History sniffing is the art of tracking where people have been on the internet. Essentially, it is to help advertisers target very specific advertisements to very specific people. However, it seems that it happens most obviously with porn sites which kinds of makes the the whole idea of 'history sniffing' sound a little dirty. Yet, the biggest problem is that this kind of snooping is really tantamount to an invasion of privacy. It is an invasion of privacy because you, the internet surfer, has not consented to your data being collected in this manner nor have you consented for it to be collected for this purpose.
Nevertheless, it would be unfair to label this as exclusively a porn site thing. It is clearly not. The data being harvested can be done through a visit to a news site, while you are doing your internet banking, or if you are visiting a porn site for the purposes of research. Some of the biggest 'offenders' based on the research / survey data was Morningstar.com and Newsmax.com. Morningstar is a financial services website and Newsmax is a news website. For example, a recent survey, conducted by the University of California at San Diego, found that most internet search browsers allow for history sniffing to continue unabated.
However, the report based on this survey also found that the more recent versions of Google Chrome prevented history sniffing from occurring. Also Apple's latest versions of Safari do not allow history sniffing to take place. Microsoft's Internet Explorer does not yet prevent history sniffing from happening although the next version will, yet will come at a price as it will seemingly disable other useful features such as allowing your computer to recognise where you have been previously. The other popular browser that continues to allow history sniffing is Mozilla Corp's Firefox.
I am currently using the latest version of Google Chrome, so with a bit of luck I am not currently susceptible to history sniffing.
It is worth noting that one's passwords are not at risk here. This technology is not being used to harvest passwords or any other personal data except for where you have been. It really is about following your trail and then modifying advertising to give you, the "consumer", the most personalised service possible.
It is also worth noting that it might not matter too much longer with respect to what internet browsers in conjunction with advertisers want as US regulators are looking at requiring the use of a "Do Not Track" tool that is designed for no other reason than to stop advertisers from tracking specific individuals in order to target them with equally specific internet bargains.
I am no techno wizard so I am never sure whether this data even know it is stated that it is being used only for advertising purposes cannot be worked to develop a comprehensive profile of one's habits. Perhaps it is better to err on the side of caution if doing things that may be misconstrued if they were to ever become publicly available.
Hmmm...
Musings about the law, politics, culture, people, education, teaching and life. An independent voice and an independent perspective - Carpe Diem!
Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts
06 December 2010
17 November 2010
Does the Government Have A Right to Sexually Assault You?
Two recent cases suggest that the government believes it has a right to touch your genitals, particularly if you choose not to have a full body scan (pretty explicit, huh?) done when you seek to board an airplane in the USA. The case of Erin Chase and John Tyner highlight just how confronting the "enhanced pat-down" procedures are. You can read Erin's blogpost about the incident here.
The "enhanced pat-down" procedures are conducted by the Transportation Security Administration or TSA.
The pat-downs take place if a traveler refuses to have a full body scan done. If a refusal occurs then the passenger is taken off to a special screening area and subject to the pat down. If the passenger refuses a pat-down then they cannot board the aircraft. And, in the case of John Tyner, a TSA official will suggest to you that you will get into serious trouble and run the risk of a substantial fine, especially if you bail out in the middle of a screening.
Cutting to the Chase case, the TSA official did not inform her about the procedure, she just went ahead and did it. The enhanced pat down, as Chase described it, included the TSA officer touching both of Chase's breasts and her vaginal area, including both labia.
In any other circumstances this would be sexual assault. Perhaps the government is working on the assumption that if you refuse the body scan then you consent to the enhanced pat-down. Therefore, it cannot be assault because you are consenting to the procedure. In essence, you are consenting to a complete stranger touching your nether regions for the purposes of security.
I am sure there are those of us out there who believe that this is not a breach of our civil liberties and that if it makes us more secure, then it is worth it. I am also certain that there are plenty of us out there who are struggling with seeing how the enhanced pat-down procedures can be truly justified. Whatever happened to the idea that you could be swabbed for explosives? After all, it was the attempt to blow up an aircraft with exploding undies which triggered these procedures. So, why not just swab people's hands and clothes?
It would seem that despite the litany of complaints and the genuine concerns people have with the procedures, the TSA is not going to back down. So, the enhanced pat-down procedure seems like it is here to stay, at least for a while.
The final image here is an alternate view of one of the images above. The technology is certainly capable of getting the details of a whole lot more than whether you are carrying a gun or a knife or some other sort of contraband.
01 October 2010
Men as Sexual Objects...
Nah, whoever would have thought that there would be a little balance placed back into the ledger of men and women behaving badly. A young woman, and recent graduate of Duke University, has placed a list of her sexual conquests online. Her exploits include 13 young men of some [former] repute, who I am quite sure were not so willing in the take my photo and critique my sexual prowess online participants stakes. However, this might be a lesson in taking a moment or two to think about where your next hook-up might end up.
The list, which is eloquently described as a thesis, "An education beyond the classroom: excelling in the realm of horizontal academics", to satisfy the completion for the award of a degree in horizontal academics, has gone viral. You can see the list over at Jezebel. I went to college just up the road at the University of North Carolina - Chapel Hill, so some of the bars and other places of interest noted in this thesis are places that were around back in 1992 when I was there (yes, punters and friends, I am that old).
The beauty of this list is that it shows pretty clearly that, there are at least, some women out there who critique men on their attractiveness, penis size, and abilities with the other appendages they possess (is the tongue an appendage?). It was particularly nice to see that an Australian accent rated highly on the suitability stakes. This means that there are genuine hopes for all Aussie fellas out there roaming the college campuses of America in search of a hook-up.
On a serious note. There is nothing funny about this list. There is nothing worthwhile in even thinking about putting it together in the first place, let alone putting it together and then seeing it published online. It says a lot more about the woman who did it than the men who fell victim to her "research". Interestingly, the vast number of research subjects targeted were members of the Duke Lacrosse team.
I guess the question that needs to be posed now is, "Is what this young woman did wrong?"
18 December 2009
Luna Maya, Twitter, Paparazzi, and Prostitutes


.jpg)

One of the good things about not having a twitter account is that there is no temptation to vent one's frustrations and anger out into the public sphere. Perhaps on a little reflection Luna Maya might have thought twice about ranting that "infotainment are lower than prostitutes, murders!!! May your soul burn in hell!!!" I guess it is fair to say that she was not mincing any words there. But does she have a point?
To work this out one needs to consider the situation that preceded this little rant. Luna Is dating a singer of one of Indonesia's bigger bands, Ariel of Peter Pan fame. Ariel was married and has a beautiful young daughter (no where near as good looking as Will of course). There has been some suggestion that Luna is a home wrecker and it is her fault that Ariel split with his former wife. However, that was not the issue that sparked the most recent venting.
Luna's twitter account, lunmay, was shut down recently after the vent went public. Luna has apologized to her 123,952 followers for shutting down the account. I probably would not have had one in the first place if I was a star of the small and silver screens. Simply, tweeting that you are watching a movie is like a red rag to a bull and is certain to bring the paparazzi stalkers out in force.
As the story goes, Luna, Ariel, and Alleia (Ariel's daughter) went to watch the premiere of Ariel's first movie, The Dreamer (Sang Pemimpi) at EX Plaza. Now, my recollections of EX are that it was an excellent place for a little bit of celebrity spotting if that was your thing. In any event, little Alleia had fallen asleep during the movie and was being carried out by Luna.
This is where it gets really interesting. In the scramble for good photos and an interview one of the infotainment throng cracked little Alleia on the head with a camera. For a parent, even the girlfriend of a parent, this can certainly arouse some pretty heated emotions. If someone clocked Will in the head with a camera, then I would be tempted to grab the camera a clock the fella right back.
The lesson here is two-fold, Luna Maya had apparently agreed to an interview in the lobby once little Alleia was in the safety of the car. So, the gathered throng of infotainment journalists would have got their interview and obligatory shots if the had been a little more patient. the second lesson is do not vent your frustrations on Twitter no matter how justified you feel about it.
The spat, if the Twitter message can be called such, has escalated with the Indonesian Journalists Association threatening to take legal action against Luna for allegedly comparing them to prostitutes. The comparison to murderers was a little harsh, but the comparison to prostitutes probably is not so harsh.
In fact, it is probably a slur against all the prostitutes out there. Let's face it, infotainment journalists and photographers sell their assets to those willing to pay for it, similar to prostitutes. But, on a more serious note, the Indonesian Association of Journalists might also want to consider that one of their members was responsible for the assault of a child. My question would be, "does the Indonesian Association of Journalists really want to pursue this one?"
Most people might have an insatiable appetite for celebrity gossip and news, but most of these people would also balk at the idea that journalists need to assault and harm children in order to get their pound of flesh.
Maybe it is time that the government considered putting into place specific laws that protect celebrities from over-zealous infotainment journalists. And, perhaps it is also time that those that drive the market, infotainment publishers started to self-regulate what is acceptable and what is not when it comes to getting that all important shot or all important interview.
Public figures are what they are, but this does not mean that they forfeit all their rights to privacy because they have appeared in a film or worked as a presenter on TV.
It is time the infotainment industry got their collective act together and showed some class.
29 August 2009
Facebook -- Dangerous?

Have you ever wondered how embarrassing or dangerous Facebook can be? If you have not, or even if you have, then this will most definitely be of interest to you.
This is certainly going to be a WTF have I done. But, in any event, Michael sounds like the man!
(You might have to enlarge the picture to read it or click on the embedded link!)
24 August 2009
Anonymous Blogger -- Outed By the Courts & Google...

This is a follow-up to an earlier post on anonymous blogging and whether one can be truly anonymous when they blog, particularly if they are writing content that offends someone and they decide to take legal action. You can read that post here.
The anonymous blogger is Rosemary Port, a 29-year-old fashion student from New York, and she is so unhappy about Google giving up her identity and breaching her right to privacy that she is allegedly going to sue Google for USD 15 million.
Port's lawyer, Salvatore Strazzullo, seems to think that the case has enough legs to get all the way to the US Supreme Court. The arguments that Strazzullo are going to run with revolve around the fact that Google has "breached its fiduciary duty to protect her [Port] expectation of anonymity".
However, the other likely angles include that Cohen had a hand in publishing the sexually provocative pictures of herself and that the defamation action was nothing more than an attempt drum up some publicity for herself and defame Port into the bargain. Furthermore, Cohen has described herself as a "serial monogamist". Interesting choice of words to accompany the pictures posted of her.
This case would seem to have some ways to go.
A long story short, Port created a blog called "Skanks in NYC" and it seems that the only 'skank' Port focused on was Liskula Cohen. Cohen was offended and felt she had been defamed but was unable to proceed with any claim against the person doing the defaming because the blog was anonymous. Jumping forward, Cohen sues Google to get the identity of the anonymous blogger, the court decides that Google must hand over the identity, Google hands over the identity, and Port is outed.
Strangely enough, Cohen has 'forgiven' Port and pretty much brushed the matter off as Port being "an irrelevant person in my life". It would seem she knew Port, but obviously they were far from being friends. Although, they seem to have known each other well-enough that Cohen was comfortable allegedly trashing Port to Port's ex-boyfriend. Ahhhhh, the lives of models and fashion students.
It will be interesting to see if all the talk of taking this case all the way to the US Supreme Court comes to fruition.
19 August 2009
How Anonymous Are You Really When You Blog?

Here is some food for thought for those of you out there, me included, who blog and say things that may or may not be considered defamatory.
A model, Liskula Cohen, has successfully sued Google for the name of an anonymous blogger who she alleges defamed her on a blog hosted by Google. The blog was called Skanks in NYC. The essence of the defamation case is that the anonymous blogger called Cohen a "skank" and an "old hag".
The anonymous blogger identified Cohen as the "skankiest in NYC". This was then followed with, "How old is this skank? 40 something? She's a psychotic, lying, whoring, still going to clubs at her age, skank." I am guessing that this does not leave much to one's imagination. Is it defamatory? On face value, probably.
However, there are defenses to defamation that if the decision survives appeal, assuming there is one, then the anonymous blogger would likely be arguing an extension of what the blogger's lawyer has put forward so far, namely: this was mere opinion and "trash talk" rather than any intent to defame. The extension here would be to argue that, in essence, what has been said is in fact true.
Judge Joan Madden has ruled in favour of Cohen and has ordered that Google must provide the name of the anonymous blogger. It is expected that the name of the anonymous blogger is to be revealed in court as a means of allowing Cohen to proceed with her defamation action against the currently anonymous blogger. According to Judge Madden the assertions made were that Cohen was sexually promiscuous and the accompanying photos on the blog bore this intent out sufficiently well.
Cohen's modelling career was seemingly cut short when she was glassed in 2007. The resulting injuries required 46 stitches to close the wounds. Cohen was glassed when she objected to some drunk bloke stealing a bottle of vodka off her table. The bloke decided his best course of action in response to this objection was to glass Cohen in the face. The bloke was sent to jail, and deservedly so.
The case is interesting because of the potential implications. These implications are that anyone who thinks they are blogging anonymously may not be so anonymous after all. There are undoubtedly many techno savvy individuals out there with the knowledge and means of ratcheting up their anonymity to make discovery of their true identities even more difficult or impossible.
I am not one of them. I have enough trouble just using the features of blogger to be worried about whether I am anonymous or not. That said, I am using my real name to blog. So, if I have defamed you then you know where I reside in cyberspace.
There is a belief that this decision will open the floodgates to litigation and defamation claims based on comments written online that people do not agree with. This would seemingly be the case.
It is worth noting that the blog in question was shut down in March of this year. The blog contained only five entries and all of them related to Cohen. My guess is that the anonymous blogger is likely someone she knows or someone she has had some acquaintance with. Alternatively, it is, or was, a cyber-stalker which is a scary thought.
Something for all you anonymous bloggers out there to consider is this statement from Google:
"We sympathise with anyone who may be the victim of cyber bullying. We also take great care to respect privacy concerns and will only provide information about a user in response to a subpoena or other court order." So, make sure you re-read the privacy statement from Google again if you thought what you clicked guaranteed your absolute privacy.
Food for thought.
22 June 2009
Privacy Rights...
This particular post reflects neither my interest in all things Australian or Indonesian. However, there are interesting parallels between things happening in Bozeman, Montana, and Australia and Indonesia as this post relates to privacy, rights, and civil liberties.
It seems that the city of Bozeman in their standard job application form is asking for prospective employees to divulge their passwords to myriad of sites and accounts that they may hold. This includes your standard Facebook and other social networking sites like MySpace, and it also includes sites such as Google, You Tube, and Yahoo as well.
Now, according to the city, the failure to provide these passwords is not going to draw a negative inference on your application and nor will it preclude you from the advertised position. The city intends to use your passwords as a means of verifying the information that you provided in your application. I wonder whatever happened to calling an applicant's referees?
I guess I would not be getting a job in Bozeman anytime soon if this policy is continued. As a matter of principle I would not be supplying my passwords to anyone. Most civil libertarians are up in arms that this is a clear invasion of one's right to privacy. However, this is also an issue that relates to identity theft. Just about everyone that requires you to have a password unequivocally states that under no circumstances should you give your password to others. This is generally to ensure that your identity cannot be stolen and used by others.
One of the rationale being proffered is that it is reasonable that if a person has a public profile that an employer has a right to check it out. I agree, if a prospective employee has a public profile listed somewhere then there is no reason why a prospective employer cannot go and check it out. I would have no problems with a prospective employer reading my Facebook profile or my blog. However, I would object to the idea that they would need my passwords to get into the inner sanctum of my Facebook account or blog. Those parts are not part of the public profile or the public record and as such access to them by a prospective employer is an unreasonable request.
The idea that an employer has this right to this level of access to the personal information that the divulging of these type of passwords provides begs the question, "would an employer be comfortable with a prospective employee having the same degree and level of access to company, corporate, and management information in order to make a decision about whether to apply to work for the company?"
Next we will be hearing that we have to supply this information in order that employers can make certain they are not employing terrorists or other "undesirables".
I guess my point is, once you start on this slippery slope of openness or transparency, where does it stop?
It seems that the city of Bozeman in their standard job application form is asking for prospective employees to divulge their passwords to myriad of sites and accounts that they may hold. This includes your standard Facebook and other social networking sites like MySpace, and it also includes sites such as Google, You Tube, and Yahoo as well.
Now, according to the city, the failure to provide these passwords is not going to draw a negative inference on your application and nor will it preclude you from the advertised position. The city intends to use your passwords as a means of verifying the information that you provided in your application. I wonder whatever happened to calling an applicant's referees?
I guess I would not be getting a job in Bozeman anytime soon if this policy is continued. As a matter of principle I would not be supplying my passwords to anyone. Most civil libertarians are up in arms that this is a clear invasion of one's right to privacy. However, this is also an issue that relates to identity theft. Just about everyone that requires you to have a password unequivocally states that under no circumstances should you give your password to others. This is generally to ensure that your identity cannot be stolen and used by others.
One of the rationale being proffered is that it is reasonable that if a person has a public profile that an employer has a right to check it out. I agree, if a prospective employee has a public profile listed somewhere then there is no reason why a prospective employer cannot go and check it out. I would have no problems with a prospective employer reading my Facebook profile or my blog. However, I would object to the idea that they would need my passwords to get into the inner sanctum of my Facebook account or blog. Those parts are not part of the public profile or the public record and as such access to them by a prospective employer is an unreasonable request.
The idea that an employer has this right to this level of access to the personal information that the divulging of these type of passwords provides begs the question, "would an employer be comfortable with a prospective employee having the same degree and level of access to company, corporate, and management information in order to make a decision about whether to apply to work for the company?"
Next we will be hearing that we have to supply this information in order that employers can make certain they are not employing terrorists or other "undesirables".
I guess my point is, once you start on this slippery slope of openness or transparency, where does it stop?
04 June 2009
Really? Privacy?
I went to the doctor yesterday to get a check-up. The check-up was more for peace of mind rather than anything else, particularly when you have recently been blessed with the addition we have to our family in the form of Will. You tend to want to make sure everything is running smoothly and like a well-oiled machine. Anyways, the end result of the trip to the doctor was a blood test this morning.
The doctor said something about testing blood sugar levels and cholesterol, and then gave me a standard form for the lab/pathology people. I just whacked the form in my bag and headed home without reading it.
This morning after fasting for 10 hours or so, off I headed to the lab, for the inevitable test.
It was a fascinating affair to be sure. The nurse or pathology person or whatever one is known as in a pathology lab gave me a serve because my medicare had a different last digit (which represents the number of cards you have had) was different to that which the doctor had printed on the form. Smile No. one and a promise to rectify the "problem" as soon as possible. Then it was off into the little room to be stabbed and have my blood drawn.
Now, while walking to the lab I took the opportunity to have a squiz at the form and see if I could work out what the letter codes meant for what was being tested. There seemed to be a lot more letters than what I believed I was being tested for, blood sugars and cholesterol. So, in my infinite wisdom, I figured I would ask the woman drawing my blood what all the letters meant. And, this is the fun part.
"I cannot tell you because of privacy legislation". Huh? And, on she goes, "Doctors are allowed to test your blood for all manner of things before talking to the patient". Huh? They can? I was struggling to contain myself from bursting out laughing considering the needle was still in my arm. But, I could not contain the smile. As this is total and utter crap.
So, in my most nonchalant of ways I asked her whose privacy was at stake when it was my blood? And, since when could doctors take samples from their patients without the patients knowledge? Unfortunately, I had filled up the necessary vials and she hurried out, presumably to the next but yet to arrive patient.
Oh well, I guess I will just have to ask the doctor once the results are in.
The doctor said something about testing blood sugar levels and cholesterol, and then gave me a standard form for the lab/pathology people. I just whacked the form in my bag and headed home without reading it.
This morning after fasting for 10 hours or so, off I headed to the lab, for the inevitable test.
It was a fascinating affair to be sure. The nurse or pathology person or whatever one is known as in a pathology lab gave me a serve because my medicare had a different last digit (which represents the number of cards you have had) was different to that which the doctor had printed on the form. Smile No. one and a promise to rectify the "problem" as soon as possible. Then it was off into the little room to be stabbed and have my blood drawn.
Now, while walking to the lab I took the opportunity to have a squiz at the form and see if I could work out what the letter codes meant for what was being tested. There seemed to be a lot more letters than what I believed I was being tested for, blood sugars and cholesterol. So, in my infinite wisdom, I figured I would ask the woman drawing my blood what all the letters meant. And, this is the fun part.
"I cannot tell you because of privacy legislation". Huh? And, on she goes, "Doctors are allowed to test your blood for all manner of things before talking to the patient". Huh? They can? I was struggling to contain myself from bursting out laughing considering the needle was still in my arm. But, I could not contain the smile. As this is total and utter crap.
So, in my most nonchalant of ways I asked her whose privacy was at stake when it was my blood? And, since when could doctors take samples from their patients without the patients knowledge? Unfortunately, I had filled up the necessary vials and she hurried out, presumably to the next but yet to arrive patient.
Oh well, I guess I will just have to ask the doctor once the results are in.
15 October 2008
Privacy -- The Virtual Strip Search
The privacy theme is one that resonates in all manner of places and in a large number of countries. Australia is currently trialling body scanning technology at a small number of airports with a view to providing enhanced security for flights.I have written on this previously here. The privacy issues here are that the technology does not have the ability to blur the genitals of the people that it screens. More accurately, it does have the ability to blur the genitals but the powers that be have decided not to. So, in essence the person sitting behind the monitor will be viewing you in all your glory. I wonder if they are taking volunteers for these screening positions.
The picture leaves very little to the imagination. It is worth noting that in this picture I can make out what appears to be bones in the lower legs and the knees of the person being screened. The idea is that the x-rays used are at the lower end of the spectrum and would require up to 10,000 screens before you would be in danger of excessive radiation exposure.
So, if you are a domestic traveller leaving Melbourne Airport over the next six weeks you may well be asked to test new x-ray scanners and not only be exposed to the x-rays but be exposed in other ways too.
The new X-ray backscatter body scanner has been described by some critics as a "virtual strip search". Looking at the image above you can see why. The trialling authorities have made it clear that they are not going to blur the images of the genitals. However, the technology has been set up so that faces are automatically blurred.
The blurring of the faces is an attempt to try and avoid claims that the technology violates privacy. Probably more important is that there are very explicit regulations in place with respect to the storage and access to any images that are saved. Even with faces blurred, the mere thought of these images appearing online in some porn site would bother many people.
The current procedures are that once a person walks through the scanner and they are clear of any nasty stuff like explosives, the screener presses a button and the image is automatically deleted. Sounds fair enough assuming that the screener is deleting the images.
Happy traveling!
14 October 2008
The Department of National Education, Student Data, and Privacy
There has been an interesting phenomenon occur over the past few days that highlights the power that blogging has in getting out a message and seeing changes made. The Treespotter posted a piece on the Department of National Education and their posting on their site of complete sets of student data.
The data itself is important in terms of administering the individual schools and perhaps also in terms of ensuring that the Department has up-to-date data on students so that it can do its job better. Well, at least, potentially more efficiently and effectively. There is no problem in collecting the data, the problem related only to the need to publish this data online.
There are a number of problems with publishing the names and addresses of some 30 million plus students online from primary school through to senior high school. The most likely of these problems would be identity theft and kidnapping. The identity theft would affect only a small number of students and more than likely those in senior high school who are 18 or 19 years old. They might have all manner of accounts and perhaps even credit cards.
Identity theft is pretty easy as the hacking into of Sarah Palin's email account highlights. If a candidate for the office of vice president and potentially the second in-line to the leadership of the free world is not safe, then what chance does some senior high school student in Indonesia have?
The kidnapping angle is also an interesting one and Indonesia, and in particular Jakarta, has had a few kidnappings occur of late. The idea that all of the research can be done online and at one site, in terms of targeting particular children, is frightening.
Kidnapping might only be one of the problems that could arise. Pedophiles might also find the detailed information useful in targeting certain children as well.
It is worth noting that the site and the downloadable files have been altered to remove the dates of birth and the addresses of the children whose names are included in the files. However, what is less clear is whether the Department has contacted Google and other search engines in order for them to have the cached and indexed files removed from their servers. If they have not then the files are still out there in the cyber world and can be recovered and reposted.
If you do not believe this to be so, then look no further than the ongoing fiasco of the Chinese gymnasts who competed in the Beijing Olympics. It was suspected that some of the Chinese gymnasts were under age, but the documentation provided suggested otherwise. Nevertheless, an enterprising individual managed to find cached files on a Chinese server that contained official documents stating that the ages of the gymnasts were not those contained in the passports provided as proof of their age.
The point, quite simply, is that until these files are removed from the search engines of Google and others the data is still out there. This is always going to be the problem of letting the genie out of the bottle. Once the genie is out, it is almost impossible to get it back in.
The privacy issues are also important. The law in Indonesia does not include a specific privacy law. However, there are privacy provisions in a number of laws that might be able to be used as a means of ensuring this kind of breach does not occur again. Some might argue that this disparate collection of provisions is no substitute for a specific law on privacy, and I might tend to agree. Nevertheless, there is enough in these provisions to prove that Indonesia recognizes a right to privacy and there is also enough in these provisions to sustain a case for a breach of privacy.
For example, Indonesia has ratified the International Covenant on Civil and Political Rights as Law No. 12 of 2005. It is clear in Article 17 of the Covenant that there is a right to privacy and that this right is one that cannot be arbitrarily interfered with. Simply, the Department's arbitrary and unilateral decision to post this private and personal data on the Internet without the express permission of the parents of the students involved is a breach.
Privacy also makes an appearance in Law No. 11 of 2008 on Information and Electronic Transactions. In this Law it relates more to investigations, but it must be noted that the principle is that there is a conceptual understanding of privacy and the damage that can be done if private or confidential information is publicly released.
Furthermore, the Supreme Court of Indonesia has also recognized that individuals have a right to privacy and that their personal or confidential information must not be traded in the public domain. In Article 22 of the Decision of the Chief Justice No. 144 of 2007 it is explicitly clear that any court official that is in a position to provide private or personal information must take into consideration any losses that might be sustained by the individual whose information is released.
Privacy has also been a feature of a Joint Decision of the General Election Commission and the Indonesian Broadcasting Commission. The Decision, No. 12 of 2004, states in Article 15 that candidates in broadcast debates cannot attack issues that are private. Once again, this presupposes that some information cannot be brought to the public domain without the express permission of the individual to whom that information relates.
The Child Protection Law, Law No. 23 of 2002, does not expressly deal with privacy. However, it is clear that the rights of the child are paramount and it is reasonable to assume that a sustainable argument can be made that the posting of the Department of National Education files on the Internet is not in the best interests of children.
In human rights terms the right to collect, collate, provide, and access information is set out in Article 14 of the Law No. 39 of 1999 on Human Rights. This provision supports the Department's right to collect the information. However, the provision also requires that the purpose of the collection of the information must be clear and for a valid purpose.
Article 47 and 48 of the Indonesian Criminal Procedure Code provide the power to investigators to open mail and other correspondence in the course of an investigation. However, if the correspondence does not relate to the criminal case that they are investigating then any information that the learn from the correspondence is to be kept secret. Although this provision does not specifically relate to privacy, it does highlight that, at least, conceptually Indonesia recognizes a right to privacy to some degree.
With the passage of the Freedom of Public Information Law (Law No. 14 of 2008) it is clear that some personal and private information is not to be provided to the public and presumably this would include posting it in a public domain such as the Internet.
For example, Article 6 of this Law is explicit that personal information cannot be provided by a public agency, and the Department of National Education would be classified as such, and therefore the information included in the school children files is conceivably out of play with regards to access by the general public. The type of information contained in the Department files would also seem to be protected from public release by the provisions of Article 17.
The Department has removed the most obvious breaches from their files. Yet, the damage might have already been done with the letting of the genie out of the bottle. This is a valuable lesson in thinking laterally and outside of the box. In this day and age of rapidly developing technology and an ever-smaller world, one must think their actions through from myriad of possibilities before uploading information to the Web.
It would seem that to try and close the chapter on this book the Department of National Education needs to make requests to all search engines that they do whatever they can to ensure that all cached and indexed files relating to this data are removed and / or are made inaccessible.
Information is important, but some information must remain private and this is a case in point.
The data itself is important in terms of administering the individual schools and perhaps also in terms of ensuring that the Department has up-to-date data on students so that it can do its job better. Well, at least, potentially more efficiently and effectively. There is no problem in collecting the data, the problem related only to the need to publish this data online.
There are a number of problems with publishing the names and addresses of some 30 million plus students online from primary school through to senior high school. The most likely of these problems would be identity theft and kidnapping. The identity theft would affect only a small number of students and more than likely those in senior high school who are 18 or 19 years old. They might have all manner of accounts and perhaps even credit cards.
Identity theft is pretty easy as the hacking into of Sarah Palin's email account highlights. If a candidate for the office of vice president and potentially the second in-line to the leadership of the free world is not safe, then what chance does some senior high school student in Indonesia have?
The kidnapping angle is also an interesting one and Indonesia, and in particular Jakarta, has had a few kidnappings occur of late. The idea that all of the research can be done online and at one site, in terms of targeting particular children, is frightening.
Kidnapping might only be one of the problems that could arise. Pedophiles might also find the detailed information useful in targeting certain children as well.
It is worth noting that the site and the downloadable files have been altered to remove the dates of birth and the addresses of the children whose names are included in the files. However, what is less clear is whether the Department has contacted Google and other search engines in order for them to have the cached and indexed files removed from their servers. If they have not then the files are still out there in the cyber world and can be recovered and reposted.
If you do not believe this to be so, then look no further than the ongoing fiasco of the Chinese gymnasts who competed in the Beijing Olympics. It was suspected that some of the Chinese gymnasts were under age, but the documentation provided suggested otherwise. Nevertheless, an enterprising individual managed to find cached files on a Chinese server that contained official documents stating that the ages of the gymnasts were not those contained in the passports provided as proof of their age.
The point, quite simply, is that until these files are removed from the search engines of Google and others the data is still out there. This is always going to be the problem of letting the genie out of the bottle. Once the genie is out, it is almost impossible to get it back in.
The privacy issues are also important. The law in Indonesia does not include a specific privacy law. However, there are privacy provisions in a number of laws that might be able to be used as a means of ensuring this kind of breach does not occur again. Some might argue that this disparate collection of provisions is no substitute for a specific law on privacy, and I might tend to agree. Nevertheless, there is enough in these provisions to prove that Indonesia recognizes a right to privacy and there is also enough in these provisions to sustain a case for a breach of privacy.
For example, Indonesia has ratified the International Covenant on Civil and Political Rights as Law No. 12 of 2005. It is clear in Article 17 of the Covenant that there is a right to privacy and that this right is one that cannot be arbitrarily interfered with. Simply, the Department's arbitrary and unilateral decision to post this private and personal data on the Internet without the express permission of the parents of the students involved is a breach.
Privacy also makes an appearance in Law No. 11 of 2008 on Information and Electronic Transactions. In this Law it relates more to investigations, but it must be noted that the principle is that there is a conceptual understanding of privacy and the damage that can be done if private or confidential information is publicly released.
Furthermore, the Supreme Court of Indonesia has also recognized that individuals have a right to privacy and that their personal or confidential information must not be traded in the public domain. In Article 22 of the Decision of the Chief Justice No. 144 of 2007 it is explicitly clear that any court official that is in a position to provide private or personal information must take into consideration any losses that might be sustained by the individual whose information is released.
Privacy has also been a feature of a Joint Decision of the General Election Commission and the Indonesian Broadcasting Commission. The Decision, No. 12 of 2004, states in Article 15 that candidates in broadcast debates cannot attack issues that are private. Once again, this presupposes that some information cannot be brought to the public domain without the express permission of the individual to whom that information relates.
The Child Protection Law, Law No. 23 of 2002, does not expressly deal with privacy. However, it is clear that the rights of the child are paramount and it is reasonable to assume that a sustainable argument can be made that the posting of the Department of National Education files on the Internet is not in the best interests of children.
In human rights terms the right to collect, collate, provide, and access information is set out in Article 14 of the Law No. 39 of 1999 on Human Rights. This provision supports the Department's right to collect the information. However, the provision also requires that the purpose of the collection of the information must be clear and for a valid purpose.
Article 47 and 48 of the Indonesian Criminal Procedure Code provide the power to investigators to open mail and other correspondence in the course of an investigation. However, if the correspondence does not relate to the criminal case that they are investigating then any information that the learn from the correspondence is to be kept secret. Although this provision does not specifically relate to privacy, it does highlight that, at least, conceptually Indonesia recognizes a right to privacy to some degree.
With the passage of the Freedom of Public Information Law (Law No. 14 of 2008) it is clear that some personal and private information is not to be provided to the public and presumably this would include posting it in a public domain such as the Internet.
For example, Article 6 of this Law is explicit that personal information cannot be provided by a public agency, and the Department of National Education would be classified as such, and therefore the information included in the school children files is conceivably out of play with regards to access by the general public. The type of information contained in the Department files would also seem to be protected from public release by the provisions of Article 17.
The Department has removed the most obvious breaches from their files. Yet, the damage might have already been done with the letting of the genie out of the bottle. This is a valuable lesson in thinking laterally and outside of the box. In this day and age of rapidly developing technology and an ever-smaller world, one must think their actions through from myriad of possibilities before uploading information to the Web.
It would seem that to try and close the chapter on this book the Department of National Education needs to make requests to all search engines that they do whatever they can to ensure that all cached and indexed files relating to this data are removed and / or are made inaccessible.
Information is important, but some information must remain private and this is a case in point.
12 October 2008
Privacy and Children
I was not going to post on this subject. I figured it had been done by the Treespotter and by my reckoning his readership is much bigger than mine and includes a lot of the same people. However, it is probably important that as many people as possible read about this stupidity and then write about it. Perhaps, the more it is written about will increase the chances that it will be talked about in the right circles, and then something will be done about it.The Department of National Education in their drive to greater transparency and accountability has decided in its infinite wisdom to post the names, student numbers, addresses, and other details of some several million students in easy to download excel files. These files have been available for a little while now.
I am not going to post the link even though I have it. I checked earlier today and it is still operational.
What this means. If you have school age children and they go to one of the schools on the list then in all likelihood their details and probably your address are online. This would seem to be a kidnapper's dream tool. As it limits their basic research to one site and provides them with all manner of information.
One of the problems is that these files have already been indexed by Google and most probably a whole lot of other search engines. The problem is that any request to remove these files from indexes and the cache memories or search engines will fall on deaf ears until such time as the Department of National Education removes them from their system. Simply, for Google and others to remove them would provide no solution as the next time indexing and caching was done the files would reappear.
What is interesting is that all those people that are in a position to do something about this are aware of it. There does not seem to be a lot of interest or urgency in getting these files and the information that they contain out of the public domain. This is where blogging and getting the word around might help in illuminating to those that can remove these files that this is a serious issue and people's privacy and the privacy of children is at stake. This is a public safety as well as a law and order issue.
The law in Indonesia would seem to provide some basic protections for privacy. However, the best protections might come from more recent Indonesian legislation that seeks to enact the intent of several human rights instruments such as those contained in the International Covenant on Civil and Political Rights and the UN Convention on the Protection of the Rights of the Child.
The need for access to information is critical. There is no dispute that the Department of Education needs this information to effectively and efficiently do its job. What is not so clear is why this information is needed in the public domain and what purpose it serves by being there.
More will follow as any updates become available (photo was found here).
Labels:
Child Rights,
Children,
Education,
ICCPR,
Indonesia,
Law,
Legislation,
Life,
Privacy
28 May 2008
Map Jack -- Roving Cameras



For any one that is not familiar with Google's Street View technology, then this is likely to scare you even more! Google has a service know as Street View, which is essentially small hatchback cars with a camera attached to the roof that then cruises the streets taking happy snappies of generally unsuspecting people. This strikes me as kind of like unscripted reality television at its worst. Not surprisingly a few civil libertarians and people snapped were a little upset at the invasion of their privacy.
To Google's credit they have developed automatic face-blurring technology that prevents easy identification. However, if the person viewing the picture knows who you are then face blurring technology might not save you any embarrassment.
But back to Map Jack. Map Jack offers a similar service and the template used is the Google Street View template. However, there are several additional navigation features that make it fun and the pictures are of a high resolution.
The service so far has photographed six cities that it has since uploaded to its site. Of the six, four are US cities and there are the Thai cities of Chiang Mai and Pattaya.
Without a doubt there will be some privacy concerns here, particularly as the resolution of the imagery is high. However, if for example you have been snapped on a public street coming out of a "massage" parlour, then the obvious question is has your privacy been invaded and how so, if you feel that it has?
12 April 2008
Information and Electronic Transactions
The House of Representatives (DPR) have finally been able to pass the Bill on Information and Electronic Transactions into what will become the prevailing law in this area (Undang-undang Informasi dan Transaksi Elektronik / UU ITE). The Bill first came before this DPR in September 2005 and this is the 96th bill to be passed into law by the DPR since 2004. It is worth pointing out that such a long gestation period is not uncommon for bills wanting to be passed into law. Unfortunately, it is not always the case of better late than never.
Much of the public commentary over the past few days has focused on Article 27(1) which prohibits the transmission, distribution, and the making available of material in an electronic form that breaches prevailing moral standards. However, the bill does not seem to criminalize those that choose to download this morally questionable material unless where once it is downloaded it is then transmitted to someone else.
However, the bill is about so much more than trying to limit the spread of what is considered to be morally suspect material. The bill deals with subject matter such as electronic signatures, electronic contracts, domain names, and electronic transactions. The overriding theme of the bill is to increase legal certainty and security for electronic transactions.
Much of the focus of the bill will not be on what it permits but rather on what it prohibits. In addition to the focus on pornography noted earlier the bill explicitly prohibits any electronic communication that threatens physical violence or strikes fear into the reader of the communication. The potential criminal liability for this is up to 12 years imprisonment and / or fines of up to IDR 2 billion.
Other prohibitions are expected such as the interception and tapping of communications and then the misuse or abuse of personal data. This would include such things as identity theft.
The biggest question that the bill poses is enforcement; particularly where there conceivably are competing privacy rights. The bill is clear as to what is permitted and what is prohibited. Any Internet user is aware of the great amount of anonymity in cyber space and myriad of web logs (blogs) are testament to this.
However, the bill would seem to grant the necessary powers and authorities to search and seize any tools or equipment allegedly used in the commission of an offence. Yet, it must be noted that the bill stipulates that investigators must comply with prevailing laws and regulations as they relate to privacy, confidentiality, the provision of public services, and the integrity of data. Therefore, this must be interpreted as preventing investigators from conducting fishing expeditions for example by requesting all the data of an Internet service provider (ISP) in the hope of finding supporting evidence of a crime.
The definition of what constitutes evidence has been expanded beyond that of the provisions in current legislation to include specifically electronic information and electronic documents.
The world is a very different place than it was 5 years ago, 10 years ago, 20 years ago, or 50 years ago. We as a race of people are well and truly into the electronic age and much of our personal and professional existence relies on sophisticated technology. We can to all intents and purposes live online and never have to physically leave the places that we live, if we wanted to of course.
We can shop online for everything we need and do not need from groceries to books to pornography; we can work online; yes, just about everything we need to do is something that can be done online or electronically. Most of us if we thought about it would be able to identify an occasion where rather than get up out of our office chair and walk to a colleagues office we sent an email instead or an SMS in preference to calling and talking to a colleague or a friend. This in and of itself evidences how much of our lives are now dependent on technology.
We must therefore ask ourselves how safe are we in this virtual world? How safe are our identities? And, How safe are our transactions? If we do not ask ourselves these questions then we expose ourselves to considerable danger. For those that have never considered these issues the government has done so on your behalf and this bill is an attempt to provide regulatory certainty to information and electronic transactions that are conducted using the sophisticated technology now at our disposal.
The world has quickly become a borderless place in the sense that electronic transactions are instantaneous and cross traditional sovereign State lines without ever having to ask for directions or permission. This is in spite of some sovereign states trying to filter information and electronic transactions through selected and approved service providers. Most experts tend to agree that censorship and regulation in this way has often proved ineffective at best.
This phenomenon has given birth to cyber law and this bill fits within Indonesia’s developing cyber law regulatory framework.
A quick scan or reading of the ‘General Provisions’, which in an Indonesian law is usually where all the definitions of the terms are listed, highlights that the bill is about so much more than protecting Indonesians from themselves with respect to the perceived dangers of morally suspect behaviours such as pornography, gambling, and violence.
The definitions include entries for what constitutes an electronic transaction, what constitutes an electronic document, what constitutes an electronic agent, what constitutes an electronic certificate, what constitutes an electronic signature and the authentication and validity of any such signatures used in an electronic transaction, as well as who constitutes a sender and a receiver of an electronic document or piece of information.
Each of these definitions are important as this is a new area of law for most, including practitioners of the law who will ultimately be tasked with prosecuting or defending cases in this field along with the judges who will decide who is in breach of the provisions and who is not.
Article 2 purports to include a degree of extra-territoriality as it explicitly states that the provisions of this law apply to all persons who commit an act against the provisions of this law whether they are within the jurisdiction of the Republic of Indonesia or outside of it provided that the act committed is an offence either within the Republic of Indonesia or outside of it and it causes a loss to an Indonesian interest. The Elucidation to the Law states that the utilization of information technology is trans-national and therefore universal, which thereby allows Indonesia’s jurisdictional reach to extend beyond its physical borders and into the realm of cyber space.
It is likely that this extra-territorial jurisdiction that is proclaimed here is going to be heavily reliant on mutual legal assistance and bilateral extradition treaties.
The basic purpose of the bill is to:
a. to develop a smarter nation able to participate more fully in the world of information;
b. expand national trade and the national economy to improve the social welfare of the citizens;
c. increase the levels of effective and efficient public services;
d. provide broader and greater opportunities for citizens to develop their talents and skills; and
e. to provide security, justice, and legal certainty to users and providers of information technology.
The bill gets straight to the point in Article 5(1) in stating that electronic information, electronic documents, or any printed version of either is to be considered legally valid evidence. However, there are exceptions. In this case if there are certain documents that must be in written form or notarized, then an electronic version of these documents is presumably not acceptable evidence for the purposes of a criminal or civil hearing.
Interestingly, a business person who offers a product via an electronic system is obligated to provide all relevant information associated with the product being offered including any contract conditions, the producer of the product, and the product itself. Furthermore, these types of businesses must be certified by an accredited agency.
Electronic signatures are to be considered the same as any ordinary written signature and consequently binding at law provided it meets certain conditions. Generally, these conditions will require that evidence be adduced that the electronic signature at all relevant times was only under the control of the person who is alleged to be the owner of that signature.
In consideration of the binding nature of an electronic signature, the Law is explicit that any one who is involved in the use of electronic signatures is under a special duty of care to ensure the safety and security of the signature and the identity of the relevant person. Businesses and signature holders must pay particular note to this as Article 12(3) states unequivocally that any breach of the provisions relating to electronic signature exposes the person that causes the breach to be liable for all losses associated with the breach. This includes any legal consequences that arise in addition to the losses accrued.
The critical feature of electronic transactions is that they can be either public or private but in any case they are binding on the parties who are signatories to them. An electronic transaction that binds the parties also allows those parties to choose the forum to resolve any disputes or grievances that may arise in the course of their contractual relationship. This includes court based mechanisms or arbitration or any other form of alternative dispute resolution. It must be noted that where one of the parties is international then the prevailing law is to be International Commercial Law.
As was noted earlier much of the public debate and perhaps much private debate has centered more on what is prohibited under the provisions of the law as opposed to what is permitted. Furthermore, much of this debate has focused on the pornography components to the detriment of other critical prohibitions contained in the Law.
In terms of pornography the target of the legislation is clearly the disseminators, distributors, and transmitters of the offending material as opposed to the downloader of the suspect pictures. Nevertheless, businesses should be aware that for their own protection filters should be installed so that a legitimate claim to making an attempt to restrict access from office servers was made. It was pointed out earlier that historically software filters have been ineffective. This is not the point though.
It might prove for interesting legal argument if a company’s internal server did not block offending material but allowed it to pass through to individual employee inboxes as to whether this would be a breach of the distributing or transmission provisions, particularly if the receiver of the offending material was then to forward it to all their friends back through the internal servers of the company and out into cyber space. It may be better to adopt “a better to be safe than sorry” attitude in this regard.
Aside from pornography the Law also explicitly prohibits gambling, defamation and slander, as well as threats of violence or just threats generally.
Furthermore, the Law prohibits the spreading of lies that are likely to result in a loss to consumers partaking in an electronic transaction. The Law also prohibits the spreading of information that is likely to lead to clashes between groups based on matters of race, ethnicity, and religion, among others.
The Law also explicitly prohibits the sending of threats or other information that is intended to cause fear in the receiver of that information.
Hacking in all its forms are prohibited with the simple provision that prohibits access by any means by anyone to the electronic system of another. This is then elaborated to include specific motivations such as to obtain personal data and information. The Law also prohibits interception of electronic documents and the tapping of electronic communications. These provisions obviously include exceptions in order to facilitate the work of law enforcement.
Piracy in all its forms also is prohibited. This includes the standard prohibitions against the piracy of hardware and software but also includes the reproduction of computer codes access codes, among others.
The Law provides for terms of imprisonment up to 12 years and fines of up to IDR 12 billion for the standard breaches noted earlier. However, where there are aggravating circumstances these terms of imprisonment and fines can be extended by a 1/3 or 2/3 depending on the breach and who it is committed against.
The closing provisions provide that all of the subsidiary legislation that is required to give force to this Law must be issued and enacted no later than two years after the law comes in to force. This law will come into full force once signed by the President or after 30 days from 25 March 2008.
It is clear from the provisions in the new Law that the government is taking seriously the need to regulate in the sphere of cyber space. The reality is that as time passes more and more of peoples’ personal and professional lives will be conducted online. The impact is that over time governments’ are also going to have to provide more and more of their public services online to satisfy the demand of people not wanting to travel to a government office to complete a form or apply for a permit.
This in turn means that there will be vast amounts of personal information, whether it be about individuals or corporations that if abused would conceivably result in very significant losses.
Therefore, this is a responsible piece of legislation. It may not be perfect and some of the imperfections have already been alluded to, but in comparison to a completely unregulated area of law, this is a significant improvement.
Much of the public commentary over the past few days has focused on Article 27(1) which prohibits the transmission, distribution, and the making available of material in an electronic form that breaches prevailing moral standards. However, the bill does not seem to criminalize those that choose to download this morally questionable material unless where once it is downloaded it is then transmitted to someone else.
However, the bill is about so much more than trying to limit the spread of what is considered to be morally suspect material. The bill deals with subject matter such as electronic signatures, electronic contracts, domain names, and electronic transactions. The overriding theme of the bill is to increase legal certainty and security for electronic transactions.
Much of the focus of the bill will not be on what it permits but rather on what it prohibits. In addition to the focus on pornography noted earlier the bill explicitly prohibits any electronic communication that threatens physical violence or strikes fear into the reader of the communication. The potential criminal liability for this is up to 12 years imprisonment and / or fines of up to IDR 2 billion.
Other prohibitions are expected such as the interception and tapping of communications and then the misuse or abuse of personal data. This would include such things as identity theft.
The biggest question that the bill poses is enforcement; particularly where there conceivably are competing privacy rights. The bill is clear as to what is permitted and what is prohibited. Any Internet user is aware of the great amount of anonymity in cyber space and myriad of web logs (blogs) are testament to this.
However, the bill would seem to grant the necessary powers and authorities to search and seize any tools or equipment allegedly used in the commission of an offence. Yet, it must be noted that the bill stipulates that investigators must comply with prevailing laws and regulations as they relate to privacy, confidentiality, the provision of public services, and the integrity of data. Therefore, this must be interpreted as preventing investigators from conducting fishing expeditions for example by requesting all the data of an Internet service provider (ISP) in the hope of finding supporting evidence of a crime.
The definition of what constitutes evidence has been expanded beyond that of the provisions in current legislation to include specifically electronic information and electronic documents.
The world is a very different place than it was 5 years ago, 10 years ago, 20 years ago, or 50 years ago. We as a race of people are well and truly into the electronic age and much of our personal and professional existence relies on sophisticated technology. We can to all intents and purposes live online and never have to physically leave the places that we live, if we wanted to of course.
We can shop online for everything we need and do not need from groceries to books to pornography; we can work online; yes, just about everything we need to do is something that can be done online or electronically. Most of us if we thought about it would be able to identify an occasion where rather than get up out of our office chair and walk to a colleagues office we sent an email instead or an SMS in preference to calling and talking to a colleague or a friend. This in and of itself evidences how much of our lives are now dependent on technology.
We must therefore ask ourselves how safe are we in this virtual world? How safe are our identities? And, How safe are our transactions? If we do not ask ourselves these questions then we expose ourselves to considerable danger. For those that have never considered these issues the government has done so on your behalf and this bill is an attempt to provide regulatory certainty to information and electronic transactions that are conducted using the sophisticated technology now at our disposal.
The world has quickly become a borderless place in the sense that electronic transactions are instantaneous and cross traditional sovereign State lines without ever having to ask for directions or permission. This is in spite of some sovereign states trying to filter information and electronic transactions through selected and approved service providers. Most experts tend to agree that censorship and regulation in this way has often proved ineffective at best.
This phenomenon has given birth to cyber law and this bill fits within Indonesia’s developing cyber law regulatory framework.
A quick scan or reading of the ‘General Provisions’, which in an Indonesian law is usually where all the definitions of the terms are listed, highlights that the bill is about so much more than protecting Indonesians from themselves with respect to the perceived dangers of morally suspect behaviours such as pornography, gambling, and violence.
The definitions include entries for what constitutes an electronic transaction, what constitutes an electronic document, what constitutes an electronic agent, what constitutes an electronic certificate, what constitutes an electronic signature and the authentication and validity of any such signatures used in an electronic transaction, as well as who constitutes a sender and a receiver of an electronic document or piece of information.
Each of these definitions are important as this is a new area of law for most, including practitioners of the law who will ultimately be tasked with prosecuting or defending cases in this field along with the judges who will decide who is in breach of the provisions and who is not.
Article 2 purports to include a degree of extra-territoriality as it explicitly states that the provisions of this law apply to all persons who commit an act against the provisions of this law whether they are within the jurisdiction of the Republic of Indonesia or outside of it provided that the act committed is an offence either within the Republic of Indonesia or outside of it and it causes a loss to an Indonesian interest. The Elucidation to the Law states that the utilization of information technology is trans-national and therefore universal, which thereby allows Indonesia’s jurisdictional reach to extend beyond its physical borders and into the realm of cyber space.
It is likely that this extra-territorial jurisdiction that is proclaimed here is going to be heavily reliant on mutual legal assistance and bilateral extradition treaties.
The basic purpose of the bill is to:
a. to develop a smarter nation able to participate more fully in the world of information;
b. expand national trade and the national economy to improve the social welfare of the citizens;
c. increase the levels of effective and efficient public services;
d. provide broader and greater opportunities for citizens to develop their talents and skills; and
e. to provide security, justice, and legal certainty to users and providers of information technology.
The bill gets straight to the point in Article 5(1) in stating that electronic information, electronic documents, or any printed version of either is to be considered legally valid evidence. However, there are exceptions. In this case if there are certain documents that must be in written form or notarized, then an electronic version of these documents is presumably not acceptable evidence for the purposes of a criminal or civil hearing.
Interestingly, a business person who offers a product via an electronic system is obligated to provide all relevant information associated with the product being offered including any contract conditions, the producer of the product, and the product itself. Furthermore, these types of businesses must be certified by an accredited agency.
Electronic signatures are to be considered the same as any ordinary written signature and consequently binding at law provided it meets certain conditions. Generally, these conditions will require that evidence be adduced that the electronic signature at all relevant times was only under the control of the person who is alleged to be the owner of that signature.
In consideration of the binding nature of an electronic signature, the Law is explicit that any one who is involved in the use of electronic signatures is under a special duty of care to ensure the safety and security of the signature and the identity of the relevant person. Businesses and signature holders must pay particular note to this as Article 12(3) states unequivocally that any breach of the provisions relating to electronic signature exposes the person that causes the breach to be liable for all losses associated with the breach. This includes any legal consequences that arise in addition to the losses accrued.
The critical feature of electronic transactions is that they can be either public or private but in any case they are binding on the parties who are signatories to them. An electronic transaction that binds the parties also allows those parties to choose the forum to resolve any disputes or grievances that may arise in the course of their contractual relationship. This includes court based mechanisms or arbitration or any other form of alternative dispute resolution. It must be noted that where one of the parties is international then the prevailing law is to be International Commercial Law.
As was noted earlier much of the public debate and perhaps much private debate has centered more on what is prohibited under the provisions of the law as opposed to what is permitted. Furthermore, much of this debate has focused on the pornography components to the detriment of other critical prohibitions contained in the Law.
In terms of pornography the target of the legislation is clearly the disseminators, distributors, and transmitters of the offending material as opposed to the downloader of the suspect pictures. Nevertheless, businesses should be aware that for their own protection filters should be installed so that a legitimate claim to making an attempt to restrict access from office servers was made. It was pointed out earlier that historically software filters have been ineffective. This is not the point though.
It might prove for interesting legal argument if a company’s internal server did not block offending material but allowed it to pass through to individual employee inboxes as to whether this would be a breach of the distributing or transmission provisions, particularly if the receiver of the offending material was then to forward it to all their friends back through the internal servers of the company and out into cyber space. It may be better to adopt “a better to be safe than sorry” attitude in this regard.
Aside from pornography the Law also explicitly prohibits gambling, defamation and slander, as well as threats of violence or just threats generally.
Furthermore, the Law prohibits the spreading of lies that are likely to result in a loss to consumers partaking in an electronic transaction. The Law also prohibits the spreading of information that is likely to lead to clashes between groups based on matters of race, ethnicity, and religion, among others.
The Law also explicitly prohibits the sending of threats or other information that is intended to cause fear in the receiver of that information.
Hacking in all its forms are prohibited with the simple provision that prohibits access by any means by anyone to the electronic system of another. This is then elaborated to include specific motivations such as to obtain personal data and information. The Law also prohibits interception of electronic documents and the tapping of electronic communications. These provisions obviously include exceptions in order to facilitate the work of law enforcement.
Piracy in all its forms also is prohibited. This includes the standard prohibitions against the piracy of hardware and software but also includes the reproduction of computer codes access codes, among others.
The Law provides for terms of imprisonment up to 12 years and fines of up to IDR 12 billion for the standard breaches noted earlier. However, where there are aggravating circumstances these terms of imprisonment and fines can be extended by a 1/3 or 2/3 depending on the breach and who it is committed against.
The closing provisions provide that all of the subsidiary legislation that is required to give force to this Law must be issued and enacted no later than two years after the law comes in to force. This law will come into full force once signed by the President or after 30 days from 25 March 2008.
It is clear from the provisions in the new Law that the government is taking seriously the need to regulate in the sphere of cyber space. The reality is that as time passes more and more of peoples’ personal and professional lives will be conducted online. The impact is that over time governments’ are also going to have to provide more and more of their public services online to satisfy the demand of people not wanting to travel to a government office to complete a form or apply for a permit.
This in turn means that there will be vast amounts of personal information, whether it be about individuals or corporations that if abused would conceivably result in very significant losses.
Therefore, this is a responsible piece of legislation. It may not be perfect and some of the imperfections have already been alluded to, but in comparison to a completely unregulated area of law, this is a significant improvement.
10 April 2008
Google Maps Street View



Got any privacy concerns? Well, if you do then you will need to get 'em sorted out as Google is coming to get ya through its Google Maps "Street View" service! Google does not see any privacy concerns here as the vehicles that take these happy snappies are very easily identified in the sense that they are decked out in the Google colours with a roof mounted camera!
Besides, and as Google claims, any content that people find invades their privacy or is inappropriate they can ask that Google take it down or remove it from the site. However, as fair as this might sound on face value, even an inexperienced Internet user will be able to tell you that once the image is uploaded the damage is already done! Indonesians should be acutely aware of this with the latest attempts of the Indonesian government to prevent the spread of Geert Wilders film into Indonesia.
Yet, there are other issues aside from the fact that Google is hiding behind the claim that it is only filming in public places and the very definition of a public place is that it is sans privacy. The question is where does the public domain start and the private domain end.
Can Google photograph someone in their car in their driveway or the parking lot of a shopping centre...perhaps in common and civil law jurisdictions lawyers with expertise in trespass are about to get plenty of work or so it would seem? What about where people who need to be protected from having their identities released, particularly a whistle blower or someone else in a witness protection program. An extreme and perhaps one of those rare to never happenings but even with the odds against it there is still that slim chance...then what? Google takes the image down and apologizes? Damage done! Google is being sued already for alleged invasions of privacy through the use of this service -- let's see how that plays out and then perhaps more definitive statements might be made on the privacy concerns.
In any event the rapid spread of mobile phone technology with camera and video capabilities should have educated people that they will need to be more vigilant with their conduct in both public and private places. This technology means that there is a budding Scorsese in all of us just waiting for that 15 minutes of grainy 3gp fame!
Subscribe to:
Posts (Atom)






