2014-01-31

Web site operators will have to apply to UK government to allow their web site to be seen by UK citizens

Sounds like an unlikely headline, but how far from the truth is that I wonder?

The BBC article on whitelisting sites to not be accidentally black listed is clearly making this one step closer to reality.

The next step, obviously, is that they realise that the existing porn blocking is simply not good enough as it will miss so many sites. But they have this whitelisting system in place - all they have to do is block everything except the whitelist, and problem solved.

This really need stamping on - it is simply getting silly.

The politicians clearly have no clue. They think porn blocks are even possible (without making "the Internet" in to a whitelist of web sites only), and they even think that a "nanny state" of default blocks is sensible.

We have people like Baroness Howe using A&A as an example for why we need legislation on this, not realising that we already meet her proposed measures. That makes us an example of not needing legislation as her worst example already complies, yet all of this with no evidence of any actual harm caused in the first place!

Do we really want access to information in this country to be government controlled and censored?

THIS IS NOT CHINA
THIS IS NOT NORTH KOREA

So please talk to your MP and tell them this nonsense must stop now.

2014-01-29

Open letter to Baroness Howe

Dear Baroness Howe,

I see that you mentioned Andrews & Arnold in your recent speech in The House of Lords in relation to child protection and Internet censorship.

I would be delighted to have the opportunity to discuss such issues with you if possible, both on a technical basis, and a practical basis, but also as a father having raised five children in the Internet age.

Whilst I am pleased that our marketing efforts have brought us to your attention, I am slightly puzzled that you seem to have mentioned Andrews & Arnold in a context of being something of a problem ISP, and a reason for your amendments. Therefore, I would like to take this opportunity to clear up any misunderstanding you have about our service.

For a start, we appear to be a company that already complies with the requirements of your proposals:
  1. We do not sell to individuals under 18. We already ask anyone ordering to confirm that they are not under 18. Obviously if OFCOM were to come up with some practical means to verify age on an on-line order we'd be more than happy to consider integrating such a system, but at present we feel it very unlikely that an under 18 could order. For our type of services it means having access to a phone line (without Internet already) in order to install equipment, or access to allow a phone line to be installed - both of which seem unlikely to go unnoticed by parents in a household. Our services are also unlikely to be cost effective for a minor to purchase.
  2. We already confirm that our customers want fully unfiltered Internet access, and this is made very clear when ordering. Indeed, it is one of the main reasons people come to us in the first place to obtain Internet access.
So it seems to me that we are already exactly the sort of ISP you want - one that does not sell to minors and only provides unfiltered Internet access to those that specifically request it.

I am quite sure that most other small ISPs would be happy to work in a similar way, and I would be happy to engage with ISPA, LONAP, LINX, and UKNOF to try and build an informal arrangement regarding such clear information at the point of sale.

Indeed, specifically for parents, we even go as far as providing means to set alternative DNS servers which are a way of helping block accidental access to unsavoury content on a customers Internet access with us.

In light of this, I am somewhat surprised that you appear to use us an example of why legislation would be needed. It seems to me that we are exactly the opposite, an example of why legislation is not needed.

However, as I said earlier, I would be delighted if there was an opportunity to discuss such matters more directly. I am sure, if you would like, that we could arrange a dinner/meeting with a number of similar small ISPs if that would be helpful. Alternatively, I would be delighted if you would like to visit our offices in Bracknell and discuss matters and see what we do.

I also have a suggestion for age verification which could be achieved by a change in BACS, using a variation of normal Direct Debit set up as a means to verify that an account holder is 18 or over. After all, the banks already do significant checks on account holders, and it would be ideal to make use of their information for such a purpose.

Regards,
-- 
Adrian Kennard
Director
AAISP.

[Being posted as well, I'll update any reply]

Mentioned in The House of Lords

It seems A&A got a mention in the Lords yesterday

Baroness Howe of Idlicote: "Self-regulation, for example, provides no means of dealing with the likes of Andrews and Arnold where default filters are concerned. Its closed loop system does not provide for proper age verification and the mobile phone code all too often—and at very real cost to children—has not been respected. If we believe that child protection is really important—and I have every belief that your Lordships believe just that—we must introduce robust statutory measures to help prevent children accessing this material."

I am pleased to see that some of my good work has been noticed, and I would love to have the opportunity to try and explain things to the Lords or Parliament.

I am, however, somewhat concerned at the comments that have been made. "age verification" seems an odd one, as we do not sell to minors (and ask people to confirm they are over 18 when buying as well as expecting a bank account with Direct Debit). I am not sure what "mobile phone code" means in this context either.

Indeed, we have no "age verifications" when a child uses a telephone to make a call, and no checks on the words spoken in that call. Similarly no "age verification" for a child to receive post.

As a father I am very interested in the "very real cost to children" this causes, and I would love to see a reference to any credible study of the impact of access to pornography by children and how it has affected them. I wonder how many MPs saw some porn when still a minor? I don't believe I know any man who did not, at some point, when a minor, see porn. I am sure such clear evidence must exist, or else Baroness Howe would not have used such strong words as "very real cost". I am always interested to learn.

However, with the comment "we must introduce robust statutory measures to help prevent children accessing this material." I do wonder what the objective here is.

I see two issues, one is younger children happening across something unsavoury when unsupervised accessing the Internet. This is, of course, easy to address, and many tools exist already, such as alternative DNS servers. Some ISPs (Andrews & Arnold included) will happily help parents set up alternative DNS servers on customer equipment or even pre-configure the equipment supplied to make use of such free services.

The second case is where a child wants to access "such material", such as a teenage boy (or girl, lets not be sexist here!). This is, of course, impossible to stop. None of the blocks in place by ISPs stop such access. The blocks in place do little more than stop accidental access and have lots of side effects with technical issues and over blocking. There are already people selling USB sticks pre-loaded with TOR+flash browsers to bypass all logging and blocking with one click.

But really, if this is such a real cost, why not make a law "It shall be an offence for any child to access porn on The Internet, over the phone or by post" - there you go - job done? Perhaps better would be "It shall be an offence for any parent or guardian of any child to allow that child to access porn on The Internet, over the phone or by post". That is a very simple law.

Or is it that such a law would be totally ineffective? Just like a law suggesting ISPs should block communications would be totally ineffective. I suppose we could cripple all communications in the UK massively by making the Internet some sort of white list only set of web sites you can access and no more - that could have a fun impact on the economy - I am sure that will be good for our children!

All the current ISP porn blocks do is give parents the false impression that the Internet is now "safe"meaning they supervise children less.

The recent blocks on The Pirate Bay, a single web site, being so ineffective that the Dutch courts have reversed the bans, just shows how ineffective blocks are. That was just one web site and not an attempt to block an entire, well funded, and legal industry.

If you are not convinced, go order one of these USB sticks and try, or better still ask a 12-15 year old, as an OFCOM report confirms that 1 in 5 of them know how to bypass filters, and that is a survey that pre-dates the recent introduction of filtering by major ISPs.

I do think the Baroness needs to think a little more on exactly what she is asking for here, and why. As I say, I am more than happy to come and explain things and can be contacted through the A&A press email address.

Update: As someone commented, we have been mentioned earlier and she even quotes our web site!

Interestingly the Baroness's actual proposals, having read them, would do nothing to our service as all of our customers have already opted for an unfiltered Internet connection and are over 18, so the service would remain exactly the same and we would simply not take on customers that ask for network level filtering.

Update: I see we are not alone in our views, comment from Lord Lucas.

My letter to the Baroness.

Pirate Bay News

So, it seems the Dutch courts have lifted bans on The Pirate Bay. The main reasoning being that it is ineffective. Well done!

This is no surprise to anyone. It will be interesting to see if other courts take a similar view in light of this.

It is, however, highly relevant for the whole "Porn blocking" fiasco.

The Pirate Bay is one web site, just one. It did not have huge corporate resources, but still, it was able to avoid the blocks put in place by court orders on major ISPs. These ISPs had to play "whack a mole" games trying to track down where the site had gone and multiple mirrors, and so on. They fail, unsurprisingly.

But Cameron wants the UK ISPs to block not just one small web site but an entire, well funded, legal, world wide, industry: porn.

Each and every one of the sites blocked by such filters can (and probably will) take all of the same steps as The Pirate Bay to get around the blocks, and their actions won't even be seen as illegal in any way.

It really does seem like we have heard this story before by a chap called Knut.

2014-01-27

Thank you (iMessage)

Finally, it seems 6 character emails can, once again, receive iMessages. This is great news for those of us with short email addresses (including many of my family).

I know that this was the result of various reports in to Apple by several people, and I'd like to thank you all for your help in this.

It is a shame that Apple seem to be immune from the normal rules of being a telco (even if done for free, they contract with end users under their T&Cs to provide a telecoms service, and you have to buy their stuff, so paying money, to so that). OFCOM feel they do not have to provide ADR even. If nothing else, it is useful to know how one can be outside the rules - it may be useful one day.

But, once again, thank you all.

Update: Thanks for the comments and tweets - this was really about iMessage working again - but the implications for stepping outside the rules really do get interesting, especially as and when there are stronger (legislative) moves to filter Internet content. Ways to not be within the scope of such rules could be handy :-)

Update: .... and it is not working again, FFS.

2014-01-22

Royal Ascot Racecourse associated with criminal activity?

Well, I am surprised.

I received a junk email to me (as an individual subscriber) with no prior consent, trying to sell me tickets to Ascot, on the "New Official Royal Ascot Hospitality Site!". This is a crime under section 22 of The Privacy and Electronic Communications (EC Directive) Regulations 2003.

It claimed to be from "EVENTS LNTERNATIONAL LTD" (sic) company 04278759 (which is actually PLATINUM EVENT TRAVEL LIMITED).

No reply to an email to them, but, to my surprise, no reply from Royal Ascot Racecourse's press office either. I did give them to chance to provide a reply to my impending blog post, but no reply after over 24 hours.

I can only assume that they are happy to be associated with this criminal activity. It is very disappointing indeed.

Barclays Fraud Debt, again

I am dreading it.

I can see that Barclays have obviously decided something is up, as my card is blocked when buying stuff, again. Blocked when buying top up for smartstamp, as we do every couple of weeks, even with the annoying "verified by visa" crap I have to go through every damn time.

I can also see that there are no unexpected transactions or authorisations on my account, so no reason for them to have done it.

So, do I waste half an hour of my life calling their fraud department only to go through the recent transactions and say "yes, that was me, like I do every time I buy from them" half a dozen times.

Or do I await the inevitable call from a withheld number only to spend half an hour arguing how giving personal information to a withheld number caller is exactly how card details get compromised in the first place, and "have I passed the test?" Only to then have to spend half an hour calling their fraud department anyway?

It is so fucking annoying - they are protecting their own arse's here, not mine. If there has been any fraud, it is them that have been defrauded, not me. I really am sick of it.

I may call and start (recorded) with "if this turns out to be not fraud I will charge for my time making this call, OK?", followed by "what? do you work for free or is your time valuable too?" if they say "no".

Sick of it.

Update: Due to the tweet, Barclays are looking in to it - if this can be sorted without a call, I will be amazed.

Update: I think I see the trigger, eventbrite putting a transaction through as USA. If that is the cause then it is not any fraud (to bank or me) but highlights the stupidity as that transaction has gone through, but serious business affecting transactions like us paying Royal Mail to top up postage with verified by visa checking being blocked. We pay Royal Mail every few days for postage, yet they blocked it. I have had to expense it on my personal card, which is hassle.

Update: As expected, they could not sort by email, and even when they called (from an 0800) about my complaint they could not actually sort the issue, only saying that I would still have to call the fraud dept. I'll do it, but i have told them that in future I expect to be paid for my time. They really struggle to understand that "thinking there was fraud" when there is not is a "mistake" and that they should, perhaps, maybe, pay for their mistakes.

Update: 25 minute to fraud dept and unblocked. What triggered it? Paying annual RIPE NCC fees, as we do EVERY YEAR! And who the hell would buy RIPE membership, fraudulently, OMG!

Wallot inspector

What is fun with a nice UV ink jet printer is on what you can print... One thing is a bank card. This is now my Monzo card, oops. Yeh, I can...