the fingerprinting technology employed is from GraceNote, with intermediate systems provided by Copyright Data Clearinghouse (CDC).

Once a match is found, rightholders want ISPs to automatically block the allegedly infringing content. But according to one report, there may even be requests to send out warning letters to uploaders. If implemented this would amount to the most invasive “3 strikes” style regime anywhere in the world.

The system is being promoted as a benefit to ISPs, in the sense that once installed (and licensed at a cost of around $600 per month) they can potentially avoid being held liable for copyright infringements carried out by their customers. Whether not having it installed will save ISPs from privacy invasion lawsuits remains to be seen.

Rightsholders have tried to get service providers to install this kind of system before, most notably resulting in the legal battle between music rights group SABAM and Belgian ISP Scarlet. That case ended in 2011 with the European Court of Justice declaring that spying on Internet users would breach their privacy and violate the fundamental rights of both the ISP and its subscribers.

20120623

Ninth Circuit to DEA: Putting a Gun to an 11-Year-Old's Head Is Not OK

Mike Riggs

At 7 a.m. on January 20, 2007, DEA agents battered down the door to Thomas and Rosalie Avina’s mobile home in Seeley, California, in search of suspected drug trafficker Louis Alvarez. Thomas Avina met the agents in his living room and told them they were making a mistake. Shouting “Don’t you fucking move,” the agents forced Thomas Avina to the floor at gunpoint, and handcuffed him and his wife, who had been lying on a couch in the living room. As the officers made their way to the back of the house, where the Avina’s 11-year-old and 14-year-old daughters were sleeping, Rosalie Avina screamed, “Don’t hurt my babies. Don’t hurt my babies.”

The agents entered the 14-year-old girl’s room first, shouting “Get down on the fucking ground.” The girl, who was lying on her bed, rolled onto the floor, where the agents handcuffed her. Next they went to the 11-year-old’s room. The girl was sleeping. Agents woke her up by shouting “Get down on the fucking ground.” The girl’s eyes shot open, but she was, according to her own testimony, “frozen in fear.” So the agents dragged her onto the floor. While one agent handcuffed her, another held a gun to her head.

Moments later the two daughters were carried into the living room and placed next to their parents on the floor while DEA agents ransacked their home. After 30 minutes, the agents removed the children’s handcuffs. After two hours, the agents realized they had the wrong house—the product of a sloppy license plate transcription—and left.

In 2008, the Avinas—mom, dad, and both daughters—filed a federal suit against the DEA for excessive use of force, assault, and battery in the U.S. District Court for the Southern District of California. That court ruled in favor of the DEA, and the Avinas appealed. Last week, the family got justice.

While the Ninth Circuit Court of Appeals defended the agents' rough treatment of Thomas and Rosalie, it also declared that yanking the Avina children of their beds and putting guns to their heads did, in fact, constitute the “intentional infliction of emotional distress.”

(Read the Obama administration's defense of the DEA agents.)

"A jury could find that the agents pointed their guns at the head of an eleven-year-old girl, 'like they were going to shoot [her],' while she lay on the floor in handcuffs, and that it was excessive for them to do so," reads the Ninth Circuit's decision, which was filed June 12. "Similarly, a jury could find that the agents’ decision to force the two girls to lie face down on the floor with their hands cuffed behind their backs was unreasonable."

More from the decision:

Under our case law, an issue of material fact exists as to whether the actions of the agents were excessive in light of the ages of B.S.A. (age eleven) and B.F.A. (age fourteen) and the limited threat they posed. See Tekle, 511 F.3d 839 (holding that officers were not entitled to summary judgment on excessive force claim where officers pointed guns at an eleven-year-old boy’s head during the arrest of the boy’s father); Motley v. Parks, 432 F.3d 1072, 1089 (9th Cir. 2005) (en banc) (holding that officer’s act of pointing a gun at an infant during the search of a gang member’s house was objectively unreasonable); see also McDonald ex rel. McDonald v. Haskins, 966 F.2d 292, 294-95 (7th Cir. 1992) (holding that officer’s act of pointing his gun at a nine-year-old’s head during the search of home was excessive use of force). Accordingly, we reverse the district court’s grant of summary judgment in favor of the United States on B.F.A.’s and B.S.A.’s claims for assault and battery.
In a footnote, the court wrote:
Although there is evidence that the agents released the girls from their handcuffs once they realized how young they were, there is also evidence that the agents knew, prior to entering the girls’ bedrooms, that the girls were children. Rosalie testified that, as the agents were heading towards the girls’ rooms, she screamed at the agents several times, “Don’t hurt my babies.” Moreover, one of the agents testified at his deposition that, when he first saw one of the girls (presumably the older of the two girls), she appeared to be “12 [or] 13 years old.”
The ruling concludes:
Viewing the evidence in the light most favorable to the Avinas, a rational trier of fact could find that agents engaged in “extreme or outrageous” conduct when the agents: (1) pointed their guns at the head of eleven-year-old B.S.A. “like they were going to shoot [her]” while B.S.A. was lying on the floor in handcuffs; (2) forced eleven-year-old B.S.A. and fourteen-year-old B.F.A. to lie face down on the floor with their hands cuffed behind their backs; (3) left B.S.A. and B.F.A. in handcuffs for half an hour; and (4) yelled at eleven-year-old B.S.A. and fourteen-year-old B.F.A. to “[g]et down on the f[uck]ing ground.” See Tekle, 511 F.3d at 856 (holding that officers were not entitled to summary judgment on claim for intentional infliction of emotional distress where officers pointed guns at eleven-year old’s head during the arrest of the eleven-year-old’s father); see also id. at 859 (Fisher, J., concurring). Accordingly, we reverse the district court’s grant of summary judgment in favor of the United States on B.F.A.’s and B.S.A.’s claims for intentional infliction of emotional distress.
As a side note: While this raid was conducted under President George W. Bush, the deputy administrator of the DEA at that time was Michele Leonhart. She is now the administrator of the DEA, thanks to an appointment by President Barack Obama. Furthermore, the Obama Administration could have declined to defend the DEA in this case. Instead, Obama's Justice Department has decided to make the case that federal agents should be allowed to hold guns to the heads of children.

20120622

Louisiana sex offenders must identify themselves on Facebook

by Cyrus Farivar

Starting August 1, a new Louisiana state law will require sex offenders to disclose their status on social networks. But in theory, that shouldn't be necessary: Facebook and other social networks’ existing policies already forbid registered sex offenders from creating accounts.

"I don't want to leave in the hands of social network or Facebook administrators, 'Gee, I hope someone is telling the truth,'" State Rep. Jeff Thompson told CNN Tuesday. "This is another tool for prosecutors."

The new bill, formally known as Act 385, was signed into law by Gov. Bobby Jindal earlier this month.

“[A sex offender] shall include in his profile for the networking website an indication that he is a sex offender or child predator and shall include notice of the crime for which he was convicted, the jurisdiction of conviction, a description of his physical characteristics as required by this Section, and his residential address,” the law states.

“The person shall ensure that this information is displayed in his profile for the networking website and that such information is visible to, or is able to be viewed by, other users and visitors of the networking website.”

But if actual sex offenders do follow this law, it seems that they’d be asking Facebook to pull down their accounts pretty quickly. The new law comes on the heels of an overbroad state law that was struck down, and aimed to forbid sex offenders from using social media entirely.

Why Product Recalls Make You Less Safe

Genuinely dangerous products should be pulled from the shelves. But government recalls sometimes punish manufacturers for vague problems and blatant consumer misuse, actually reducing public safety. Even the word "recall" turns out to be defective.

By Dan Koeppel

Elmo was in danger. In the video Bryan Dussault posted on YouTube in February 2010, the Sesame Street favorite is strapped into a child-safety seat. Dussault tightens the five-point harness and then abruptly yanks the unit's shoulder straps, which are supposed to be snug against the infant passenger. The harness straps loosen. Dussault pulls the shaggy toy away as if it were being tossed, unprotected, in a high-speed collision. To anyone viewing the clip, but perhaps especially to anyone who travels in a car with a child, the scenario is startling and scary.

The series of events that led Dussault to film the sequence began on a freezing Chicago day earlier that winter. At the time his son was 3 years old. It was Grandma's turn to pick up the boy at preschool. But there was a problem. "My mother-in-law called me," Dussault says, "and said she couldn't get the car-seat straps to tighten up."

Dussault drove to the school and took his child home himself, along with the car seat that had apparently failed. He owned the same item—the $79 Vantage, purchased at Walmart and sold under the Safety 1st brand name. In his garage Dussault tested his own seat; again, the straps loosened. "I knew that if I got two doing that," he says, "there were probably thousands out there doing the same thing."

Dussault contacted the seats' manufacturer, Dorel Juvenile Group. Based in Columbus, Ind., Dorel is the world's largest maker of children's car seats. It sells about 8 million child-restraint systems—the official term for car seats—each year. But shoppers won't find the Dorel name in stores. Instead, the company's goods appear under a range of recognizable brands including Disney, Cosco, Eddie Bauer, and Maxi-Cosi.

Dorel offered to exchange Dussault's seats. But when the replacements arrived, Dussault says they failed his test as well. He filed a complaint with the National Highway Traffic Safety Administration (NHTSA). Meanwhile, Dorel asked him to return the original seats so the company could test them, standard procedure when an exchange is offered. Dussault was hesitant. "They were hot on my tail to get these seats out of my hands," he says. The company, he believed, intended to "sweep things under the rug."

To prevent that from happening, Dussault made the video. He contacted the news media. A local NBC affiliate dispatched a crew. The demise of Elmo went viral, and in 2011 Dorel recalled 800,000 car seats. A win for Elmo and kids everywhere?

That's debatable.

Dussault describes his struggle in David and Goliath terms, a concerned parent confronting a faceless corporation whose interests are driven more by sales than by safety. When it comes to products designed to protect children, that position isn't difficult to understand. I'm the father of a 16-month-old, and even before our son arrived, my wife and I did what most expectant families do: We went shopping.

I was amazed by the number of products available and dismayed by how many appeared to be defective—car seats, strollers, toys, cribs, nursery monitors. It seemed impossible to pick a category that wasn't prone to recalls. When my wife and I debated whether to allow our infant to sleep in the same bed with us, we were told that the only safe way to do so was to buy a "positioning device," a product that would prevent a sleepy parent from rolling over and smushing the poor tyke (never mind that parents have been cuddling their children to sleep for millennia). We rejected the advice, and good thing: On our next visit to Babies "R" Us, the positioner aisle was empty. It turned out the device itself could lead to suffocation if a child were pressed against it the wrong way.

At first my impression was similar to Dussault's: a rogue industry. A little research seemed to back that up. NHTSA recalled more than 100 different models of car seats from nearly a dozen manufacturers during the past decade. And media accounts almost always emphasize the profit-trumps-all angle when it comes to product defects. Particularly notable is a 2007 Chicago Tribune story that chronicled Dorel's attempts to prevent an earlier recall. Dorel had argued—correctly but unsuccessfully—that the straps on the car seats weren't up to standards because there were no clear standards when they were manufactured in 2000 and 2001. Other companies, it pointed out, used materials of similar strength and design and hadn't been penalized. The reporters painted the company as uncaring, even conspiratorial—quoting an internal email from a Dorel executive who wrote: "Why? It still sells." The series of investigative reports that included the story won a Pulitzer Prize. And after losing an appeal to the NHTSA in 2010, Dorel was forced to recall about 4 million car seats.

But eventually I began to question whether product defects could really be so rampant. Most of the recalls I had read about appeared to be for items that caused no injuries or where injuries could only be vaguely attributed to a specific problem. As I began to search my home for recalled products—not just stuff aimed at kids, but appliances, tools, electronics, and everything else modern shoppers own and covet—I quickly became overwhelmed. There were so many recalls and so many sources of information on recalled products that I could barely keep track. Did I own dangerous items? Were they really dangerous or just potentially dangerous? And what action should I take, if any?

Trying to sort through it all was impossible, so I gave up. And in that way I became an even more typical American consumer: one unable to make my home truly safer, because the system by which we judge, identify, and correct broken gear is as defective as anything found on store shelves.

In the United States, product recalls are overseen by six federal agencies. The majority come under the jurisdiction of the Consumer Product Safety Commission (CPSC), which handles everything from toys and power tools to appliances. Recalls connected to automobiles—cars, tires, and child-restraint systems—are within the NHTSA's purview. Boats and nautical items are regulated by the Coast Guard. Products containing chemicals, such as house paint and pesticides, are Environmental Protection Agency territory; the U.S. Department of Agriculture (USDA) and the Food and Drug Administration (FDA) handle edibles, pharmaceuticals, and cosmetics.

The division of federal oversight—car seats to the NHTSA, strollers to the CPSC; burgers to the USDA, fries to the FDA—is just the beginning of the knot consumers need to untangle if they're hoping to learn whether a product they own poses a threat. Though there's ostensibly a one-stop database of product alerts, recalls.gov, the website's utility is marred by confusing design and poor information retrieval. Clicking on the Search for Recalls button opens a page with six additional search boxes, each tied to a different agency or category. If you don't know what jurisdiction a product falls under, you'll have little success, which may be just as well: Sometimes products are identified only by inventory-control codes useful to retailers and manufacturers. Photographs are often unavailable. If you do manage to discover a potentially relevant recall, you're given the investigation number assigned by the overseeing agency but not always a link to the investigative details themselves.

Details that are included don't generally provide context for injuries or useful consumer information. For example, the notice for a Task Force electric log splitter, recalled in July 2011, states that two injuries had been reported after operators placed their hands on the handle while the splitter was in operation. The notice instructs consumers to stop using the product and send for free warning labels. "That has got to be one of the weirdest recalls we've ever seen," wrote Everett Snyder on ProToolReviews.com. "The recall itself doesn't do too much to explain the problem or deliver specific (detailed) instructions for safe use of the tool... No, for that you need to wait for the stickers to show up."

This muddle is made worse by the scale and number of recalls. During the past five years, more than 150 million children's items, 110 million household goods, and 9 million pieces of sporting equipment have been recalled by the CPSC alone, according to the recall-tracking group WeMakeItSafer. There are so many recalls—nearly 1500 by all six agencies in 2011—that many consumers have simply stopped paying attention to them. A 2010 Consumer Reports survey found that just under 25 percent of respondents ever bothered to research whether a product they owned had been subject to a recall; of those who knew they owned a recalled product, only about 30 percent actually did something about it. There's even a new term for the phenomenon of ignoring product-safety warnings: recall fatigue. "So many recalls are announced in so many ways that when you hear it on the news, it just doesn't register," says Craig Wilson, vice president of quality assurance at Costco Wholesale Corp. "The perception is that there's a lot of crying wolf going on."

A day after Elmo's mishap hit Chicago airwaves, the NHTSA's Office of Defects Investigation opened case PE10-009—a preliminary evaluation, which doesn't indicate that a recall is necessary or even being contemplated. Though the agency receives about 35,000 consumer complaints each year, just two—both Dussault's—had been registered for the Vantage, which had been highly rated in Consumer Reports.

Preliminary or not, opening an investigation also opens floodgates. The manufacturer of the product in question is required to deliver thousands of pages of data: test results, transcripts of customer-service calls, descriptions of manufacturing procedures, sales figures. The NHTSA announces the inquiry to the public, an evidence-seeking strategy that can lead to hundreds of additional complaints. For the Vantage, it yielded only six new reports, none of which involved injuries. Despite this, the agency moved the inquiry to the next level: engineering analysis. On July 2,2010, case EA10-005 was opened: Dorel was asked to provide complete details on how the seat was built and tested, and whether any changes had been made at the factory that might have coincided with the complaints of strap slippage. Over the next couple of months, Dorel submitted thousands more pages of documentation.

In an 11-page letter to the NHTSA dated Sept. 21, Terry Emerson, Dorel's director of quality assurance, stated that no slippage had occurred in the Vantage's initial rounds of testing—2900 on crash sleds and 2000 mechanical strap pulls. The public investigation attracted 40 additional complaints, representing 0.00005 percent of seats sold. No injuries or deaths were reported. Dorel, Emerson wrote, "does not believe the subject units contain a safety-related defect."

But the company did find that some center front adjusters (CFAs)—the locking and release buttons that secure the straps—could, if excessively dirty, not tighten as well as a new product's (though that could be remedied by making sure the CFA is actually pressed firmly into place). And so, on Feb. 14, 2011, Dorel initiated a voluntary recall, offering what consumer-safety specialists call a sealed fix—a repair kit rather than a full product swap. The kit consisted of a tiny tube of food-grade lubricant; the primary ingredient, canola oil.

The main difference between Dorel's remedy and a squirt of something from a typical pantry is a sticker that comes with the kit, indicating the fix has been applied. But there is no evidence that the tube-of-lube solution addresses what caused Dussault's seats to fail. When Dorel finally got those car seats back, it couldn't reproduce the problem. Nor could outside testers, including Consumer Reports, which takes an aggressive stance toward product safety. Though Dorel won't disclose how much the recall cost, its annual reports indicate the juvenile division has spent more than $50 million in the past five years on product liability expenses.

Barry Mahal, Dorel's executive vice president for child-restraint systems, says the company agreed to the recall out of "an abundance of caution." What Mahal didn't add was that Dorel also likely agreed to the recall because it knew it couldn't win; it had already been down that road with the recall that led to the Pulitzer Prize—winning investigation. Though the Tribune reporters quoted a Dorel attorney pointing out that a particular car crash, not a product defect, may have caused a child's injuries, the story ended with a depiction of that child rocking back and forth in her kindergarten class, unable to speak or seemingly comprehend.

The interplay between tragedy and recall makes for gripping narrative; there's little doubt that such stories can compel normally glacial federal agencies to react quickly. The most prominent example of this is the fairly well-known—but still poorly understood—story of Toyota and the phenomenon called unintended acceleration.

Accounts of Prius, Lexus, and Camry models unexpectedly gathering speed began to dominate the headlines in 2009. That was when the audio of a horrific 911 call—made from the car of off-duty California Highway Patrol officer Mark Saylor—garnered hundreds of thousands of online plays. Saylor and three members of his family died when their Lexus spun out of control while traveling more than 100 mph. The incident was ultimately attributed to the wrong floor mat installed by a dealer, but experts, including Joan Claybrook, former head of the NHTSA, insisted the problem had to be an electronic defect. In February 2010, Department of Transportation secretary Ray LaHood recommended that Americans stop driving their Toyotas. Three weeks later, the company's CEO, Akio Toyoda, issued a public apology. Toyota ended up recalling more than 8.5 million vehicles. The damage to the company ran into the billions of dollars: Its U.S. market share dropped from 17 percent in 2009 to 12.6 percent in 2011, putting it in third place behind General Motors and Ford.

In an effort to find the alleged bug, the NHTSA enlisted NASA to conduct the largest automotive defect investigation in history. In February 2011, the agencies concluded that no flaws in Toyota's control systems could be found. The most likely culprit, the report revealed, was "the driver's unintended application of the accelerator, rather than, or in addition to, the brake." In other words, human error.

Brian Lyons, safety and quality communications manager at Toyota USA, says that the company didn't realize how quickly media reports would snowball. "The evidence said that there wasn't anything wrong with the electronics systems," he says. "The battle was getting the truth out there."

Though Toyota's market share is recovering, the company faces nearly 200 lawsuits. In the first of those cases, Toyota argued (in accordance with NASA findings) that driver error was the main cause of the accident—a defense that resulted in a storm of condemnation. Many of those who chastised Toyota for blaming the victim wrote for blogs operated, with varying degrees of transparency, by law firms looking to identify such victims and file claims on their behalf. These firms use technological savvy to game Web results, either by purchasing keywords and advertising or by optimizing their sites to register prominently with Google. Enter "car seat defect" into the search engine and of the first 50 results, 43 are law firms.

"What we've ended up with is a protection racket," says Michael Krauss, a professor of law at George Mason University who specializes in product liability. "These lawyers are on a never-ending search for clients. Paying them off has become part of the cost of doing business."

Krauss says that excessive litigation has skewed the entire way products are built, sold, and marketed today. Companies hesitate to deal openly with flaws because they fear litigation; consumers, noticing this, mistrust manufacturers. And the U.S. legal system has become an enabler, Krauss says, because liability cases here—unlike in most other countries—are decided by juries rather than judges, allowing room for emotion to swamp facts. Multimillion-dollar settlements are far more likely, Krauss says, "because a company is going to be very averse to being in a courtroom where aggrieved parents are holding up pictures of a dead or disfigured child while the jury hears the evidence and deliberates."

Companies like Dorel work in such a charged atmosphere that they can't even obtain product-liability insurance; instead, they keep tens of millions of dollars reserved for private lawsuit settlements. Dave Campbell, an analyst with the Juvenile Products Manufacturers Association, says that consumers pay a premium of up to 5 percent on most kid-oriented products in order to fund settlement pools. For smaller businesses, operating closer to the margin, high liability insurance can push them out of the market—or dissuade an entrepreneur with a smart innovation from launching a company in the first place.

Government has a role in ensuring product safety. But the bottom line is that a recall—whether or not the product is dangerous—is useless if nobody hears about it. Most current efforts to spread the word seem to do little but add to the clamor. Federal agencies now offer more mobile apps, more text alerts, and more website widgets, all drawing on the same vast stores of raw data. The most recent addition to this well-intentioned deluge is saferproducts.gov, mandated by the Consumer Product Safety Improvement Act (CPSIA) of 2008. The site duplicates much of the information on recalls.gov, though with a better-looking interface and a new feature: a public forum for reporting defects.

As valuable as such a tool might seem, one result has been to turn the site into an electronic complaint department. (Recent incidents included a man who was burned by fireworks and another who felt nauseated after shaving.) CPSC commissioner Anne Northup objected to the use of agency resources to investigate such claims in Congressional testimony in March 2011. "Many believe the public database, if left unchanged, will be useful only to trial lawyers or advocacy groups that will be able to populate it with unverifiable, secondhand information for their own purposes," she stated. (CPSC chairwoman Inez Tenenbaum disputes the reports are unverifiable.) More promising is that the CPSC recently opened its database and underlying code. This should enable private software developers to build custom, highly targeted applications, says agency spokesman Alex Filip.

Both the NHTSA and the CPSC have also been plagued by an investigative process that hasn't kept up with technology. In congressional hearings following the Toyota recalls, NHTSA administrator David Strickland said the agency employed just five electrical engineers and one software engineer out of its 125 engineers working on automotive investigations. The CPSIA mandated that the agency improve its technical facilities so it could conduct more authoritative product tests. In a 2011 report to Congress, the CPSC said that it was unable to adequately accomplish that goal because it "lacked the necessary infrastructure to directly accredit the testing laboratories." In both internal documents and public statements, the federal agencies admit to being as overwhelmed as consumers. "We've got very, very full plates, and we don't move at the speed we'd like to," an NHTSA official told me. "But we do what we can with what we have."

Most observers say the solution lies in both addressing the recall process and rethinking how recalls are communicated. That includes examining the terminology. In the United Kingdom, the word "recall" is used only for products that have caused, or are likely to cause, deaths or very serious injuries. Lesser cases are termed corrective actions; they can be addressed via consumer education or minor fixes, like the tubes of oil offered by Dorel. The adoption of more nuanced wording has been proposed repeatedly in the U.S., but government officials involved in recalls say that such a system is too risky because it might prompt consumers to further ignore product-defect notices. "The problem is that we end up making the judgment, when that should be left to consumers," the NHTSA official says. "If they think the risk is too minor, they won't take advantage of the remedy."

If scare tactics worked—if they actually made people comply with recalls—then perhaps a little hyperbolic horror would be a good thing. Unfortunately, says William K. Hallman, a psychologist and director of the Rutgers University Food Policy Institute, fear turns out to be a lousy motivator. "Scaring the crap out of people doesn't work," says Hallman, who is working with the FDA to help improve recall communications. "When people are that terrified, the outcome is usually no action at all."

As I read through the accounts of various recalls, I found myself wondering: Regardless of whether the issue is a foot on the wrong pedal or a Roman candle aimed in the wrong direction, how much responsibility do manufacturers bear for operator error? In the case of Mark Saylor, someone was clearly at fault: the dealer who installed the floor mats in his loaner vehicle. But what about when consumers purchased floor mats that weren't made by Toyota? The company's corrective action, which included a pedal redesign to make mat entrapment less likely, was the right thing to do; a shopper should be able to reasonably expect that a product will be safe under standard usage. That said, many cases I looked at seemed to revolve around good people making honest mistakes—bad mistakes, sometimes—and being unable to recognize or admit to the fact.

One company that attempted to both do the right thing—fix a problem that wasn't necessarily a defect—and point out that customers had a responsibility to use its product correctly is Maclaren, one of the world's largest makers of baby strollers. In November 2009, the U.S. subsidiary of the British firm recalled 1 million umbrella-type folding baby carriers. Twelve children had suffered injuries, including partial amputations, when their fingertips got caught in the product's folding mechanism. Those injuries never occurred when children were actually in the strollers—only when they became entangled as parents were folding the equipment. The problem also wasn't unique to Maclaren strollers.

Despite clear instructions on proper usage, Maclaren agreed to a recall. It was preparing to announce the effort when the process suddenly went awry, according to company CEO Farzad Rastegar, writing in the January 2011 Harvard Business Review. Maclaren had planned to issue a press release announcing the recall on Nov. 10, 2009, but one day earlier, word of the recall leaked to the New York Daily News, setting off a media frenzy. "For several months," Rastegar wrote, "we had worked with the CPSC on a plan to make owners more aware of the danger and to provide protective hinge covers... But the news story provided none of this context. Nor did it explain that practically all strollers on the market have similar hinges."

Within 24 hours TV crews showed up at the company's Connecticut headquarters and hundreds of mommy blogs issued frantic warnings. Panic ensued. A Brooklyn mother told The New York Times that the two biggest threats her children faced were "swine flu and Maclaren strollers." The company's website and email crashed—and even that was portrayed as an example of Maclaren's ineptness.

"We had hoped that the recall would build awareness about the wider risks of operating a stroller, not just about hinges," Rastegar wrote. "Instead, we would have to start defending our brand."

In the end Maclaren distributed more than 300,000 hinge covers. Even so, by the end of 2011, 149 additional injury reports had been filed, indicating typically low recall compliance. Even as it reissued notices, Maclaren insisted the process was flawed. Its website pointed visitors toward a document calling for all stroller manufacturers to offer hinge covers. (Several brands with similar designs have been recalled, but I was able to find five folding strollers with unprotected hinges in less than an hour of shopping.)

CPSC's Filip says the piecemeal approach to umbrella-stroller recalls could change; the CPSC could issue a category-wide product-defect order, as it did for drop-side cribs in 2011. But in order to do that, the agency would need "to make a strong case for intrinsic danger," he says. So far, such a case hasn't emerged.

Just after Christmas 2011, Maclaren USA filed for bankruptcy. Among the listed liabilities were "unknown" claims (meaning the amounts were undetermined) by seven families and law firms suing the company, along with the CPSC, for ongoing expenses related to the stroller recall.

Products need to be user-friendly in the real world, where people are in a rush, where crevices get jammed with gunk and goo, where—in the case of car seats—Mom's vehicle might have deep buckets and Dad's truck might have a bench. We're a one-car family, but even so, I was surprised at how difficult it was to install our car seat (it didn't help that I was doing it for the first time while my wife was in labor—don't ask). Statistics show that as many as 80 percent of existing car seats—depending on the seat type, the age of the child, and the vehicle—are improperly installed or misused. It's been that way for decades despite efforts to teach parents the correct process. There are more than 25,000 certified car-seat-installation technicians in the U.S., most of whom offer their services for free through local hospitals and police and fire departments.

Maybe the expectation of ease is unreasonable. A car seat is a complex product that has a very critical function. As much as I wish that my car seat would simply click in and always be secure, I know better: I've got to learn how it works, use it correctly, and maintain it.

By the end of this year, Dorel will submit a report to the NHTSA outlining the results of the Vantage recall. Most likely, compliance will be low, and most likely, it will be difficult to determine if any injuries have occurred because of the recalled product or if any have been prevented by the recall. What's certain is that there will be more recalls. Parents and manufacturers will continue to make mistakes—something I became personally aware of when, using Urban Apps' Recalls for iPhone, I made a second pass through my house.

One of our son's earliest favorites was a bright yellow baby chair called a Bumbo. I discovered it had been recalled in 2007 after reports that children pitched themselves out of it. Though there were some design flaws, the bigger issue seemed to be misuse: Serious injuries occurred when the product was placed on a table or counter, resulting in a fall from height.

I was well aware of this problem; I'd almost let it happen myself. We were having dinner, and I'd placed the Bumbo in the center of our dining room table. Our son wriggled forward, and suddenly he was out of the chair. He didn't fall off the table, but it was close—and I felt terrible about the bump on his head.

With the Bumbo I broke two major rules when it comes to product safety. First, I didn't follow the instructions. That was because—here's the second broken rule—I didn't have instructions. We bought the product used, as more and more parents are doing these days; reselling a recalled product is illegal, though such goods can be readily found at garage sales and on auctions sites like eBay. But mostly I didn't use common sense.

Personal responsibility isn't the sole answer. It needs to be backed up with an approach to defects that's evidence-based, and with communications that get genuinely bad products off the market. One such model can be found in membership clubs. Costco's Wilson says that traditional recall notices have been so ineffective that his company created its own system, maintaining a database of everything a customer buys. When a recall is announced, the company calls everyone who has ever purchased the product, then follows up with a letter. It also has an internal recall process that moves far more quickly than a government agency's, issuing notices for products it believes are unsafe based on negative customer feedback. Wilson says that Costco's effectiveness rate for reaching consumers is more than 90 percent.

Could that Costco model be applied to consumers who don't buy at membership-based stores? Widespread use of debit cards, transactions that automatically register serial numbers for inventory control, and the fact that most major retailers now have loyalty programs that track purchases indicate the data may be available. (CPSC's Filip says such a program is not within the agency's current mandate.)

Several companies are developing search-engine-like technology that trolls federal recall sites. WeMakeItSafer, for example, reformats and consolidates the information into useful data, then notifies registered users directly when there is a relevant recall, or works with retailers and manufacturers, who can direct the recall toward a specific database of customers. That way, consumers will receive information only about products they own. "The answer isn't telling the world there's a recall in the hope of reaching the few people that own a product," CEO Jennifer Toney says. "It is about using technology to home in on just the people who need to know they have issues with something they own and need to get it fixed."

I want—for myself and my family—to be protected from truly defective products. But I also want to see a system that is honest about identifying those products, that assesses risk properly, that advocates responsibility as much as—or more than—it assigns blame. I want to know that decisions are being made carefully enough that I'll be likely to hear about them—and likely to care about them. I'd be delighted if the government did that; I'd also be delighted if that was something that could happen via new technology or through my favorite retailer or anyone else who could figure it out. I'd even be happy to get the message from Elmo. I just want the message to mean something.