cPanel’s new EULA: more software industry arrogance?

[Update 16 April 2012: Early communications with cPanel indicated that their EULA may in fact have been unchanged, just presented again as part of the license activation — which would put a very different perspective on things. I added a question mark at the end of the headline at that time. Either way, their eventual official response indicates that this process might well be changed. That’s a win for us all.]

What is it with software companies that shove a multi-page contract in your face and expect you to click “I Agree” on the spot? Seriously, what level of ignorant arrogance does that require? cPanel Inc, creators of a popular web hosting management system, are just the latest in this conga line of suckholes.

(Note to fragile American readers: that’s a literary reference. Grow up and deal with it.)

This morning the shared web server I provide for clients had updated its cPanel/WHM software overnight. As it should. But I had to agree to a new end user license agreement (EULA) before I could even start to address an urgent maintenance matter.

I was far from impressed. If you want to change the rules, cPanel, you’ll bloody well give me the chance to consider those changes and decide whether I agree.

I just fired off this email. I await their reply.

Dear cPanel Inc,

I take serious issue with the way you have just handled the change to your end user license agreement (EULA) that came with the new version 11.30.6.7. of cPanel/WHM installed automatically overnight.

There is no warning of an impending change to the EULA that I can immediately see in either the news or blog sections of your website, nor was there any notice that I saw in the cPanel/WHM interface. You simply popped up the new EULA in front of people once the new software had been installed, giving them no choice but to agree or be unable to maintain their servers.

Forcing people to agree to a new contract on the spot?

This is appalling!

cPanel/WHM is not consumer entertainment software. This is operational internet-facing software used by businesses. The EULA sets out all manner of terms and conditions with operational, risk and security implications — not only for your direct customers but for their customers in turn.

To pick just two examples, you grant yourself the right to “access to any facilities in which the Software is used or stored, including without limitation the facilities which house the Licensed Server”, and to “copy, access, store, disclose and use cPanel Data indefinitely in its sole discretion”.

While there are phrases limiting those rights in some cases, you have not given your users a reasonable time in which to assess the changes, decide whether they will accept them and, if they are unhappy with them, to make other arrangements — let alone discuss them with their customers.

Maybe the changes are minimal. Maybe not. Did you provide us with a clear list of changes, explaining the implications? No, you did not.

Your customers face a true dilemma today. Do they roll back to the previous version of the software, knowing that it doubtless contains security flaws that have been patched in the new version? Or do they blindly accept your new EULA without being able to think through the implications for their business and their customers?

Your new EULA will not have been written overnight. Your lawyers will have taken time to consider it, and it will have gone through an approval process within your own company. Why did you not have the simple, basic courtesy to extend the same opportunity to your customers?

Not impressed.

I have pressed “I Agree” because I needed to perform an urgent maintenance task on my server. However I wish to make it clear that I have not, in fact, agreed to your new EULA because I have not been given a reasonable opportunity to consider it.

Your once-happy but now extremely unhappy customer,

Stilgherrian

Of course cPanel are far from the only example of this arsehattery. Who have you had to deal with lately?

Talking total surveillance at the Sydney Writers’ Festival

I’m speaking at this year’s Sydney Writers’ Festival in a free session on Sunday 20 May called iSpy.

Even before Google controversially demolished the privacy walls between its various products, we were already living in the total surveillance society. With every keystroke we are voluntarily telling companies, governments and heaven knows who else an awful lot about ourselves. Should we be worried about the uses to which this information could be put? Technology writer Stilgherrian discusses the implications of what we share with social media consultant Thomas Tudehope.

I daresay I’ll be covering material like that in my Sydney Morning Herald story You are what you surf, buy or tweet, and the more recent ZDNet Australia story The Facebook experiment, but the conversation will be up to you, the audience.

The theme for SWF this year is “the line between the public and the private”. As artistic director Chip Rolley says in his welcome message:

The question of the limits of what is personal is one of the hottest subjects around.

“Privacy is for paedos,” ex-News of the World journalist Paul McMullan told the UK Leveson Inquiry into the media. Now, via Facebook and Twitter, we voluntarily tell the world things we previously might not have told even our loved ones. Investigative journalists thrive on leaks and finding out what others don’t want us to know. And the state knows few boundaries (personal or political) in its need to prevent another 9/11.

(If you want a high-powered discussion of these issues, Sydney Town Hall discussion on Friday 18 May with former High Court judge Michael Kirby, former director general of MI5-turned-thriller writer Stella Rimington, former CIA interrogator Glenn Carle, media and news blogger Jeff Jarvis and investigative journalist Heather Brooke.)

iSpy is on Sunday 20 May 2012 at 2.30pm at the Bangarra Theatre, Pier 4/5, Hickson Road, Walsh Bay. It’s free, and you don’t need to book — but I’m told that it can sometimes get busy at SWF.

Before that I have speaking engagements on 27 April at DigitalMe in Perth and 11 May at the Saasu Cloud Conference 2012.

Talking NBN rollout on ABC Local Radio

NBNCo announced the three-year rollout plan for Australia’s National Broadband Network today, explaining when (roughly) they’ll lay fibre or make fixed wireless available to 3.5 million out of the country’s 10 million premises.

So far there’s really only just been time for straight reportage from the launch and set-piece criticism from the opposition. It’ll take a few days at least, perhaps even a week, before analysts have done real analysis on who’s getting the network when and whether that’s been decided by politics rather than practicalities.

(Of course one way around that would have been far greater transparency from NBNCo, including putting their raw data and the software they used online for all to see and cross-check. But like that’ll ever happen.)

I daresay I’ll end up writing more about this over coming weeks. Meanwhile here’s an interview I just did on ABC 702 Sydney and ABC Regional Radio around NSW with Dom Knight.

The audio is ©2012 Australian Broadcasting Corporation. But these program items usually aren’t archived on their website so here it is.

Keynoting the Saasu Cloud Conference 2012 with security

On 11 May I’ll be delivering one of the keynote presentations at Saasu’s inaugural conference, the Saasu Cloud Conference 2012 in Sydney.

The cloud is the enabler, it’s the medium that automation grows in. We want to focus on the value of online accounting automation, why it’s often undervalued and how you can get some for your own business or practice.

Saasu makes the online accounting system that I’ve been using since July 2007, and I know the chief executive officer and founder Marc Lehmann and chief happiness officer Tony Hollingsworth.

Good leadership and a good attitude continues to deliver a good product. Well, I think so anyway. At least it works for me.

My keynote will be something about security and the cloud, obviously enough, but I’ll lock down the details before the end of this week.

Mind you, I wrote the ZDNet Australia feature Cloud security? Better get a lawyer, Son! in October 2010, and since then I’ve written Cloud could be ‘privacy enhancing’: Pilgrim and Hybrid clouds the eventual reality for risk management and Today’s cloud winners: the cybercriminals and Want government cloud? Rethink security! so I’ve got plenty of material to start with.

Saasu has kept the price down to a reasonable $99 for a full-day event. You can register online.

[Update 11 May 2012: I’ve just posted notes and background material for my presentation, Security and the Cloud: Hype versus Reality.]

Visiting Perth for DigitalMe (and other diversions)

I’ll be in Perth on Friday 27 April to present at DigitalMe, one of a series of media140 events, the other two being DigitalBusiness on Thursday 26 and DigitalFamily on Saturday 28 April.

(These events are part of the City of Perth’s Innovation Month. It looks like there’s some good stuff happening, including the screening of some classic futuristic films.)

DigitalMe is a full day of activities that “takes the individual on a journey through the digital landscape of blogging, video, personal privacy, personal reputation, mobile web and social media helping to demystify the digital world and understand more about your personal digital footprint.”

My half-hour session at 2pm is “Destroying your world, tweet by tweet, like by like”:

Facebook, Twitter and social mobile applications encourage you to share your life. But what happens when you share too much? Every time you share, tweet, email or browse a website you leave a digital footprint that reveals far more than you may realise — or want. Find out what Facebook, Twitter and the secretive online advertising companies know about you and take control.

I covered some related themes in a piece for the Sydney Morning Herald a few weeks back.

DigitalMe is being held at Northbridge Piazza. It’s free, but you’ll need to register online.

I’m flying into Perth on Thursday 26 April around lunchtime and leaving on Sunday 29 April in the mid-afternoon. My schedule is fairly open so far, so other diversions are welcome.

Talking the death of passwords on ABC 105.7 Darwin

A story in the Fairfax outlets yesterday about work on cognitive fingerprinting for user authentication led to this conversation with Kate O’Toole on ABC 105.7 Darwin this morning.

I managed to include a mention of the voice biometric work by Australian company Auraya that’s based on technology used by Centrelink, and the concept of two-factor authentication.

The audio is of course ©2012 Australian Broadcasting Corporation, but since they don’t usually post it online here it is.