<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":794,"date":"2016-05-25T17:44:44","date_gmt":"2016-05-25T17:44:44","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=794"},"modified":"2019-04-17T10:49:18","modified_gmt":"2019-04-17T10:49:18","slug":"not-just-for-spam-any-more-casl-targets-software-installations","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2016\/05\/25\/not-just-for-spam-any-more-casl-targets-software-installations\/","title":{"rendered":"Not Just for Breakfast Any more: CASL Targets Software Installations"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"  wp-image-795 alignleft\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/requirements-and-enforcement-of-casl-1.jpg\" alt=\"Requirements-and-Enforcement-of-CASL (1)\" width=\"329\" height=\"305\" srcset=\"https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/requirements-and-enforcement-of-casl-1.jpg 383w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/requirements-and-enforcement-of-casl-1-300x278.jpg 300w, https:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/requirements-and-enforcement-of-casl-1-162x150.jpg 162w\" sizes=\"auto, (max-width: 329px) 100vw, 329px\" \/>Bill C-28, <a href=\"http:\/\/en.wikipedia.org\/wiki\/Fighting_Internet_and_Wireless_Spam_Act\">the Fighting Internet and Wireless Spam Act<\/a> of 2010, has certainly caused quite a furor since it was introduced in 2009. Canada\u2019s Anti-Spam Legislation (CASL), as it\u2019s more commonly known, first garnered ballyhoo over its severe proposed penalties for organizations that haven\u2019t aligned their marketing strategies with reality, or individuals that think spam is a pretty good alternative to getting a job. Under the original law, businesses that got caught spamming would be subject to fines as much as $10 million, and individuals faced penalties of up to $1 million.<!--more--><\/p>\n<p>The outcry then morphed into a frenzied lobbying effort by conservative Prime Minister Stephen Harper\u2019s corporate pals, worried that the new legislation would harsh their mellow and cripple their ability to buy that shiny new jet airplane. The law was <a href=\"http:\/\/nakedsecurity.sophos.com\/2010\/05\/27\/canada-reintroducing-spam-law-legislation\/\">tweaked<\/a> and re-tweaked, each time threatening to be the <a href=\"http:\/\/nakedsecurity.sophos.com\/2013\/06\/24\/canadas-long-delayed-spam-laws-risk-being-quietly-shelved\/\">death of the law<\/a>. And while Canada\u2019s anti-spam legislation risked <a href=\"http:\/\/www.thestar.com\/business\/2013\/06\/21\/antispam_law_could_be_canned_by_government_geist.html\">total collapse<\/a>, many pointed out that Canada was already the last G-8 country to impose such a law, so it had already failed, in a very real sense.<\/p>\n<p>Then, cynicism and criticism set in. Truthfully, it\u2019s a bit of a miracle that this law ever grew up to be reality, and there\u2019s still <a href=\"http:\/\/www.allspammedup.com\/2013\/07\/killing-a-good-idea-or-why-canada-sucks\/\">doubt<\/a> that the government of Canada will actually do anything with the law. Nevertheless, it\u2019s set to go into action on July 1<sup>st<\/sup> of this year, and the next wave of craziness has ensued. Just Google CASL. Lawyers, marketing agencies and bloggers everywhere are gearing up for the change, advising their clients and interested parties how to comport themselves come July 1.<\/p>\n<p>But with all the mayhem over CASL, we seem to have missed something. Everyone has been so focused on the email and spamming aspects of the law, so they can be forgiven for failing to notice another key mechanism:&nbsp; the law\u2019s interest in regulating software installations.<\/p>\n<p>According to <a href=\"http:\/\/www.itbusiness.ca\/news\/casls-computer-software-installation-laws-could-shake-up-tech-industry\/48929\">ITBusiness.ca<\/a>, Michael Fekete, a privacy and IT lawyer says that \u201cCASL\u2019s computer software regulations will set ground rules on installing programs on other people\u2019s devices.\u201d This particular component of the law won\u2019t come into effect until January 15, 2015, and there will be a three-year \u2018transition period,\u2019 but it\u2019s as important as the spamming components of the law. \u201cThese computer software rules will apply to anyone who installs a computer program on another person\u2019s computer system, as well as anyone who causes an electronic message to be sent from a computer system where he or she installed a computer program. A program is defined as any executable code, Fekete said.\u201d<\/p>\n<p>Like the rest of the law, the software installation portion applies to anyone located in Canada, or any computer system housed in Canada. One of the sore points of the law, critics have pointed out, is that while CASL promises to be tougher than any other legislation of its kind, enforcement of offshore violators will be difficult at best, impossible at worst. So enforcing what an application coming from, say, south of the border in the US, does to a computer located in Canada, presents obvious legal difficulties.<\/p>\n<p>On the other hand, if a computer in Canada is installing software on a computer in the US, then that counts as a violation under CASL and is subject to harsh penalties. And it doesn\u2019t just apply to desktop systems. In what Fekete calls \u201cvery broad, prescriptive rules,\u201d mobile devices are covered as well. One should infer that it could even extend to other connected devices like TVs, set-top boxes, and even <a href=\"http:\/\/www.allspammedup.com\/2014\/01\/rise-of-the-machines-a-botnet-that-can-dispense-ice\/\">refrigerators<\/a>. So many of these devices run on either a Windows or Linux platform and it\u2019s not inconceivable that rogue software installations can be performed on them.<\/p>\n<p>\u201cFor someone to be able to install a program on another person\u2019s computer, and still be in compliance with CASL, he or she will have to get express consent.\u201d Like the spam aspects of the law, that express consent means either written or verbal, and that poses a real problem for legitimate uses of remote software installations. For example, I have a couple of smart TVs, both which connect routinely to the Internet for firmware updates. Same with my XBox, PS3, and PS4. Under CASL, will those vendors have to contact me and get my go-ahead before I can get new firmware? If this is a gray area, then the companies which manufacture these devices will opt for the safest route.<\/p>\n<p>In addition, there are a number of <a href=\"http:\/\/www.osler.com\/uploadedFiles\/Expertise\/Areas_of_Expertise\/Areas_Of_Practice\/Privacy_Law\/CASL-Computer-Program-Rules.pdf\">invasive activities<\/a> like collecting information or interfering with normal operation. So sit back and enjoy the show. This could be fun to watch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bill C-28, the Fighting Internet and Wireless Spam Act of 2010, has certainly caused quite a furor since it was introduced in 2009. Canada\u2019s Anti-Spam&hellip; <\/p>\n","protected":false},"author":3,"featured_media":795,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,14],"tags":[11,9,10,8,7],"class_list":["post-794","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/794","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=794"}],"version-history":[{"count":2,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/794\/revisions"}],"predecessor-version":[{"id":1691,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/794\/revisions\/1691"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/795"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}