Feeds

Video download site ordered to spy on users

Yes, it's really called TorrentSpy

SANS - Survey on application security programs

When the founders called the site TorrentSpy, this isn't what they had in mind. In a recent court ruling, made public last week, a federal judge ordered TorrentSpy.com to track the behavior of its own users - a means of gathering evidence in a lawsuit against the site by the Motion Picture Association of America (MPAA). On Friday, the judge granted a stay of the order, and TorrentSpy plans to appeal.

The MPAA filed suit against TorrentSpy in February last year, accusing the BitTorrent-based site of facilitating illegal downloads of copyrighted material. The new court order requires the site to turn over server logs of user activity, including IP addresses and downloaded files. TorrentSpy already collects this data in memory, but never saves it to disk. The site says that keeping server logs would violate its privacy policy.

"We have succeeded in delaying the court order to turn on logs while we appeal it. TorrentSpy will not create logs of what you do on the site without your consent," reads an open letter from the site to its users. "We are dedicated to your privacy. We are fighting for your rights."

With the order, Judge Jacqueline Chooljian, a federal judge in the Central District of California, argues that TorrentSpy is not protected by its privacy policy. "The key detail in the order is that the site can't rely on a self-serving privacy policy as a means of avoiding its obligation to provide evidence," says Ian Ballon, a California intellectual property lawyer and the author of Ecommerce and Internet Law: Treatise With Forms.

What's more, the ruling orders TorrentSpy to "mask" the IP addresses it provides to court, so they can't be associated with particular people. "So [TorrentSpy] wouldn't be violating anyone's privacy anyway," says Todd Bonder, a new media copyright expert with the international law firm Rosenfeld, Meyer, and Susman. He expects the decision to be upheld.

If the decision is upheld, some believe it's capable of eroding end-user privacy across the Net. Before Judge Choijian's ruling, no US company has been required to log memory data and turn it over to a court as evidence.

"We think it's a very troubling ruling that goes well beyond TorrentSpy," says Fred von Lohmann, a lawyer with the Electronic Frontier Foundation, a privacy watchdog. "It potentially allows any company's privacy policy to be re-written by its adversary's lawyers. It's a bad precedent to set." ®

3 Big data security analytics techniques

More from The Register

next story
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
APPLE FAILS to ditch class action suit over ebook PRICE-FIX fiasco
Do not pass go, do cough (up to) $840m in damages
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.