Re: Service location vs. careless privacy infringement

Peter Gietz <[email protected]> Thu, 2 Jul 1998 17:01:27 +0000
Newsgroups gmane.ietf.lsd
Message-ID <v03130337b1c1669916b4@[193.63.211.16]>
Hallvard,

Although I think the legal issue comes up at the moment of publishing the data
on an LDAP server rather than when such data are searched or collected for
indexing purposes, I regard your point as valueable input.

Except the situation where there is a well defined set of servers committed
to the same privacy policy and an indexing robot has knowledge about these
servers, there is no way out.

Any solution involves the maintainer of the server. For instance the
storage of information about the access policy, comparable to the robots
exclusion protocol for the Webcrawlers. Well behaving LDAP crawlers should
in such a scenario only
collect data from servers which provide this policy information. But this
presupposes a standardisation process anyway.

But to cut off server location because illegal data could be retrieved
would be the same as to cut HTTP because illegal pictures can be
transmitted via it.

Peter

>Has anything been done to prevent service location from magnifying the
>problem of servers that carelessly ignore privacy protection?  This
>needs to be addressed, but seems woefully absent from the documents I've
>plowed through so far.
>
>There are a lot of LDAP/directory servers that ignore privacy protection
>laws.  As with WWW a few years ago, "everybody" are setting up such
>servers, and a lot of them seem to forget about privacy protection.
>Unindexed, such servers are in practice more or less local, so the
>problem ism't that severe.  However, automatic service location will
>magnify this problem enormously, at least location via the simple
>convention DNS CNAME = <service>.<domain>.  We should not do that.
>
>It may even be illegal to run a search robot in Norway which doesn't do
>a reasonable job of exluding illegal servers.  Along with NameFLOW,
>UNINETT wants to run a search robot which indexes legal LDAP servers.
>(Well, servers that *claim* to be legal, I suppose.  We are not police.)
>OTOH, we don't want to be outcompeted by a more careless robot abroad
>which indexes all servers and is immune to Norwegian law.
>
>BTW, if any of you are nearby, please give be a swift kick for not
>mentioning this a few years ago:-(
>
>--
>Hallvard B Furuseth
>UNINETT Directory Service


________________________________________________________________

       * *      Karl-Peter Gietz     -     Applications Engineer
     *    *
    *           Francis House           [email protected]
   *            112 Hills Road               Tel +44 1223 302992
   *            Cambridge CB2 1PQ            Fax +44 1223 303005
 D A N T E      United Kingdom          WWW http://www.dante.net
________________________________________________________________