Posts on this blog represent my opinion. It may be my considered opinion on the basis of my formal study of law and technology. But it is not legal advice. It must not be treated as, or acted upon as, legal advice and no liability is accepted for doing so.
Showing posts with label Cloud computing. Show all posts
Showing posts with label Cloud computing. Show all posts

Monday, 4 July 2011

Dropbox Terms of Service not actually that evil

There's an old saying that there's no such thing as bad publicity, but I'm not sure that Dropbox believe that right now.

It was embarrassing enough a couple of months ago when in response to security concerns Dropbox had to concede that their much-vaunted claim for totally secure encrypted hosting of data via the cloud wasn't quite as totally secure as most people assumed. Dropbox's explanation made sense - in order to allow web-based access, they need the ability to decrypt user files - and they reiterated assurances that there were procedural safeguards against their staff snooping such content. But trust in Dropbox took a dent.

Nothing like the dent it took the other week though, when a technical glitch left all Dropbox accounts open to access for several hours. Dropbox management were at least quick to concede fault and to advise users to check their account logs for unexpected activity, but this incident seriously tarnished Dropbox's reputation.

Which is probably why Dropbox are now in the news again, following a recent revision of their Terms of Service. When you've heard two lots of worrying news about a company, it's easy to believe the worst when a third story comes along. Now, ToS of cloud service providers are a particular interest of mine, so as a somewhat concerned Dropbox user myself I was keen to see whether there was genuine cause for concern.

What Dropbox have done is to make a generally admirable attempt to make their ToS as comprehensive, open and at the same time easy to understand as possible. I can well imagine why, in light of recent problems, they'd want to do this, although it's a difficult balancing act to try to achieve at the best of times. As Facebook found out, with its infamously longer-than-the-US-constitution privacy policy, detail and readability don't always go together. But having said that I think Dropbox have made a pretty good attempt at it, and their revised ToS are certainly a lot more concise and accessible than many I've had to review.

The particularly contentious part comes under the heading Your Stuff and Your Privacy. It says:

We sometimes need your permission to do what you ask us to do with your stuff (for example, hosting, making public, or sharing your files). By submitting your stuff to the Services, you grant us (and those we work with to provide the Services) worldwide, non-exclusive, royalty-free, sublicenseable rights to use, copy, distribute, prepare derivative works (such as translations or format conversions) of, perform, or publicly display that stuff to the extent reasonably necessary for the Service. This license is solely to enable us to technically administer, display, and operate the Services. You must ensure you have the rights you need to grant us that permission.

Is this a massive rights-grap by Dropbox? Well, no. This particular term is very common in cloud, blogging and social-networking services. It arises because in any cloud-based service the provider has to copy your data in order to store it and make it available, and indeed has to publish it if you share that data with friends or the world at large. Whilst there are good legal arguments that you are implicitly granting Dropbox (or any other provider) permission to do this by the act of signing up to the service, for entirely understandable reasons Dropbox prefer to make it clear in your user agreement that this is what they're going to do, and that you the user are happy with it. As one of the comments to the Slashdot story I linked to explains, the scary-looking language is actually quite reasonable given how the service is used:

Worldwide = Dropbox provide a globally-available service.
Non-Exclusive = Dropbox can't and don't prevent you from licensing your data in other ways.
Royalty-Free = You won't charge us for this!
Sublicensable = Dropbox need to allow technology partners to copy your data too.

The caveats in the terms make it clear that Dropbox are invoking this licence only for the purposes of providing the service to users. In that respect it's narrower than, say, Facebook's corresponding term (here, clause 2.1), which sets no limits on the use Facebook may make of data that you share online.

What I know has concerned some people though is the rider at the end of Dropbox's clause about 'You must ensure you have the rights you need to grant us that permission.' Does this mean that you can only store content on Dropbox if you either created it or have licensed it on terms that allow you to copy it?

I think that the practical answer to this is that you are probably fine so long as you don't go beyond the implied scope of what you are supposed to do with the material in question. To take an example, I quite often use my Westlaw access to download a case report or journal article. Westlaw give me the option to email it to myself - an activity which necessarily creates transient and, via webmail, not-so-transient copies of the copyright work in question. But nobody else has access to those, and they are incidental to my approved use of the service. I consider that saving such reports or articles to my Dropbox folder is equally legitimate. What would not be legitimate is sharing or publishing links to them - that would be outside the scope of what Westlaw is letting me use the service for.

In a similar vein, just because Dropbox is in a very technical sense 'publishing' your content back to you when you view it via a web interface, that is not what I, or anyone, would normally regard as 'publishing'. If you store the manuscript of your novel on Dropbox, you aren't publishing it by doing so; indeed, you still aren't even if you share it with a circle of test readers. As such, you're not breaking any exclusivity clause with your actual publishers by doing so.

There's a lot of concern about the security of cloud and social networking services and the fine detail of what can be found in their ToS (often with very good reason). However, if you do find a scary-looking clause, look to see if it's a common one, and if so find out what it actually means. It may well be a lot less alarming than you might at first think.


Tuesday, 7 December 2010

Cloud, Copyright, Hosting and Jurisdiction

Computerworld UK has published a short piece by me on the jurisdictional issues of copyright and database infringement in the Cloud. I discuss the recent ruling on this point in Football Dataco v Sportradar and suggest an alternative model for determining where material is 'made available'.

Friday, 3 December 2010

Wikileaks - Cloud's First PR Crisis?

This week has seen what may be a first for Cloud computing: the very public termination of service of a major customer for alleged terms-of-service violations. I refer of course to Wikileaks, thrown off of Amazon Web Services for a range of reasons relating to the controversial content Wikileaks was hosting there. Of course, organisations have had Cloud services terminated before, but this is by far the highest profile case I’m aware of. Equally high-profile has been the resulting criticism of Amazon, with many supporters of Wikileaks complaining that a company that is in the very business of promoting the free flow of knowledge is now engated in censorship. So, what was Amazon’s motivation here?

Amazon is still first and foremost an online shopping site (I would have said bookshop, but it is long past being just that). Its web services account for a little over one percent of its turnover, although that fraction is rapidly growing. But this doesn’t mean that Amazon is a bit player in the Cloud computing business. Far from it; Amazon Web Services is one of the market leaders and is the standard against which IaaS (Infrastructure as a Service) Cloud services are judged. A vast number of online services, including many other Cloud-based organisations, use one or more of AWS’s products; EC2 for on-demand computing power, S3 for flexible storage, or one of many others. Amazon lists an impressive array of businesses that use AWS; ironically, it includes Guardian News and Media - one of the main disseminators of the leaked cables - among many others.

It’s not hard to see that Amazon found itself in a difficult position when it became aware that it was hosting Wikileaks. (And yes, ‘became aware’ is probably how it happened – I’ll explain in a moment). Yes, there have been threats of a boycott from those upset that it has dumped Wikileaks. But if it had continued to host it, I don’t doubt that there would have been widespread calls for a boycott from those unhappy with Wikileaks – and there are a lot of people in that camp. On the figures above, Amazon would only have to lose 1% of their online retail business to wipe out their entire income from AWS, and someone in Amazon’s management probably made a pragmatic call that they’d lose a lot more business by continuing to host Wikileaks than by dropping it.

But that’s not the only consideration. Pretty much everywhere that has hosted Wikileaks has sooner or later seen denial-of-service attacks. You don’t even have to ascribe these to conspiracies; there are plenty of people out there who combine a political viewpoint at odds with Wikileaks with the technical knowledge needed to hire a botnet. (Which isn’t much, and in yet another irony botnet-based DDOS attacks are yet another form of Cloud computing). But if you start to DDOS an organisation hosted by a Cloud provider, then you risk causing a lot of collateral damage. We saw a version of this when Spamhaus started to block spam sites that had been set up on AWS, and in doing so inadvertently blacklisted numerous legitimate users of Amazon’s services. A DDOS attack on Wikileaks whilst it was hosted on AWS could well have knocked out many of those sites listed earlier. And if their lawyers could show that AWS knew that it was hosting a prime target for attack alongside them… well, it would be an interesting question as to how liable Amazon would be, but I dare say Amazon’s own lawyers may have suggested that finding out in the courts could be expensive.

In short, Amazon faced a lot of grief if it kept Wikileaks on board. And, under their Terms of Service, they were entitled to drop them. A lot has been written about whether Amazon’s explanation – a breach of Acceptable Use terms – holds water, but at the end of the day Clauses 3.4.1(vii) and (viii) of the AWS Customer Agreement give AWS very broad grounds for summarily terminating the use of even a paid account:

(vii) we receive notice or we otherwise determine, in our sole discretion, that you may be using AWS Services for any illegal purpose or in a way that violates the law or violates, infringes, or misappropriates the rights of any third party; (viii) we determine, in our sole discretion, that our provision of any of the Services to you is prohibited by applicable law, or has become impractical or unfeasible for any legal or regulatory reason;

Now, why didn’t AWS act sooner? This story suggests that Wikileaks started using AWS on Sunday 28 November. But it’s not as if Assange negotiated to use the service; one of the common characteristics of Cloud computing sites is that users can sign up online and pay via credit card. When Joe Lieberman asks, as he apparently has, for details of Amazon’s relationship with Wikileaks, the answer is that it was probably very like Transport for London’s relationship with me concerning my Oyster card. Yes, we have a contract, but it’s one I made by buying credits from a top-up point; TfL are barely aware in any meaningful sense that I exist. Amazon probably only realised they were hosting Wikileaks when they began to get complaints.

So what does this affair tell us about Cloud computing? It’s a big business, but still small in comparison with, for example, online retailing. It’s easy to sign up to, but it’s also easy to get booted off from, thanks to very permissive terms of service (and AWS’s terms are entirely typical of those we saw in the QMUL survey of Cloud terms). But perhaps the most important aspect of Cablegate for Cloud computing is the way that, by drawing attention to Amazon’s Cloud business, it’s put Cloud computing into the public eye.

Thursday, 9 September 2010

I Aten't Dead

...as Sir Terry Pratchett's Granny Weatherwax would put it, although one might be forgiven for wondering, looking at this blog of late. My sole excuse is that I've been employed investigating and writing about IT law as my day job for the last few months, which has inclined me less to blog about it as a hobby.

However, that work has now borne fruit and so this is a good point at which to get LawClanger going again. The QMUL Cloud Legal Project has just produced 'Contracts for Clouds: Comparison and Analysis of the Terms and Conditions of Cloud Computing Services', by Simon Bradshaw, Christopher Millard and Ian Walden, and available for download from SSRN.

'Contracts for Clouds' is based upon a detailed survey I carried out of the Terms and Conditions (T&C) for 31 different Cloud computing services from 27 providers. It began as a baseline study to identify how Cloud providers made reference to some of the wider legal issues we are planning to address in other Cloud Legal Project papers, but it soon became clear that the results were worthy of a paper in their own right. Although there have been a few other reports looking at Cloud T&C, we believe ours is the first that provides a detailed, referenced review of a wide set of T&C together with a comparitive analysis of the terms found. And what we found makes for interesting (to put it politely) reading for prospective Cloud customers.

Many Cloud services, for instance, have clauses in their Terms & Conditions that disclaim all responsibility of the provider for keeping the user’s data secure or intact. Often, providers will reserve the right to terminate accounts for apparent neglect (important if they are used for occasional backup), for violation of the provider’s Acceptable Use Policy, or indeed for any or no reason at all. Customers more worried about their data being seen by others than being lost might also be concerned at some of the terms seen in the survey that related to third-party disclosure. Whilst some providers promise only to hand over customer data if served with a court order, others state that they will do so on much wider grounds – including it being in their own business interests to do so.

We also found that providers very commonly exclude any liability for loss of data or for damage arising from it, or seek to strictly limit the damages that can be claimed against them – damages which might otherwise be substantial if loss of data or services brought down an e-commerce web site, for instance. Customers who seek to challenge their Cloud provider in court might also be in for a surprise when they look at the relevant terms: such providers usually claim that the contract is made under the law governing their main place of business, which in many cases is a US state, and that any dispute must be heard in the provider’s local court.

This isn't to say that Cloud services are dangerous, or that providers are especially cavalier. The terms we saw most likely reflect a desire of many Cloud hosts to remain as much a 'mere conduit' of information services (even though they are clearly hosts) as possible, and to keep customers at arm's length. Whether such T&C evolve so as to be more aligned with customer expectations and interestes will be interesting to see, and indeed will be an ongoing point of study for the Cloud Legal Project.