The Knights Who Say SOPA

At last count, the EFF has over 40 attorneys on staff* and lord only knows how many communications minions.  So, if this organization is going to maintain its loose relationship with reality, they might at least take a meeting and invent some fresh exaggerations.  But no. SOPA is just too provocative a buzzword to let go. And as part of their unrelenting strategy to keep trying to scare the hell out of people, the EFF has invoked SOPA so many times, I’ve personally run out of colorful metaphors by which to mock them for it and have had to resort to Monty Python references.

For instance, in this recent missive, EFFer Mitch Stoltz uses the acronym SOPA seven times in the first four paragraphs, which might lead the reader to think that the subject of the article has something to do with SOPA.  Of course, it has nothing to do with SOPA.  Heck, SOPA didn’t even have anything to do with SOPA, but let’s not worry about that right now.

What the knights at the EFF are saying SOPA about at the moment is the fact that as part of the major motion picture studios’ litigation against the pirate network MovieTube, they are seeking injunctive relief that would include disabling domains registered to the network and the discontinuation of services to MovieTube sites by third-party providers.  Granting such an injunction, according to the EFF, is reason to say SOPA, meaning that such a ruling by the court would inevitably lead to crippling the Internet as we know it.  Sound familiar?

But true to form for the EFF, Stoltz neither acknowledges that MovieTube is doing any tangible harm nor the fact that the relief being sought by the studios is far from unprecedented legal territory.  It is well-settled law that injunctions against a named party, which is directly harming a plaintiff, can also bind third parties that may be contributing to, or facilitating, ongoing harm.  And although this principle is nothing new in legal terms, it is a chronic sticking point for Internet companies because they are frequently facilitating harm, whether they mean to or not.  But, in another case involving injunctive relief, the British Columbia  Supreme Court demonstrated in the Equustek case that Google may be ordered to de-index on a global basis all sites (and not just pages) belonging to a business that was engaged in counterfeiting the plaintiff’s products and using its websites to hijack Equustek’s likely customers.  And still the Internet hums along.

Of course, Silicon Valley doesn’t like this sort of thing, but not because of anything to do with your freedoms so much as with their bottom line. News flash:  industries don’t like regulation.  And so, the Web industry likes to portray every prospect of this type of legal action — especially when it involves the motion picture industry — as the beginning of the end.  They say SOPA, and hope the peasants cringe. (And make no mistake, to the wealthy .01 percent of that industry, we are all peasants.) Thus, the EFF invests tremendous energy in this strategy, breathlessly warning us about the inevitable doom that will surely follow if, heaven-forbid, the rule of law might apply to trade across our precious tubes.

Stoltz’s post implies a lack of due process and a dangerous slippery slope, despite the fact that injunctions are court ordered on a case-by-case basis.  And just because an entity is granted this type of relief in one case does not mean it will then have free reign to seek random, baseless injunctions at will. (Or is the real problem that the Internet companies are acutely aware of how much global traffic is driven by piracy, that they really don’t want to go there; and they can always rely on millions of people who like free media to help evangelize their erroneous legal claims?)  If so, they should at least call it what it is and lay off the pretensions to be upholding some principle for the greater good.  Yet,  Stoltz writes:

“If the court signs this proposed order, the MPAA companies will have the power to force practically every Internet company within the reach of U.S. law to help them disappear the MovieTube websites. Regardless of whether those sites are engaged in copyright infringement or not, this is a scary amount of power to confer on the movie studios. And it looks even worse at scale: if orders like this become the norm, Internet companies large and small will have to build infrastructure resembling the Great Firewall of China in order to comply.”

Of course that makes perfect sense. Because what could filmed-entertainment companies want more than a completely dysfunctional Internet and a “wall” of censorship? Filmmakers love censorship! And they certainly don’t want their products to be seen by the paying public via the growing number of legal streaming services that are entirely dependent upon a well-functioning Internet. Naturally, the MPAA is looking for a legal wooden shoe that it can wield to the ultimate sabotage of these distribution portals for studio products.  And in a related story, the Teamsters are going to lobby to defund highway maintenance.

But to put it less sarcastically, if Internet companies truly cannot help to foster a web ecosystem that honors certain rights, including intellectual property rights, without “building a Great Firewall of China,” then maybe they just suck at what they do.  Because, in the long run, we don’t need an Internet that remains the proverbial Wild West, we need one that matures into a vital component of a functioning civilization.

Anyway, if you want a proper (and admittedly calmer) legal analysis of the relief being sought by the studios in this case, I recommend this post by Terry Hart because he actually knows, y’know, legal stuff. I’m mostly being a smart-ass because this kind of fear-mongering is at least as offensive as it is repetitive.  Above all, I resent the tone the EFF consistently takes with regard to piracy — as though it’s some adolescent prank that doesn’t hurt anybody. I and others have cited volumes of data that proves piracy is a big, black-market business that causes tangible and multi-faceted harm to real people.  I will also add that during the anti-SOPA campaign, organizations like EFF, as well as the Googles of the world, implied in their populist messaging that they cared about ending piracy, but the bills SOPA and PIPA were too flawed.  Where in the last four years, have we seen any substantive indication that anyone speaking for the Internet was remotely sincere when they made those statements?

So, if as a general rule, any of EFF’s writers framed these articles by stipulating that a site like MovieTube is — and damn-well should be — illegal and deserves to be shut down, then by all means they should play the role of the public advocate they claim to be.  Instead, the organization’s thesaurus appears to favor repeating SOPA as often as possible and using calculated, provocative language, like the way Stoltz uses the word disappear as a verb to imply that MovieTube is akin to a political dissident being silenced by an authoritarian government. (If nothing else, this kind of rhetoric is just irresponsible in a world with real dissidents and real tyrants.)  For all the attorneys on staff at the EFF, they rarely seem to produce an even-toned, nuanced analysis for public consumption regarding cases of this nature.  I guess it’s just easier to be The Knights Who Say SOPA.  Maybe if somebody brings them a nice shrubbery, they’ll knock it off.


*To be fair, and at last count, the EFF had what I counted as over 40 attorneys spread among staff, board, special counsel, and advisors, which is not exactly the same as 40 staff attorneys.  But in the spirit of this post, suffice to say, they have a buttload of lawyers to keep coming up with the same talking point over and over.

NOTE:  Within an hour or so of TorrentFreak citing this article, I received comments from anonymous trolls with handles including Adolf Hitler and Osama Bin Laden calling me “faggot.”  I think the EFF should be proud to have such erudite supporters.  I don’t know what I was thinking by criticizing their rhetoric, which has clearly elevated the debate.

We Have a RAT Problem Says DCA

“We the consumers are outgunned and outmanned. We don’t have the tools needed to protect ourselves.  While you are still better off having a 2013 anti-virus program, it won’t protect you against zero-day malware anymore than the polio vaccine will protect you from Ebola.”

That quote is from the introduction of a new report published last week by the Digital Citizens Alliance entitled Selling “Slaving.”  It focuses on an especially pernicious form of malware called RATs (Remote Access Trojans); the users of these applications; their victims; and the enablers — both corporate and criminal — that help spread and even monetize this growing trend in what sounds a bit like hobbyist hacking.  I have never explicitly recommended reading a whole report of this nature before — often the bulk of a study contains a lot of data supporting the main findings — but I do recommend reading all of this one.  Not only does it discuss a cybersecurity threat of concern to any computer or device user anywhere, but the report reads much more like a very long article that provides insight into the nature, motives, methods, and victims of this class of hackers called ratters.  Their brands of mischief include a wide range — from pranking people for sophomoric amusement; to identity and data theft; to slaving built-in webcams on the computers of women and girls to record Peeping Tom photos and videos that may or may not be used for the purposes of extortion and/or sold through black-market channels trading in child pornography.

The DCA report indicates that ratting is on the rise — and going mobile — but readers should take particular note of the lack of sophistication required relative to the amount of harm that can be caused to victims who fall prey to RATs.  In fact, many ratters can hardly be called hackers at all because they don’t hack into computers by means of any remarkable coding skills. Instead, the unsuspecting victim inadvertently downloads malware to her operating system, and a ratter is then able to control that computer (slave it) using one of a handful of cheap, easy-to-acquire, easy-to-operate software applications. An attack can be targeted (i.e. aimed at a specific victim like someone the ratter knows and has a motive to assault), but it seems that most victims are random people downloading files they assume are innocuous but that contain RAT malware.

Probably the most archetypal story of a malicious and targeted RAT assault — one the DCA report cites in some detail — is that of Cassidy Wolf, the California teenager, who was voted Miss Teen USA in 2013.  In the months leading up to her pageant victory, Wolf was the victim of a ratter, who turned out to be a teenage boy at her high school named Jared Abrahams.  Abrahams had taken control of Wolf’s computer as well as her entire social media presence, and she was completely unaware that he had been slaving her webcam to capture naked images of her until the day she received an anonymous email threatening to leak these images and other personal information on the Web, saying that he would ruin her career plans by turning her into an “internet porn star.”  His demand in trade for his silence was that she provide him with a “sexually explicit” video; and Wolf has been rightly praised for her courage in standing up to her assailant, even after he made good on his threat to release compromising images. She contacted the FBI, went public with her story, and used her pageant celebrity status to raise awareness of the problem. Her decision helped lead to the identification and conviction of Abrahams, and by the time authorities caught up with him, they discovered he had been “slaving” the devices of approximately 150 young women and female minors around the world.  He served 18 months and is currently under house arrest.

Abrahams was a relatively sophisticated hacker — and he clearly chose to target Cassidy Wolf — but many ratters are more casual, random, and technologically inept than Abrahams, so they turn to the same resource many of us use for How-To advice — YouTube.  The fledgling ratter (sometimes called a script kiddie) need not find some remote corner of the dark web in order to learn how to spread and use RAT malware because there are dozens — if not hundreds — of tutorial videos on YouTube right now that provide complete, step-by-step guides to ratting along with helpful comments and links by fellow ratters.  (See, the Web really is about community!) In addition to these tutorials, we find ratter “fan vids,” which are not so much tutorial in nature as  vicarious viewing, so you can watch a ratter harass or spy on a victim while narrating his  observations like “Dude, watch this!” and “Oh, fuck, did you see that?  This shit is sick.”

RATs on YT
Just one of many ratter videos on YouTube. All the visible titles suggest tutorials in how to be a ratter.

Collectively, both the tutorial and the ratter “fan videos” have tens of thousands of views, and the DCA report indicates that about 38 percent of these videos are ad-supported, which means that both Google and the ratter are earning some revenue from the ad buys of major brand advertisers.  This means Google has a problem that reads something like this:  “This illegal invasion of an underage girl’s bedroom brought to you by Procter & Gamble.”  And as much as I criticize Google for profiting from the exploitative aspects of digital life, I would not be surprised if the company seeks to mitigate its role as an enabler of ratting just as it has with a zero-tolerance approach to keeping child pornography out of the Google-verse.  The DCA recommends Google assign a “human team” to address the role that both search and the YouTube platform are playing in this regard, but it cannot be overlooked that the Internet industry’s larger policy agenda, advocating a “hands off” approach to all things Web, provides cover for bad actors in a variety of ways.

And that brings us to one of the primary channels through which RATs are spread (and you’ll be terribly surprised), which is illegal file-sharing sites.  Because Trojan Horse malware is delivered by sneaking the virus into an OS while the user downloads a file he/she assumes is safe, it stands to reason that the black-market world of illegal media and software provides an ideal hunting ground for ratters to set their traps.  In fact, some of those tutorials on YouTube demonstrate how a ratter can download a file from, say, kickasstorrents, modify the file with his RAT, then re-upload the newly infected file awaiting random downloaders because, y’know, “sharing.”

By these methods, ratters trap random prey to be fed upon at leisure and prioritized according to the intent of the ratter.  This may include mining victims for credit card or other sensitive information;  or the ratter may slave the computer to mine bitcoins or to spread RAT infiltration to a larger system, like the victim’s place of business.  But in many cases, it seems, the goal of many a low-skilled ratter (i.e. teenage boys and young men) is to gain access to the computers of women and girls who have webcams.  Thus, as ratters manage to trap these prized victims (often with the enthusiasm of trophy hunters), they sell the IP addresses to other ratters — like commodities in their own little RAT exchange — where access to a boy’s computer sells for about $1 while access to a girl’s computer sells for about $5, according to the DCA.

Now, I have at least implied in the past that piracy sites should be boycotted by anyone who considers herself — or himself — a defender of feminist principles.  In addition to the fact that the site owners directly profit from advertising links to “services” that are tied to varying degrees of exploitation of women (e.g. MEET ASIAN GIRLS NOW!!), this DCA study of RATs demonstrates that these sites also unintentionally provide fertile ground for spreading malware that is consistently used to exploit girls, which is apparently valued at a 5:1 ratio over the exploitation of boys. I’m not sure what else needs to be said about that.

Finally, the DCA report does contain some indication as to how Internet companies, users, and law enforcement might actually work to address the challenge of this growing risk of personal invasion.  But in order to get there, the public will first have to accept that Internet companies and law enforcement have a role to play, that our RAT infestation is just more evidence that a free-for-all policy on the Web is a fundamental failure.

The Copyright Hub is Launched in Britain

In this post from June of 2014, I argued that the Internet is a reason for the average person to care more about copyright, not less.  The premise of that piece was that just because it’s a right most people will never need or care to enforce, that’s not a reason to allow—let alone get fooled into evangelizing—a weakening of those rights for the sake of Internet industry profits.  And among the many dubious talking points oft-repeated by the tech sector and its network of faux-progressive organizations, are variations on the theme that copyrights are today exclusively a barrier to the “free flow of information.”

Not only do I find that premise philosophically offensive (akin to saying “civil rights are a barrier to the free flow of bigotry”), but I also think it is remarkably non-innovative, especially coming from the presumptive problem solvers of our future.  Rather than take the view that the ideal Internet requires that property interests in data (e.g. a photograph or a musical work) be removed as nuisance barriers, why not seek technological solutions that facilitate easy licensing and other methods of leveraging those property interests, so that more people share in the digital-age bounty other than just the Facebooks and Googles of the world?  Crazy, right? Maybe not.

As Andrew Orlowski reports in The Register, The Copyright Hub was unveiled this week in the U.K., and the principle is precisely based on—get this—harnessing the power of data to enable people to easily identify the owner of a work, the terms of the owner’s interest in that work, and to request a license to use that work according to those terms.  That might sound a little bit like Creative Commons, except it isn’t at all. Creative Commons functions much more as a PR tool evangelizing the vague ideology of the “sharing economy,” rather than providing any kind of transactional efficiency between the creator of a work and the proposed user of a work.  Orlowski writes about the prospect of the Hub …

So what previously took days or weeks to track down and negotiate is handled in the background in fractions of a second, because content has identifiers. By reducing the friction and the cost of licensing to almost zero, lots more licensing should be possible. One can envisage a whole new internet that supports functioning markets growing out of the rancid free-for-all of today’s clickbait-infested swamp.

When big corporations get away with practices like stripping metadata from images or pushing the boundaries of infringing an individual’s right of publicity to the extent that all data, all images, all “content” becomes one big grab-bag of decontextualized—free flowing thought it may be—stuff, this is not only bad for professional creators of works but is ultimately bad for the aspirations we have for the Internet itself.  An initiative like The Copyright Hub seems designed to fulfill one goal of the web, which is to connect people, in this case by fostering respectful relationships through content, rather than treating content like wildflowers meant to be picked at will. And in many cases, these transactions will involve no more than the exchange of a simple please and a thank you.   

Orlowski reports that the head of The Copyright Hub, Dominic Young, views this initiative as restoring the right of choice to the owner of a work, which is, of course, the backbone of copyright.  To quote Young from Orlowski’s article, “Copyright is actually the freedom to decide what happens to your work. Everyone has it. Should people be able to make their own choice about how it’s used? Most people would say ‘Yes’. Should they have a single choice thrust one them? Most people would say ’No’.”

Internet industry practices by the big boys have not only chipped away—if not utterly destroyed—that freedom of choice for rights holders, but they have so successfully planted the idea in a new generation of creators that copyright is a state-imposed, mandatory barrier to freedom, that many contemporary creators have been duped into advocating a weakening of rights that are completely optional in the first place.  The hope is that through efficient, technological applications like the Hub, creators who have, to some extent, given up on copyright may find a renewed faith in their ability to connect with users of their works through interactions based on the idea that permission can still be part of our digital future.

For more information about The Copyright Hub visit www.copyrightdoneright.org