Judge: An IP-Address Doesn’t Identify a Person (or BitTorrent Pirate)
torrentfreak.com
torrentfreak.com
That could be gigantic to those who deal with HIPAA, PCI, GLBA, etc. Although I guess this has no impact on the European Union regulations and what they consider PII -- those are much tougher to deal with anyway.
Just because an IP address alone is not enough to legally beyond doubt identify a person doesn't mean collecting IP addresses in combination with online behavior doesn't violate people's privacy.
These are two fundamentally different things. The only real way to identify someone is through things like DNA or fingerprints. Everything else is just an indication, it may not be enough to serve as evidence in court, but it's definitely personal.
The birthmark on my ass may not be unique, but it doesn't give you the right to collect pictures of it without my permission.
An opposing example to this would be the recent ruling in Massachusetts, and why I found this one so interesting. The court there found that zip codes are PII[2].
[2] http://blog.martindale.com/massachusetts-federal-district-co...
It also means that collecting data based on your IP is not an invasion of privacy. With IPv6 there is the potential for much finer grained assignment of IP addresses to such an extent that an IP address could become uniquely identified with an individual more readily than today.
Firstly, each publicly route-able address (for both IPv4 and IPv6) belongs to a particular network (known as an Autonomous System). The traceroute utility on unix and windows can be used to show you the path from your local network to a particular network, simply by traceroute'ing address that you know are operated by a particular network.
The way this works is a series of routing protocols that ask the question, "Which network routes this address and what is the best path to get there?" and answer it in various ways.
So, I do not think it is possible or desirable for a single publicly route-able IPv6 address to follow a particular device between networks.
Finally, I would like to point out that, even though we can change them, MAC addresses are supposed to be the permanent unique identifier for a particular network interface. I do not think adding an IP equivalent makes any sense, especially when a particular interface may have multiple IP addresses, and a particular machine may have multiple interfaces.
Now I will forget my hackernews password once again, until I am needed.
Edit: and to address the comment that slipped in just ahead of me...MAC addresses as a part of IPv6 addresses are fine. If the interface is on several subnets, then the network portion of the IP address will be different.
Edit2: To clarify my initial comment, as the other commenter stated, there is no effective way to handle the routing for keeping the network portion the same, so that would always depend upon where you are. The only possibility could be to be assigned a permanent host ID, but considering how many devices the average person has with network access (I have a couple dozen easily, but I'm not average,) I'd think that this would be impractical anyway.
Now, if you argue that the judge should follow the letter of the law, and ignore the spirit, remember that the first amendment protects the freedom of "speech" and the "press". It doesn't say anything about websites. Of course, the spirit of the law was clearly anti-censorship and would obviously apply to written texts that haven't physically been through a printing press, but the letter of the law says no such thing.
Alternately, you could stick to the letter of the law and simply redefine the word "speech" to include things obviously not spoken, like websites.
Convincing judges that the spirit of the law does not match the letter, or that the dictionary definition of a word isn't the definition to be used in the case, are ways of hacking the law that have nothing to do with judicial corruption.
It is similar to the case of catching a speeding car but not being able to identify the driver (except speeding isn't a tort). You can't assume the owner is guilty unless the law is drafted to make it so that a car owner is responsible for all authorised use of their vehicle.
Talking about the spirit of the law is considering the law makers intentions and how they would have drafted the details in the current technological background.
Even if you narrow down the guilty party to one of a small group you can't convict the whole group or even a random member of the group on that strength alone. That's not how European or USA law works (though there may be other crime, withholding evidence, harbouring a criminal and such that members of the party would be guilty of).
However, I want to take your speeding car analogy a step further. The police have video of my car parked outside a murder scene during a murder. The murder was performed with my handgun. On the 911 tapes, the victim is shouting that he's being attacked by someone with my name (John Smith). The victim is someone I've previously stated that I intend to kill. The argument that none of those identify me aren't going to form a reasonable doubt unless I can also provide an alibi or implicate a different John Smith.
In the same way, the original poster has publicly stated their intention to start an open network for the specific intent of hiding their downloads. The MPAA has an IP address that shows that a download was made from the account that was purchased by a person intending to hide downloads. If they have server logs showing that other people use that network on a regular basis, they have a decent chance. As it stands, however, it's pushing the bounds of reasonable doubt, not to mention preponderance of the evidence, as needed for a civil case.
You say: "excuses that would easily fool a computer probably won't fool a judge for a second any more than it would fool a guy on the street."
I don't think it comes across as an excuse although prosecution would of course present it that way.
There is certainly instances where someone would provide an open hotspot for neighbors. (My neighbor at one building did this.) I don't think it would be difficult at all for this to be shown by any defense attorney after some research with examples of kind people doing the same. I don't think this is as open and shut as you are presenting it. And that is the job of a defense attorney to try to make things appear possible by presenting evidence of the practice (which doesn't have to be widespread either.)
There are of course ways to address this via legislation--but that will never happen as it goes to the very core of the corporate personhood issue.
If the corp is opened in a place that offers nominee owners or directors even better. Although there are most certainly legal ways that someone could figure out who to sue, in a mass lawsuit it would simply not pay to put the effort in to pierce the corporate veil of any individual when there were 1500 other targets.
Despite what others have said you've made a good point to always keep in mind as an entrepreneur. Something that you are legally obligated to do by contract is very often not worth the time for the other party to file a lawsuit over. If you rely on attorneys this is not something they always will make you aware of. (My points are based upon surviving many many years in business both with and w/o contracts.)
1) invulnerable to lawsuits
2) the coolest person in the whole internet
For all the people who are saying that this is hacking the legal system you are correct. This is routinely done and I recommend you spend some time reading up on it, because it is fascinating.
For example, did you know that most cities are corporations?
I work for a portal that was recently acquired. The company who acquired the portal is, in part, owned by the same companies that own the telco that sold the portal, but the composition is different. I'm not even sure there are no cycles in the graph - it's perfectly possible some of the entities involved own themselves.
Is detection of copyright infringement through or from an IP address enough to get a warrant issued that allows searching of the devices belonging to the individual using that IP address (or happens to be connected to the internet through that IP address)?
EDIT: likelihood wasn't spelled likely
You can either take the ticket, or tell them who was driving. You cannot say 'it wasn't me, but I won't tell you who it was'.
It is also a serious criminal offence to take speeding points on someone else's behalf (as it was suggested that government minister Chris Huhne asked his wife to)
In Sweden a clear photo of the driver is required for anyone to be fined.
Sure, I could ask who was driving but I wouldn't know if they for some reason were lying.
And wait, what? Why should the owner care if the driver is insured? The vehicle is insured by the owner, as required by the law.
As someone else touched on: in most states of Australia, the owner of the vehicle (as per the registration) is responsible. If you "don't know" who was driving your car it doesn't matter-you are responsible for the vehicle unless you have reported it stolen. Which I think is fair: if you're going to lend your car out, make sure you trust the person driving it.
In Egypt three speeding tickets means jail time (if I remember correctly), only not for the driver but for the owner. IMO that's just sick.
[1] Germany has Napoleon compliant highways while the UK was much more interested in resisting anything from Napoleon.
It's a hierarchy, from the district courts to the circuit courts on up to the Supreme Court. Basically, decisions made at one level may be binding on that court and its "descendents", but that's as far as it goes. If you want a decision to reach nation-wide, it's got to be handed down by the Supreme Court.
Today this is difficult, since the average person doesn't have a clue how to set up a secure network. But this is a usability problem more than anything, and if our laws demanded that this be do-able even by somebody's mom, then I think manufacturers would address that usability problem.
If I lend someone an easily obtainable item such as a pencil sharpener or a cat, and they commit a crime using it, I don't see how I'm responsible.
The question is which of those categories Internet access falls into.
I would go so far as to say that, in addition to the legal obligation to not violate a government license, you also have an ethical obligation to provide reasonable protection against theft, misuse, &c. Yet somehow it seems strange to apply that logic to network devices.
$ cat BigMoney > MyAccountYour only obligation in most places is to ask, "Are you legally allowed to own a gun".
I think in a practical sense this is never going to happen. If you lend someone your car you are responsible and will get sued if they kill someone. The type of lawsuit and even criminal charges might depend on whether you knew of their capacity at the time to commit a crime or fitness to drive. Important distinction with cars and guns. With both you know they can be dangerous. (In the case of a gun you know even more so obviously.) There is not the same widespread knowledge or even possibility with the internet for harm along the lines of death because of use of an internet connection. Although I'm sure it's happened a few times (harassment or planning terrorism.)
As far as the requirement to lock down a network that also is not going to happen as you well know in a world that chooses "football" or "123456" for a password not to mention key loggers and viruses. Simply not the same as keeping your gun in a gun safe or knowing your neighbor is drunk and shouldn't drive your car.
"and if our laws demanded that this be do-able even by somebody's mom, then I think manufacturers would address that usability problem."
I think there is quite the demand from users to not have constant viruses, infections and hacking of computer networks (as well as embarrassment to both the software and hardware industries and to high profile websites.) Do you really think that this can be achieved with "beyond a reasonable doubt" standards so that someone's mom can have secure wifi in her house? I don't. I get calls every day from people who type domain names into the google search box instead of the browser bar.
If you ask to use my phone, I'm going to let you borrow it, but I can't know whether you're going to use it to order a pizza or call in a bomb threat.
Of course I have some degree of responsibility, but with guns its is completely different - we went out of our way as a society to make rules about the responsibilities of gun owners.
Analogies such as these should be avoided because you're falling in the same "you won't download a car" trap.
Say, if someone comes to my party and uses a kitchen knife to commit a crime, what is the degree of my responsibility?
The legal system depends on treating every person who is mentally competent as being responsible for his or her own actions with regard to the law. What you suggest upends that dependency.
Publishing metasploit, running a torrent tracker, running a car rental service or a gun range would all require extremely expensive liability insurance if liability always transferred.
- Discussion about a time when it WAS possible to associate an IP address with a specific device and that, for the purposes of allowing discovery, it was REASONABLE to assume that the traffic from that device was initiated by the owner of that device. This has important implications for the future, as IPv6 may make "one ISP IP per actual end device" common again
- Some hilarious footnotes describing the hypocritical nature of the claims of this and plaintiffs in previous cases. In one case, a plaintiff made a claim that part of the reason for vigorous copyright claims was to "protect minors", when the very plaintiff had a teen porn website. Another footnote was about this plaintiff (K-beech) attempting to claim the moral high ground when in fact the person behind the company was the same who previously tried to extort adult book store owners with violence and bomb threats.
- A VERY interesting footnote which points out that it is still somewhat of an open question whether pornographic works are copyrightable at ALL
- The fact that, in the case of pornography, plaintiffs often rely on defendants settling even though they are innocent, simply because they don't want their name published in association with a video called "My Little Panties #2"
- Abusive tactics by the plaintiff to use information provided by discovery to harass defendants to settle. This includes asking for phone numbers and email addresses which, the judge observes, aren't necessary for servicing defendants and are mostly used to further the plaintiff's aggressive settlement tactics
- The hilarity of seeing things like "Maryjane Young Love and Gangbanged" in an official court filing
- And a whole section that's arguable more important than the IP address opinion...
Plaintiffs in these cases usually file a joinder[2] of claims and combine 10s, 100s, and sometimes 1000s of defendants in a single suit. However, the judge argues that even if he were to grant discovery on all the John Does in the case, he still might sever the joinder because:
- It is transparently an attempt to avoid paying the ~$350 filing fee for each claim. The courts, he says, don't take kindly on losing that much revenue simply because the fees don't fit the plaintiff's business model
- Joinder rules require, among other things, that the group of defendants must be related by the action “arising out of the same transaction, occurrence, or series of transactions or occurrences” and “any question of law or fact common to all defendants will arise in the action.”. In a wonderful display of deeply understanding the technical matters here, the judge argues that the technical nature of BitTorrent (to wit: that multiple parties seed the same file at the same time) does not alone satisfy the joinder requirement, simply because the user is not usually aware of these technical details.
- That, in any event, these co-defendants are only related by technical protocol and not case fact. Because of this, each defendant would still get to retain counsel, call witnesses, and defend him- or herself separately. In addition, the rules of joinder require certain actions that would involve n*(n-1) separate filings and would complicate the discovery process. This, the judge points out, turns an otherwise simple case into a massively complex one and thereby goes against the very reason why joinder was created in the first place.
In my opinion, this has the potential to be an even bigger setback to the copyright owners' tactics than the IP address opinion. If joinders like these are routinely severed because of these reasons, it would certainly make the "mass lawsuits against thousands of unnamed defendants" tactic a losing business model.
[1] http://www.scribd.com/fullscreen/92215098 [scribd fullscreen]
In terms of non-contractual terms, perhaps a film company for example could argue the subscriber was under a duty of care but again this is unlikely to stick.
Generally speaking, I think it would depend on a case by case basis and it would always be open to the subscriber to argue that although the IP address was linked to them, they were not responsible for the infringing activities. This would be determined on the evidence in each case therefore.
Where do you get these?
Same principle here right? - you can always say it was a roommate or that you had an unsecured wifi router right?