Followers

Monday, February 16, 2009

Facebook's New Terms Of Service: "We Can Do Anything We Want With Your Content. Forever."


By Chris Walters

This post has generated a lot of responses, including from Facebook. Check them out here.

Facebook's terms of service (TOS) used to say that when you closed an account on their network, any rights they claimed to the original content you uploaded would expire. Not anymore.

Now, anything you upload to Facebook can be used by Facebook in any way they deem fit, forever, no matter what you do later.* Want to close your account? Good for you, but Facebook still has the right to do whatever it wants with your old content. They can even sublicense it if they want.

You hereby grant Facebook an irrevocable, perpetual, non-exclusive, transferable, fully paid, worldwide license (with the right to sublicense) to (a) use, copy, publish, stream, store, retain, publicly perform or display, transmit, scan, reformat, modify, edit, frame, translate, excerpt, adapt, create derivative works and distribute (through multiple tiers), any User Content you (i) Post on or in connection with the Facebook Service or the promotion thereof subject only to your privacy settings or (ii) enable a user to Post, including by offering a Share Link on your website and (b) to use your name, likeness and image for any purpose, including commercial or advertising, each of (a) and (b) on or in connection with the Facebook Service or the promotion thereof.

That language is the same as in the old TOS, but there was an important couple of lines at the end of that section that have been removed:

You may remove your User Content from the Site at any time. If you choose to remove your User Content, the license granted above will automatically expire, however you acknowledge that the Company may retain archived copies of your User Content.

Furthermore, the "Termination" section near the end of the TOS states:

The following sections will survive any termination of your use of the Facebook Service: Prohibited Conduct, User Content, Your Privacy Practices, Gift Credits, Ownership; Proprietary Rights, Licenses, Submissions, User Disputes; Complaints, Indemnity, General Disclaimers, Limitation on Liability, Termination and Changes to the Facebook Service, Arbitration, Governing Law; Venue and Jurisdiction and Other.

Make sure you never upload anything you don't feel comfortable giving away forever, because it's Facebook's now.

(Note that as several readers have pointed out, this seems to be subject to your privacy settings, so anything you've protected from full public view doesn't seem to be usable in other ways regardless.)

Oh, you also agree to arbitration, naturally. Have fun with that.


Update: Several Facebook groups have formed to protest the new TOS:
"People Against the new Terms of Service (TOS)"
"FACEBOOK OWNS YOU: Protest the New Changes to the TOS!"
"Those against Facebook's new TOS!"


Update 2: Facebook founder Mark Zuckerberg has posted a response on the Facebook blog. A crude summary: "trust us, we're not doing this to profit from you, it's so we are legally protected as we enable you to share content with other users and services." His point, I think, is that there are interesting issues of ownership and rights clearance when you're dealing with content shared in a social network:
Still, the interesting thing about this change in our terms is that it highlights the importance of these issues and their complexity. People want full ownership and control of their information so they can turn off access to it at any time. At the same time, people also want to be able to bring the information others have shared with them-like email addresses, phone numbers, photos and so on-to other services and grant those services access to those people's information. These two positions are at odds with each other. There is no system today that enables me to share my email address with you and then simultaneously lets me control who you share it with and also lets you control what services you share it with.



Update 3: I just found this clarification posted earlier this afternoon on The Industry Standard. It was emailed to them by a Facebook representative and seems to confirm that your privacy settings trump all else:
We are not claiming and have never claimed ownership of material that users upload. The new Terms were clarified to be more consistent with the behavior of the site. That is, if you send a message to another user (or post to their wall, etc...), that content might not be removed by Facebook if you delete your account (but can be deleted by your friend). Furthermore, it is important to note that this license is made subject to the user's privacy settings. So any limitations that a user puts on display of the relevant content (e.g. To specific friends) are respected by Facebook. Also, the license only allows us to use the info "in connection with the Facebook Service or the promotion thereof." Users generally expect and understand this behavior as it has been a common practice for web services since the advent of webmail. For example, if you send a message to a friend on a webmail service, that service will not delete that message from your friend's inbox if you delete your account.

Original here

News from The Pirate Bay Press Conference

Written by enigmax

Just hours ago The Pirate Bay and Piratbyrån held a joint press conference at the Museum of Technology in Stockholm. It was broadcasted live on the web and Pirate Bay co-founders Peter Sunde and Gottfrid Svartholm spoke at length. Here is a breakdown of some of the key points.

The joint press conference was held mainly in Swedish and there was very little English. The media present had applied for invitations, and some representatives from the media had already been banned from attending by The Pirate Bay. Those in attendance were told that they should be courteous, which they were.

Sitting at the top table from left to right were Rasmus Fleischer of Piratbyrån, Sara Sajjad of Piratbyrån, Gottfrid Svartholm Warg (aka Anakata), Peter Sunde (aka Brokep) and Magnus Eriksson of Piratbyrån. Fredrik Neij (TiAMO) and the fourth defendant Carl Lundström were not at the table.

Spectrial Press Conference (pic credit)

spectrial

First off, they said that the whole case can be best described as a theater play and that all the people involved are potential actors. They vowed to make a reality TV-show of the whole trial, in fact Rasmus Fleischer has written the prologue for the show already. It’s a Spectrial, and they are happy to play along. As soon as the cameras stopped flashing, the panel took questions from the media that was present.

The Pirate Bay said that they feel that their overall case would not end quickly, implying legal appeals and were defiant that no matter what happens to them, the site will continue. “What are they going to do? They have already failed to take the site down once. Let them fail again,” said Gottfrid. It isn’t the site facing the courts noted Peter Sunde. “It has its own life without us,” he said.

The Pirate Bay team said that although they face huge financial claims, they weren’t going to be intimidated, with Gottfrid declaring, “I already have more debt in Sweden than I will ever be able to pay off. I don’t even live here. They are welcome to send me a bill. I will frame it and put it on the wall.”

Peter went on to explain there was no basis for the massive financial claims. “It does not matter if they require several million or one billion. We are not rich and have no money to pay,” he said. “They won’t get a cent.”

When asked if it was ok to download media without paying for it, Peter deemed the question to be “uninteresting” and said he was tired of hearing it.

A member of the media then posed this question: “Do you feel like defendants, or defenders of technology?”

Peter responded: “I think it is something in between actually. We have a personal liability for this, we have a personal risk which has some impact on our feelings. But definitely it’s not defending the technology, it’s more like defending the idea of the technology and that’s probably the most important thing in this case - the political aspect of letting the technology be free and not controlled by an entity which doesn’t like technology.”

Gottfrid added that the prosecutor of the case seems to focus a lot on the individuals in the case. “At least one fourth of the evidence is character assassination of the people involved,” he said.

Peter went on to explain that when he was arrested the police didn’t immediately start questioning him about site, rather his motivation. “When I had my only hearing with the police the first question was if I wanted to explain my ideology and my politics, not if I was involved in The Pirate Bay, which kind of sets the tone for all of this.”

The site’s finances were brought up, with the pair saying they started it and keep it going through advertising revenue, although the pair don’t make any money themselves.

A reporter from the BBC asked what the on-going maintenance costs of The Pirate Bay amount to. Peter responded, “So, the costs for Pirate Bay, I don’t actually don’t have any numbers for it. We use quite a lot of bandwidth and we have to buy new servers every other week.”

Gottfrid said that the tracker itself uses an average of 600mbits of bandwidth which increases further at weekends. He also revealed that their current hardware has to be replaced once a year and is currently estimated to be worth $120,000, therefore it is depreciating at the rate of $10,000 each month.

Towards the end of the conference the pair were asked for their assessment of the way they have been handled by the press.

“Well, that’s a very interesting question,” said Peter. “There are some members of the press who we don’t like so we didn’t invite them today and they are very mad at us.” Peter didn’t mention them by name at this point, but they were Aftonbladet, Metro and TV4. He explained the problem he has with these publications;

“They are just interested in doing something spectacular instead of actually discussing the issues. The media that are not invited today are basically the media that have not been negative, but lying instead and keeping things from the public.”

“We don’t have a problem with negative press,” Peter continued. “There are a lot of people in this room who don’t like us and we don’t really care about that as long as they discuss the issues. But I would say that most of the press have been very good towards us actually, in discussing more and more the issues surrounding The Pirate Bay instead of focusing on us as persons, which is what we actually want.”

The trial starts tomorrow and of course, TorrentFreak will keep everyone updated, but in the meantime, a thought-provoking comment from Peter;

“I do not believe The Pirate Bay will be a major player in five years. But I think BitTorrent technology will improve. File sharing will always exist. I think people will tire of the debate.”

Original here

Do We Need a New Internet?


By JOHN MARKOFF

Two decades ago a 23-year-old Cornell University graduate student brought the Internet to its knees with a simple software program that skipped from computer to computer at blinding speed, thoroughly clogging the then-tiny network in the space of a few hours.

The program was intended to be a digital “Kilroy Was Here.” Just a bit of cybernetic fungus that would unobtrusively wander the net. However, a programming error turned it into a harbinger heralding the arrival of a darker cyberspace, more of a mirror for all of the chaos and conflict of the physical world than a utopian refuge from it.

Since then things have gotten much, much worse.

Bad enough that there is a growing belief among engineers and security experts that Internet security and privacy have become so maddeningly elusive that the only way to fix the problem is to start over.

What a new Internet might look like is still widely debated, but one alternative would, in effect, create a “gated community” where users would give up their anonymity and certain freedoms in return for safety. Today that is already the case for many corporate and government Internet users. As a new and more secure network becomes widely adopted, the current Internet might end up as the bad neighborhood of cyberspace. You would enter at your own risk and keep an eye over your shoulder while you were there.

“Unless we’re willing to rethink today’s Internet,” says Nick McKeown, a Stanford engineer involved in building a new Internet, “we’re just waiting for a series of public catastrophes.”

That was driven home late last year, when a malicious software program thought to have been unleashed by a criminal gang in Eastern Europe suddenly appeared after easily sidestepping the world’s best cyberdefenses. Known as Conficker, it quickly infected more than 12 million computers, ravaging everything from the computer system at a surgical ward in England to the computer networks of the French military.

Conficker remains a ticking time bomb. It now has the power to lash together those infected computers into a vast supercomputer called a botnet that can be controlled clandestinely by its creators. What comes next remains a puzzle. Conficker could be used as the world’s most powerful spam engine, perhaps to distribute software programs to trick computer users into purchasing fake antivirus protection. Or much worse. It might also be used to shut off entire sections of the Internet. But whatever happens, Conficker has demonstrated that the Internet remains highly vulnerable to a concerted attack.

“If you’re looking for a digital Pearl Harbor, we now have the Japanese ships streaming toward us on the horizon,” Rick Wesson, the chief executive of Support Intelligence, a computer consulting firm, said recently.

The Internet’s original designers never foresaw that the academic and military research network they created would one day bear the burden of carrying all the world’s communications and commerce. There was no one central control point and its designers wanted to make it possible for every network to exchange data with every other network. Little attention was given to security. Since then, there have been immense efforts to bolt on security, to little effect.

“In many respects we are probably worse off than we were 20 years ago,” said Eugene Spafford, the executive director of the Center for Education and Research in Information Assurance and Security at Purdue University and a pioneering Internet security researcher, “because all of the money has been devoted to patching the current problem rather than investing in the redesign of our infrastructure.”

In fact, many computer security researchers view the nearly two decades of efforts to patch the existing network as a Maginot Line approach to defense, a reference to France’s series of fortifications that proved ineffective during World War II. The shortcoming in focusing on such sturdy digital walls is that once they are evaded, the attacker has access to all the protected data behind them. “Hard on the outside, with a soft chewy center,” is the way many veteran computer security researchers think of such strategies.

Despite a thriving global computer security industry that is projected to reach $79 billion in revenues next year, and the fact that in 2002 Microsoft itself began an intense corporatewide effort to improve the security of its software, Internet security has continued to deteriorate globally.

Even the most heavily garrisoned military networks have proved vulnerable. Last November, the United States military command in charge of both the Iraq and Afghanistan wars discovered that its computer networks had been purposely infected with software that may have permitted a devastating espionage attack.

That is why the scientists armed with federal research dollars and working in collaboration with the industry are trying to figure out the best way to start over. At Stanford, where the software protocols for original Internet were designed, researchers are creating a system to make it possible to slide a more advanced network quietly underneath today’s Internet. By the end of the summer it will be running on eight campus networks around the country.

The idea is to build a new Internet with improved security and the capabilities to support a new generation of not-yet-invented Internet applications, as well as to do some things the current Internet does poorly — such as supporting mobile users.

The Stanford Clean Slate project won’t by itself solve all the main security issues of the Internet, but it will equip software and hardware designers with a toolkit to make security features a more integral part of the network and ultimately give law enforcement officials more effective ways of tracking criminals through cyberspace. That alone may provide a deterrent.

This is not the first time a replacement has been proposed for the current Internet. For example, modern Windows and Macintosh computers already come equipped to support a new Internet protocol known as IPv6 that would fix many of the shortcomings of the current IPv4 version. However, because of cost, performance and compatibility questions it has languished.

That has not discouraged the Stanford engineers who say they are on a mission to “reinvent the Internet.” They argue that their new strategy is intended to allow new ideas to emerge in an evolutionary fashion, making it possible to move data traffic seamlessly to a new networking world. Like the existing Internet, the new network will almost certainly have no one central point of control and no one organization will run it. It is most likely to emerge as new hardware and software are built in to the router computers that run today’s network and are adopted as Internet standards.

For all those efforts, though, the real limits to computer security may lie in human nature.

The Internet’s current design virtually guarantees anonymity to its users. (As a New Yorker cartoon noted some years ago, “On the Internet, nobody knows that you’re a dog.”) But that anonymity is now the most vexing challenge for law enforcement. An Internet attacker can route a connection through many countries to hide his location, which may be from an account in an Internet cafe purchased with a stolen credit card.

“As soon as you start dealing with the public Internet, the whole notion of trust becomes a quagmire,” said Stefan Savage, an expert on computer security at the University of California, San Diego.

A more secure network is one that would almost certainly offer less anonymity and privacy. That is likely to be the great tradeoff for the designers of the next Internet. One idea, for example, would be to require the equivalent of drivers’ licenses to permit someone to connect to a public computer network. But that runs against the deeply held libertarian ethos of the Internet.

Proving identity is likely to remain remarkably difficult in a world where it is trivial to take over someone’s computer from half a world away and operate it as your own. As long as that remains true, building a completely trustable system will remain virtually impossible.

Original here