2011-05-26

How the cookie crumbles

ICO, number 10, parliament and EU web sites flout new cookie law!

The modifications to The Privacy and Electronic Communications (EC Directive) Regulations 2003 and in particular Section 6, which essentially relates to use of cookies on web browsers, comes in to force today.

First problem is that legislation.gov.uk does not update UK SIs. Why? That is crazy. Anyway, to read the regs in their current form you have to read The Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011 and specifically the changes to Section 6.

This makes it read as follows :-

6.
(1) Subject to paragraph (4), a person shall not use an electronic communications network to store information, or to store or gain access to information stored, in the terminal equipment of a subscriber or user unless the requirements of paragraph (2) are met.

(2) The requirements are that the subscriber or user of that terminal equipment—
(a)is provided with clear and comprehensive information about the purposes of the storage of, or access to, that information; and
(b)is given the opportunity to refuse the storage of or access to that information.
(b) has given his or her consent

(3) Where an electronic communications network is used by the same person to store or access information in the terminal equipment of a subscriber or user on more than one occasion, it is sufficient for the purposes of this regulation that the requirements of paragraph (2) are met in respect of the initial use.

(3A) For the purposes of paragraph (2), consent may be signified by a subscriber who amends or sets controls on the internet browser which the subscriber uses or by using another application or programme to signify consent.

(4) Paragraph (1) shall not apply to the technical storage of, or access to, information—
(a)for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network; or
(b)where such storage or access is strictly necessary for the provision of an information society service requested by the subscriber or user.

So, what does this mean?
Basically, you cannot store or retrieve any information (e.g. a Cookie) in/from terminal equipment (e.g. a Browser) without consent, and no longer can that be a failure to opt out - it has to be specific and informed consent. The exception is for strictly necessary usage for a service that was requested by the user.

Now this could be a real pain for web developers. Sesison cookies are pretty common, although for what most web sites do they are clearly not strictly necessary. But so are analytics to track numbers of users, and they tend to use cookies as well. It could be argued it even applies to controls for caching like Last-Modified headers as caching is not strictly necessary. Even so, plenty of people argue that even session cookies are strictly necessary - but who knows.

What is extra special is that Ed Vaizey has written a letter just two days before the legistaltion comes in to effect (so well after many people have spent a lot of time trying to comply) essentially saying not to worry. He seems to be saying :-

(a) Browers will change so that you have to say you want cookies rather than the default of allowing them. (would be fun any browsers doing that as a blanket change to a default setting as everyone would turn cookies on just to get to facebook and so would be consenting to the situation before the new law)

(b) That the legislation specifically does not say the consent has to be prior consent. He says consent could be obtained afterwards! He seems to be suggesting that we just all wait until browsers are updated and in the mean time the ICO will do bugger all.

Now sorry if I am being thick here, and I am not a lawyer so not sure how to read that, but surely such a notion creates a Schoedinger's legislation, making sending of cookies create a sort of quantum state of being legal and illegal at the same time. You can only resolve that once you later ask for consent and either find you get it or not.

Note that civil cases for damages for breach of this act can be taken to the county court from today and so he cannot say no enforcement will happen yet. Sadly it is hard to contrive damages for this else I would have issued a county court claim against the ICO this morning. Next holiday on expensive roaming mobile data I'll have a good look around the ICO site and then add up how much the extra header lines for cookies each way have cost me...

Yes, that is right, several sites are flouting the new law...

www.ico.gov.uk Two cookies on main page
www.parliament.uk Four cookies on main page
www.number10.gov.uk Five cookies on main page
www.legislation.gov.uk Two cookies on main page
europa.eu/index_en.htm A survey cookie

Note that www.legislation.gov.uk even serves two third party cookies from uk.sitestat.com so not even just own-site session cookies!

P.S. This blog is a blogger.com web site and any cookies you get are fully in their control and not mine. I do not own, run or host this web site at all (though the domain is mine it just points to blogger.com). My role is just as a contributor to blogger.com's site. I contribute text and images for articles. I am not storing or retrieving anything on your terminal equipment!

2011-05-23

Stupid new in sewer ants law

Ok, seems vehicles need to have some insurance specifically listing them from 1st June or the keeper gets fined.

1. This is a tad crazy, all you have to do is declare SORN to avoid this, and that lasts a year and is free. It does not stop you taxing, insuring or driving the vehicle and there is no "un-SORN". You can do it on a web site. I bet it could be scripted even. So new law totally undermined by a once a year free web form. Why have the new law at all then?

2. Cars are not insured, people are, and there are plenty of cases where a car may be validly driven with the driver insured and not having the car listed on a specific policy. Police already make that a nightmare stopping you for no insurance when the driver may well be insured. Indeed most comprehensive policies allow driving someone else's vehicle with permission 3rd party.

So what the hell is the point in this?

P.S. To add to the fun! and not having read in detail yet, you can avoid the new requirement by SORN, but have someone other than the owner driving on their 3rd party clause still. When stopped by police they have to show now only the drivers 3rd part insurance, but to avoid a fine on a new law, the SORN as well even though clearly not at that point "off road"... That will be very silly and blow the mind of the copper I expect.

P.P.S reading this more, the P.S is not the case. But still trying to get a clear idea of what is actually required.

P.P.P.S thanks to Brian Widdas a break down...

Seems to me you can be exempt from  new insurance requirement if the keeper keeps the vehicle off road and is complying with SORN regs (which only require a SORN when not taxed so easy to comply with if you have tax by doing nothing)

Ok, here we go...

Section 22 of the Road Safety Act 2006 amends the Road Traffic Act
1988 (sections 144A-D):

http://www.legislation.gov.uk/ukpga/1988/52/part/VI/crossheading/compulsory-insurance-or-security-against-thirdparty-risks


144A: Offence of keeping vehicle which does not meet insurance requirements

If a motor vehicle registered under the Vehicle Excise and
Registration Act 1994 does not meet the insurance requirements, the
person in whose name the vehicle is registered is guilty of an
offence.

[etc]

144B: Exceptions to section 144A offence

(5)The fourth condition is that—

(a)the registered keeper is at the relevant time the person keeping the vehicle,

(b)at the relevant time the vehicle is not used on a road or other
public place, and

(c)the registered keeper has by the relevant time complied with any
requirements under subsection (7)(a) below that he is required to have
complied with by the relevant or any earlier time.


Subsection (7)(a) relates to the making of regulations. It is under
this subsection that the The Motor Vehicles (Insurance Requirements)
Regulations 2011 are made

http://www.legislation.gov.uk/uksi/2011/20/contents/made


3. For the purposes of section 144B(5)(c) of the 1988 Act (the fourth
condition), the registered
keeper of the vehicle must, by the relevant time and in relation to
that vehicle, have delivered the
required particulars, and made the required declaration, in accordance
with paragraph 5(3) of
Schedule 4 to the 2002 Regulations.


The 2002 Regulations are the The Road Vehicles (Registration and
Licensing) Regulations 2002. Paragraph 5(3) of Schedule 4 is all about
giving your tax SORN notice (as, indeed, is all of Schedule 4)

http://www.legislation.gov.uk/uksi/2002/2742/schedule/4/made

2011-05-22

Progress

Start of Day 2.
Electronics all made.
Now to do the wiring...
And to find a 12V 5A supply.

2011-05-20

3D party

Well, I am planning to have a bash at making the 3D printer tomorrow. May turn in to a party if I can persuade a few of my geek friends to help out. I'll take along a bottle of whiskey just in case. Ask in irc if you want to join in :-)

I still have no idea what we will "print" on it when made though...

3G Dongles, USB and PPP fun

Techie post this time (e.g. Pauline you can stop reading about now...)

As some of you know the new FireBrick FB2700 has a USB port to allow a 3G dongle to be attached. Thanks to a lot of work by Cliff on the USB library we now have something working. The latest alpha should connect, but the code needs a lot of polish. No there is no status page or command yet, etc. If you want to try, just add to the config. Actually, is likely to be more helpful.

The fun bit is finding out how they work, and this is where, from a technical point of view, you probably need to start with a good head of hair...

We have only tried two so far (ZTE and Huawei).

The first thing that strikes you is that they need a mode switch to work. What this means is that they start life as a USB mass storage device and not as a modem or such. Why? Well, the best guess is windows. By appearing to be a mass storage device then windows will look for and offer to install any drivers for you. If they started off as a modem then windows would either ask for drivers or install its own drivers which then need un-installing. So it has to pretend not to be a modem at all. Great! But then the mode switch itself does not use the standard USB alternative configuration system at all, no. It uses a specific message - in this case one uses an Eject command as if it was a CD and another users a message allowing a Wakeup request from the dongle. Neither is intuitive. Thankfully we can just send both.

It then reconnects and appears as mass storage still, and, well, not a modem in fact. USB allows it to be a communications device but it claims to be a vendor specific device instead - hmmm. Thankfully it is pretty clear it has a serial type interface we can talk to at this stage...

So, we are talking to a device that apparently has to understand packets on the air, but we are talking to it as if it were an old fashioned serially connected modem. Yes, that means old Hayes modem style AT commands.

Once we get that sorted, we finally CONNECT, and get PPP in HDLC style async serial framing. Why??? The HDLC style framing was designed for slow serial modems that may confuse XON and XOFF with data, and so on, and needs escaping. It even has a 16 bit CRC which is generated by the dongle or host and sent to the other - it gets no further, and is being sent over a short reliable USB link and protocol. What is more of a surprise is that the dongle bothers to check the CRC even, and ignore you if not valid.

OK, but even with this tedious escaping and CRC, we can finally talk PPP. Woohoo... Except...

You are talking to the dongle, not the network, it seems. Most, if not all, of the PPP negotiation stage is local. And the dongle is actually extra special with its use of PPP...

1. It does not actually offer up any IP for the remote end. This is odd, most systems expect that. In fact it sends an IPCP conf Req that is totally empty!!!

2. It initially refuses to negotiate the local IP at all, and says DNS is 10.11.12.13 and 10.11.12.14. It also insists that WINS servers are 10.11.12.13 and 10.11.12.14 even if you did not ask for them, so you have to ask for DNS and WINS.

3. It keeps NAKing even though what it NAKs is what you asked for, and not ACKing, until (presumably) it managed to get through to the far end...

4. It eventually Rejects the WINS servers you asked for (why did it NAK them then, doh), and ACKs with proper DNS and IP details at last.

5. It ignores IPV6CP, which it should either pass on, or reject.

Thankfully, with the addition of WINS, my PPP stack copes with this fiasco and finally gets connected.

So, all good fun... Do let the normal support email or irc channel have any feedback if you try it.

Next trick is to try bonding 3G dongles. Watch this space.

2011-05-19

Borrowers

OK proper rant today...

I know different people have some very different ideas on "borrowing" stuff.

Some people have very strong views on property ownership, and would not dream of touching something that belonged to someone else and would expect the same for things they have.

Some people have a much more relaxed view, and feel that they could just use something that belongs to someone else if they thing what they are doing is no harm. Some people would assume they can just take stuff even if it is a consumable such as "borrowing some coffee, or milk, etc"...

I can see there are different views on this, and I an not trying to be totally anal, honest.

Of course, it makes a difference what relationship you have, and with a family in a household it is normal to borrow stuff from other people, usually asking or at least informing them. It is also usual, I think, to take in to account if people do have strong views they have made clear previously.

There are lines that get crossed! I don't mind too much my kids borrowing stuff if it does not effect me, and ideally if they ask.

What really pisses me off is borrowing stuff, not asking, not telling me, not putting it back, still not putting it back when I came to use it and got cross, still not putting it back a day later, and a day after that and a day after that, and then finally trying to fob me off with something else and losing what they borrowed!!!

You know who you are - it is not acceptable.

If I want to use something that is mine, I expect it to be where I left it and in the same state I left it (e.g. not battery suddenly flat, etc). If you can borrow it without affecting that logic, then that is generally OK, but not otherwise.

PUT IT BACK!!!

Dodecahedron

I was shown a dodecahedron with LEDs inside. Looked great, so decided to have a go. The principle is not that hard - a PCB strip on the insi...