Tuesday, 14 March 2017

FA Premier League takes extra step to fight piracy - admission that DMCA is not working

Very interesting order from Justice Arnold this week in which, for a period from this Saturday to the end of this FAPL season, will require the main UK ISP's to block certain streaming server IP addresses which stream FAPL content live. The blocking will occur in real time based on information provided by a technical provider to the FAPL to the ISP's.

The FAPL have experimented with blocking orders before but previously they were aimed at websites and despite arguments to the contrary were fairly easily avoided using proxies.

Contained within the judgement were the following comments;

1. The problem of illegal streaming is getting bigger
2. The audiences are large
3. DMCA notices are not effective with non-compliant operators

Of the 3 criteria being used to justify the blocking one was kept confidential to minimise risk of circumvention  but the other two are;

1. FAPL and its contractor must reasonably believe that the server has the sole or predominant purpose of enabling or facilitating access to infringing streams of Premier League match footage.
2. FAPL and its contractor must not know or have reason to believe that the server is being used for any other substantial purpose.

Collateral damage is a key issue therefore.

Ian Mill QC instructed by DLA Piper acted for the FAPL.

Klipcorp IP will monitor the effectiveness of this approach this Saturday and report back on initial effectiveness levels.

If this approach works it will be a major step forward in dealing with piracy and hats off to the FAPL for taking the risk of failure here.

Areas likely to provide a technical challenge are;

Deliberate concealing or spoofing of the source video stream IP address leading to blocking of the wrong IP
Rapid automated switching of IP address between different hosts
Unanticipated collateral damage.


 More information early next week.


Thursday, 19 January 2017

The limits of consent to the use of personal data

When does yes really mean yes ? That is a very broad subject but it becomes very specific in the context of data protection.

The areas of data protection, cyber security and IP protection in the Digital Age generally are very much in the news. They are a slightly splintered area of law falling variously under the Data Protection Act 1998, the Computer Misuse Act 1990, Investigatory Powers Act 2016, Freedom of Information Act 2000, Human Rights Act 1998  and the Copyrights, Designs and Patents Act 1988 as amended and updated by various WIPO treaties.

A key tension is the balance between an individual’s right to privacy and protection of their personal data and IP balanced against the often quoted desire of the state to keep us safe. The rapid growth of the internet, computing power and increased storage capacity allow for unprecedented data collection and processing.

Generally hackers make the news and highlight security shortcomings leading to the Information Commissioners Office becoming involved. However serious breaches of Data Protection law occur without a hacker anywhere to be seen through the illegal use of data provided voluntarily.

In the case of the RSPCA (until recently taking some very aggressive positions in respect of private prosecution) they were collecting personal data from donors who were presented with the following notice;

“The RSPCA may allow other organisations whose aims are in sympathy with our own or whose offers will benefit animal welfare to contact our supporters, if you do not wish to hear from them please tick the box”

It seems that the RSPCA then decided this was carte blanche to use the data collected very broadly indeed and participated in a data sharing scheme called “reciprocate” without knowing who the other parties in the scheme were. They also provided data to wealth screening companies and participated in data matching and telematching schemes. On a few occasions they also released data on individuals who had opted out.

This was brought to the attention of the new Information Commissioner Elizabeth Denham via the press and unsurprisingly after a 9 month investigation serious breaches of the Data Protection Act were identified. A monetary penalty was issued of £25,000 but criminal charges could have been brought.

The Data Protection Act has at its heart 8 key principles of Data Protection with the first 2 being that personal data must be processed fairly and lawfully and that, crucially in this case, shall be obtained for a specified purpose and used consistently with that purpose. Generally to be lawful consent must have been obtained in respect of the purpose.

The Commissioners view was that the initial notice was too vague and ambiguous and did not provide data subjects with sufficient information. Consent must be freely given, specific and informed. Just ticking any old box does not do it.  Therefore the data subjects had not consented and therefore the data processing was illegal.

The Data Protection Act covers all personal data (with certain limited exemptions) which includes names, addresses and even IP addresses. Generally consent must be sought to process that data so everybody is going to need to take great care when collecting data to ensure proper consent has been obtained and also that if the person collecting the data (the data controller) decides to use the data for another purpose to seek fresh consent.

The world of big data is going to struggle a bit with this but perhaps has consoled itself that currently the maximum fine from the ICO is capped at £500,000. Fatal for an SME probably but merely a deduction for a large corporate. However new legislation proposes a fine of 4% of turnover.

Of the 8 principles of Data Protection only 1 is directly concerned with security of data (principle 7). Organisations and individuals need to devote resources to ensure the legal collection and management of personal data as well as making sure appropriate security is in place to avoid substantial fines and potential criminal prosecution.


Personal data collected which requires consent can only be lawfully used in ways which derive directly from the consent given. It has been said that personal data is like money and if so when you provide your personal data to a third party it is analogous to a loan on specific terms for a specific purpose.

Friday, 6 January 2017

2016 - how secure do you feel (about your data) ?

With thanks to Lewis Morgan, blogger in residence at IT Governance, for putting together a list of breaches in 2016 that he was aware of. Notable by it's absence is the alleged hack of the US Elections which was possibly the Russians, or possibly the Democrats or possibly Elvis Presley from beyond the grave.

In any event it certainly shows that the hackers look to have the upper hand at the moment.

2016 Cyber Attacks & Data Breaches

US health insurer Centene loses 950,000 people’s records

Asda website leaves customer details vulnerable for 677 days

Etihad Airways investigating data breach dating back to 2013

Wendy’s Probes Reports of Credit Card Breach

Bitcoin Worth $USD 6 Million Stolen

Hackers have stolen €50 million from an aerospace parts manufacturer

Linux Mint hacked – lone attacker creates botnet

Lincolnshire Council forced to use pen and paper after ransomware attack

@ChileanCrew Hacks, Leaks Details for 300,000 Chilean Citizens Looking for State Benefits

9000+ Department of Homeland Security staff have their details leaked by hacker

3,000 Tidewater Community College workers victimized in W-2 scam

Attacker compromises information of 250K in Bailey’s data breach

Cyber criminals steal $25 million from Russian banks via phishing attack

Rosen Hotel chain was hit by credit card-stealing malware for 17 months

Minecraft community lifeboat suffers data breach affecting seven million members

CoinWallet Bitcoin Trader Shuts Down Following Data Breach

93.4 million Mexicans at risk after voter database breach

BeautifulPeople.com Leaks Very Private Data of 1.1 Million ‘Elite’ Daters — And It’s All For Sale

ShapeShift loses $230,000 in bitcoin data breach – ex-employee to blame

Trump Hotel chain suffers data breach again

MySpace and Tumblr hit by ‘mega breach’

117 million hacked LinkedIn email addresses and passwords put up for sale

Kiddicare customers at risk after data spills from test server

EPISD employee accounts hacked, money stolen

Payroll vendor employee falls for phishing scam, all clients’ W-2 data involved

1.4 Billion Yen Stolen From 1,400 Japanese ATMs

154 million voter records exposed, revealing gun ownership, Facebook profiles, and more

77K accounts of Financial Giant, State Farm, leaked due to DAC Group Hack

Muslim Match dating website hack exposes more than half a million intimate messages

45 million records from over 1100 Verticalscope.com domains and communities hacked and leaked

51 Million iMesh Passwords Dumped Online

Personal info on 7.93 million people feared leaked

King’s counselling department breaches students’ privacy

Athens Orthopedic Clinic to begin notifying patients of hack

WikiLeaks Put Women in Turkey in Danger, for No Reason

10 million customer’s data leaked from online shopping site

‘Warframe’ Hacked, Details on 775,000 Players Traded

Illinois online voter registration portal hacked, information compromised

Omegle, the Popular ‘Chat with Strangers’ Service Leaks Your Dirty Chats and Personal Info

Data for 6 Million Minecraft Gamers Stolen from Leet.cc Servers

SCAN Health Plan notifying members of unauthorized access to their information

Dominican Hospital notifies patients whose PHI was sent to wrong health plan

Epic’s forums hacked again, with thousands of logins stolen

Turkish Hackers Launch Second Cyber-Attack on Killeen’s Website

Defense university computers hacked, ‘information secure’

Olympics: Hackers attack Russian whistleblower’s doping account

Florida Bar Association hacked, members’ data leaked

6.6 million plaintext passwords exposed as site gets hacked to the bone

Russian hackers leak Simone Biles and Serena Williams files

Russian internet giant Rambler.ru hacked, leaking 98 million accounts

Login details for 800,000 Brazzers users leaked

MarsJoke ransomware targets the government and K-12 educational sector

A single ransomware network has pulled in $121 million

Medical marijuana patients’ personal information found in trash pile

Security Firm Tries Desperate Solution to Alert Company of Data Leak

Hacker grabs over 58 million customer records from data storage firm

Hutchinson Community Foundation falls victim to data breach

DDoS attack against DNS provider knocks major sites offline

Whoops: Pro-Donald Trump super PAC publishes donor credit card numbers

Hackers stole credit card data from Republican website for 6 months

Department of National Defence investigating possible hack of its recruiting site

Over 412 million ‘adult’ accounts exposed – including 15 million deleted ones

Ransomware attack targets Seguin dermatology practice

Report holds Hitachi responsible for debit card data theft

Thieves Use Skimmers on ATMs in Four NYC Hospitals

Madison Square Garden Company Alerts Customers of Payment Card Data Breach

Data of 34 million Keralites leaked in massive breach

85 million login details stolen from Dailymotion

Joan Jett’s BlackHeart Records leaks thousands of files online

KFC warns 1.2 million Colonel’s Club loyalty scheme members of data breach after website hacked

Japanese hosting company Kagoya hacked; credit card data stolen

ThyssenKrupp secrets stolen in ‘massive’ cyber attack

Yahoo’s billion account database for sale on the black market

Thursday, 8 December 2016

New UK Information Commissioner shows her teeth issuing fines for wealth screening to RSPCA and BHF

What on earth has been going on at the RSPCA ? Assumed to be a quiet backwater for helping out animals in distress it became a vehicle for what looked like politically motivated criminal cases and now has been found to have been breaking the law with very aggressive data profiling or "wealth screening" without consent in order to generate income.

All credit to Elizabeth Denning, the new head of the  ICO, for the bravery to take this organisation on as they would not immediately fit into the category of data villain.

One of the areas of breach was the sharing of data in a group with others (unidentified) called "reciprocate". Effectively when agreeing to share data (or not) with the RSPCA they took it as carte blanche to share your personal data with everyone.

Perhaps up to now Data Protection has been seen as a box ticking exercise with many government agencies relying on blanket exemptions and busily building databases.

However as the Alan Lord case showed there are no blanket exemptions and each case must be considered on its merits. The rights of data subjects to request information via a subject access request will need to be taken even more seriously now.

A new attitude at the ICO should send a warning shot across the bows of both government and big business who have been harvesting and processing personal data without getting proper consent and being clear about the purpose.

Friday, 25 November 2016

Data protection and cyber issues for small and medium sized business

Having been involved in setting up and running a number of small businesses it is very clear that generally there is a relentless focus on sales, cash and new customers (and survival). Regulation and bureaucracy are not your friend as unlike larger businesses there is not the scale to support the army of required admin people ticking boxes with feverish intensity.

Overall the digital age has been a positive for small business allowing lots of admin activity to be simplified and reducing the need for infrastructure. A lot can be done with a mobile phone number, email address and website. Welcome to the gig economy.

However it has become very clear that digital data has a huge value, and personal data even more so. Data is like money. Since it has value some people want to steal it and stealing data is generally called hacking.

Also Governments, ever keen to "guide" or "nudge" the people to the correct conclusions (not going so well with Brexit and Trump) have been spying on the population leading to the game changing revelations from Edward Snowden.

Therefore into the previous wild west of big digital data comes regulation. In the UK the very analog Data Protection Act has been updated piecemeal by the Regulation of Investigatory Powers Act, The Protection of Freedoms Act, Freedom of Information Act soon to be in force GDPR.

Small and Medium Businesses are presented with quite a challenge as a result. For example issues like encryption of sensitive data, explicit consent and right to be forgotten all need to be considered. All these are important issues but for the owner of a small business who has not changed his passwords in 12 month these issues seem esoteric at best.

Unfortunately if small business does ignore this issue they can destroy customer trust if hacked and also suffer on the compliance side as this case from the ICO shows. 

Therefore what ?

At klipcorp IP we have developed this simple free risk assessment tool aimed to help small business on this complex journey and would encourage engagement with it.

It is inevitable that business will need to allocate resource into this area (both large and small) and over time those that do not will lose customer trust / business and sometimes suffer at the hands of the regulator.

Thursday, 6 October 2016

Yahoo: Directors liability for cyber breach : IP protection in the Digital Age

With only 20 months until the implementation of the GDPR large organisations such as Barclays have already put big teams and resources in place to meet the new requirements. With breach fines up to 4% of turnover and the requirements to maintain a personal data inventory and report breaches within 72 hours this will be a big challenge for the SME and Mid Size community. The requirements of explicit consent for processing sensitive personal data (likely to include video and voice) and a linked right to be forgotten will require significant resource commitment and expertise.

TalkTalk were fined a record £400,000 yesterday by the ICO for a very poor level of cyber security which is close to the maximum under current UK legislation. This is a wake up call for businesses handling personal data in the UK as fines will be much higher under the new regime. Dido Harding may be regretting that she did not obtain an independent view of her cyber safety levels and allowed her IT team to mark their own homework.

The Yahoo hack has made the news but most of the focus has been around its scale in terms of numbers of email addresses. The class action suit available HERE  alleges under Count V Negligence. The specific wording is "Defendant owed a duty to Plaintiffs and the other class members to exercise reasonable care in safeguarding and protecting their PI and financial information in its possession from being compromised, lost, stolen, misused, and/or disclosed to unauthorised parties".

Further in the suit it is suggested that that the identity thieves may wait for years to use the information gained and that therefore class members will need to be vigilant for years or decades to come.

The combination of negligence and the potential for decades of required monitoring points to a potentially huge damages number. This could be the end of the road for Yahoo and open the way for personal negligence claims against Directors in this area.


Taken together the regulatory regime in terms of personal data is significantly tightening up and the associated risk level is beginning to become clear. 

Friday, 16 September 2016

Amazon Echo raises the stakes on privacy in the home and IP protection in the digital age.


Is it safe or is there a storm coming over the horizon ? Difficult to tell. Great excitement about the new Amazon Echo (new to the UK) which is a voice activated networked microphone and speaker which allows interaction with the web via voice command. It is intended to sit in the home and answer questions, play selected music, adjust smart devices in the home order things online etc.

It works by constantly monitoring sounds in the home and responding to its name Alexa. However in order to recognise the word Alexa it needs to listen to everything and the microphones are so good that it can listen across the room and filter our loud music.

The convenience is very appealing but the loss of privacy substantial. Who owns the data that is collected by Alexa and the profiling that results from that data ? Who will carry the liability if that data is misplaced or stolen or for example voice activated financial transactions are carried out by the wrong people ?

A company with the scale of Amazon will have worked through these issues no doubt but the significance of networked always on audio monitoring in the home may not fully register with a technology enthusiast simply looking for an easier way to stream music in the home.