Saturday, December 19, 2009

MIRLN --- 29 November – 19 December 2009 (v12.17)

• Cyber breaches are a closely kept secret
• Obama Wants Computer Privacy Ruling Overturned
• Facebook’s Claim of Ownership of Posted Content Does Not Destroy CDA Immunity
• EFF sues feds for info on social-network surveillance
• Protecting Trademarks In Web 2.0
• Many More Government Records Compromised in 2009 than Year Ago, Report Claims
• My K-12 Blind Spot
• Google allows publishers to limit free content
• Web ad group launches privacy education campaign
• Google Wants to Speed Up the Web: Launches Its Own DNS Service
o Redirecting DNS Requests Can Harm the Internet, Says ICANN
• Risk Avoidance May Explain Why Big Firm Blogs Are Boring, Blogger Says
• Yahoo Issues Takedown Notice for Spying Price List
• Law profs say e-marriages expand couple’s rights
• Local Governments Offer Data to Software Tinkerers
• With Lure of Cash, M.I.T. Group Builds a Balloon-Finding Team to Take Pentagon Prize
• See That Funny 2D Barcode In The Store Window? It Might Pull Up A Google Listing
• New Smithsonian Collection Search
• Florida: Judges Cannot be Facebook Friends with Litigants
• TSA accidentally reveals airport security secrets
• France to Digitize Its Own Literary Works
• Amazon Auctions Cloud Computation
• Court Finds Personal E-Mail Privileged Even if Sent From Work
o Supreme Court to Review Employer Access to Worker Text Messages
o Prosecutor’s E-Mail Sent to His Lawyer on a Work Account is Privileged, Court Says
• Free App Offers iPhone CLE Courses With Built-In Verification
• Ohio justices: Cell phone searches require warrant
• App of the Week: Google’s Eyes on the Ground
o Privacy fears force search giant to block facial recognition application on Google Goggles
• Not Just Drones: Militants Can Snoop on Most U.S. Warplanes
• EU Data Protection Meets U.S. Discovery

NEWS | PODCASTS | RESOURCES | FUN | LOOKING BACK | NOTES

Cyber breaches are a closely kept secret (Reuters, 24 Nov 2009) - Cybercriminals regularly breach computer security systems, stealing millions of dollars and credit card numbers in cases that companies keep secret, said the FBI’s top Internet crimes investigator on Tuesday. For every break-in like the highly publicized attacks against TJX Co (TJX.N) and Heartland Payment (HPY.N), where hacker rings stole millions of credit card numbers, there are many more that never make the news. “Of the thousands of cases that we’ve investigated, the public knows about a handful,” said Shawn Henry, assistant director for the Federal Bureau of Investigation’s Cyber Division. “There are million-dollar cases that nobody knows about.” Companies that are victims of cybercrime are reluctant to come forward out of fear the publicity will hurt their reputations, scare away customers and hurt profits. Sometimes they don’t report the crimes to the FBI at all. In other cases they wait so long that it is tough to track down evidence. “Keeping your head in the sand on filing a report means that the bad guys are out there hitting the next guy, and the next guy after that,” Henry said. He said the cybercrime problem has gotten bigger over the past three years because hackers have changed their attack methods as companies have tightened up security. “It’s absolutely gotten bigger, yes, absolutely,” he said. http://www.reuters.com/article/idUSTRE5AN4YH20091124

Obama Wants Computer Privacy Ruling Overturned (Wired, 25 Nov 2009) - The Obama administration is seeking to reverse a federal appeals court decision that dramatically narrows the government’s search-and-seizure powers in the digital age. Solicitor General Elena Kagan and Justice Department officials are asking the 9th U.S. Circuit Court of Appeals to reconsider its August ruling that federal prosecutors went too far when seizing 104 professional baseball players’ drug results when they had a warrant for just 10. The 9th U.S. Circuit Court of Appeals’ 9-2 decision offered Miranda-style guidelines to prosecutors and judges on how to protect Fourth Amendment privacy rights while conducting computer searches. Kagan, appointed solicitor general by President Barack Obama, joined several U.S. attorneys in telling the San Francisco-based court Monday that the guidelines are complicating federal prosecutions in the West. The circuit, the nation’s largest, covers nine states: Alaska, Arizona, California, Hawaii, Idaho, Montana, Nevada, Oregon and Washington. “In some districts, computer searches have ground to a complete halt,” the authorities wrote. “Many United States Attorney’s Offices have been chilled from seeking any new warrants to search computers.” (.pdf) The government is asking the court to review the case with all of its 27 judges, which it has never done. If the court agrees to a rehearing, a new decision is not expected for years, and the August decision would be set aside pending a new ruling. Either way, the U.S. Supreme Court has the final say. The controversial decision, which the government said was contrary to Supreme Court precedent, outlined new rules on how the government may search computers. (.pdf) http://www.wired.com/threatlevel/2009/11/obama-wants-computer-privacy-ruling-overturned/

Facebook’s Claim of Ownership of Posted Content Does Not Destroy CDA Immunity (Winston & Strawn, 30 Nov 2009) - The New York Supreme Court recently granted Facebook, Inc.’s motion to dismiss a pending defamation action because the court concluded that Facebook was immune from liability under the Communications Decency Act (“CDA”) as an interactive computer service. The plaintiff had alleged that four of her high school classmates created a Facebook group in which her classmates posted defamatory statements regarding the plaintiff. After Facebook moved to dismiss the case based upon CDA immunity, the plaintiff argued that because Facebook’s Terms of Use grant Facebook an ownership interest in the alleged defamatory content, CDA immunity is unavailable to Facebook. The court disagreed and concluded that ownership of posted content is irrelevant to a determination of whether CDA immunity should apply. The court held that as long as the defendant is an interactive computer service and the allegedly defamatory content is provided by a third party, the defendant is immune from liability under the CDA. http://www.winston.com/siteFiles/Publications/Facebook_Alert.html#page=1

EFF sues feds for info on social-network surveillance (CNET, 1 Dec 2009) - The Electronic Frontier Foundation sued the CIA, the U.S. Department of Defense, Department of Justice, and three other government agencies on Tuesday for allegedly refusing to release information about how they are using social networks in surveillance and investigations. The nonprofit Internet rights watchdog group formally asked more than a dozen agencies or departments in early October to provide records about federal guidelines on the use of sites like Facebook, Twitter, and Flickr for investigative or data gathering purposes, according to the lawsuit. The requests were prompted by published news reports about how authorities are using social networks to monitor citizen activities and aid in investigations. For example, according to the lawsuit, government officials have: used Facebook to hunt for fugitives and search for evidence of underage drinking; researched the activities of an activist on Facebook and LinkedIn; watched YouTube to identify riot suspects; searched the home of a social worker because of Twitter messages regarding police actions he sent during the G-20 summit; and used fake identities to trick Facebook users into accepting friend requests. http://news.cnet.com/8301-27080_3-10407224-245.html?part=rss&subj=news&tag=2547-1_3-0-5&utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+CnetNewscomMobile+%28CNET+News.com+Front+Door%29

Protecting Trademarks In Web 2.0 (Law.com, 1 Dec 2009) - During the past decade and a half, the internet has grown from a small array of just a few thousand websites to a vast network of hundreds of millions of distinct sites, containing billions of web pages. Although the internet has presented a new frontier for both trademark use and infringement, the growth of social media sites during the past few years has posed particular challenges for brand owners. These sites, which include blogs, virtual worlds, marketplaces, image networks and relative newcomers such as Facebook and Twitter, allow users to interact with each other, effectively building a community. With this landscape changing so rapidly, the first challenge for brand owners is simply to keep up with the evolving technologies and platforms. After all, five years ago, Facebook was a small private network for students at educational institutions and Twitter did not even exist; today, these platforms are a part of the daily lives of millions of users. In order to properly protect their brands and trademarks, brand owners should first plan to conduct regular assessments of the available social networking and Web 2.0 sites, with an eye to determining how popular these sites may be with the brand’s target consumers and the ease of using these sites for infringement purposes. Whether or not brand owners plan to become active in these spaces in the short term, they should keep in mind that their employees and customers may already be avid users of social media. Therefore, brand owners should take care to develop detailed use policies, both for employees and for third parties who may become a part of the user community. These policies should address in what context (if any) employees and third parties are permitted to mention the company and brand name, and, especially, who is authorized to speak on behalf of the company or brand and what internal reviews must take place before content is posted that mentions or concerns a brand (i.e., a review by the company’s legal department or outside counsel). These policies should extend to affiliates and licensees, and should be an element of any legal agreements between the company and third parties regarding brand and trademark use. Although social media can provide many excellent marketing and promotional opportunities for brand owners, entering these spaces can require a large time and financial investment. Thus, brand owners should take care to ensure that they are using the optimal platforms that will build their brands and reach the desired community of users. First, an assessment of the consumer demographic is a critical element of this process. Brand owners should choose the platforms that will reach their target customers and should not feel the need to build a presence on every single available platform. In addition, before committing to a social media initiative, brand owners should keep in mind that users of social media expect regular content updates, and that setting up social media sites and profiles and then neglecting them may do more harm than not using these platforms at all. Any budget for social media should take into account the costs and human capital necessary to maintain and update the content. http://www.law.com/jsp/article.jsp?id=1202435924630&rss=newswire&hbxlogin=1

Many More Government Records Compromised in 2009 than Year Ago, Report Claims (Gov’t Technology, 2 Dec 2009) - If you’re bummed about the data in your department that just got breached, you have some cold comfort. Although the combined number of reported data breaches in the government and the military has dropped in 2009 compared to last year, many more records were compromised in those breaches, according to recent figures compiled by a California nonprofit. As of Tuesday, Dec. 1., the Identity Theft Resource Center (ITRC) reported 82 breaches in U.S. government and military organizations. Although the year isn’t over, that’s fewer than the 110 that occurred in 2008. But here’s the catch: The breaches so far in 2009 have compromised more than 79 million records, whereas fewer than 3 million were hacked in 2008. http://www.govtech.com/gt/articles/734214

My K-12 Blind Spot (InsideHigherEd, 2 Dec 2009) - We are a mixed LMS household. My 7th grader uses Moodle, I use Blackboard. Watching her use of Moodle to hand in her assignments, watch linked videos, download readings, participate in discussions and check her grades is a nightly reminder that utilization of educational technology is not restricted to the post-secondary world. Some of my daughter’s teachers make the sort of use of Moodle that would be a great model faculty members wanting to leverage their campus LMS. Embarrassingly, my knowledge of K-12 utilization of learning technology basically starts and ends from whatever my daughter does while at home. The primary/secondary and post-secondary educational technology communities don’t seem to overlap very much. I get my news from Inside Higher Ed and the Chronicle of Higher Education. EDUCAUSE, my professional organization, defines its mission in part “to advance higher education by promoting the intelligent use of information technology”. The blogs I read tend to be written by people working in higher ed. But in looking at how my daughter’s teachers use Moodle I can’t help to wonder what I’m missing. Is there a great deal of innovation around pedagogy and technology occurring in the K-12 world? What is the penetration of the Learning Management System (LMS) at the secondary level of education? What is the adoption curve? Are there practices in teacher training and support in learning technology that we can learn from and adopt at the college/university level? Does anyone know any good publications that cross the secondary / post-secondary divide? Are there a whole bunch of innovative and disruptive thinkers, writers, and bloggers in middle and high-schools that I don’t know about? http://www.insidehighered.com/blogs/technology_and_learning/my_k_12_blind_spot

Google allows publishers to limit free content (AP, 2 Dec 2009) - Google Inc. is allowing publishers of paid content to limit the number of free news articles accessed by people using its Internet search engine, a concession to an increasingly disgruntled media industry. There has been mounting criticism of Google’s practices from media publishers — most notably News Corp. chairman and chief executive Rupert Murdoch — that argue the company is profiting from online news pages. In an official blog posted late Tuesday, Josh Cohen, Google’s senior business product manager, said the company had updated its so-called First Click Free program so publishers can limit users to viewing no more than five articles a day without registering or subscribing. Previously, each click from a user of Google’s search engine would be treated as free. “If you’re a Google user, this means that you may start to see a registration page after you’ve clicked through to more than five articles on the website of a publisher using First Click Free in a day ... while allowing publishers to focus on potential subscribers who are accessing a lot of their content on a regular basis,” Cohen said in the post. Cohen said that Google will also begin crawling, indexing and treating as “free” any preview pages — usually the headline and first few paragraphs of a story — from subscription websites. People using Google would then see the same content that would be shown free to a user of the media site and the stories labelled as “subscription” in Google News. http://news.yahoo.com/s/ap/20091202/ap_on_bi_ge/eu_google_free_news

Web ad group launches privacy education campaign (Washington Post, 3 Dec 2009) - A group of leading Internet publishers and digital marketing services on Thursday launched an online campaign to educate consumers about how they are tracked and targeted for pitches on the Web. The Interactive Advertising Bureau, based in New York, unveiled its “Privacy Matters” Web site. The site explains how Internet marketers track where people go and what they do online and then mine that data to serve up targeted ads. The practice, known as behavioral advertising, has raised concerns among privacy watchdogs and lawmakers in Congress. A number of IAB members plan to run banner spots on their Web pages linking back to the Privacy Matters site. Those include Internet-only players such as Yahoo Inc. and Google Inc. and traditional media outlets such as Walt Disney Co. and The New York Times Co. The goal of the program, explained IAB Senior Vice President David Doty, is to describe “in plain English” how online advertising works. Among other things, the Privacy Matters Web site offers explanations of demographic targeting, interest group targeting and data-tracking files known as cookies. The site also informs consumers how they can control the information collected about them by changing their cookies settings. The new campaign is part of a broader self-regulatory push by the Interactive Advertising Bureau and other advertising trade groups that want to head off federal regulation. http://www.washingtonpost.com/wp-dyn/content/article/2009/12/03/AR2009120303517.html

Google Wants to Speed Up the Web: Launches Its Own DNS Service (ReadWriteWeb, 3 Dec 2009) - Google just launched the Google Public DNS. Just like OpenDNS, Google Public DNS will allow users to bypass their ISPs Domain Name Servers (DNS). DNS servers are, in many respects, the backbone of the Internet. DNS allows you to type a domain name like www.senate.gov into a browser instead of a machine-readable IP number like http://156.33.195.33/. Google’s argues that it wants to give consumers an alternative to their ISPs’ DNS services in order to market the Internet “faster, safer and more reliable.” According to Google product manager Prem Ramaswami, the company’s engineers have been working to improve DNS over the last few months. Instead of performing DNS lookups on an ISP’s DNS server, Google will use its data-center and caching infrastructure to resolve these domain names. http://www.readwriteweb.com/archives/google_launches_google_public_dns_opendns_competitor.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29 [COMMENTARY: Michael Fleming, of Larkin Hoffman, comments: “I’ve been using OpenDNS for years. I like it for a number of reasons, including speed, reliability, as well as a sense that it’s less likely to get polluted by a hacker that might gain access to my ISP’s DNS (which, for most ISPs, is rather minimally monitored since they consider it automated, and hence a security risk for its users). If Google upholds those same principles, it’s OK by me. But... One concern is what happens when I type in a non-existent domain. It might just go blank or show a 404 error message. It might try to direct me to something that benefits Google (much akin to the highly complained about thing that NSI did a couple of years ago). It could be something in between, with a little bit of ads and some reasonable suggestions on what I might have meant to type in (which is what OpenDNS does now). Another concern is whether Google may try to influence the DNS by editing out domains it doesn’t like. OpenDNS, as well as most typical DNS providers, will not censor the DNS. Google could choose another policy. It might do so for admirable reasons (such as disabling access to known phishing sites), but that same thought could lead to less admirable reasons (such as disabling access to anonymous communication sites, or sites that a particular government doesn’t like, or the ability to go to bing.com, for example). * * * Done faithfully DNS is innocuous, but since it can be dangerous if misused we should not make decisions to switch lightly.” Another expert comments: “Another worry... DNS provides a centralized and low-bandwidth place for monitoring user behaviour. If you wanted to compile a database of IP addresses and the websites they visit, the DNS server is the best place to do it. Google openly engages in consumer monitoring via their ad and search services. I see no reason why they wouldn’t also retain DNS data.”]

- and -

Redirecting DNS Requests Can Harm the Internet, Says ICANN (PC World, 25 Nov 2009) - ICANN (Internet Corporation for Assigned Names and Numbers) on Tuesday condemned the practice of redirecting Internet users to a third-party Web site or portal when they misspell a Web address and type a domain name that does not exist. Rather than return an error message for DNS (Domain Name System) requests for nonexistent domains, some DNS operators send back the IP (Internet Protocol) address of another domain, a process known as NXDOMAIN substitution. http://www.pcworld.com/article/183135/redirecting_dns_requests_can_harm_the_internet_says_icann.html

Risk Avoidance May Explain Why Big Firm Blogs Are Boring, Blogger Says (ABA Journal, 3 Dec 2009) - An inquiring blogger wants to know: Why are blogs associated with large law firms sometimes so boring, and why did so few appear in the ABA Journal’s Blawg 100? Blogger Mark Herrmann is a partner with Jones Day’s Chicago office who writes for the Drug and Device Law blog. He identified only two blogs on the ABA Journal list that are affiliated with large firms: his blog and SCOTUSblog. Herrmann says successful legal blogs can succeed in three ways: They can be the first source of news, such as the Wall Street Journal’s Law Blog. They can be written by extremely smart people who are paid to “sit around thinking great thoughts,” such as the law professors writing for the Volokh Conspiracy, Concurring Opinions or Prawfs Blog. Or they can have a voice, such as the blog Simple Justice. The voice thing can be a problem for law firm blogs, according to Herrmann, because it’s so risky. Blogging solo practitioners may have to field complaints about their posts, but no one can complain to their colleagues. “Not so for those of us in the AmLaw 200.” The result of risk avoidance: “You strip all humor and provocation out of your posts. You lose your voice. The posts are good. They’re informative. They’re lawyerly. But they’re boring; no one’s drawn to them.” http://www.abajournal.com/news/article/risk_avoidance_may_explain_why_big_firm_blogs_are_boring_blogger_says/?utm_source=feedburner&utm_medium=feed&utm_campaign=ABA+Journal+Daily+News&utm_content=Twitter

Yahoo Issues Takedown Notice for Spying Price List (Wired, 4 Dec 2009) - Yahoo isn’t happy that a detailed menu of the spying services it provides law enforcement agencies has leaked onto the web. Shortly after Threat Level reported this week that Yahoo had blocked the FOIA release of its law enforcement and intelligence price list, someone provided a copy of the company’s spying guide to the whistleblower site Cryptome. The 17-page guide describes Yahoo’s data retention policies and the surveillance capabilities it can provide law enforcement, with a pricing list for these services. Cryptome also published lawful data-interception guides for Cox Communications, SBC, Cingular, Nextel, GTE and other telecoms and service providers. But of all those companies, it appears to be Yahoo’s lawyers alone who have issued a DMCA takedown notice to Cryptome demanding the document be removed. Yahoo claims that publication of the document is a copyright violation, and gave Cryptome owner John Young a Thursday deadline for removing the document. So far, Young has refused. Yahoo’s letter was sent on Wednesday, within hours of the posting of Yahoo’s Compliance Guide for Law Enforcement at Cryptome. In addition to copyright infringement, the letter accuses the site of revealing Yahoo’s trade secrets and engaging in “business interference.” According to the letter, disclosure of its surveillance services (.pdf) would help criminals evade surveillance. http://www.wired.com/threatlevel/2009/12/yahoo-spy-prices?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

Law profs say e-marriages expand couple’s rights (SiliconValley.com, 6 Dec 2009) - A Boston couple wanting to wed under Louisiana’s covenant marriage law, or two New Orleans women seeking to wed in Massachusetts should be able to do so without leaving home, two law professors say. Michigan State University’s Adam Candeub and Mae Kuykendall have started the Legal E-Marriage Project, a clearinghouse for legislative proposals to establish “e-marriages.” “According to the team, the proposal refutes suggestions the state should get out of the marriage business and has the potential to alter the landscape of marriage culture wars,” Michigan State law school spokeswoman Katie Gallagher wrote on the school’s Web site. Candeub and Kuykendall said states should let couples marry under the laws of whatever place they chose. A couple’s physical presence in the state authorizing a marriage has never been a universal rule, the professors said. Couples long have married by proxy, mail and telephone. “The state needs to fight marital fraud, harness modern technology to make marriage more accessible and open its symbolic value to a variety of communities both online and off line,” Kuykendall said. At San Diego’s Thomas Jefferson Law School, professor Bryan Wildenthal called it a “groundbreaking, an innovative approach to the entire issue of how law should regulate family relationships.” Same-sex couples could marry in California under the laws of Massachusetts or Vermont, if the states enacted e-marriage provisions, Candeub and Kuykendall said. A couple’s home state would not necessarily have to recognize the marriage. http://www.siliconvalley.com/news/ci_13939808?nclick_check=1

Local Governments Offer Data to Software Tinkerers (New York Times, 6 Dec 2009) - A big pile of city crime reports is not all that useful. But what if you could combine that data with information on bars, sidewalks and subway stations to find the safest route home after a night out? Stamen Design put together the San Francisco Crimespotting site using information from the city’s police department. DC Bikes, which shows bike paths in the Washington area, and Stumble Safely, which shows the safest way to get home from bars at night there, were both developed using government data. In Washington, a Web site called Stumble Safely makes that possible. It is one example of the kind of creativity that cities are hoping to mobilize by turning over big chunks of data to programmers and the public. Many local governments are figuring out how to use the Internet to make government data more accessible. The goal is to spawn useful Web sites and mobile applications — and perhaps even have people think differently about their city and its government. “It will change the way citizens and government interact, but perhaps most important, it’s going to change the way elected officials and civil servants deliver programs, services and promises,” said Gavin Newsom, the mayor of San Francisco, which is one of the cities leading the way in releasing government data to Web developers. “I can’t wait until it challenges and infuriates the bureaucracy.” Advocates of these open-data efforts say they can help citizens figure out what is going on in their backyards and judge how their government is performing. But programmers have had trouble getting their hands on some data. And some activists and software developers wonder whether historically reticent governments will release data that exposes problems or only information that makes them look good. It is too early to say whether releasing city data will actually make civil servants more accountable, but it can clearly be useful. Even data about mundane things like public transit and traffic can improve people’s lives when it is packaged and customized in an accessible way — a situation that governments themselves may not be equipped to realize. A Web site called CleanScores, for instance, tracks restaurant inspection scores in various cities and explains each violation. After School Special combines data from San Francisco schools, libraries and restaurants so parents can plan after-school activities and see how children’s nutritional options compare by neighborhood. And Trees Near You, available for the iPhone, lets people identify trees on New York streets. By releasing data in easy-to-use formats, cities and states hope that people will create sites or applications that use it in ways City Hall never would have considered. http://www.nytimes.com/2009/12/07/technology/internet/07cities.html

With Lure of Cash, M.I.T. Group Builds a Balloon-Finding Team to Take Pentagon Prize (New York Times, 6 Dec 2009) - A group of researchers at the Massachusetts Institute of Technology edged out about 4,300 other teams on Saturday in a Pentagon-sponsored contest to correctly identify the location of 10 red balloons distributed around the United States. The contest, which featured a $40,000 prize, was organized by the Defense Advanced Research Projects Agency, in an effort to develop new ways to understand how information is disseminated through social networks. The winning group, a small team at the M.I.T. Media Laboratory Human Dynamics Group led by a physicist, Riley Crane, took just eight hours and 56 minutes to complete the challenge. The balloons, which were 8 feet in diameter, were arrayed around the country. Some were in highly trafficked locations like Union Square in San Francisco; others were in more obscure places, like Katy Park, a baseball field in the Houston suburbs. The winning researchers, who specialize in studying human interactions that emerge from computer networks, set up a Web site asking people to join their team. They relied on visitors to the Web site to invite their friends. They also sent e-mail messages inviting people to participate and sent a small number of advertisements to mobile phones. They said that they would dole out the prize money both to chains of individuals who referred people who had correct information on the balloons’ locations and to charities. They described their method as a “recursive incentive structure.” http://www.nytimes.com/2009/12/07/technology/internet/07contest.html

See That Funny 2D Barcode In The Store Window? It Might Pull Up A Google Listing (TechCrunch, 6 Dec 2009) - What if every store had a bar-code sticker on its window so that you could pull out your iPhone, wave it in front of the bar code and get all sorts of information about that business—the telephone number, photos, customer reviews? Starting on Monday, you’ll be able to do that at up to 190,000 local businesses throughout the U.S. Google has mailed out window stickers with two-dimensional bar codes (aka, QR codes) to the most-searched for or clicked-on businesses in its local business directory. Anyone with a QR code reader in their phone can scan it to call up a Google Mobile local directory page for one of these “Favorite Places,” which generally includes a map, phone number, directions, address, reviews, and a link to the store’s website. (It’s a mobile version of Google Places). Local businesses can also set up coupon offers through their Google directory page, which would turn the QR code into a mobile coupon, and help entice someone standing outside a store to come in: “If you found us on Google, you get 20% off.” Japan is already QR-crazy. Google wants the U.S. to be next. In conjunction with the QR code sticker roll-out, Google is also giving away 40,000 Quickmark QR Code Reader apps for the iPhone, which normally cost $1.99 apiece. But you can use any QR code reader. There are a bunch of free ones, some on Android phones as well. There are now over a million local businesses which have claimed their Google local listing, up from a few hundred thousand last summer. If these QR code stickers become popular in the U.S., it could encourage more small businesses to claim their listings and give Google cleaner data. http://www.techcrunch.com/2009/12/06/google-local-maps-qr-code/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

New Smithsonian Collection Search (BeSpacific, 7 Dec 2009) - The Collections Search Center provides easy “one-stop searching” of more than 2 million of the Smithsonian’s museum, archives, library and research holdings and collections. The access to more Smithsonian collections via this Search Center is increasing over time. Collections currently available include: 265,900 images, video and sound files, electronic journals and other resources from the Smithsonian’s museums, archives & libraries.” http://www.bespacific.com/mt/archives/022958.html

Florida: Judges Cannot be Facebook Friends with Litigants (Social Media Law Student, 9 Dec 2009) - Florida’s Judicial Ethics Advisory Committee responded to a few questions from one Florida judge about the use of social networking sites. The Committee found that judges cannot accept friend requests from litigants in their court. They take special care to note: “This opinion should not be interpreted to mean that the inquiring judge is prohibited from identifying any person as a “friend” on a social networking site. Instead, it is limited to the facts presented by the inquiring judge, related to lawyers who may appear before the judge. Therefore, this opinion does not apply to the practice of listing as “friends” persons other than lawyers, or to listing as “friends” lawyers who do not appear before the judge, either because they do not practice in the judge’s area or court or because the judge has listed them on the judge’s recusal list so that their cases are not assigned to the judge.” It’s pretty clear from this opinion that accepting a request on Facebook, LinkedIn and Myspace from a litigant in the judge’s court are out. The opinion does not just apply to those sites though: “Although Facebook has been used as an example in this opinion, the holding of the opinion would apply to any social networking site which requires the member of the site to approve the listing of a “friend” or contact on the member’s site, if (1) that person is a lawyer who appears before the judge, and (2) identification of the lawyer as the judge’s “friend” is thereafter displayed to the public or the judge’s or lawyer’s other “friends” on the judge’s or the lawyer’s page.” Any sites with a Facebook-like approach will obviously meet the criteria of this opinion. My question is: what about Twitter? If someone is protected on Twitter, they have to approve all followers. However, anybody can see which followers have been approved. So, does that constitute identification as a “friend” on the judge’s page? I think it very well might. You can read the full committee opinion, which also discusses campaign committees, here.
http://socialmedialawstudent.com/featured/florida-judges-cannot-be-facebook-friends-with-litigants/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+SocialMediaLawStudent+%28Social+Media+Law+Student%29

TSA accidentally reveals airport security secrets (Washington Post, 9 Dec 2009) - The Transportation Security Administration inadvertently revealed closely guarded secrets related to airport passenger screening practices when it posted online this spring a document as part of a contract solicitation, the agency confirmed Tuesday. The 93-page TSA operating manual details procedures for screening passengers and checked baggage, such as technical settings used by X-ray machines and explosives detectors. It also includes pictures of credentials used by members of Congress, CIA employees and federal air marshals, and it identifies 12 countries whose passport holders are automatically subjected to added scrutiny. TSA officials said that the manual was posted online in a redacted form on a federal procurement Web site, but that the digital redactions were inadequate. They allowed computer users to recover blacked-out passages by copying and pasting them into a new document or an e-mail. Current and former security officials called the breach troubling, saying it exposed TSA practices that were implemented after the Sept. 11, 2001, terrorist attacks and expanded after the August 2006 disruption of a plot to down transatlantic airliners using liquid explosives. Checkpoint screening has been a fixture of the TSA’s operations -- as well as a lightning rod for public criticism of the agency’s practices. Stewart A. Baker, a former assistant secretary at the Department of Homeland Security, said that the manual will become a textbook for those seeking to penetrate aviation security and that its leaking was serious. “It increases the risk that terrorists will find a way through the defenses,” Baker said. “The problem is there are so many different holes that while [the TSA] can fix any one of them by changing procedures and making adjustments in the process . . . they can’t change everything about the way they operate.” Another former DHS official, however, called the loss a public relations blunder but not a major risk, because TSA manuals are shared widely with airlines and airports and are available in the aviation community. http://www.washingtonpost.com/wp-dyn/content/article/2009/12/08/AR2009120803206_pf.html

France to Digitize Its Own Literary Works (New York Times, 14 Dec 2009) - President Nicolas Sarkozy pledged nearly $1.1 billion on Monday toward the computer scanning of French literary works, audiovisual archives and historical documents, an announcement that underscored his government’s desire to maintain control over France’s cultural heritage in an era of digitization. The French National Library announced in August that it was engaged in discussions with Google over the digitization of its collections, part of a global effort by Google to digitize the world’s literary works. This provoked an uproar among French officials and the publishing community here, and the discussions were suspended. “We won’t let ourselves be stripped of our heritage to the benefit of a big company, no matter how friendly, big or American it is,” Mr. Sarkozy said last week, apparently in a reference to Google. The money pledged Monday will finance a public-private partnership that will digitize the nation’s cultural works, Mr. Sarkozy said. Yet that partnership might well involve Google. “The question remains open,” said Bruno Racine, president of the National Library, in a telephone interview. He emphasized the “necessity of a partnership with the private sector” in order to secure the capital needed for vast digitization projects. He put the cost of digitizing the National Library’s collections, which include over 14 million books and several million other documents, at more than $1.5 billion. Those who opposed the National Library’s discussions with Google were concerned primarily with its “dominant place” in the digital market, he said, noting, “It’s not so much that it is a private company.” The French culture minister, Frédéric Mitterrand, met last week with David C. Drummond, a senior vice president and chief legal officer at Google, to express his concerns about a potential collaboration with the company. France has long regarded Google warily. In 2005, French and German leaders announced plans, since abandoned, to develop a multimedia search engine to be called Quaero — “I seek,” in Latin — seen by many as a direct challenge to the company. The French government has also urged the European Union to undertake its own book digitization project. http://www.nytimes.com/2009/12/15/world/europe/15france.html?_r=1

Amazon Auctions Cloud Computation (Information Week, 14 Dec 2009) - Amazon on Monday began offering its Amazon Elastic Compute Cloud (EC2) customers the chance to bid on unused computing capacity. The new purchasing model, called Spot Instances, allows Amazon Web Services (AWS) customers to place bids for computing power and have their jobs processed if their bid exceeds the fluctuating “Spot Price.” “The central concept in this new option is that of the Spot Price, which we determine based on current supply and demand and will fluctuate periodically,” explained Amazon CTO Werner Vogels in a blog post. “If the maximum price a customer has bid exceeds the current Spot Price then their instances will be run, priced at the current Spot Price. If the Spot Price rises above the customer’s bid, their instances will be terminated and restarted (if the customer wants it restarted at all) when the Spot Price falls below the customer’s bid. This gives customers exact control over the maximum cost they are incurring for their workloads, and often will provide them with substantial savings.” Vogels said that bids higher than the Spot Price are only charged at Spot Price rate. Jeff Barr, Amazon Web Services evangelist, explains in a blog post that Spot Instances can be particularly useful for low-priority work that can be deferred until computing demand and price are low. EC2 continues to offer two other pricing methods: On-Demand Instances, which are charged at a published rate, and Reserved Instances, pre-paid at a discounted rate for use up to three years later. Typical jobs for EC2 involve analyzing data sets, media file format conversion, or Web crawling for a search index, for example. Pharmaceutical giant Pfizer has been using AWS -- EC2 and other services like S3, SQS, and SimpleDB -- to model antibody behavior. http://www.informationweek.com/news/software/web_services/showArticle.jhtml?articleID=222001983&cid=RSSfeed_IWK_News

Court Finds Personal E-Mail Privileged Even if Sent From Work (NLJ, 14 Dec 2009) - A federal prosecutor has won his fight to conceal e-mails he sent to his attorney over the government’s computers, contradicting a popular belief that employees have no expectation of privacy on work computers. The U.S. District Court for the District of Columbia ruled on Thursday that Assistant U.S. Attorney Jonathan Tukel had a reasonable expectation of privacy in those e-mails because federal prosecutors were allowed to use work e-mail for personal matters. Therefore, Tukel’s messages to his private lawyer sent from work are covered by the attorney-client privilege and can remain confidential. The party trying to get the e-mails is former federal prosecutor Richard Convertino, who lost his job after his convictions in a high-profile terrorism trial in Detroit were overturned in 2004 due to prosecutorial misconduct. Convertino, who believes he was retaliated against for blowing the whistle on incompetence in the Bush administration’s war on terror, is trying to find out who leaked confidential information about an investigation into his conduct to the Detroit Free Press. Convertino believes Tukel’s e-mails to his lawyer may shed some light on the matter. According to court documents, Tukel was the prosecutor in Detroit who reviewed Convertino’s cases, and he was “one of the original parties that initiated confidential personal matters” related to Convertino. Tukel has denied in an affidavit that he’s the source of the leak. But Convertino still wants the e-mails. He argued that Tukel had no privacy expectations in e-mails sent over a government computer. The court disagreed. “The DOJ maintains a policy that does not ban personal use of the company email. Although the DOJ does have access to personal emails sent through this account, Mr. Tukel was unaware that they would be regularly accessing and saving emails sent from his account. Because his expectations were reasonable, Mr. Tukel’s private emails will remain protected by the attorney-client privilege,” wrote Chief Judge Royce Lamberth. Tukel’s lawyer, James K. Robinson, a partner in the Washington office of Cadwalader, Wickersham & Taft, said the judge got it right -- “Where someone who uses their company e-mail, whether with the Justice Department or someone else, intends the communication to be confidential and takes reasonable steps to ensure the confidentiality ... there is no waiver of the attorney-client privilege.” http://www.law.com/jsp/article.jsp?id=1202436284416&rss=newswire&hbxlogin=1

- and -

Supreme Court to Review Employer Access to Worker Text Messages (Law.com, 15 Dec 2009) - The U.S. Supreme Court said Monday it will decide how much privacy workers have when they send text messages from company accounts. The justices said they will review a federal appeals court ruling that sided with California police officers who complained that the department improperly snooped on their electronic exchanges. The 9th U.S. Circuit Court of Appeals in San Francisco also faulted the text-messaging service for turning over transcripts of the messages without the officers’ consent. Users of text-messaging services “have a reasonable expectation of privacy” regarding messages stored on the service provider’s network, 9th Circuit Judge Kim Wardlaw said. Both the city and USA Mobility Wireless, Inc., which bought the text-messaging service involved in the case, appealed the 9th Circuit ruling. The justices turned down the company’s appeal, but said they would hear arguments next year in the city’s case. The appeals court ruling came in a lawsuit filed by Ontario police Sgt. Jeff Quon and three others after Arch Wireless gave their department transcripts of Quon’s text messages in 2002. Police officials read the messages to determine whether department-issued pagers were being used solely for work purposes. The city said it discovered that Quon sent and received hundreds of personal messages, including many that were sexually explicit. Quon and the others said the police force had an informal policy of not monitoring the usage as long as employees paid for messages in excess of monthly character limits. http://www.law.com/jsp/article.jsp?id=1202436331177&rss=newswire&hbxlogin=1

- and -

Prosecutor’s E-Mail Sent to His Lawyer on a Work Account is Privileged, Court Says (ABA Journal, 15 Dec 2009) - A federal prosecutor’s e-mail to his own lawyer is privileged, even though he sent it from work on a government computer, a federal court has ruled. Because he is allowed to use his work e-mail account for personal communications, assistant U.S. Attorney Jonathan Tukel had a reasonable expectation of privacy in those personal communications, explains the U.S. District Court for the District of Columbia in a written opinion. And because there was a reasonable expectation of privacy, they are confidential attorney-client privileged documents. Another factor in the decision, according to the National Law Journal, is that Tukel wasn’t aware that the government had access to his account and might be looking at his personal e-mail. However, partner James Robinson of Cadwalader Wickersham & Taft, who represents Tukel, called for confidentiality of work e-mail communications to be generally recognized, when they are intended to be confidential. http://www.abajournal.com/news/article/e-mail_sent_to_lawyer_on_work_account_is_privileged_appeals_court_says/?utm_source=feedburner&utm_medium=feed&utm_campaign=ABA+Journal+Daily+News&utm_content=Twitter

Free App Offers iPhone CLE Courses With Built-In Verification (ABA Journal, 15 Dec 2009) - Lawyers looking for continuing legal education credit can download a new app that allows them to find courses, listen to audio programs and access materials on their iPhone and iPod touch. Users can set up a free account at West LegalEdcenter to buy programs that can be downloaded using the free app, known as CLE Mobile, according to a Thomson Reuters press release. More than 2,000 audio courses are available. But don’t think that you can get credit just by downloading CLE programs. The app tracks and ensures that the program has played, and randomly verifies interaction in states that require the feature, according to West LegalEdcenter accreditation manager Gina Roers, writing at the center’s CLE Mobile blog. To verify attendance, a bell sounds during the program, and the lawyer has to tap “verify,” according to a CLE Mobile reference guide. When lawyers complete the programs, they can use the app to request CLE credit. A YouTube video shows a lawyer using the program while riding a train, at a coffeeshop and while taking a walk. The app is available from the App Store. http://www.abajournal.com/news/article/free_app_offers_iphone_cle_courses_with_built-in_verification/?utm_source=feedburner&utm_medium=feed&utm_campaign=ABA+Journal+Daily+News&utm_content=Twitter

Ohio justices: Cell phone searches require warrant (Washington Post, 15 Dec 2009) - The Ohio Supreme Court said Tuesday police officers must obtain a search warrant before scouring the contents of a suspect’s cell phone, unless their safety is in danger. The American Civil Liberties Union of Ohio described the ruling as a landmark case. The issue appears never to have reached another state high court or the U.S. Supreme Court. The Ohio high court ruled 5-4 in favor of Antwaun Smith, who was arrested on drug charges after he answered a cell phone call from a crack cocaine user acting as a police informant. Officers took Smith’s cell phone when he was arrested and, acting without a warrant and without his consent, searched it. They found a call history and stored numbers that showed Smith had previously been in contact with the drug user. http://www.washingtonpost.com/wp-dyn/content/article/2009/12/15/AR2009121501903.html

App of the Week: Google’s Eyes on the Ground (New York Times, 16 Dec 2009) - Google Goggles is a new free app for smartphones using the Android operating system. With its grab bag of features, the app is a bit hard to define. Goggles uses a phone’s camera for data entry, Web searching and shopping, with a little bit of augmented reality thrown in. Here’s how it works. You use your phone to take a photo of a building, artwork, a bar code or some text and Goggles identifies it and brings back Google search results. A photo of a book cover brought back links to where the book is sold online, reviews, a Wikipedia entry on the author and more. A picture of the exterior of a restaurant brings back reviews, links to the restaurant’s Web site and a link to call the place with one click. When the phone is held parallel to the ground, nearby points of interest, like businesses and restaurants, float by on the bottom of the screen in what is called augmented reality. http://www.nytimes.com/2009/12/17/technology/personaltech/17app.html?_r=1&scp=1&sq=google%20goggles&st=cse [Artwork? From museums or galleries? How cool would that be!]

- but -

Privacy fears force search giant to block facial recognition application on Google Goggles (Daily Mail, 14 Dec 2009) - Privacy concerns have forced Google to delay an expansion of its Goggles service which would have enabled camera-phone users to identify strangers on the street. The experimental Google Goggles application, which was launched last week, allows smart-phone users to search for subjects simply by snapping a picture of them. Users can focus their phone’s camera on an object and Google will try to match portions of the picture with the tens of millions of images in its database. But privacy campaigners have raised fears over the ‘ facial recognition’ potential of the service, which would allow users to track strangers through a photograph. Google, which has confirmed the technology is available but has yet to decide if it will be rolled-out as part of Goggles, has now confirmed that it is blocking aspects of the application until privacy implications have been fully explored. http://www.dailymail.co.uk/sciencetech/article-1235741/Google-Goggles-Search-giant-blocks-facial-recognition-picture-search-app-privacy-concerns.html

Not Just Drones: Militants Can Snoop on Most U.S. Warplanes (DangerRoom, 17 Dec 2009) - Tapping into drones’ video feeds was just the start. The U.S. military’s primary system for bringing overhead surveillance down to soldiers and Marines on the ground is also vulnerable to electronic interception, multiple military sources tell Danger Room. That means militants have the ability to see through the eyes of all kinds of combat aircraft — from traditional fighters and bombers to unmanned spy planes. The problem is in the process of being addressed. But for now, an enormous security breach is even larger than previously thought. The military initially developed the Remotely Operated Video Enhanced Receiver, or ROVER, in 2002. The idea was let troops on the ground download footage from Predator drones and AC-130 gunships as it was being taken. Since then, nearly every airplane in the American fleet — from F-16 and F/A-18 fighters to A-10 attack planes to Harrier jump jets to B-1B bombers has been outfitted with equipment that lets them transmit to ROVERs. Thousands of ROVER terminals have been distributed to troops in Afghanistan and Iraq. But those early units were “fielded so fast that it was done with an unencrypted signal. It could be both intercepted (e.g. hacked into) and jammed,” e-mails an Air Force officer with knowledge of the program. In a presentation last month before a conference of the Army Aviation Association of America, a military official noted that the current ROVER terminal “receives only unencrypted L, C, S, Ku [satellite] bands.” So the same security breach that allowed insurgent to use satellite dishes and $26 software to intercept drone feeds can be used the tap into the video transmissions of any plane. The military is working to plug the hole — introducing new ROVER models that communicate without spilling its secrets. “Recognizing the potential for future exploitation the Air Force has been working aggressively to encrypt these ROVER downlink signals. It is my understanding that we have already developed the technical encryption solutions and are fielding them,” the Air Force officer notes. But it won’t be easy. An unnamed Pentagon official tells reporters that “this is an old issue that’s been addressed.” Air Force officers contacted by Danger Room disagree, strongly. “This is not a trivial solution,” one officer observes. “Almost every fighter/bomber/ISR [intelligence surveillance reconnaissance] platform we have in theater has a ROVER downlink. All of our Tactical Air Control Parties and most ground TOCs [tactical operations centers] have ROVER receivers. We need to essentially fix all of the capabilities before a full transition can occur and in the transition most capabilities need to be dual-capable (encrypted and unencrypted).” http://www.wired.com/dangerroom/2009/12/not-just-drones-militants-can-snoop-on-most-us-warplanes/

EU Data Protection Meets U.S. Discovery (Law.com, 18 Dec 2009) - As a result of an increase in U.S. lawsuits requiring the transfer of personal data from France to the United States, the French Data Protection Agency (CNIL) published a recommendation in August 2009, which is designed to offer guidance on data transfers in connection with U.S. civil discovery proceedings.[FOOTNOTE 1] The CNIL’s recommendation expands on the guidelines adopted by the body of European data protection agencies (the Article 29 Data Protection Working Party) in February 2009.[FOOTNOTE 2] EU member states increasingly enforce their data protection laws. For instance, in 2008, the Spanish data protection agency imposed fines amounting in total to €22.6 million. In France and other EU countries, companies are under pressure to comply with U.S. discovery requests, which frequently call for the production of personal data about employees, clients, or customers. The CNIL’s recommendation reflects a tension between a company’s obligation to respond to U.S. discovery requests and its obligation to comply with EU data protection laws. Because data protection laws pursue a legitimate interest and are increasingly enforced in Europe, courts and litigants in the U.S. should take them into account when ordering discovery abroad. * * * The CNIL indicates that, where a person in France engages in a “single and non-massive transfer” of data to the US, which is necessary or legally required for the establishment, exercise, or defense of legal claims, the company responding to the U.S. discovery request does not need to request the CNIL’s prior authorization, but should simply provide advance notice. By contrast, “massive and repeated” transfers of data require the CNIL’s authorization and are only lawful where (i) the recipient of personal data is an entity established in the U.S. that has subscribed to the Safe Harbor Scheme; (ii) the parties have adopted standard contract clauses issued by the European Commission; or (iii) the recipient has a set of strict and binding corporate rules in place providing an adequate level of protection of personal data. The CNIL does not provide guidance regarding the volume of data that would trigger the need for CNIL authorization. http://www.law.com/jsp/article.jsp?id=1202436660249&rss=newswire&hbxlogin=1

**** NOTED PODCASTS ****
Rethinking Green (Stewart Brand, 9 Oct 2009) - Brand builds his case for rethinking environmental goals and methods on two major changes going on in the world. The one that most people still don’t take into consideration is that power is shifting to the developing world, where 5 out of 6 people live, where the bulk of humanity is getting out of poverty by moving to cities and creating their own jobs and communities (slums, for now). He noted that history has always been driven by the world’s largest cities, and these years they are places like Mumbai, Lagos, Dhaka, Sao Paulo, Karachi, and Mexico City, which are growing 3 times faster and 9 times bigger than cities in the currently developed world ever did. The people in those cities are unstoppably moving up the “energy ladder” to high quality grid electricity and up the “food ladder” toward better nutrition, including meat. As soon as they can afford it, everyone in the global South is going to get air conditioning. The second dominant global fact is climate change. Brand emphasized that climate is a severely nonlinear system packed with tipping points and positive feedbacks such as the unpredicted rapid melting of Arctic ice. Warming causes droughts, which lowers carrying capacity for humans, and they fight over the diminishing resources, as in Darfur. It also is melting the glaciers of the Himalayan plateau, which feed the rivers on which 40% of humanity depends for water in the dry season—the Indus, Ganges, Brahmaputra, Mekong, Irrawaddy, Yangtze, and Yellow. http://www.longnow.org/seminars/02009/oct/09/rethinking-green/ [Editor: This is fascinating, especially given that Brand is extremely thoughtful and credible. Has nothing to do with IT law, but worth your time anyway. 90-minute podcast; ONE-STAR]

**** RESOURCES ****
Disclosure, Deception and Deep-Packet Inspection: The Role of the Federal Trade Commision Act’s Deceptive Conduct Prohibitions in the Net Neutrality Debate (SSRN paper by Prof. Catherine Sandoval) - This Article examines a largely unexplored frontier in the “Net Neutrality” debate: the Federal Trade Commission (FTC) Act’s proscriptions against deceptive conduct as a legal limit on Internet Service Provider (ISP) discrimination against Internet traffic. ISP discrimination against certain types of Internet traffic has blossomed since 2005 when the Federal Communications Commission (FCC), with the Supreme Court’s blessing in NCTA v. Brand X and FCC, relieved ISPs from common-carrier regulations that prohibited discrimination and reclassified ISPs as “information service providers.” This Article argues that the Internet’s architecture and codes presumed common carriage, indicating that the Internet’s design and industry “self-regulation” cannot alone prevent ISPs who control access to the Internet’s physical layer from becoming its gatekeepers. The FTC and FCC must use their respective authority to police the gulf between ISP promises and practices, protect Internet users and competition, and safeguard the Internet itself as a source for innovation and a wide range of speech. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1516705

**** FUN ****
Most Awesomely Bad Military Acronyms 7 (Danger Room, 1 Dec 2009) - It’s the most wonderful time of the year. Not because of some lame holiday. Because it’s time again for our Most Awesomely bad Military Acronyms (MAMAs).
The defense and intelligence establishment is famous for stirring words into an insane alphabet soup of acronyms, abbreviations, and neologisms. For over a year, we’ve been on a quest to find the silliest, most agonizing MAMAs out there. Our latest batch has a heroic bent - the champions of mil-jargon, if you will. Behold!
* Communications Electronic Attack with Surveillance And Reconnaissance. (CEASAR)
* Game-theoretic Optimal Deformable Zone including Inertia with Local Approach (GODZILA)
* Applied Research reGarding Operationally Novel And Unique Technologies (ARGONAUT)
* Automated Low-Level Analysis and Description of Diverse Intelligence Video (ALADDIN)
* Joint Counter Radio Controlled Improvised Explosive Device Electronic (JCREW)
* Bioterrorism Operations Policy for Public Emergency/Chemoterrorism Operations Policy for Public Emergency (BOPPER/COPPER)
http://www.wired.com/dangerroom/2009/11/most-awesomely-bad-military-acronyms-7/

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
HAS GOVERNMENT ENCRYPTION EXPORT POLICY FAILED? -- Researchers at George Washington University’s Cyberspace Policy Institute are telling the Senate Commerce Committee that the most powerful encryption software is now widely accessible internationally, despite the Clinton Administration’s efforts to restrict the spread of “strong encryption” technology for fear it would be used by terrorists and criminals. But the U.S. has lost its monopoly on the mathematical algorithms underlying advanced encryption techniques, and 167 products now available internationally use algorithms that can not be decoded by even the largest and most sophisticated computers. (New York Times 10 Jun 99) http://www.nytimes.com/library/tech/99/06/biztech/articles/10code.html

**** NOTES ****
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC. Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note,
8. Steptoe & Johnson’s E-Commerce Law Week,
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, November 28, 2009

MIRLN --- 8-28 November 2009 (v12.16)

• Leaked ACTA Internet Provisions: Three Strikes and a Global DMCA
• Federal Judge Calls Courtroom Tweets Banned Broadcasts Under Rule 53
• Consent Will be Required for Cookies in Europe
o French Senate Issues New Legislation to Amend Data Protection Act: Provisions Include Breach Notice Obligation and Consent for Use of Cookies
• Towards a “Privacy Privilege” to Oppose Discovery Requests?
• Sticks and Stones – More about Online Reputation Management
• Department of Interior Fails Cybersecurity Audit
o NIST Drafts Cybersecurity Guidance
• World Justice Project Rule of Law Index
• Ninth Circuit Ruling Leads to Spike in Class Actions Over Text Messages from Retailers
• Employers Win a Round in the Fight over whether Disloyal Employees are “Authorized” to Access Company Computers
• Two German Killers Demanding Anonymity Sue Wikipedia’s Parent
• W.Va. Supreme Court Opts for E-Mail Secrecy
• International Activists Launch New Website to Gather and Share Copyright Knowledge
• A Rush to Learn English by Cell
• Twitter and the Learning Technology Stream
• More Hackers Target Law Firms, Often ‘Spear Fishing’ in Spam E-Mail
• Goal of New ABA Website: All the Federal Decisions that are Fit to Print
o Bridging the Digital Divide: a New Vendor in Town? Google Scholar Now Includes Case Law
o Google Scholar Legal Opinion and Journal Search, ABA LTRC Free Full-Text Law Review/Law Journal Search
• Wow! Top Execs Say they are Influenced by Social Networks
• In-Q-Tel Invests in Cybersecurity Company
• DHS Critical Infrastructure Protection Website Launched
• India Establishes Broad Interception, Data Retention, Cyber Security, and Website Blocking Requirements
• Some Courts Raise Bar on Reading Employee Email
• 200 Web Sites Spread al-Qaida’s Message in English
• Military Video System is Like YouTube with Artillery
• Memento: Protocol-Based Time Travel for the Web
• A Look at Twitter’s Updated Privacy Policy
• Law Firm Invokes Privacy Laws in Suing Rival over Search Engine Keywords
• Levi’s is Paying Orrick a Flat Fee to Handle all but its IP Work
• Wikileaks Releases over Half a Million Pager Messages from 9/11
• Google Profiles turn into OpenIds

NEWS | RESOURCES | FUN | LOOKING BACK | NOTES

LEAKED ACTA INTERNET PROVISIONS: THREE STRIKES AND A GLOBAL DMCA (EFF, 9 Nov 2009) - Negotiations on the highly controversial Anti-Counterfeiting Trade Agreement (ACTA) began last week in Seoul, Korea. The closed negotiations focused on “enforcement in the digital environment.” Negotiators discussed the Internet provisions drafted by the US government. No text has been officially released, but as Professor Michael Geist and IDG are reporting, leaks have surfaced. The leaks confirm everything we have feared about the secret ACTA negotiations. The Internet provisions have nothing to do with addressing counterfeit products but are all aimed at imposing a set of copyright industry demands on the global Internet, including obligations on ISPs to adopt Three Strikes Internet disconnection policies and a global expansion of DMCA-style TPM laws. For the leaked commission memo: http://www.michaelgeist.ca/content/view/4516/125/ https://www.eff.org/deeplinks/2009/11/leaked-acta-internet-provisions-three-strikes-and-

FEDERAL JUDGE CALLS COURTROOM TWEETS BANNED BROADCASTS UNDER RULE 53 (ABA Journal, 9 Nov 2009) - A federal judge in Georgia has banned reporters from sending live-action tweets from his courtroom, saying that Twitter is a form of broadcasting and hence prohibited under Rule 53 of the Federal Rules of Criminal Procedure. But the ruling by U.S. District Judge Clay Land only extends as far as the courtroom door, suggests the Taking Liberties blog of CBS News: “All an intrepid spectator in Judge Clay Land’s courtroom apparently needs to do is write something inside the courtroom, and then step outside before pressing ‘send,’ “ the blog states. The Volokh Conspiracy provides a link to the judge’s four-page order (PDF), which was made last week in response to a request by a Columbus Ledger-Enquirer reporter to tweet about an upcoming trial. http://www.abajournal.com/news/federal_judge_calls_courtroom_tweets_banned_broadcasts_under_rule_53/

CONSENT WILL BE REQUIRED FOR COOKIES IN EUROPE (Out-Law.com, 9 Nov 2009) - A law that demands consent to internet cookies has been approved and will be in force across the EU within 18 months. It is so breathtakingly stupid that the normally law-abiding business may be tempted to bend the rules to breaking point. The fate of Europe’s cookie law became improbably entwined with a debate over file-sharing. To cut a long story short, it broke free. On 26th October, it was voted through by the Council of the EU. It cannot be stopped and awaits only the rubber-stamp formalities of signature and publication. The vote’s result was announced by way of a whisper. It featured at the tail end of an 18-page Council press release (PDF) that first had to address fishing quotas, train driving licences and a maritime treaty with China. I’m afraid we missed it. There was no attempt to bury this news – but the hushed tones of its reporting were consistent with the media attention it has received to date. There has been almost no fuss about this little law, despite the harm it could do to advertising, the lifeblood of online publishing. It also threatens to irritate all web users by appearing at every new destination like an over-zealous security guard. Here’s what’s coming. The now-finalised text says that a cookie can be stored on a user’s computer, or accessed from that computer, only if the user “has given his or her consent, having been provided with clear and comprehensive information”. An exception exists where the cookie is “strictly necessary” for the provision of a service “explicitly requested” by the user – so cookies can take a user from a product page to a checkout without the need for consent. Other cookies will require prior consent, though. So almost every site that carries advertising should be seeking its visitors’ consent to the serving of cookies. It also catches sites that count visitors – so if your site uses Google Analytics or WebTrends, you’re caught. You could seek consent with pop-ups, if you’re happy to ignore accessibility guidelines that discourage pop-ups – though users’ browsers may block pop-ups by default, which risks confusion. Or you could do it with a landing page that contains a load of information and some choices. The choices for users could be: * * * http://www.out-law.com/page-10510 [Spotted by MIRLN reader Michael Fleming of Larkin Hoffman.]

- and -

FRENCH SENATE ISSUES NEW LEGISLATION TO AMEND DATA PROTECTION ACT: PROVISIONS INCLUDE BREACH NOTICE OBLIGATION AND CONSENT FOR USE OF COOKIES (Hunton & Williams, 17 Nov 2009) - On November 6, 2009, the French Senate proposed a new draft law to reinforce the right to privacy in the digital age (“Proposition de loi visant à garantir le droit à la vie privée à l’heure du numérique”) (the “Draft Law”). Following a Report on the same topic issued last spring, the Senate made concrete proposals with this Draft Law to amend the Data Protection Act. The Draft Law requires that data controllers provide information on their data processing activities to their data subjects in a clear, specific and easily accessible manner. The data subjects would be able to exercise their right of access more easily, including by email. The Draft Law also distinguishes between the data subject’s right to object to the use of his/her personal data for commercial purposes and his/her right to delete his personal data after it has been processed. The Draft Law also proposes an increase in the obligations of data controllers. Organizations with more than fifty employees that either access or process the personal data are required to appoint a data protection officer. In addition to his obligation to inform the data subjects about a data processing activity, a data controller would have to obtain a data subject’s consent to process data (including for the use of cookies), except if a legal exception applies. Data controllers would also have to implement stronger security measures to preserve the security and confidentiality of personal data. In particular, in case of a data security breach, a data controller would have to notify the French data protection authority (“CNIL”), which would then decide whether to inform the data subjects concerned by this breach. Finally, passage of the law would increase the CNIL’s enforcement authority. Fines imposed by the CNIL for violations of the law would be increased to a maximum €600,000 (instead of the current €300,000). http://www.huntonprivacyblog.com/2009/11/articles/enforcement-1/french-senate-issues-new-legislation-to-amend-data-protection-act-provisions-include-breach-notice-obligation-and-consent-for-use-of-cookies/#page=1

TOWARDS A “PRIVACY PRIVILEGE” TO OPPOSE DISCOVERY REQUESTS? (White & Case, 10 Nov 2009) - On July 23, 2009, the French Data Protection Authority [Commission nationale de l’informatique et des libertés (“CNIL”)] released its Deliberation No. 2009-474 concerning recommendations for the transfer of personal data in the context of discovery in US litigation (the “Recommendation”). This Recommendation must be taken into account by all parties that find themselves in the position of transferring documents or other information containing personal data from France to the United States in the discovery or litigation context. In the Recommendation, the CNIL, a governmental agency whose stated goal is in particular to protect individuals with regard to the processing of their personal data in France, has wrestled with the threats posed to personal data privacy by discovery requests served in US civil and commercial litigation. The Recommendation was issued in response to “an increase in the number of matters concerning the transfer of personal data to the United States, filed principally either by French subsidiaries of American companies or by French companies that have commercial ties with the United States, in the context of ‘Discovery’ proceedings before American courts.” For those familiar with the CNIL’s prior Recommendations and privacy-friendly positions, this one will not come as a complete surprise; nonetheless, the Recommendation represents an important new authoritative statement regarding the defense of privacy rights in the discovery context. (The Recommendation does not apply to US criminal litigation or the investigations by governmental agencies.) http://www.whitecase.com/files/Publication/bb6e0abd-1b64-4110-8d9e-90262a7dc057/Presentation/PublicationAttachment/fb2a0260-3ad1-4f93-a550-966d2bb69a4b/alert_paris_IP_english.pdf#page=1

STICKS AND STONES – MORE ABOUT ONLINE REPUTATION MANAGEMENT (ABA’s LTRC, 10 Nov 2009) - When people are searching for information they are most likely to be using Google. According to Experian Hitwise, a global online competitive intelligence service, Google accounted for 71.08 percent of all U.S. searches conducted in September 2009. Therefore, Google’s Reputation Management Advice carries considerable weight. A lawyer’s reputation is his or her stock in trade; making this topic particularly relevant to the legal profession. Following is a collection of resources for lawyers regarding online reputation management: * * * http://new.abanet.org/sitetation/Lists/Posts/Post.aspx?ID=577

DEPARTMENT OF INTERIOR FAILS CYBERSECURITY AUDIT (Information Week, 10 Nov 2009) - The Department of the Interior inspector general has issued a report that’s sharply critical of the agency’s cybersecurity performance, concluding that its efforts fall short of federal government requirements. The recently issued report points to broad problems at the agency, from a decentralized IT organization to “fragmented governance processes.” It says that the agency has “substantially under-qualified” cybersecurity personnel and that its IT leadership hasn’t been as involved in cybersecurity as it should be. “Personnel responsible for management of the IT programs are not accountable for results, and existing investments are not leveraged to their full potential,” the report says. Interior has budgeted $182 million for cybersecurity this year and has 677 employees and contractors devoted to information security and another 3,531 with “significant” responsibilities in that area. The Department of Interior has CIOs for each of its large bureaus, and those CIOs are supposed to have responsibility for their organizations’ IT and cybersecurity. However, the inspector general found that responsibilities were delegated to smaller offices, resulting in inefficiencies and higher costs. The report describes IT and cybersecurity governance at the department as being inefficient, wasteful, and lacking accountability. It says that Interior has been cited for similar problems in the past by the inspector general and by the Government Accountability Office, but that recommendations for fixing the situation haven’t been applied. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=221601054&cid=RSSfeed_IWK_News [Editor: anybody remember Corbell v. Norton? Fiduciary duty to protect information security?]

- and -

NIST DRAFTS CYBERSECURITY GUIDANCE (Information Week, 23 Nov 2009) - Draft guidance from the National Institute of Standards and Technology issued last week, pushes government agencies to adopt a comprehensive, continuous approach to cybersecurity, tackling criticism that federal cybersecurity regulations have placed too much weight on periodic compliance audits. The guidance, encapsulated in a draft revision to NIST Special Publication 800-37, will likely be finalized early next year. While federal agencies aren’t required to follow all of its recommendations, NIST is officially charged with creating standards for compliance with the Federal Information Systems Management Act, (FISMA), which sets cybersecurity requirements in government, so this guidance should at the very least be influential. The new document puts more onus on applying risk management throughout the lifecycle of IT systems. “This is part of a larger strategy to try to do more on the front end of security as opposed to just on the back end,” says NIST’s Ron Ross, who is in charge of FISMA guidance at the agency. “We don’t think of security as a separate undertaking, but as a consideration we make in our normal lifecycle processes.” Special Publication 800-37 fleshes out six steps federal agencies should take to tackle cybersecurity: categorization, selection of controls, implementation, assessment, authorization, and continuous monitoring. It improves on earlier guidance by emphasizing making rigorous cybersecurity part and parcel of the deployment and operation of IT systems. The document breaks out its cybersecurity guidance in several steps. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=221900722&cid=RSSfeed_IWK_News

WORLD JUSTICE PROJECT RULE OF LAW INDEX (BeSpacific, 11 Nov 2009) - “The Rule of Law Index is a new tool, created by the WJP [World Justice Project Rule], which measures countries’ adherence to the rule of law...The Rule of Law Index is the first index that examines the rule of law comprehensively. Other indices cover only aspects of the rule of law, such as human rights, commercial law, and corruption. Because the Index looks at the rule of law in practice and not solely as it exists on the books, the Index will be able to guide governments, civil society, NGOs and business leaders in targeting efforts to strengthen the rule of law.” http://www.bespacific.com/mt/archives/022774.html Index materials here: http://www.worldjusticeproject.org/rule-of-law-index

NINTH CIRCUIT RULING LEADS TO SPIKE IN CLASS ACTIONS OVER TEXT MESSAGES FROM RETAILERS (Pillsbury, 11 Nov 2009) - In Satterfield v. Simon & Schuster, Inc., 569 F.3d 946 (9th Cir. 2009), the Ninth Circuit held that unsolicited text messages to mobile phones sent by a retailer may constitute a “call” in violation of the Telephone Consumer Protection Act (the “TCPA”). This decision has sparked an increase in consumer class actions filed against retailers who send advertisements to consumers by text message. http://www.pillsburylaw.com/siteFiles/Publications/C6477E2271CD58A3DA7F5B3CED5F6CF3.pdf#page=1

EMPLOYERS WIN A ROUND IN THE FIGHT OVER WHETHER DISLOYAL EMPLOYEES ARE “AUTHORIZED” TO ACCESS COMPANY COMPUTERS (Steptoe & Johnson’s E-Commerce Law Week, 12 Nov 2009) - A federal court in Missouri has weighed in on whether a disloyal employee’s use of his employer’s computer system is acting “without authorization” or “exceed[ing] authorized access,” in violation of the Computer Fraud and Abuse Act. As we’ve previously reported, courts have split on the issue, with many courts (notably the Ninth Circuit) holding that an employee who is permitted to access the system is not acting “without authorization” or in excess of authorization even if he is accessing the system for an illegitimate purpose, such as taking proprietary information to give to a competing firm. The court in Missouri, however, followed the Seventh Circuit’s decision in International Airport Centers, L.L.C., v. Citrin, which held that an employee loses authorization to access company computers when he acts to benefit his own interests, and not those of the company. http://www.steptoe.com/publications-6472.html

TWO GERMAN KILLERS DEMANDING ANONYMITY SUE WIKIPEDIA’S PARENT (New York Times, 12 Nov 2009) - Wolfgang Werlé and Manfred Lauber became infamous for killing a German actor in 1990. Now they are suing to force Wikipedia to forget them. The legal fight pits German privacy law against the American First Amendment. German courts allow the suppression of a criminal’s name in news accounts once he has paid his debt to society, noted Alexander H. Stopp, the lawyer for the two men, who are now out of prison. Mr. Stopp has already successfully pressured German publications to remove the killers’ names from their online coverage. German editors of Wikipedia have scrubbed the names from the German-language version of the article about the victim, Walter Sedlmayr. Now Mr. Stopp, in suits in German courts, is demanding that the Wikimedia Foundation, the American organization that runs Wikipedia, do the same with the English-language version of the article. That has free-speech advocates quoting George Orwell. Floyd Abrams, a prominent First Amendment lawyer who has represented The New York Times, said every justice on the United States Supreme Court would agree that the Wikipedia article “is easily, comfortably protected by the First Amendment.” But Germany’s courts have come up with a different balance between the right to privacy and the public’s right to know, Mr. Abrams said, and “once you’re in the business of suppressing speech, the quest for more speech to suppress is endless.” The German law springs from a decision of Germany’s highest court in 1973, said Julian Höppner, a lawyer with the Berlin law firm JBB who has represented the Wikimedia Foundation, though not in this case. Publications generally comply with the law, Mr. Höppner said, by referring to “the perpetrator — or, Mr. L.” But with such a well-known case, he said, expunging the record “is difficult to accomplish — and, morally speaking, rightly so.” http://www.nytimes.com/2009/11/13/us/13wiki.html?_r=1

W.VA. SUPREME COURT OPTS FOR E-MAIL SECRECY (AP, 12 Nov 2009) - The state Supreme Court has ruled that public officials and public employees can keep their personal e-mails secret. The court ruled 4-1 Thursday that none of the 13 e-mails between former Supreme Court Chief Justice Elliott “Spike” Maynard and Massey Energy Chief Executive Don Blankenship are public records. The Associated Press had sued to gain access to the correspondence last year, when Massey had several cases pending before the high court. Kanawha County Circuit Court Judge Duke Bloom ruled that five of the e-mails were public, but that eight were not. Bloom reasoned that the five e-mails were public records because they touched on Maynard’s ultimately unsuccessful campaign in the Democratic primary, in which he ran against two of the justices now sitting on the court. The five e-mails were released after that ruling. But the Supreme Court ruled that Bloom was wrong to release those e-mails, and sent the case back to his court. Justice Margaret Workman was the lone dissenter. In writing for the majority, Justice Robin Davis said “None of the e-mails’ contents involved the official duties, responsibilities or obligations of Justice Maynard as a duly elected member of the court.” Davis’ opinion says that 12 of the e-mails “simply provided URL links to privately operated Internet Web sites that carried news articles,” while the 13th was an “agenda for a meeting being held by a private organization.” This description is not accurate. Of the five e-mails released by Bloom’s order, two contained links not to news articles, but to pages on the Web site of a Huntington law firm, along with comments Maynard wrote about the firm. One e-mail mocked the firm’s advertisements as “unbelievable,” while another slammed the firm for claiming that a fire at Massey’s Aracoma Alma Mine No. 1 that killed two miners could have been prevented. http://www.phillyburbs.com/news/news_details/article/92/2009/november/12/wva-supreme-court-opts-for-e-mail-secrecy.html

INTERNATIONAL ACTIVISTS LAUNCH NEW WEBSITE TO GATHER AND SHARE COPYRIGHT KNOWLEDGE (EFF, 13 Nov 2009) - The Electronic Frontier Foundation (EFF), Electronic Information for Libraries (eIFL.net), and other international copyright experts joined together today to launch Copyright Watch -- a public website created to centralize resources on national copyright laws at www.copyright-watch.org. “Copyright laws are changing across the world, and it’s hard to keep track of these changes, even for those whose daily work is affected by them,” said Teresa Hackett, Program Manager at eIFL.net. “A law that is passed in one nation can quickly be taken up by others, bilateral trade agreements, regional policy initiatives, or international treaties. With Copyright Watch, people can learn about the similarities and differences in national copyright laws, and they can use that information to more easily spot patterns and emerging trends.” Copyright Watch is the first comprehensive and up-to-date online repository of national copyright laws. To find links to national and regional copyright laws, users can choose a continent or search using a country name. The site will be updated over time to include proposed amendments to laws, as well as commentary and context from national copyright experts. Copyright Watch will help document how legislators around the world are coping with the challenges of new technology and new business models. https://www.eff.org/press/archives/2009/11/13

A RUSH TO LEARN ENGLISH BY CELL (Washington Post, 14 Nov 2009) - More than 300,000 people in Bangladesh, one of Asia’s poorest but fastest-growing economies, have rushed to sign up to learn English over their cellphones, threatening to swamp the service even before its official launch Thursday. The project, which costs users less than the price of a cup of tea for each three-minute lesson, is being run by the BBC World Service Trust, the international charity arm of the broadcaster. Part of a British government initiative to help develop English skills in Bangladesh, it marks the first time that cellphones have been used as an educational tool on this scale. Since cellphone services began in Bangladesh just over a decade ago, more than 50 million Bangladeshis have acquired phone connections, including many in remote rural areas. That far outnumbers the 4 million who have Internet access. English is increasingly seen as a key to economic mobility, especially as ever larger numbers of Bangladeshis go abroad to find work unavailable to them at home. An estimated 6.2 million Bangladeshis work overseas, and their nearly $10 billion in annual remittances represent the country’s second-largest source of foreign exchange. However, English is also important for securing jobs at home, where about 70 percent of employers look for workers with “communicative English.” Through its Janala service, the BBC offers 250 audio and text-message lessons at different levels -- from basic English conversation to grammar and comprehension of simple news stories. Each lesson is a three-minute phone call, costing about 4 cents. http://www.washingtonpost.com/wp-dyn/content/article/2009/11/13/AR2009111304245.html

TWITTER AND THE LEARNING TECHNOLOGY STREAM (InsideHigherEd, 15 Nov 2009) - Twitter is changing how I keep up with the educational technology world. I’m moving from relying on an RSS reader (I use Google Reader) to relying on Twitter subscriptions and hashtags. For the first time I’m wondering if Google should be worried about their core business model, as if my experience is any guide on how we use the Web to understand the world, may be moving away from search and more towards microblogging Twitter clients (I use Twhirl by Seesmic). At EDUCAUSE 09 Twitter was much debated (go watch the fabulous Campbell/Maas point/counterpoint) and extravagantly utilized for sharing and communication (see the #EDUCAUSE09 transcript). I’m pretty certain that Course Management Systems will start to build in Twitter capabilities and that hashtags will automatically be generated for each course. Tweeting will become a standard way for students and instructors to share information, thoughts and links around the course material. Many instructors will become comfortable incorporating and leveraging a Twitter-enabled backchannel to both in-class and out-of-class communication. Scanning the educational technology news stream via a Twitter client vs. relying on an RSS reader means that I look at content that has been recommended by a person. The learning technology community is small enough that I can pretty quickly begin to filter by reputation. If one person consistently links to material that I find useful and interesting then I’m more likely to click on her links. Rather then going to particular blogs, or presentations, or videos, or articles based on the title or site (as I do with an RSS reader), I go because of a colleague’s recommendation. This is a big change, and I’m still getting my head around this shift. My apologies for all those folks like Clay Shriky (and perhaps) you who understood (and blogged about) the implications of microblogging and social media a long time ago. I feel like I’m sort of coming late to this bandwagon. My conversion to information gathering by Twitter client has me wondering about the need to explore this method in course design, faculty training, and student information literacy.http://www.insidehighered.com/blogs/technology_and_learning/twitter_and_the_learning_technology_stream

MORE HACKERS TARGET LAW FIRMS, OFTEN ‘SPEAR FISHING’ IN SPAM E-MAIL (ABA Journal, 16 Nov 2009) - Computer hackers are targeting law firms as a potential motherlode of confidential information, often relying on “spear fishing” attacks in which personalized spam e-mail appears to come from a trusted individual. While the e-mail itself doesn’t pose a danger, clicking on a link within the e-mail can invite malicious software into the law firm’s computer system. The trend of focusing hack attacks on law firms began two years ago, according to a FBI advisory, but there has been a “noticeable increase” recently, reports the Associated Press. Law firms representing client corporations that are negotiating major international deals are particularly inviting targets. “Law firms have a tremendous concentration of really critical, private information,” says Bradford Bleier of the FBI’s cyber division. Hence, sneaking into their computer systems “is a really optimal way to obtain economic, personal and personal security-related information.” http://www.abajournal.com/news/more_hackers_target_law_firms_often_spear-fishing_in_spam_e-mail/?utm_source=feedburner&utm_medium=feed&utm_campaign=ABA+Journal+Daily+News&utm_content=Twitter [The FBI advisory is here: http://files.knowconnect.com/public/cyber_advisory.pdf; it was published by the FBI on November 1 entirely without fanfare, and only picked up by the AP after Mr. Bleier talked about it at an ABA meeting on November 13.]

GOAL OF NEW ABA WEBSITE: ALL THE FEDERAL DECISIONS THAT ARE FIT TO PRINT (ABA Journal, 17 Nov 2009) - Want to know more about a 9th Circuit opinion on the First Amendment rights of a citizen ejected from a city council meeting for giving a Nazi salute? Or the 5th Circuit opinion allowing a Halliburton employee to sue over her alleged rape in Iraq? You can find those opinions summarized on the new Media Alerts on Federal Courts of Appeals website. Students and professors at four law schools are choosing the opinions most likely to be of interest to journalists and the public for the pilot project, sponsored by the ABA Standing Committee on Federal Judicial Improvements. The website, which officially launches on Wednesday, now covers the U.S. Courts of Appeals for the 3rd, 5th and 9th Circuits. The plan is to add eventually all of the circuits. Judge M. Margaret McKeown of the 9th Circuit, a special adviser to the project, says the idea for the website grew out of some discussions between judges and journalists at a meeting at the First Amendment Center earlier this year. About 60,000 cases are filed every year in the federal courts of appeals, McKeown told the ABA Journal. “Most courts have very good websites, but there is a lot of information out there, so this provides a special niche,” she says. “There is a certain needle-in-the-haystack element for someone to go through them every day in every jurisdiction of interest to find cases.” “Our view is that fair and accurate reporting about the courts is important, both for the public and also in order to emphasize judicial independence,” says McKeown, whose three-year term as chair of the ABA Standing Committee on Federal Judicial Improvements ended in August. Law schools working on the project are the University of Texas School of Law, Temple University Beasley School of Law, the University of Arizona James E. Rogers College of Law, and the University of San Diego School of Law. http://www.abajournal.com/news/goal_of_new_aba_website_all_the_federal_decisions_that_are_fit_to_print/?utm_source=feedburner&utm_medium=feed&utm_campaign=ABA+Journal+Daily+News

- and -

BRIDGING THE DIGITAL DIVIDE: A NEW VENDOR IN TOWN? GOOGLE SCHOLAR NOW INCLUDES CASE LAW (LLRX, 18 Nov 2009) - An unexpected salvo was fired in the battle to bring case law to the consumer today by none other than Web search giant, Google. The announcement that Google Scholar would now allow for precedent searches set the internet and legal world a buzz. With law firms still being battered by the struggling economy, Google’s move is opportune. Legal researchers are hungry for low cost alternatives to the industry’s major players. Just how Google’s new case offerings and functionality will stack up remains to be seen. Will it be a revolution in the world of case research or just another case of getting for what we pay (or don’t pay, as it may be)? Google is taking on the old adage that ignorance of the law is not a defense when running afoul of it. Its announcement clearly targeted the average person, promising to enable “people everywhere to find and read full text legal opinions from U.S. federal and state district, appellate and supreme courts.” What it may lack in the wide breadth of coverage we have come to expect from major vendors like Westlaw and Lexis, Google makes up for with the simple, popular, and widely-used power of its search engine. Folks who have never touched the other major vendors have almost certainly “googled” something. Thus, though new to the law scene, Google’s brand and familiarity could make it a formidable foe to the industry elite. Searching for case law on Google is simple and versatile. You can search by case name, topic, or even phrase (“separate but equal” is the example they use). All you need to do is go to Google Scholar (http://scholar.google.com) and click the new radio button for “Legal opinions and journals”. It is just that easy. But what of the results? How do they compare to what we in the legal community are accustomed? A simple test of the new search might just surprise you. Take a case like Bowers v. Hardwick, for example - seminal, controversial, and heavily cited. Run it’s name through the Google Scholar search. What you get is almost overwhelming. Yes your search results will return the text of the decision. But that is not all. Decisions, in this case Bowers, can come with official citations and pagination. Key factors for anyone writing and citing to the case. The cases cited in the body of the decision, if Google has them, actually show up as clickable links. That should give the major vendors pause! But this is STILL not all Google Scholar has to offer. If there are legal journals that cite the case you have searched and Google has them, you will see them in your search. By clicking the “How Cited” link next to the case name on the results page, you can see how the document has been cited, where it has been cited, and other related cases. Searching for Bowers brings up a list of cases that have been seminal in the area of privacy rights, for example. Even the footnotes are clickable links! Suffice it to say that Google is on to something really good here. http://www.llrx.com/featres/googlescholarcaselaw

- and -

GOOGLE SCHOLAR LEGAL OPINION AND JOURNAL SEARCH, ABA LTRC FREE FULL-TEXT LAW REVIEW/LAW JOURNAL SEARCH (ABA’s LTRC, 19 Nov 2009) - Google officially announced adding legal opinion and journal search features to Google Scholar this week, following the ABA Legal Technology Resource Center’s announcement of the release of a free full-text online law review/law journal search engine created using Google Custom Search. What are some differences between the two search engines? Google Scholar legal searches often return a large number of fee-based journal sites and cannot currently be limited to searching free sources only; the LTRC search engine is designed to search free full-text sites. Google Scholar legal searches often return a mix of legal opinions and journal articles and cannot currently be limited to searching journals only; the LTRC search engine is designed to search only law review, law journal, and related article sites. Google Scholar’s options for searching legal opinions are more developed than those for searching legal journals. Searches can be limited to legal opinions and by jurisdiction through the Google Scholar Advanced Search interface. The legal opinions linked to in the search results are free full-text and include pagination. Google Scholar includes a citator feature for legal opinions: clicking on a “How cited” link appearing next to an opinion in the search results leads to a page which displays text snippets from citing paragraphs in citing opinions (no editorial analysis such as treatment is given). “Cited by” and “Related documents” links display lists of citing and related opinions and articles. Information regarding coverage of Google Scholar’s legal opinion database can be found at http://scholar.google.com/intl/en/scholar/help.html under the heading “Which court opinions do you include?” For more legal opinion-related information on the web, also see the ABA Standing Committee on Federal Judicial Improvements’ new Media Alerts on Federal Courts of Appeals website, which features case summaries and information on selected Federal Courts of Appeals cases. http://new.abanet.org/sitetation/Lists/Posts/Post.aspx?ID=581

WOW! TOP EXECS SAY THEY ARE INFLUENCED BY SOCIAL NETWORKS (ZDnet, 18 Nov 2009) - This new research study from the Society for New Communications Research (SNCR) is important because it shows that company executives are influenced by their online networks. And the trend is growing. The influence on business decisions by online communities is at its highest in three years. The research was conducted by Don Bulmer from SAP and Vanessa DiMauro. Here are some key findings from this survey 365 business professionals:
Professional decision-making is becoming more social - enter the era of Social Media Peer Groups (SMPG)
• Traditional influence cycles are being disrupted by Social Media as decision makers utilize social networks to inform and validate decisions
• Professionals want to be collaborative in the decision-cycle but not be marketed or sold to online; however online marketing is a preferred activity by companies.
Professional networks are emerging as decision-support tools
• Decision-makers are broadening reach to gather information especially among active users
Professionals trust online information almost as much as information gotten from in-person
• Information obtained from offline networks still have highest levels of trust with slight advantage over online (offline: 92% - combined strongly/somewhat trust; online: 83% combined strongly/somewhat trust)
Reliance on web-based professional networks and online communities has increased significantly over the past 3 years
• Three quarters of respondents rely on professional networks to support business decisions
• Reliance has increased for essentially all respondents over the past three years
Social Media use patterns are not pre-determined by age or organizational affiliation
• Younger (20-35) and older professionals (55+) are more active users of social tools than middle aged professionals.
• There are more people collaborating outside their company wall than within their organizational intranet.
http://blogs.zdnet.com/Foremski/?p=953

IN-Q-TEL INVESTS IN CYBERSECURITY COMPANY (Information Week, 18 Nov 2009) - The independent venture arm of the U.S. intelligence community, In-Q-Tel, has invested in cybersecurity company FireEye, the company announced Wednesday. In-Q-Tel and FireEye didn’t disclose terms of the agreement, or which intelligence agencies are particularly interested in the technology. However, in a release, they said that the investment “will extend FireEye’s cyber security product development and stealth malware technical capabilities to protect against cyber threats.” The intelligence community has a clear interest in cybersecurity investment. At a conference earlier this month, deputy secretary of defense William Lynn said that more than 100 foreign intelligence agencies are actively trying to hack into federal government systems. The NSA recently announced plans to build a $1.5 billion cybersecurity data center in Utah. California-based FireEye sells an out-of-band security appliance that monitors all inbound network traffic, employing a blend of signatures and heuristics to analyze traffic for evidence of suspicious behavior. After identifying suspicious traffic, the appliance captures and replays the traffic on virtual machines running in the appliance, which imitate real PCs. If those PCs are compromised, FireEye alerts administrators. By routing the traffic to a virtual machine, FireEye claims it is able to mitigate false positives. The virtual machines are invisible to the customer’s production network. FireEye claims that its products are especially useful for protection against zero-day malware attacks and botnets. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=221900133&cid=RSSfeed_IWK_News

DHS CRITICAL INFRASTRUCTURE PROTECTION WEBSITE LAUNCHED (BeSpacific, 18 Nov 2009) - The nation’s critical infrastructure and key resources (CIKR) include systems and assets, whether physical or virtual, so vital to the United States that their incapacitation or destruction would have a debilitating impact on national security, national economic vitality, or public health and safety. Ensuring CIKR resiliency and protection is essential to our security and way of life. The Department’s Office of Infrastructure Protection leads the coordinated national effort to build resiliency and reduce and mitigate risk across the 18 CIKR Sectors, which include such key areas as food and water, energy, communications and transportation systems, and emergency services. Since the vast majority of the nation’s critical infrastructure is privately owned and operated, strong partnerships between government and private industry are essential to achieve these shared goals.” See also the new CIKR Resource Center, “which includes information about how to sign up for free Web-based seminars on the tools, trends, issues, and best practices for infrastructure protection and resilience; resources concerning potential vulnerabilities for chemical facilities; and details about the National Response Framework, which outlines guidance for all response partners to prepare for and provide a unified response to disasters and emergencies.” http://www.bespacific.com/mt/archives/022838.html and http://training.fema.gov/EMIWeb/IS/IS860a/CIKR/CIKRintro.htm

INDIA ESTABLISHES BROAD INTERCEPTION, DATA RETENTION, CYBER SECURITY, AND WEBSITE BLOCKING REQUIREMENTS (Steptoe & Johnson’s E-Commerce Law Week, 19 Nov 2009) - India’s Information Technology (Amendment) Act, 2008, came into effect at the end of last month, instituting significant new requirements governing the interception and decryption of communications, access to stored data, data retention, cyber security, and website blocking. The law also appears to authorize the government to restrict what encryption may be used in India. Regulations implementing many of these requirements have already been “notified,” while other key regulations remain to be issued. Communications providers and other companies that do business in India thus will have to satisfy burdensome new requirements, and may be faced with even more significant restrictions in the near future. http://www.steptoe.com/publications-6482.html

SOME COURTS RAISE BAR ON READING EMPLOYEE EMAIL (WSJ, 19 Nov 2009) -Big Brother is watching. That is the message corporations routinely send their employees about using email. But recent cases have shown that employees sometimes have more privacy rights than they might expect when it comes to the corporate email server. Legal experts say that courts in some instances are showing more consideration for employees who feel their employer has violated their privacy electronically. Driving the change in how these cases are treated is a growing national concern about privacy issues in the age of the Internet, where acquiring someone else’s personal and financial information is easier than ever. “Courts are more inclined to rule based on arguments presented to them that privacy issues need to be carefully considered,” said Katharine Parker, a lawyer at Proskauer Rose who specializes in employment issues. In past years, courts showed sympathy for corporations that monitored personal email accounts accessed over corporate computer networks. Generally, judges treated corporate computers, and anything on them, as company property. Now, courts are increasingly taking into account whether employers have explicitly described how email is monitored to their employees. That was what happened in a case earlier this year in New Jersey, when an appeals court ruled that an employee of a home health-care company had a reasonable expectation that email sent on a personal account wouldn’t be read. And last year, a federal appeals court in San Francisco came down on the side of employee privacy, ruling employers that contract with an outside business to transmit text messages can’t read them unless the worker agrees. The ruling came in a lawsuit filed by Ontario, Calif., police officers who sued after a wireless provider gave their department transcripts of an officer’s text messages in 2002. The case is on appeal to the U.S. Supreme Court. Lawyers for corporations argue that employers are entitled to take ownership of the keystrokes that occur on work property. In addition, employers fear productivity drops when workers spend too much time crafting personal email messages. http://online.wsj.com/article/SB125859862658454923.html?mod=article-outset-box [Spotted by MIRLN reader Mathew Lodge of Symantec.]

200 WEB SITES SPREAD AL-QAIDA’S MESSAGE IN ENGLISH (Washington Post, 20 Nov 2009) - Increasing numbers of English-language Web sites are spreading al-Qaida’s message to Muslims in the West. They translate writings and sermons once largely out of reach of English readers and often feature charismatic clerics like Anwar al-Awlaki, who exchanged dozens of e-mails with the Army psychiatrist accused of the Fort Hood shootings. “If you look at the most influential documents in terms of homegrown terrorism cases, it’s not training manuals on building bombs,” Kohlmann said. “The most influential documents are the ones that are written by theological advisers, some of whom are not even official al-Qaida members.” Most of the radical Islamic sites are not run or directed by al-Qaida, but they provide a powerful tool for recruiting sympathizers to its cause of jihad, or holy war, against the United States, experts who track the activity said. The number of English-language sites sympathetic to al-Qaida has risen from about 30 seven years ago to more than 200 recently, said Abdulmanam Almushawah, head of a Saudi government program called Assakeena, which works to combat militant Islamic Web sites. In contrast, Arabic-language radical sites have dropped to around 50, down from 1,000 seven years ago, because of efforts by governments around the world to shut them down, he said. http://www.washingtonpost.com/wp-dyn/content/article/2009/11/19/AR2009111903570.html

MILITARY VIDEO SYSTEM IS LIKE YOUTUBE WITH ARTILLERY (Wired, 20 Nov 2009) - Making footage shareable and searchable online has sparked a revolution in the cute animal, stupid human, and delicious tamale communities. New software just might mean a similar upgrade for military video intelligence: Think of it as a real-time YouTube with heavy artillery. The release of the new version has just been announced. The U.S. military’s Task Force ODIN demonstrated the effectiveness of combining the video inputs from networked drones, aircraft and helicopters. When a roadside bomb went off, the team could wind back the video to see who planted it — and where they went. ODIN allegedly assisted in the takedown of thousands of insurgents in Iraq; their counterparts are starting work in Afghanistan. The process of handling, archiving and then searching through a large number of video feeds is a challenging one. That’s one of the reasons why something like YouTube can be so helpful: Instead of having to search through a pile of videotapes, you can just type in a few keywords. Even better, you can search all your friends’ video collections and they can search yours. And this is where a system like adLib produced by EchoStorm Worldwide LLC comes in. It does the same sort of thing for the military by automatically archiving video feeds along with the associated telemetry data. For example, suppose you want to find out what happened at point X at 8:30 yesterday. You don’t even have to know which platforms were in the area at the time. “You can ask for video that matches a specific location using latitude and longitude or the MGRS (Military Grid Reference System) or by clicking and dragging on a map,” David Barton of EchoStorm told Danger Room. http://www.wired.com/dangerroom/2009/11/military-video-system-is-like-youtube-with-artillery/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29

MEMENTO: PROTOCOL-BASED TIME TRAVEL FOR THE WEB (ReadWriteWeb, 20 Nov 2009) - The Web constantly changes and evolves. That, of course, is what makes the Internet so exciting, but it also means that finding older versions of a website is hard. The current push towards the real-time web is making this problem even more apparent. Memento, a project based at Old Dominion University, wants to make it easier to access older versions of a web page without having to go to the Internet Archive. To do this, the project is using a relatively obscure feature of the hypertext transfer protocol (HTTP). The Memento project wants to give browsers a ‘time-travel’ mode. Currently, the only way to find these pages is the Wayback Machine. According to an interview with Memento’s Herbert Van de Sompel, the mission of this project is to make it far easier for users to find older pages without having to go through the hassle of putting the right URL into the Wayback Machine’s search engine. To do this, Van de Sompel and his colleagues are exploiting a feature in the HTTP content negotiation specs that allows them to add date-and-time negotiation to the standard negotiations that already happen whenever your browser connects to a web server. Instead of just asking for the current page, a Memento-enabled browser can also ask for an older version of that page. Some servers and content management systems already offer this feature and the Memento project has developed a demo that shows how this feature would look. According to Van de Sompel, it only takes four extra lines of codes in Apache to make this work. http://www.readwriteweb.com/archives/memento_protocol-based_time_travel_for_the_web.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29

A LOOK AT TWITTER’S UPDATED PRIVACY POLICY (Eric Goldman’s blog, 20 Nov 2009) - As noted on Twitter’s blog, Twitter refreshed its privacy policy yesterday. Given that virtually everything Twitter does is placed under the microscope, I’m sure the policy will be pored over in detail. (Here’s a link to the updated policy and a link to the old policy.) General thoughts on the policy: The policy is short, easy to understand, and in plain English. The thrust of the policy is that most users typically use Twitter to publicly disseminate information, and users should expect any of this information to be broadly disseminated. This includes dissemination by Twitter, third party applications, search engines, etc. To the extent you want to restrict use of this information, Twitter gives you the tools to do so in your profile settings. Much of what’s in the policy is very typical of what you would find in the privacy policy of any other website or social network. However, a few things are worth mentioning:
1. Geolocation: The policy provides that you can turn geolocation on and off, and if you have it turned on, your location information is obviously broadcast and also used by Twitter. Geolocation is opt-in and this makes sense.
2. Cookies: The policy also mentions that Twitter places cookies on your computer. Virtually all privacy policies contain this, since most websites use cookies. But for some reason this part of the privacy policy jumped out at me. I guess it’s a reminder of the tremendous advertising power that Twitter could wield. Everyone who uses Twitter expresses their preferences through Twitter, by clicking on links, using applications, and just through general usage. Most people probably do more, such as expressing their food, drink, entertainment, political, and other preferences. (Some more than others.) By being able to identify the computer of someone who expresses those preferences, Twitter can build a valuable network that would be useful to advertisers. I’m not only talking about advertising on Twitter.com (the web client), but also advertising on other websites or networks as well. This is pretty common in the industry, and subject to attack by privacy advocates, some of whom are pushing for an opt-in system for this type of tracking. Thus far Twitter has been free of advertising, but this is likely to change, as indicated by Twitter’s own statements. (See Scoble’s link below.)
3. Metadata: Interestingly, the policy also treats tweet metadata as public information (“information you are asking us to make public”). This seems to create some grey area between information which you broadcast and is truly public, and information which is available to Twitter (but not to your followers) from your use of Twitter. Robert Scoble has a post with comments from Twitter’s COO signaling Twitter’s turn to advertising and possible use of metadata in this context. I didn’t pick up on this at first, but I think this is significant. http://blog.ericgoldman.org/archives/2009/11/a_look_at_twitt_1.htm

LAW FIRM INVOKES PRIVACY LAWS IN SUING RIVAL OVER SEARCH ENGINE KEYWORDS (Law.com, 20 Nov 2009) - A lawsuit in Wisconsin is bringing a fresh challenge to the practice of paying for keywords on Google and other search engines to boost one company’s link over a rival’s. The practice has occasionally prompted a rival to file legal challenges alleging trademark infringement. Now a Wisconsin law firm is trying a new angle -- accusing its competitor of violating privacy laws. Habush Habush & Rottier is one of Wisconsin’s largest law firms, specializing in personal injury cases. But search for iterations of “Habush” and “Rottier” and a sponsored link for Cannon & Dunphy attorneys often shows up, just above the link for the Habush site. Habush alleges that Cannon paid for the keywords “Habush” and “Rottier,” in effect hijacking the names and reputation of Habush attorneys. Cannon acknowledged paying for the keywords but denied wrongdoing, saying it was following a clearly legal business strategy. The lawsuit was filed Thursday in Milwaukee, where Habush is headquartered. Cannon is based in nearby Brookfield. Habush based its lawsuit on a Wisconsin right-to-privacy statute that prohibits the use of any living person’s name for advertising purposes without the person’s consent. “We believe this is deceptive, confusing and misleading,” firm president Robert Habush said of Cannon’s strategy. “If Bill Cannon thinks this is a correct way to do business he needs to have his moral compass taken to the repair shop.” William Cannon, the founding partner of Cannon & Dunphy, said every business uses the same tactic to remind consumers of their choices. “This is equally available to Habush if he weren’t so cheap to bid on his own name,” Cannon said. One legal expert said it wasn’t clear how successful Habush’s lawsuit would be. Ryan Calo, a fellow at the Center for Internet and Society at Stanford Law School, said the statute seemingly was meant to protect people from having their names and images misused to suggest they endorse or represent something. That’s not the case here, he said. http://www.law.com/jsp/article.jsp?id=1202435677621&rss=newswire

LEVI’S IS PAYING ORRICK A FLAT FEE TO HANDLE ALL BUT ITS IP WORK (ABA Journal, 23 Nov 2009) - Orrick, Herrington & Sutcliffe is earning a flat fee to handle all of the legal work worldwide for Levi Strauss & Co., with just one exception. Levi’s is paying Orrick an annual fee in monthly increments for all but its brand protection work, the Recorder (sub. req.) reports. Townsend and Townsend and Crew is handling that aspect of Levi’s legal business. If work needs to be done where Orrick doesn’t have an office, it will hire an outside law firm at its own expense. The arrangement is unusual because it is so all-encompassing, according to Frederick Krebs, president of the Association of Corporate Counsel. “It is still news when a big firm and a big company do a significant amount of work or transactions in that way,” Krebs told the Recorder. Orrick wouldn’t disclose how much the Levi’s deal is worth, but the story calls the deal a “multimillion-dollar arrangement.” Twenty-five percent of revenue comes from alternative billing. Orrick partner Karen Johnson-McKewan worked out the details of the deal. “The core principle that we’re operating with here is that we’re trusting each other,” she told the Recorder. “We all are committed to doing whatever we can to make it work. We know there will be bits and pieces where it may not.” http://www.abajournal.com/weekly/article/levis_is_paying_orrick_a_flat_fee_to_handle_all_but_its_ip_work

WIKILEAKS RELEASES OVER HALF A MILLION PAGER MESSAGES FROM 9/11 (ReadWriteWeb, 25 Nov 2009) - Earlier this morning, Wikileaks began to post pager messages that were sent on September 11, 2001. According to Wikileaks, these messages were intercepted by an “organization which has been intercepting and archiving US national telecommunications since prior to 9/11.” Some of these messages are from officials in police and fire departments, though a large number of messages are also from businesses. Others are automated messages to engineers that were sent by computers about network and hardware issues. Wikileaks is posting these messages semi-live - in sync with the events of 9/11. It’s not clear how Wikileaks got this data or who intercepted these messages. This archive is likely to become an invaluable source for anybody who wants to study the events and the public’s reaction on this day. Chances are that conspiracy theorists are already wading through this data looking for an official page that authorized the destruction of Building 7. As is to be expected, the archive includes many Twitter-like messages like “Bush calls World Trade Center crashes apparent terrorist attack.” Others are internal messages from unknown businesses or government departments (“please due to the incidents taking place and with trying to close centers Please do not tie up aol today unless it is business. Thanks”) or personal message (“Things are getting worse....fear is rampid...please call me. HISD are advising to come get children etc.-sm”). This thread on Reddit highlights some of the most interesting (and often shocking) messages. We don’t know the nature of Wikileaks this source yet, so it’s only prudent to treat this data with some skepticism. Wikileaks, however, has a track record of releasing authentic information and it seems unlikely (but not impossible) that somebody would go through the trouble of writing 500,000 pager messages just to be featured on Wikileaks. http://www.readwriteweb.com/archives/wikileaks_releases_over_half_a_million_pager_messages_from_911.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29

GOOGLE PROFILES TURN INTO OPENIDS (TechCrunch, 25 Nov 2009) - As part of its push to go more social, Google has been attempting to unify its various account profiles into one Google Profile. And now it’s more useful. Google’s Brad Fitzpatrick has just tweeted out that Google Profiles can now be used as OpenIDs. What this means is that you can sign into any site that accepts OpenID simply by using your Google Profile domain. Luckily, a few months ago Google started allowing these profiles to have vanity URLs, like /mgsiegler, instead of the previous /32090329039402903. Chris Messina, a huge proponent of the open web movement, has just sent out a picture of what signing in with OpenID via your Google Profile looks like. http://www.techcrunch.com/2009/11/25/google-profile-openid/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Techcrunch+%28TechCrunch%29

**** RESOURCES ****
8 THINGS TO REMEMBER WHEN IMPLEMENTING AN E-MAIL POLICY (Digital Landfill, 12 Nov 2009) – [useful checklist and explication]: http://aiim.typepad.com/aiim_blog/2009/11/8-things-to-remember-when-implementing-an-email-policy.html?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+EcmIndustryWatch+%28Digital+Landfill%29 [Spotted by MIRLN-reader Claude Baudoin of Cebe KM and IT.]

**** FUN ****
WIFI BODY SCALE AUTO-TWEETS EACH TIME YOU STEP ON IT (Mashable, 10 Nov 2009) - This sounds like our worst nightmare, but a WiFi Body Scale has hit the market, and it’s designed to auto-tweet your every weigh-in along with the number of pounds you need to gain or lose to reach your goal. The enhanced $159.99 scale is available for purchase from the manufacturer’s website. Previously able to record weight data and track it via an iPhone app, the addition of auto-tweeting is apparently a motivational feature to keep you focused on your weight-loss (or gain) goals. Should this seemingly outlandish functionality appeal to you, you can configure your Twitter account for auto-posting on a per weigh-in, daily, weekly, or monthly basis after the initial Twitter activation process. The scale records your body weight, lean & fat mass (ouch), and body mass index, all of which is posted to your personal webpage and/or the iPhone application. http://mashable.com/2009/11/10/wifi-body-scale/ [Editor: Clearly moves Web 2.0 into the TMI space.]

**** LOOKING BACK ****
FORMER VOLUNTEERS SUE AOL, SEEKING BACK PAY FOR WORK (New York Times, 26 May 1999) - Two former volunteers for America Online have filed a lawsuit in Federal Court in Manhattan in an attempt to obtain back wages, saying that they and thousands of other volunteers should have been compensated for their work. The plaintiffs, Kelly Hallisey of Nassau County and Brian Williams of Dallas, allege that AOL violated the Fair Labor Standards Act, a Federal law that mandates a minimum hourly wage for employees, by using volunteers to perform work for the on-line service. They and their lawyer, Leon Greenberg, said they were hoping other volunteers for the on-line service would join the suit, which was filed Monday. The amount of damages sought was not specified. The volunteers, called community leaders, perform a variety of tasks for the service, like moderating on-line discussions and overseeing other volunteers. http://www.nytimes.com/1999/05/26/nyregion/former-volunteers-sue-aol-seeking-back-pay-for-work.html [Editor: today, could the analogue be crowd-sourcing volunteers?]

**** NOTES ****
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC. Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note,
8. Steptoe & Johnson’s E-Commerce Law Week,
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, November 07, 2009

MIRLN --- 18 October – 7 November 2009 (v12.15)

NEWS | PODCASTS | RESOURCES | FUN | LOOKING BACK | NOTES

• Heartland Breach: Inside Look at the Plaintiffs’ Case
• Site Lets Investors See and Copy Experts’ Trades
• Check E-Mail Hourly, Quinn Partner Says, Unless in Court, in Tunnel or Asleep
• Baited and Duped on Facebook
• Court Rules that Phones Ringing in Public Don’t Infringe Copyright
o Apology for Singing Shop Worker
• CIA Invests in Firm that Datamines Social Networks
o U.S. Navy CIO: Social Media Should Be Part of Military IT Standard
o US Department of Defense Embraces Open Source
• Web Store Offering New Jersey Shipments Avails Itself of Forum Even Absent Any Sales
o Hosting Sponsored Ad Links Targeting New York Not Enough for Jurisdiction There
• Data Breach Notification Spreads South of The Border -- Way South
• SEC Proposes Amending Rules for Internet Availability of Proxy Materials
• Microsoft Wants ISO Security Certification for its Cloud Services
• Obama’s Ethics Counsel Faces Tough Crowd at ABA Conference
• Obama Family Portrait Posted to Flickr
• MI5 Comes Out Against Cutting Off Internet Pirates
• Privacy Coalition Seeks Investigation of DHS Chief Privacy Office
• Social Media and Ed. Tech. Companies
• FBI: Cyber Crooks Stole $40m from U.S. Small, Mid-Sized Firms
• Study: Facebook, Twitter Use at Work Costs Big Bucks
• In Industry First, Voting Machine Company to Publish Source Code
• Learning by Degrees
• ACC to GCS: Eliminate Software Costs
• Survey: Few Companies Addressing Cyberterrorism
• Educause Core Data Service Fiscal Year 2008 Summary Report
• Ct Rules Facebook Terms Claiming Ownership of User Info Did Not Destroy CDA Protections
• Lawyerese Goes Galactic as Contracts Try to Master the Universe
• Judge Rules Metadata is Public Record
o PA Bar Committee Examines Metadata
o Want to Update Your Avvo Listing? If So, Start Policing Client Comments, Opinion Says
• EU Sends Conflicting Messages on Keyword Advertising
• Amazon Lets Shoppers Pay with a Phrase
• Does Cloud Computing Need Malpractice Safeguards?
• Lawyers in Discovery Scandal Say Qualcomm Lied
• Attorney-Client Privilege in Work E-Mails
• Judge Spanks Lawyer for Leaking Personal Details in Brief

**** NEWS ****
HEARTLAND BREACH: INSIDE LOOK AT THE PLAINTIFFS’ CASE (BankInfoSecurity, 8 Oct 2009) - Prior to the Heartland Payment Systems (HPY) data breach, company executives misrepresented their “state of the art” security measures, says a new document filed in the class action suit against the payments processor. Heartland publicly touted its “multiple layers of security,” and said it placed “significant emphasis on maintaining a high level of security in order to protect the information of our merchants and their customers,” according to the master complaint filed last month in U.S. Southern District Court in Houston. In January, Heartland announced it had been the victim of a data breach that is now recognized as the largest ever reported, impacting more than 130 million consumer credit/debit card accounts. The complaint represents “everything we know about the Heartland data breach so far,” says attorney Richard Coffman, representing the financial institutions suing Heartland for damages. This document lays out for the first time a sequence of events and statements made by Heartland executives about security measures and actions before, during and after the breach. http://www.bankinfosecurity.com/articles.php?art_id=1844 Complaint filing here: http://www.bankinfosecurity.com/external/HEARTLAND-FILING-9_2_09.pdf

SITE LETS INVESTORS SEE AND COPY EXPERTS’ TRADES (New York Times, 19 Oct 2009) - The trouble with mutual funds is that investors can feel as though they have put their money in a black box. The 90 million Americans with money in funds know little about fees, what securities their money is invested in and who is in charge. Daniel Carroll, who started investing when he was 15, thinks he has a way to let average investors learn about investing while experts manage the money. In 2008, he started KaChing, a Web site where 400,000 amateur and professional investors manage virtual portfolios. Others have logged on to see what the investors on the site are doing and make the same trades in their own real portfolios. On Monday, KaChing is to add a new twist. Customers can set up brokerage accounts that automatically mirror the trades of a money manager, some of them professionals. “The idea of an asset manager showing all his research, his holdings — it’s unheard-of,” said Mr. Carroll, now 27 and the vice president for business development at KaChing. “In the financial industry, the idea is that information is currency; they protect it with their lives.” KaChing has attracted a roster of prominent early investors from Silicon Valley who have financed the company with $3 million. They include Marc Andreessen, co-founder of Netscape; Kevin Compton of Kleiner Perkins Caufield & Byers; and Jeffrey Jordan, chief executive of OpenTable, the online reservation service. The angel investors have also been investing their own money through KaChing during the pilot period. “The concept is great — the ability to tap into not just the wisdom of the crowd, but to be able to identify and invest with the particular geniuses in the crowd that stand out,” said Mr. Andreessen, who has invested $100,000 using the site. Customers will be able to open a brokerage account with Interactive Brokers and link their account with their choice of investors on KaChing. KaChing charges customers a single management fee of 0.25 percent to 3 percent, set by each investor. KaChing keeps a quarter of the fee, and the investors get the rest. Each time the investors make a trade, KaChing will automatically make the same trades for the customer. Customers can log on whenever they want to check their portfolio’s performance. They can send the investor private messages and receive alerts if the investor does something unusual. With the click of a mouse, customers can stop mirroring an investor. http://www.nytimes.com/2009/10/19/technology/start-ups/19kaching.html?_r=2&scp=1&sq=kaching&st=cse

CHECK E-MAIL HOURLY, QUINN PARTNER SAYS, UNLESS IN COURT, IN TUNNEL OR ASLEEP (ABA Journal, 19 Oct 2009) - After doing a great job on a rush project, a relatively new associate at Quinn Emanuel Urquhart Oliver & Hedges made a mistake. He didn’t check his e-mail. As a result, he missed a senior partner’s instruction that he should send out a draft document for client review before calling it a day. Partner A. William Urquhart notes the mistake in an e-mail he sent the next morning to firm attorneys, which is reprinted in Above the Law, and exhorts the troops to pick up the pace as far as electronic message review is concerned. Lawyers should be checking their e-mail hourly, unless they have a very good excuse for not doing so, Urquhart says, such as being in court, in a tunnel or asleep. “One of the last things you should do before you retire for the night is to check your e-mail. That is why we give you BlackBerries,” he writes. http://www.abajournal.com/weekly/check_e-mail_hourly_quinn_partner_says_unless_in_court_in_tunnel_or_asleep [Editor: Law firms have been talking about the need for immediate response—i.e., within 15 minutes—to client emails for years. This (and this story) is nuts. Clients will let you know their response requirements, and one size doesn’t fit all.]

BAITED AND DUPED ON FACEBOOK (ComputerWorld, 19 Oct 2009) - When CIO Will Weider encouraged employees at Ministry Health Care and Affinity Health System in Wisconsin to use Facebook to spread the word about new programs and successful projects, he was surprised at the result: Few did so. “I went in there thinking, ‘We’ve turned these people loose; we’ll have 10,000 marketers out there,’ “ Weider says. But the Ministry Health workforce, it turned out, had been well trained to protect sensitive data, and without explicit guidance on what they could say, their first reaction was to share nothing. “We’ve stressed the importance of data security with our employees, particularly when it comes to patient privacy, and it’s kept them from sharing all the great things about work on Facebook,” Weider says. That’s a good problem to have. Many fear that the popularity of social networking -- among individuals as well as organizations -- will precipitate an increase in social engineering attacks that could result in security breaches that expose corporate data or damage a company’s reputation. But while executives seem to grasp the potential threats of social networking, only a slim majority of organizations seem to feel the need to do something about it. In an exclusive September 2009 Computerworld survey, 53% of the 120 IT professionals polled reported that their organizations have a social media usage policy, while 41% said they don’t and 6% said they weren’t aware of such a policy. And in a July 2009 poll by advertising agency Russell Herder and law firm Ethos Business Law, both based in Minneapolis, 81% of the 438 respondents said they have concerns about social media and its implications for both corporate security and reputation management. However, only one in three said that they have implemented social media guidelines, and only 10% said that they have undertaken related employee training. http://www.computerworld.com/s/article/343908/Baited_and_Duped_on_Facebook?source=CTWNLE_nlt_pm_2009-10-19

COURT RULES THAT PHONES RINGING IN PUBLIC DON’T INFRINGE COPYRIGHT (EFF, 21 Oct 2009) - In June, we reported on ASCAP’s claim that when your cell phone’s musical ringtone sounds in a public place, you are infringing copyright. A federal court firmly rejected that argument last week, ruling that “when a ringtone plays on a cellular telephone, even when that occurs in public, the user is exempt from copyright liability, and the [cellular carrier] is not liable either secondarily or directly.” This is exactly the outcome urged by EFF, Public Knowledge, and the Center of Democracy & Technology in an amicus brief filed in the case. https://www.eff.org/deeplinks/2009/10/court-rules-phones-ringing-public-dont-infringe-co

- and -

APOLOGY FOR SINGING SHOP WORKER (BBC, 21 Oct 2009) - A shop assistant who was told she could not sing while she stacked shelves without a performance licence has been given an apology. Sandra Burt, 56, who works at A&T Food store in Clackmannanshire, was warned she could be fined for her singing by the Performing Right Society (PRS). However the organisation that collects royalties on behalf of the music industry has now reversed its stance. They have sent Mrs Burt a bouquet of flowers and letter of apology. Mrs Burt, who describes herself as a Rolling Stones fan, said that despite the initial warning from the PRS, she had been unable to stop herself singing at work. The village store where Mrs Burt works was contacted by the PRS earlier this year to warn them that a licence was needed to play a radio within earshot of customers. When the shop owner decided to get rid of the radio as a result, Mrs Burt said she began singing as she worked. http://news.bbc.co.uk/2/hi/uk_news/scotland/tayside_and_central/8317952.stm

CIA INVESTS IN FIRM THAT DATAMINES SOCIAL NETWORKS (SlashDot, 20 Oct 2009) - “In-Q-Tel, the investment arm of the CIA and the wider intelligence community, is putting cash into Visible Technologies, a software firm that specializes in monitoring social media. It’s part of a larger movement within the spy services to get better at using ‘open source intelligence’ — information that’s publicly available... Visible Technologies crawls over half a million web 2.0 sites a day, scraping more than a million posts and conversations taking place on blogs, online forums, Flickr, YouTube, Twitter and Amazon. (It doesn’t touch closed social networks, like Facebook, at the moment.) Customers get customized, real-time feeds of what’s being said on these sites, based on a series of keywords. ‘That’s kind of the basic step — get in and monitor,’ says company senior vice president Blake Cahill. Then Visible ‘scores’ each post, labeling it as positive or negative, mixed or neutral. It examines how influential a conversation or an author is. (‘Trying to determine who really matters,’ as Cahill puts it.) Finally, Visible gives users a chance to tag posts, forward them to colleagues and allow them to response through a web interface.” http://yro.slashdot.org/story/09/10/20/1444256/CIA-Invests-In-Firm-That-Datamines-Social-Networks?from=rss

- and -

U.S. NAVY CIO: SOCIAL MEDIA SHOULD BE PART OF MILITARY IT STANDARD (ReadWriteWeb, 21 Oct 2009) – In a blog post this week, U.S. Navy CIO Rob Carey wrote that social media is a resource for the American military that should be used to build trust and collaboration, both within and outside the organization. In attempts to balance communication, transparency, and operational security, the military has encountered both practical obstacles and general criticism. In a recent podcast, Carey said, “Most social networking tools come with no rules of the road. As the Internet moves towards user-generated content, we thought there was a void we could fill... to mitigate some of the security risks associated with social media.” Beyond risk management, Carey said, “Social media has a powerful collaboration engine associated with it.” Generally, military organizations have the options to reach out directly to large IT companies to configure customized security profiles and inherent OPSEC protection for personnel; traditionally, however, social networks such as Facebook and Twitter have not been particularly receptive to working within that type of culture or framework. From the sharing-and-access social media pole to the security/military pole, both sides are resistant to different approaches to shared and social information. Still, Carey is an advocate for the usefulness of these tools, even behind a military firewall. “We must remain a learning organization. As the Internet evolves, so must our workforce and its associated skills. To that end, we must be able to embrace change,” Carey wrote in his blog post. “Many of our processes are rooted in the Industrial Age and will need to move toward the Information Age to remain relevant in the coming years.” With specific regard to social media and the American military, Carey stated, “Social media is an inherent part of the toolbox for members of the millennial workforce, while baby boomers are just adopting it. Social media tools should become the standard by which we can share and collaborate on information inside and outside the network boundaries.” He also highlighted green initiatives, mobile working, and the use of modern technological tools in recruitment efforts. To see Carey’s office’s Policy and Guidelines for Secure Use of Social Media by Federal Departments and Agencies, click here for a full PDF. http://www.readwriteweb.com/archives/us_navy_cio_social_media_should_be_part_of_militar.php

- and -

US DEPARTMENT OF DEFENSE EMBRACES OPEN SOURCE (ReadWriteWeb, 28 Oct 2009) - At the US Department of Defense, open source and proprietary software are now on equal footing. According to Defense Department guidance issued yesterday (PDF), open-source software (OSS) should be treated just like any other software product. The document also specifies some of the advantages of OSS for the Department of Defense (DoD). These include the ability to quickly alter the code as situations and missions change, the stability of the software because of the broad peer-review, as well as the absence of per-seat licensing costs. The document also stresses that OSS is “particularly suitable for rapid prototyping and experimentation, where the ability to ‘test drive’ the software with minimal costs and administrative delays can be important.” The DoD already uses some open-source products. This new memorandum is meant to provide guidance on the use of OSS and to clarify some misconceptions. According to the DoD, these misconceptions have hampered “effective DoD use and development of OSS.” One of these misconceptions is that the DoD would have to distribute any changes made to the OSS code. In reality, most open-source licenses permit users to modify code for internal use and these organizations only have to make the changes public if they distribute the code outside of their organizations. http://www.readwriteweb.com/archives/us_department_of_defense_embraces_open_source.php

WEB STORE OFFERING NEW JERSEY SHIPMENTS AVAILS ITSELF OF FORUM EVEN ABSENT ANY SALES (BNA’s Internet Law News, 22 Oct 2009) - BNA’s Electronic Commerce & Law Report reports that the U.S. District Court for the District of New Jersey has ruled that an interactive website that gives visitors the option of selecting New Jersey as the ship-to destination is evidence of purposeful availment of the new Jersey forum enough to support jurisdiction there, even absent evidence of actual New Jersey sales. The court said that a website offering allegedly counterfeit goods for sale specifically to New Jersey residents was a meaningful contact with the forum that would satisfy the due process clause’s purposeful availment requirement. Case name is Tristar Products Inc. v. SAS Group Inc.

- but -

HOSTING SPONSORED AD LINKS TARGETING NEW YORK NOT ENOUGH FOR JURISDICTION THERE (BNA’s Internet Law News, 5 Nov 2009) - BNA’s Electronic Commerce & Law Report reports that the U.S. District Court for the Southern District of New York has ruled that although some ads on a site sponsoring pay-per-click links may resolve to New York web addresses and companies, that contact will not, without more evidence of direct New York soliciting, support jurisdiction over the website owner there. The court said that simply claiming that sponsored links meant direct solicitation was not convincing.

DATA BREACH NOTIFICATION SPREADS SOUTH OF THE BORDER -- WAY SOUTH (Steptoe & Johnson’s E-Commerce Law Week, 22 Oct 2009) - Uruguay recently issued mandatory data breach notification provisions as part of regulations implementing its Personal Data Protection Act (Law 18331). Article 8 of the Act (Decree No. 414/009) requires that “[w]henever those responsible for or in charge of a database … learn of security breaches at any stage of the (data) treatment process that have the potential of affecting the rights of the injured parties in a significant way, they must inform them of this incident.” The Act and regulations were adopted as part of Uruguay’s effort to satisfy the EU Directive on Data Protection, No. 95/46/EC, and to become a premiere Latin American outsourcing point for banking, call-center operations, airplane ticket sales, and other international financial and administrative services. Few other countries currently require notification of individuals affected by a data breach; Japan, Norway, and Germany, are among the few that do so, along with 45 U.S. states, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands. Mandatory notification is, however, likely to come to the EU in the next year or two as part of proposed revisions to the EU electronic communications framework. And South Africa’s Protection of Personal Information Bill, which was approved by the Cabinet and is now before Parliament, would make notification mandatory. The spread of such laws makes it all the more imperative for multinational companies to put in place effective data security measures and a response plan to deal with any breaches that do occur. http://www.steptoe.com/publications-6402.html

SEC PROPOSES AMENDING RULES FOR INTERNET AVAILABILITY OF PROXY MATERIALS (Duane Morris, 22 Oct 2009) - On October 14, 2009, the U.S. Securities and Exchange Commission (the “SEC”) proposed amendments to the proxy rules under the Securities Exchange Act of 1934 that are intended to provide additional flexibility for issuers and other soliciting persons on the content and format of the Notice of Internet Availability of Proxy Materials (the “Notice”). In an effort to improve the clarity of the Notice and to better educate shareholders about the notice and access model, the SEC has proposed a new rule allowing issuers and other soliciting persons to accompany the Notice with an explanation of the process of reviewing and receiving proxy materials and voting. In addition, SEC Release No. 34-60825 (the “Release”) provides guidance about the current requirement for the Notice to identify matters to be voted upon at the shareholders’ meeting. Furthermore, the SEC has proposed revisions to the Notice delivery deadlines for soliciting persons other than issuers…. http://www.duanemorris.com/alerts/SEC_Internet_Proxy_Materials_3452.html

MICROSOFT WANTS ISO SECURITY CERTIFICATION FOR ITS CLOUD SERVICES (ComputerWorld, 23 Oct 2009) - Microsoft Corp. wants to get its suite of hosted messaging and collaboration products certified to the ISO 27001 international information security standard in an effort to reassure customers about the security of its cloud computing services. The move comes at a time of broad and continuing doubts about the ability of cloud vendors in general to properly secure their services. Google Inc., which has made no secret of its ambitions in the cloud computing arena, is currently working on getting its services certified to the government’s Federal Information Security Management Act (FISMA) standards for much the same reason. It’s unclear how much value customers of either company will attach to the certifications, particularly because the specifications were not designed specifically to audit cloud computing environments. Even so, the external validation offered by the standards is likely to put both companies in a better position to sell to the U.S. government market. Speaking with Computerworld this week, Bill Billings, chief security officer of Microsoft Federal, said the company is currently in the process of putting Microsoft’s Business Productivity Online Suite through the ISO 27001 certification process. The hosted service includes Exchange Online, SharePoint Online, Office Live Meeting and Office Communications Online. Billings declined to say just when Microsoft hopes to achieve the certification. The goal is to offer customers, particularly those in the public sector, a higher level of confidence about Microsoft’s cloud services than FISMA certification alone provides, said Teresa Carlson, vice president of Microsoft Federal. “FISMA is outdated. It is largely a paper-based exercise. We want to take it up a notch” by getting ISO 27001 certification, Carlson said. At the same time, Microsoft is also working to get its cloud services certified to the standards prescribed under FISMA; it hopes to complete that task by the end of the year, Carlson said. http://www.computerworld.com/s/article/9139820/Microsoft_wants_ISO_security_certification_for_its_cloud_services?source=CTWNLE_nlt_dailyam_2009-10-23

OBAMA’S ETHICS COUNSEL FACES TOUGH CROWD AT ABA CONFERENCE (NLJ, 23 Oct 2009) - President Barack Obama’s special counsel for ethics and government regulation Thursday afternoon gave an American Bar Association crowd an insider’s perspective into the administration’s thought path as it first embarked on, and now continues to pursue, lobbying reform in Washington. But his remarks did not go unchallenged. Many thought Obama’s promise of reform was just empty campaign rhetoric, said Norman Eisen, but the president in fact has “a deeply held personal view that political systems are susceptible to special interests” and he “speaks of it often.” “The president will hold every government servant to the highest standard of fidelity to the public interest,” Eisen told a crowd of about 40 at the ABA Administrative Law Conference luncheon. “We think it is no accident that we have had one of the most scandal-free starts of any administration in modern history.” Still, critics like Thomas Susman, the ABA’s government affairs office director, who joked when introducing Eisen to the crowd that he was responsible for “vilifying and emasculating” lobbyists, questioned Eisen as to why, if indeed these regulations are intended for the public interest, no distinction is made between corporate lobbyists and those who lobby for public interest causes. Eisen responded by saying that the administration did consider parsing types of lobbying, but in the end, “felt that as a matter of principle, we needed to be consistent in that regulation to have credibility.” Sharing the stage Eisen and Susman, William Luneburg Jr., chair of the ABA’s administrative law and regulatory practice section, which sponsored the event, told Eisen that the definition of, “lobbyist,” should be more consistent because some who don’t register as lobbyists still fit the role and slip through the cracks into government positions. Eisen responded, saying: “We thought it would be too burdensome to establish another regulatory regime” and “we felt that as a matter of workability, that was just too tough.” An audience member also harangued Eisen for not consulting with lobbyists before undertaking reform. Eisen said that in fact the administration did, though only with those whose contribution would have had a valuable impact. The criticism didn’t stop at lunch. Immediately after Eisen’s remarks, a panel discussion assembled down the hall in the Walter E. Washington Convention Center. Panelist Nick Allard, of Patton Boggs, quipped that he was “shocked” to hear Obama’s “fig-leaf counsel” complain about lobbyists because shutting lobbyists out of government is forcing them to cut corners, including unregistering. “Right now it’s popular to make a show of turning lobbyists away from the front door while sending them around the back,” he said. “The dirty little secret is the wink-wink policy toward lobbying encourages people to do things the wrong way.” He urged the lobbying community to self-regulate and hold itself to a higher standard of conduct so the government wouldn’t feel the need to intrude. Melanie Sloan, Executive Director of Citizens for Responsibility and Ethics in Washington (a group that Eisen co-founded), contended that the administration wasn’t doing enough to take the money out of politics. She advocated publicly financed elections, but admitted it seems a political impossibility right now. But small measures, like restricting bundling or forcing disclosure in so-called “Astroturf” lobbying groups would help, she said. Finally, former U.S. Solicitor General and current Harvard Professor Charles Fried addressed the constitutional implications of shutting lobbyists out from government: He said there are none. “The constitutional issue about the Obama executive order that we keep hearing about seems to me a true nothing burger,” he said. “You have the right to petition, you don’t have the right to be heard.” http://www.law.com/jsp/article.jsp?id=1202434891673&rss=newswire&hbxlogin=1

OBAMA FAMILY PORTRAIT POSTED TO FLICKR (Mashable, 23 Oct 2009) - Much was made of Barack Obama’s use of social media in his successful 2008 Presidential campaign. Although it’s now been nearly a year since he was elected, the President and his team continue to make use of the tools that helped him land the job. The latest example: the official Obama family portrait, posted to Flickr on Thursday. The photo is part of the White House Flickr stream, which includes hundreds of sets from the President’s day-to-day engagements around the world. As with all photos posted to the stream, however, users should be aware of the restrictions placed on their use: “This official White House photograph is being made available only for publication by news organizations and/or for personal use printing by the subject(s) of the photograph. The photograph may not be manipulated in any way and may not be used in commercial or political materials, advertisements, emails, products, promotions that in any way suggests approval or endorsement of the President, the First Family, or the White House.” http://mashable.com/2009/10/23/obama-family-portrait/

MI5 COMES OUT AGAINST CUTTING OFF INTERNET PIRATES (The Times, 23 Oct 2009) - The police and intelligence services are calling on the Government to drop plans to disconnect persistent internet pirates because they fear that this would make it harder to track criminals online. Lord Mandelson, the Business Secretary, has vowed to use the Government’s forthcoming Digital Economy Bill to introduce new measures to fight illegal file-sharing of music and films. He has also proposed that persistent pirates should have their internet connections suspended temporarily. But The Times understands that both the security services and police are concerned about the plans, believing that threatening to cut off pirates will increase the likelihood that they will escape detection by turning to encryption. http://www.timesonline.co.uk/tol/news/uk/crime/article6885923.ece

PRIVACY COALITION SEEKS INVESTIGATION OF DHS CHIEF PRIVACY OFFICE (BeSpacific, 24 Oct 2009) - “EPIC joined the Privacy Coalition letter sent to the House Committee on Homeland Security urging them to investigate the Department of Homeland Security’s (DHS) Chief Privacy Office. DHS is unrivaled in its authority to develop and deploy new systems of surveillance. The letter cited DHS use of Fusion Center, Whole Body Imaging, funding of CCTV Surveillance, and Suspicionless Electronic Border Searches as examples of where the agency is eroding privacy protections.” http://www.bespacific.com/mt/archives/022652.html#022652

SOCIAL MEDIA AND ED. TECH. COMPANIES (InsideHigherEd, 26 Oct 2009) - Where social media make sense to me are as a method of exposing the fact that organizations are made up of people. I don’t want to read blog posts or Facebook status updates or tweets from Microsoft, Google, Blackboard, Adobe, Apple etc.... But I do want to hear from the people who work at these companies. Particularly the people who work in the education divisions of these companies. The NYTimes has now has a social media editor named Jennifer Preston. In an interview on NYTimes Tech Talk, Preston makes the point that NYTimes reporters can use social media to engage in two-way conversations with a highly motivated community. Part of her job is to encourage this conversation. I think the time has come for companies to bring in their own social media editors. I know some of the people who work in ed. tech companies that we do business with, but I don’t know nearly enough of you. Who are the education leaders, decision makers, program managers, developers, designers, and sales folks at Microsoft? (to pick on one). What do you guys care about? What is driving you crazy? What are you working on? What articles and blogs are you reading right now? What products and services do you use? How did you get into educational technology? What do you hope to leave as your legacy? http://www.insidehighered.com/blogs/technology_and_learning/social_media_and_ed_tech_companies

FBI: CYBER CROOKS STOLE $40M FROM U.S. SMALL, MID-SIZED FIRMS (Washington Post, 26 Oct 2009) - Cyber criminals have stolen at least $40 million from small to mid-sized companies across America in a sophisticated but increasingly common form of online banking fraud, the FBI said this week. According to the FBI and other fraud experts, the perpetrators have stuck to the same basic tactics in each attack. They steal the victim’s online banking credentials with the help of malicious software distributed through spam. The intruders then initiate a series of unauthorized bank transfers out of the company’s online account in sub-$10,000 chunks to avoid banks’ anti-money-laundering reporting requirements. From there, the funds are sent to so-called “money mules,” willing or unwitting individuals recruited over the Internet through work-at-home job scams. When the mules pull the cash out of their accounts, they are instructed to wire it (minus a small commission) via services such as MoneyGram and Western Union, typically to organized criminal groups operating in countries like Moldova, Russia and Ukraine. Steve Chabinsky, deputy assistant director of the FBI’s Cyber Division, said criminals involved in these online account takeovers have attempted to steal at least $85 million from mostly small and medium-sized businesses, and have successfully made off with about $40 million of that money. http://voices.washingtonpost.com/securityfix/2009/10/fbi_cyber_gangs_stole_40mi.html

STUDY: FACEBOOK, TWITTER USE AT WORK COSTS BIG BUCKS (ComputerWorld, 26 Oct 2009) - A U.K. firm today released a study showing that people who use Facebook, Twitter and other social networks while at work extract a heavy cost on their employers. Employees who use Twitter and other social networks in the office are costing U.K. businesses about 1.38 billion pounds, or more than $2.25 billion a year, according to London-based Morse PLC, an IT services and technology company. Morse surveyed 1,460 office workers and found that 57% browse social networking sites for personal use while in the office. Those workers use social networks an average of 40 minutes a day at work, which adds up to a lost week each year, the survey found. Morse, which commissioned research firm TNS Group to do the study, isn’t alone in its findings. In July, Nucleus Research, an IT research company in Boston, released a study showing that companies where users are free to access Facebook in the workplace lose an average of 1.5% in total employee productivity. The survey also showed that 77% of workers who have a personal Facebook account use it during work hours. Earlier this month, a study commissioned by Robert Half Technology, an IT staffing firm, showed that companies are starting to take on social networkers in their offices. This study found that 54% of U.S. companies had banned office use of social networking sites like Twitter, Facebook, LinkedIn and MySpace while on the job. http://www.computerworld.com/s/article/9139902/Study_Facebook_Twitter_use_at_work_costs_big_bucks?source=CTWNLE_nlt_pm_2009-10-26

IN INDUSTRY FIRST, VOTING MACHINE COMPANY TO PUBLISH SOURCE CODE (Wired, 27 Oct 2009) - Sequoia Voting Systems plans to publicly release the source code for its new optical scan voting system, the company announced Tuesday — a remarkable reversal for a voting machine maker long criticized for resisting public examination of its proprietary systems. The company’s new public source optical-scan voting system, called Frontier Election System, will be submitted for federal certification and testing in the first quarter of next year. The code will be released for public review in November, the company said, on its web site. Sequoia’s proprietary, closed systems are currently used in 16 states and the District of Columbia. The announcement comes five days after a non-profit foundation announced the release of its open-source election software for public review. Sequoia spokeswoman Michelle Shafer says the timing of its release is unrelated to the foundation’s announcement. In the press release announcing the public-source system, a Sequoia vice president is quoted saying that “Security through obfuscation and secrecy is not security.” “Fully disclosed source code is the path to true transparency and confidence in the voting process for all involved,” said Eric Coomer, vice president of research and product development for Sequoia, in the press release. “Sequoia is proud to be the leader in providing the first publicly disclosed source code for a complete end-to-end election system from a leading supplier of voting systems and software.” Sequoia in fact has been a champion of security through obscurity since it’s been selling voting systems. The company has long had a reputation for vigorously fighting any efforts by academics, voting activists and others to examine the source code in its proprietary systems, and even threatened to sue Princeton University computer scientists if they disclosed anything learned from a court-ordered review of its software. http://www.wired.com/threatlevel/2009/10/sequoia/

LEARNING BY DEGREES (Harvard Magazine, Nov/Dec 2009) - the image is grim: “binge and purge” learning. It’s what students do when they cram for a test: consume subject matter in a large lump (binge) and then spit it back on the exam (purge). This mode of study doesn’t seem to produce durable learning. During the past four years, associate professor of surgery B. Price Kerfoot, M.D. ‘96, Ed.M. ‘00, has developed a scheme that’s more like grazing: “spaced education.” More than 10 rigorous studies on medical students and residents using randomized trials have shown its efficacy: it can increase knowledge by up to 50 percent, and strengthen retention for up to two years. Furthermore, students report enjoying spaced education; its website (www.spaceded.com) even calls it “addictive.” The website offers, online, the first courses structured in this mode. (Harvard has applied for a patent on the technology, and already licenses it to an Internet start-up company, SpacedEd.) The methodology, which Kerfoot, a urological surgeon, invented, breaks information down into discrete packages and then applies two learning principles that he gleaned from the psychological literature on learning and memory. The first principle is the spacing effect—”When you present and repeat information over intervals of time [as opposed to “binges”], you can increase the uptake of knowledge,” he explains. “And it’s encoded in ways that cause it to be preferentially retained.” The second principle is the testing effect: “When you present information in a ‘test’ format, rather than just reading it, long-term retention is dramatically improved.” http://harvardmagazine.com/2009/11/spaced-education-boosts-learning

ACC TO GCS: ELIMINATE SOFTWARE COSTS (Law.com, 27 Oct 2009) - In a market where in-house legal teams must control cost, many are seeking to eliminate it completely, at least with respect to their technology budgets. Despite its placement on the last day of the Association of Corporate Counsel’s annual conference this month, the “InExpensive/Free Applications for Your Law Department” session captivated an audience of more than 100 people for over an hour. Mark Donald, associate general counsel of Baltimore-based Vertis Communications, offered attendees a variety of ideas for leveraging open-source technology to streamline operations and eliminate unnecessary expenses. For example, he encouraged audience members seeking a full-feature, Web-based enterprise document management system to consider the open-source version of KnowledgeTree or the community edition of Alfresco. He similarly recommended that those interested in designing workflow use ProcessMaker and directed audience members to the company’s YouTube channel to see Processmaker in action. Eager to experiment with ProcessMaker “to interface with the sales effort to prepare contracts,” Atlanta-based Polysius Corp. GC Lori Ann Haydu attended this particular session because “I wanted to see how we could do more with less.” That was certainly a theme and Donald provided his peers with options for addressing routine activities with free tools like Open Office, an open-source suite of products for word processing, spreadsheets, presentations and other functions, noting that the program provides “baseline Microsoft Office compatibility and supports redlining very well in instances where one may need to quickly review a document on a computer without Microsoft Word.” And the creation of PDF documents using open-source Cute PDF Writer intrigued audience members. The discussion of PDF Creator, a program that enables users to create and manipulate PDF documents, generated enthusiastic questions from the audience, although the program is not exactly free (a one-year license costs $29.95). Co-presenter Joel Green, GC of Beverly, Mass.-based Altova, offered Web-based resources for finding answers to specific issues, documents and general guidance. He encouraged use of the ACC’s various listservs. In addition, he recommended regional and local meetings of in-house counsel, Legal OnRamp and ABA resources. However, he alerted attendees: “Your competitors or outside counsel may be on those boards as well” and advised them to be circumspect. Green also instructed audience members to read blogs, including The Wall Street Journal’s Law Blog, Patently-O and others written by law firms, including Sheppard Mullin’s blog on government contracts. “Blogs can be useful because they do provide valuable information on a variety of topics.” Another law firm resource included Wilson Sonsini Goodrich & Rosati’s Term Sheet Generator. http://www.law.com/jsp/article.jsp?id=1202434943463&rss=newswire

SURVEY: FEW COMPANIES ADDRESSING CYBERTERRORISM (CNET, 28 Oct 2009) - Cyberterrorism is on the rise around the world. But only one-third of companies are tackling it in their disaster recovery plans, says a survey released Tuesday by data center association AFCOM. Although the majority (60.9 percent) of companies questioned see cyberterrorism as a threat to be addressed, “AFCOM’s 2009/2010 Data Center Trends” survey found that only 24.8 percent have adopted it in their policies and procedures manuals. Further, only 19.7 percent provide cyberterrorism training to their employees. Around 82 percent do run background checks on new hires. But that still leaves almost 20 percent of all data centers that don’t perform security checks on new employees, even those working directly with personal, financial, and even military records, noted AFCOM. The U.S. power grid has been especially vulnerable as utility companies rely more on network-based smart-grid technology to manage it. A Wall Street Journal report said spies from Russia and China have already hacked into the grid, leaving behind traces of their activity. In an interview with “60 Minutes” in April, Defense Secretary Robert Gates said that the U.S. is “under cyberattack virtually all the time, every day.” Beyond the AFCOM survey, other reports have also noted flaws among organizations in their approach toward cyberterrorism. http://news.cnet.com/8301-1009_3-10385230-83.html

EDUCAUSE CORE DATA SERVICE FISCAL YEAR 2008 SUMMARY REPORT (Educause, 28 Oct 2009) - EDUCAUSE Core Data Service Fiscal Year 2008 Summary Report summarizes much of the data collected through the 2008 EDUCAUSE core data survey about campus information technology (IT) environments at colleges and universities in the U.S. and abroad. The report presents aggregated data and time trends through more than 100 figures and tables and accompanying descriptive text in five areas relevant to planning and managing IT in higher education: IT Organization, Staffing, and Planning; IT Financing and Management; Faculty and Student Computing; Networking and Security; and Information Systems. Appendices include a brief historical context, a list of participating campuses, the 2008 survey instrument, a glossary of terms from the survey, and a crosswalk between survey questions and figures and tables in the report. http://net.educause.edu/coredata/reports/2008/index.asp?bhcp=1 Report here: http://net.educause.edu/ir/library/pdf/PUB8006.pdf

CT RULES FACEBOOK TERMS CLAIMING OWNERSHIP OF USER INFO DID NOT DESTROY CDA PROTECTIONS (BNA’s Internet Law News, 29 Oct 2009) - BNA’s Electronic Commerce & Law Report reports that the New York Supreme Court, New York County has ruled that as an interactive computer service, Facebook was immune to defamation claims arising from content posted by its users, regardless of what its terms of service said about it owning user-generated data posted there. Judge Debra A. James said that data ownership does not factor into the analysis of whether an online service qualifies for protections granted to interactive computer services under the Communications Decency Act. Case name is Finkel v. Facebook Inc.

LAWYERESE GOES GALACTIC AS CONTRACTS TRY TO MASTER THE UNIVERSE (WSJ, 29 Oct 2009) - Decked out in sequined black and gold dresses, Anne Harrison and the other women in her Bulgarian folk-singing group were lined up to try out for NBC’s “America’s Got Talent” TV show when they noticed peculiar wording in the release papers they were asked to sign. Any of their actions that day last February, the contract said, could be “edited, in all media, throughout the universe, in perpetuity.” She and the other singers, many of whom are librarians in the Washington, D.C., area, briefly contemplated whether they should give away the rights to hurtling their images and voices across the galaxies forever. Then, like thousands of other contestants, they signed their names. Ms. Harrison figured the lawyers for the show were trying to hammer home the point that contestants have no rights to their performances, “but I think they’re just lazy and don’t want to write a real contract,” she says. Lawyers for years have added language to some contracts that stretches beyond the Earth’s atmosphere. But more and more people are encountering such everywhere-and-forever language as entertainment companies tap into amateur talent and try to anticipate every possible future stream of revenue. Experts in contract drafting say lawyers are trying to ensure that with the proliferation of new outlets -- including mobile-phone screens, Twitter, online video sites and the like -- they cover all possible venues from which their clients can derive income, even those in outer space. FremantleMedia, one of the producers of NBC’s “America’s Got Talent,” declined to comment on its contracts. The space and time continuum has extended to other realms outside the arts, including pickles. A 189-word sentence in a September agreement between Denver-based Spicy Pickle Franchising Inc. and investment bank Midtown Partners & Co. -- which has helped raise capital for the sandwich and pickle shops dotted across the region -- unconditionally releases Spicy Pickle from all claims “from the beginning of time” until the date of the agreement. “We’re trying to figure out how to cover every possible base as quickly as possible,” says Marc Geman, chief executive officer of Spicy Pickle. “When you start at the beginning of time, that is pretty clear.” As for the wordy language, he says, “the length of the paragraph is only limited by the creativity of the attorney.” [Doesn’t he have this inverted? Creative lawyers write concisely.] http://online.wsj.com/article/SB125658217507308619.html

JUDGE RULES METADATA IS PUBLIC RECORD (ArsTechnica, 29 Oct 2009) - The Arizona state Supreme Court has ruled that the metadata attached to public records is itself public, and cannot be withheld in response to a public records request. In the Arizona case, a police officer had been demoted in 2006 after reporting “serious police misconduct” to his superiors. He suspected that the demotion was done in retaliation for his blowing the whistle on his fellow officers, so he requested and obtained copies of his performance reports from the department. Thinking that perhaps the negative performance reports had been created after the fact and then backdated, he then demanded access to the file metadata for those reports, in order to find out who had written them and when. The department refused to grant him access to the metadata, and the matter went to court. After working its way through the court system in a series of rulings and appeals, this past January an Arizona appeals ruled that even though the reports themselves were public records, the metadata was not. It turned out that Arizona state law doesn’t actually define “public record” anywhere, so the appeals court relied on various common law definitions to determine that the metadata, as a mere byproduct of the act of producing a public record on a computer, was not a public record itself. The case was then appealed to the Arizona state Supreme Court, which has now ruled that the metadata is, in fact, a public record just like the document that it’s attached to. http://arstechnica.com/tech-policy/news/2009/10/lobbyists-beware-arizona-rules-metadata-is-public-record.ars?utm_source=rss&utm_medium=rss&utm_campaign=rss and http://www.law.com/jsp/article.jsp?id=1202435052835&rss=newswire

- and -

PA BAR COMMITTEE EXAMINES METADATA (Sup. Ct. Penn, Oct 2009) - The Committee on Legal Ethics and Professional Responsibility has addressed the issue of lawyer’s responsibilities regarding metadata in Formal Opinion 2009-100, “Ethical Obligations on the Transmission and Receipt of Metadata.” Formal Opinion 2009-100 addresses the responsibilities of both sending and receiving lawyers. The opinion puts particular emphasis on the duties of the sending lawyer to take reasonably diligent steps to prevent the transmission of potentially confidential information. This duty is grounded in Rules 1.1 (Competence) and 1.6 (Confidentiality) of the Rules of Professional Conduct. Comment 4 to Rule 1.6 states, “This prohibition also applies to disclosures by a lawyer that do not in themselves reveal protected information but could reasonably lead to the discovery of such information by a third person.” http://www.padisciplinaryboard.org/newsletters/index.php#story3 Opinion 2009-100 here: http://www.padisciplinaryboard.org/newsletters/2009/pdfs/f2009-100.pdf [Thanks to MIRLN reader Tom Laudise at RCG Information Technology for spotting this story.]

- and -

WANT TO UPDATE YOUR AVVO LISTING? IF SO, START POLICING CLIENT COMMENTS, OPINION SAYS (ABA Journal, 28 Oct 2009) - South Carolina lawyers tempted to update their listings on websites such as LinkedIn and Avvo should consider a new ethics opinion by the state bar’s Ethics Advisory Committee. The advisory opinion says lawyers who “claim” the website listing by clicking on an “update this listing” link or otherwise adopting the posted information must make sure the material conforms with ethics rules—even information that is posted by others, including clients. The opinion says websites such as Martindale-Hubbell, SuperLawyers, LinkedIn and Avvo may post informational listings about lawyers without their knowledge or consent. Once a lawyer participates in the listing, the rules change. “By claiming a website listing, a lawyer takes responsibility for its content and is then ethically required to conform the listing to all applicable rules,” the opinion says. “The language employed by the website for claiming a listing is irrelevant. (Martindale.com, for example, uses an ‘update this listing’ link for lawyers to claim their listings). Regardless of the terminology, by requesting access to and updating any website listing (beyond merely making corrections to directory information), a lawyer assumes responsibility for the content of the listing.” The content must not be false, misleading, deceptive or unfair, the opinion says. Client testimonials, barred by state ethics rules, should not be solicited or allowed. More general recommendations or statements of approval—client endorsements—may be allowed if they aren’t misleading and don’t create unjustified expectations. “If any part of the listing cannot be conformed to the rules (e.g., if an improper comment cannot be removed), the lawyer should remove his or her entire listing and discontinue participation in the service,” the opinion counsels. Mercer University law professor David Hricik noted the opinion at the blog Legal Ethics Forum. “Frankly, this one baffles me,” Hricik wrote. “I can understand why you can’t ask someone to say something about you that you can’t yourself say, … but am I really under an obligation to make sure nonclients comply with the lawyer advertising rules? Stay tuned, but in the meanwhile, you South Carolina lawyers better go read your various listings, I suppose including Facebook!” http://www.abajournal.com/news/want_to_update_your_avvo_listing_if_so_start_policing_client_comments_opini

EU SENDS CONFLICTING MESSAGES ON KEYWORD ADVERTISING (Steptoe & Johnson’s E-Commerce Law Week, 29 Oct 2009) - Two legal opinions in the European Union have reached conflicting conclusions about whether the use of trademarked terms in keyword advertising constitutes trademark infringement. The Paris Tribunal de Grande Instance (TGI) found eBay, Inc., and eBay International AG liable for “counterfeiting” the trademarks of four LVMH Moët Hennessy Louis Vuitton, S.A. (“LVMH”) subsidiaries by purchasing those companies’ trademarked phrases to use as keywords on search engines to draw users to eBay’s auction site. But a few days after the TGI ruling, an Advocate General (AG) of the European Court of Justice (ECJ) issued an advisory opinion in a similar case LVMH had brought in France against Google, Inc., and Google France regarding Google’s AdWords program. The AG opined that Google had not committed trademark infringement by selling trademarked terms as keywords to websites selling counterfeit products, and also that Google should not be considered a “contributory” infringer for facilitating third-party infringement. The AG also stated that advertisers do not infringe trademarks by purchasing those marks as keywords. Should the ECJ follow the advisory opinion, its ruling would likely contradict the TGI ruling against eBay and give eBay strong arguments in its appeal of that ruling. More broadly, the conflicting opinions highlight the opposing views that exist globally on how to regard use of trademarked terms as keywords. http://www.steptoe.com/publications-6433.html

AMAZON LETS SHOPPERS PAY WITH A PHRASE (CNET, 29 Oct 2009) - A simple phrase and pin code may be all you need the next time you pay for that book or CD at Amazon. The online retailer on Thursday debuted a new feature called Amazon PayPhrase, designed to let busy shoppers store their name, address, and payment information in a single phrase and pin code. Instead of entering all that data at the online checkout counter, you type your phrase and pin number when it’s time to cough up the cash. PayPhrase doesn’t just work at Amazon--it can be used at any online retailer that lets you pay via Amazon Payments. That covers a range of cyberstores, including Buy.com, J&R Electronics, DKNY, and Car Toys. PayPhrase also omits the need for a user name and password to store your personal info on every shopping site that uses Amazon Payments. However, you will need an Amazon.com account to set up and maintain your phrase. Amazon sees PayPhrase as a benefit to consumers trying to juggle different accounts at different retail sites. “PayPhrase solves the headache of trying to keep track of all the different user names and passwords people use to shop on various sites across the Web,” said Matt Williams, general manager of Amazon PayPhrase, in a statement. “With PayPhrase all you need is one phrase and one PIN to pay online.” http://news.cnet.com/8301-10797_3-10386056-235.html 30-second video explanation: http://www.amazon.com/gp/mpd/permalink/m1L3CVL0TEWNNT

DOES CLOUD COMPUTING NEED MALPRACTICE SAFEGUARDS? (CNET, 1 Nov 2009) - Recent failures to protect consumer data stored on the Internet (aka “the cloud”) point to an alarming gap between the value of that data and the care with which some vendors treat that data. Microsoft subsidiary Danger failed to put in even adequate safeguards for its customers’ data. Amazon Web Services failed to discover an obvious problem that kept a loyal customer down for 20 hours. The truth is that cloud computing means that now, more than ever, IT operations is a profession that has a very real economic and quality-of-life effect on its consumers--in very many ways much like health care or the law. I think it’s time we hold ourselves as individual and organizations to similar standards that we expect from doctors, lawyers, and law enforcement. Our ethics must reflect an understanding of the responsibility we are being granted by the rest of society. The instances above are examples of companies failing to follow well-known professional protocols, or putting the needs of the business ahead of the needs of the client. Heck, look at just about any cloud operator’s terms of service, and you see paragraph after paragraph of text that basically states, “If something goes wrong, you can’t blame us.” I think its time to change this attitude. I see a couple of options: http://news.cnet.com/8301-19413_3-10387879-240.html?part=rss&subj=news&tag=2547-1_3-0-5

LAWYERS IN DISCOVERY SCANDAL SAY QUALCOMM LIED (Law.com, 3 Nov 2009) - Lawyers in the Qualcomm discovery scandal claim that the company misled and stonewalled them, ultimately leading to the failure to turn over a mountain of relevant evidence and harsh sanctions from the court. The allegations were made in briefs filed Monday by lawyers from the now-defunct Day Casebeer Batchelder & Madrid, who for the first time are telling their side of what has become the most infamous discovery fiasco in recent times. Qualcomm Inc. was sanctioned by San Diego Magistrate Judge Barbara Major in January 2008 for intentionally withholding “tens of thousands of e-mails” in an infringement case against Broadcom Corp. involving video compression technology patents. The company’s lawyers -- six from Day Casebeer and one from Heller Ehrman -- were also sanctioned for assisting “Qualcomm in committing this incredible discovery violation,” either knowingly or recklessly, Major wrote at the time. The sanctions were later lifted while the lawyers got a chance to defend themselves. The lawyers argue they shouldn’t be penalized -- they were misled by their client. The Day Casebeer lawyers claim that they repeatedly prodded Qualcomm about whether the company had participated in industry meetings at which video compression standards were discussed. The upshot being that if the company had, then Qualcomm may have had no rights to enforce its patents against Broadcom. “Qualcomm’s failure to disclose was not limited to two or three people: Numerous individuals, including engineers in Qualcomm’s Digital Cinema group, managers of Qualcomm’s Standardization Group, and even attorneys in Qualcomm’s legal department, received inquiries from responding attorneys or Qualcomm paralegals about JVT participation and related subjects, but failed to provide critical information they had,” wrote Joel Zeldin, the Shartsis Friese partner who represents three of the Day Casebeer lawyers: partners James Batchelder and Christian Mammen and associate Kevin Leung. H. Sinclair Kerr Jr., a Kerr & Wagstaffe lawyer for former Day Casebeer lawyer Lee Patch, put it more succinctly. “Mr. Patch asked the right people the right questions at the right time and got wrong -- no, false -- answers.” http://www.law.com/jsp/article.jsp?id=1202435137932&rss=newswire&hbxlogin=1

ATTORNEY-CLIENT PRIVILEGE IN WORK E-MAILS (Law.com, 5 Nov 2009) - There are now several decisions determining whether employees can retain attorney-client privilege for e-mails sent to their lawyers using their employer-provided e-mail addresses and computers -- reaching apparently inconsistent conclusions. This article compares and seeks to reconcile the cases, and to assist lawyers in advising clients on how to avoid the risks that such communications pose. The first of these cases, Scott v. Beth Israel Medical Center Inc., 2007 WL 3053351 (N.Y. Sup. Oct. 17, 2007), was previously featured in an article in this column (“Abusive Litigation Tactics and Loss of Privilege,” March 3, 2008), but is revisited here because a New Jersey court recently reached a diametrically opposite conclusion on quite similar facts, in Stengart v. Loving Care Agency Inc., 973 A.2d 390 (N.J. Super. A.D. July 29, 2009). The article also reviews other recent decisions in the same general subject area. http://www.law.com/jsp/article.jsp?id=1202435191463&rss=newswire

JUDGE SPANKS LAWYER FOR LEAKING PERSONAL DETAILS IN BRIEF (The Register, 5 Nov 2009) - A judge has chastised a lawyer for including the social security numbers and birthdays of 179 individuals in an electronic court brief, ordering him to pay a $5,000 sanction and provide credit monitoring. US District Judge Michael J. Davis said he was meting out the penalty under his “inherent power,” meaning no one in the court case had filed a motion requesting he do so. In an order issued late last month, he said the move was designed to prevent attorney Vincent J. Moccio from repeating the carelessness again. “The court is deeply concerned with the harmful and widespread ramifications associated with negligent and inattentive electronic filing of court documents,” he wrote. “Although electronic filing significantly improves the efficiency and accessibility of our court system, it also elevates the likelihood of identity theft and damage to personal privacy when lawyers fail to follow federal and local rules.” Davis ordered Moccio to send the individuals a letter informing them that their private information had been made public and that unless they objected within seven days, they would automatically begin receiving a year’s worth of credit monitoring services free of charge. He also ordered the attorney to pay $5,000 to a Saint Paul, Minnesota, food bank. http://www.theregister.co.uk/2009/11/05/judge_sanctions_attorney/

**** PODCASTS ****
I BOUGHT THE LAW (Harvard’s Berkman Center, 4 Sept 2009) - Steve Schultze is a busy fellow. He is a fellow at the Berkman Center for Internet and Society. He recently joined the Princeton Center for Information Technology Policy as Associate Director. He also is one of the developers behind RECAP – an ambitious and provocative project that seeks to bring publicly available digital court records out from behind a costly paywall. [Interesting 22 minute podcast, delving into the technology and legal issues of PACER’s semi-controversial RECAP pug-in. Original story in MIRNL 12.12 here; related working paper by Schultze here.] http://blogs.law.harvard.edu/mediaberkman/2009/09/04/radio-berkman-129-i-bought-the-law/

LAWYER2LAWYER: E-MAIL AND THE 4TH AMENDMENT (Robert Ambrogi’s LawSites, 5 Nov 2009) - Does the Fourth Amendment’s protection against unreasonable searches and seizures extend to e-mail and data stored in “the cloud”? Surprisingly, the question remains unsettled in the courts. On this week’s legal-affairs podcast Lawyer2Lawyer, we discuss the extent to which e-mail and other online data are protected in both the criminal and civil contexts. Joining us are two experts on the topic: Orin S. Kerr, professor of criminal law at the George Washington University Law School and author of a number of law review articles on the application of the Fourth Amendment to Internet and computer data. Jason Paroff, director of computer forensics operations with the ESI Consulting practice at Kroll Ontrack. http://www.legaline.com/2009/11/lawyer2lawyer-e-mail-and-4th-amendment.html

**** RESOURCES ****
RECORD AND POST WEBCAM INTERVIEWS Wetoku, a Korean startup, has launched the public beta phase of its offering, so you and I can use it. Actually, you and I can use it together, that’s the point: Wetoku lets you record a webcam conversation and post the resulting video, with the two webcam images side by side, on your blog (it may only work with WordPress, at least for now). http://archive.constantcontact.com/fs092/1102594616158/archive/1102654849540.html

- and -

SOCIAL SEARCH (CeBe, 2 Nov 2009) - Aardvark is an experiment in social search: instead of asking a system to search through Web pages or documents, you ask the community, and an automated broker routes the search to people whose profile suggests that they may have an answer. The novelty of Aardvark is that you interact with it via instant messaging. So it pops up like a chatty friend (but you can define the frequency) and tells you, “Jane in Sacramento is asking: ...” and you reply in IM. You can pass, refer the question to someone else, etc. One interesting social aspect is whether people will give honest answers, or admit it when they don’t know. If you get ten replies, you can sort the wheat from the chaff, but if you receive just one, how do you know that you can trust it? Another question is whether we really need one more stream of interruptions... http://archive.constantcontact.com/fs092/1102594616158/archive/1102654849540.html

SHEPARDIZE? THERE’S AN APP FOR THAT (Robert Ambrogi’s LawSites, 5 Nov 2009) - It’s true. LexisNexis today announced the release of its application for the iPhone. It is called “Get Cases and Shepardize” and it lets you, well, get cases and Shepardize them simply by entering a citation. The good news is that the app is free to download from Apple’s iTunes store. The bad news is that you will need a LexisNexis subscription to use the app. http://www.legaline.com/2009/11/shepardize-theres-app-for-that.html

**** FUN ****
FAKE AP STYLEBOOK STEERS YOU COMPLETELY WRONG — WITH STYLE (Wired, 22 Oct 2009) - Like many proper news organizations, we at Wired.com use the venerable Associated Press Stylebook as an arbiter to determine whether we write “one” or “1″ or whether it’s “Calif.” or “CA.” But the trouble with venerable is that it gets old and boring. So we were delighted to learn of a disruptive newcomer to the writing style game. And the best part is that it’s on Twitter. The Fake AP Stylebook (I can just see the AP lawyers falling out of their Aero chairs) tells us that we should “Precede basic statements of fact with ‘allegedly’ to avoid accusations of bias: ‘the allegedly wet water,’ ‘the allegedly poisonous poison’” — well, that rule tracks pretty good (or is it “well?”) with that other style guide. But I bet you didn’t know that, “If you start a sentence with an action, place the actor immediately after or you will anger Christian Bale.” Or that “‘f***head’ should only be capitalized at the start of sentence. When referring to a talk radio host it is hyphenated.” The guide is very current, too. For example, be sure that you “Refer to him as ‘President Obama’ when he first appears in an article, ‘Soul Brother Number 1’ in subsequent mentions.” Other important rules:
• “Use the quintuple vowel to transcribe the utterances of small children, ‘Daaaaaddy, I waaaant a Pooooony!’”
• “The plural of Blackberry is ‘Blackberries.’ The plural of Blackberry users is “Dingleberries.’”
• “If you do not have an interviewees’ full title, use their most defining physical trait (e.g. ‘Alan Hayes, fat guy, said…’)”
• “Avoid using the letter ‘G’ as it is unlucky.”
Actually, knowing when to use words or numerals to describe numbers is one of the most vexing rules in professional journalism writing. The AP Stylebook instructs good writers to spell out one through nine, and to use numerals from 10 on. But from now on we’re following this fantastic bit of advice: “The numbers one through ten should be spelled out while numbers greater than ten are products of the Illuminati and should be avoided.” http://www.wired.com/epicenter/2009/10/fake-ap-style-book/ Related: http://www.abajournal.com/weekly/justice_scalia_delivers_lesson_on_word_usage

PSYCHIC SPIES, ACID GUINEA PIGS, NEW AGE SOLDIERS: THE TRUE MEN WHO STARE AT GOATS (DangerRoom, 6 Nov 2009) - “More of this is true than you would believe,” we’re told, just a few minutes into the movie version of The Men Who Stare At Goats, which opens today. But how many of the film’s outlandish military research projects really happened? Turns out there’s plenty of material in the movie which sticks quite close to the truth — though reality is a bit more complicated. (Warning: minor spoilers ahead.) http://www.wired.com/dangerroom/2009/11/psychic-spies-acid-guinea-pigs-new-age-gis-the-true-men-who-stare-at-goats/

**** LOOKING BACK ****
BORDERS TRIES ON-DEMAND PRINTING (WSJ, 1 June 1999) - In a deal aimed to deflate Web-based competitors Amazon.com and BarnesandNoble.com, Borders Group is planning to offer on-demand printing of out-of-print or obscure titles that it otherwise would not carry. The deal includes an investment in Atlanta startup Sprout Inc., and eventually will enable Borders stores to print high-quality paperbacks in the store in about 15 minutes. “Making a book will be no more difficult than making a latte at Starbucks,” says Sprout co-founder Henry Topping. When a customer wants a book that’s not in stock, Borders employees will be able to check Sprout’s database of titles licensed from publishers. If the title is available, they can download a digital file of the book from Sprout’s central server, and use in-store equipment to print and bind the book. Print-on-demand “is another way for a Borders or Barnes & Noble to take advantage of retail-store assets rather than let Amazon.com eviscerate them,” says a Forrester Research analyst. (Wall Street Journal 1 Jun 99) http:wsj.com/ http://scout.wisc.edu/Projects/PastProjects/net-news/99-06/99-06-01/0007.html

**** NOTES ****
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC. Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note,
8. Steptoe & Johnson’s E-Commerce Law Week,
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, October 17, 2009

MIRLN --- 27 September – 17 October 2009 (v12.14)

• PCI More of a ‘Check-Box’ than Security for Most Retailers
• DHS Privacy Report: Laptop Searches at Airports Infrequent
• The Mortgage Machine Backfires
• Virtual Town not Like Company Town for Purposes of First Amendment Protection
• New Hires to Monitor Outbound E-Mail
• Hawaii Supreme Court Disputes Laser Gun Test in Speeding Case
• Court Order Served Over Twitter
• Amazon Settles Kindle Deletion Lawsuit for $150,000
• Child-Porn Arrests: `Shooting Fish in a Barrel’
• Soon, Bloggers Must Give Full Disclosure
• AT&T to Allow Expanded Internet Calling Services on Apple’s iPhone
• Post-Breach Fear of Identity Theft Satisfies Standing Requirements, but Fails to Support Negligence and Other Claims
o Autumn Brings Amendments to Data Breach Notification Laws
o Germany Broaches the Breach Question in the EU
• Companies Say No to Friending or Tweeting
• E-Discovery Issues with Digital Voicemail
• Sidekick Outage Casts Cloud over Microsoft
• FBI Uses Facial-Recognition Technology on DMV Photos
• Gov’t Unveils New Short URLS
o White House Confronts Barriers to Gov 2.0
• Web Content Posted Abroad not Simultaneously Published in America
• Libraries and Readers Wade into Digital Lending
• LAW.gov Proposes Open-Source Stash of all Primary US Legal Materials

NEWS | RESOURCES | BOOK REVIEW | DIFFERENT | LOOKING BACK | NOTES

**** NEWS ****
PCI MORE OF A ‘CHECK-BOX’ THAN SECURITY FOR MOST RETAILERS (Darkreading, 23 Sept 2009) - Nearly 80 percent of retailers and organizations that handle credit card transactions have been hit with a data breach, but more than 70 percent still don’t consider security strategic to their operations, according to a new report released today. This apparent incongruity has more to do with organizations accepting a certain level of risk with doing business on the Internet, says Brian Contos, chief security strategist at Imperva, which commissioned the 2009 PCI DSS Compliance Survey conducted by the Ponemon Institute. “Roughly 30 percent take [PCI security] seriously,” Contos says. “And the others see it as a check box.” But Contos says the 30 percent figure is actually promising: “It’s encouraging to see that many are saying this is not just about compliance, and, ‘I have to make this investment now, anyhow, so I’ll make the best of it.’ That’s reassuring.” The Ponemon study also found 55 percent of organizations focus only on protecting credit card data and don’t bother securing other sensitive customer data, such as Social Security numbers, driver’s license numbers, and bank account information. “We like to think wherever our information is, people are securing it, but that’s not necessarily the case,” Imperva’s Contos says. “Small companies with a limited budget and resources simply don’t generally secure credit card and other supporting information.” Only 28 percent of small businesses in the survey (501 to 1,000 employees) are PCI-compliant, according to the survey, while 70 percent of companies with 75,000 or more employees are. But even the PCI-compliant ones aren’t necessarily more secure if they only treat it as a check-box item to appease the auditors, Contos says. http://www.darkreading.com/security/attacks/showArticle.jhtml;?articleID=220100919&subSection=Attacks/breaches

DHS PRIVACY REPORT: LAPTOP SEARCHES AT AIRPORTS INFREQUENT (NetworkWorld, 25 Sept 2009) - The U.S. Department of Homeland Security’s annual privacy report card revealed more details on the agency’s controversial policy involving searches of electronic devices at U.S. borders. The 99-page report, which was released Thursday, also offered details on the agency’s efforts to address privacy risks in social media and the use of imaging technologies that produce whole-body scans at airport security checkpoints. The report is the first DHS privacy assessment released to Congress since the new administration took office. It covers the activities of the DHS Privacy Office between July 2008 and June 2009. Of the more than 144 million travelers that arrived at U.S. ports of entry between Oct. 1, 2008 and May 5, 2009, searches of electronic media were conducted on 1,947 of them, the DHS said. Of this number, 696 searches were performed on laptop computers, the DHS said. Even here, not all of the laptops received an “in-depth” search of the device, the report states. A search sometimes may have been as simple as turning on a device to ensure that it was what it purported to be. U.S. Customs and Border Protection agents conducted “in-depth” searches on 40 laptops, but the report did not describe what an in-depth search entailed. http://www.networkworld.com/news/2009/092509-dhs-privacy-report-laptop-searches.html DHS’s privacy report here: http://www.dhs.gov/xlibrary/assets/privacy/privacy_rpt_annual_2009.pdf

THE MORTGAGE MACHINE BACKFIRES (New York Times, 26 Sept 2009) – With the mortgage bust approaching Year Three, it is increasingly up to the nation’s courts to examine the dubious practices that guided the mania. A ruling that the Kansas Supreme Court issued last month has done precisely that, and it has significant implications for both the mortgage industry and troubled borrowers. The opinion spotlights a crucial but obscure cog in the nation’s lending machinery: a privately owned loan tracking service known as the Mortgage Electronic Registration System. This registry, created in 1997 to improve profits and efficiency among lenders, eliminates the need to record changes in property ownership in local land records. “MERS is basically an electronic phone book for mortgages,” said Kevin Byers, an expert on mortgage securities and a principal at Parkside Associates, a consulting firm in Atlanta. In January 2007, [a Court] found that Sovereign’s failure to register its interest with the county clerk barred it from asserting rights to the mortgage after the judgment had been entered. The court also said that even though MERS was named as mortgagee on the second loan, it didn’t have an interest in the underlying property. By letting the sale stand and by rejecting Sovereign’s argument, the lower court, in essence, rejected MERS’s business model. Although the Kansas court’s ruling applies only to cases in its jurisdiction, foreclosure experts said it could encourage judges elsewhere to question MERS’s standing in their cases. http://www.nytimes.com/2009/09/27/business/27gret.html

VIRTUAL TOWN NOT LIKE COMPANY TOWN FOR PURPOSES OF FIRST AMENDMENT PROTECTION (BNA’s Internet Law News, 1 Oct 2009) – BNA’s Electronic Commerce & Law Report reports that the U.S. District Court for the Northern District of California has ruled that virtual world that includes homes, offices, and shops is simply an entertainment space, not a „company town‰ that would liken the operator to the government for purposes of the First Amendment. The court dismissed a First Amendment claim brought against Sony on finding that Sony was not acting as the government in its virtual world, and was thus not obligated to allow participants the free speech guaranteed by the Constitution. Case name is Estavillo v. Sony Computer Entertainment America.

NEW HIRES TO MONITOR OUTBOUND E-MAIL (Law.com, 30 Sept 2009) - The economy has employers extra jittery about company secrets getting out, so nervous that they’re hiring staff just to monitor outbound e-mails. That’s the conclusion of a recent study by Proofpoint, an Internet security and data loss prevention company, which found that 38 percent of large U.S. employers are monitoring outbound e-mail to prevent data leaks, up from 29 percent in 2008. And it’s not just inappropriate use of e-mail that has employers scrutinizing employees. Social networking sites like Twitter and Facebook are also compounding data leak fears, companies reported, with 8 percent saying they had fired an employee for misuse of social networks in the past 12 months. Another 17 percent had disciplined an employee for violating blog or message board policies, up from 11 percent the year before. No surprise, say some employment attorneys, noting the ease with which employees can swipe confidential information or taint a company’s image has Corporate America on edge. “It’s almost impossible to keep up with what might be walking out of the door or sliding out the door,” said Anthony Oncidi, chairman of the labor and employment department in the Los Angeles office of New York-based Proskauer Rose. http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202434171378

HAWAII SUPREME COURT DISPUTES LASER GUN TEST IN SPEEDING CASE (Honolulu Advertiser, 1 Oct 2009) - The Hawai’i Supreme Court has thrown out a man’s conviction for excessive speeding, a ruling that could put in jeopardy dozens of cases in which drivers have been pulled over by police officers armed with a laser gun. In a ruling released yesterday involving a man accused of exceeding the speed limit by more than 30 mph, the court wrote that prosecutors could not show that the way Honolulu police tested the laser gun used to nab drivers conformed with standards of the device’s manufacturer. HPD does conduct tests on the device, but the court said that without proof that the speed guns were functioning properly, police had no way of proving that the laser was accurately recording speeds of vehicles. At trial, HPD motorcycle Officer Jeremy Franks testified that he was certified to use the laser gun and that he tested the equipment before going on duty on the day of the incident. He testified that the tests were standard and done according to HPD procedures. But the defense argued that there was no evidence to show that the testing practice conformed with the manufacturer’s operating manual. Without this proof that the machine met established standards, the evidence should be thrown out, the defense argued. The justices agreed and said the laser gun reading should not have been admitted in court. http://www.honoluluadvertiser.com/article/20091001/NEWS01/910010353/Hawaii+Supreme+Court+disputes+laser+gun+test+in+speeding+case

COURT ORDER SERVED OVER TWITTER (BBC, 1 Oct 2009) - The High Court has given permission for an injunction to be served via social-networking site Twitter. The order is to be served against an unknown Twitter user who anonymously posts to the site using the same name as a right-wing political blogger. The order demands the anonymous Twitter user reveal their identity and stop posing as Donal Blaney, who blogs at a site called Blaney’s Blarney. The order says the Twitter user is breaching the copyright of Mr Blaney. He told BBC News that the content being posted to Twitter in his name was “mildly objectionable”. Mr Blaney turned to Twitter to serve the injunction rather than go through the potentially lengthy process of contacting Twitter headquarters in California and asking it to deal with the matter. UK law states that an injunction does not have to be served in person and can be delivered by several different means including fax or e-mail. Danvers Baillieu, a solicitor specialising in technology, said it was possible for anyone to approach the court about any method of serving an injunction if the traditional methods are unavailable. “The rules already allow for electronic service of some documents, so that they can be sent by e-mail, and it should also be possible to use social networks,” he said. Mr Blaney decided to use Twitter after a recent case in Australia where Facebook was used to serve a court order. http://news.bbc.co.uk/2/hi/8285954.stm

AMAZON SETTLES KINDLE DELETION LAWSUIT FOR $150,000 (Information Week, 2 Oct 2009) - Amazon.com has agreed to pay $150,000 to the student who sued the company for deleting his digital copy of George Orwell’s 1984 from his Kindle e-book reading device. In June, Amazon received a demand to remove unauthorized copies of George Orwell’s 1984 and Animal Farm from its Kindle Store. The company then refunded the $0.99 purchase price to customers who had bought the e-books for their Kindle devices and deleted copies of the e-book files for almost 2000 customers. The deletion prompted widespread criticism from Amazon customers, rights advocates, and bloggers, on whom the Orwellian nature of Amazon’s actions were not lost. Two days later, one of the customers stripped of his Kindle copy of 1984, Justin D. Gawronski, sued, in part because the deletion affected annotations about the book he had made using his Kindle. Amazon’s Kindle license agreement makes it clear that e-books bought for the Kindle are licensed rather than owned. The document also claims rights to alter the service. However, lawyers have argued that it’s not clear from the Kindle license agreement that Amazon has the right delete purchased content. As part of the settlement terms, Amazon has agreed not to delete Kindle e-books purchased and used in the US in the future, unless (a) the user consents; (b) the user seeks a refund or an electronic payment fails to clear; (c) a court orders the deletion; or (d) deletion is necessary to protect against malware. This does not apply, however, to software code, “transient content such as blogs,” or “content that the publisher intends to be updated and replaced with newer content as newer content becomes available.” In the case of Kindle newspaper and magazine content subscriptions, content is designed to be deleted, unless the user takes steps to save the content. http://www.informationweek.com/news/internet/ebusiness/showArticle.jhtml?articleID=220300915

CHILD-PORN ARRESTS: `SHOOTING FISH IN A BARREL’ (Washington Post, 5 Oct 2009) - When a single Florida county arrested 45 men and boys from all walks of life last June on charges of downloading child pornography, some people worried the place had become a haven for deviants. But top law enforcement officials and child welfare experts say the only thing unusual about Polk County is that its sheriff, Grady Judd, happens to pursue child-porn enthusiasts with more fervor and resources than most. Child porn has grown so pervasive on the Internet, they say, that police agencies all over the country, using the latest file-tracking technology, could easily spend every day finding and arresting offenders. “Today, it’s truly like shooting fish in a barrel,” said Judd, who has directed four child pornography roundups since 2006, resulting in at least 176 arrests in Polk County, a patchwork of orange groves, phosphate mines, modest towns and a half-million people between Tampa and Orlando. The biggest city is Lakeland, population 90,000. Mike Phillips, chief of the computer crimes section at the Florida Department of Law Enforcement, said Polk’s sheer number of child pornography arrests in recent years is almost unheard of nationally for a single agency. http://www.washingtonpost.com/wp-dyn/content/article/2009/10/05/AR2009100502221.html

SOON, BLOGGERS MUST GIVE FULL DISCLOSURE (New York Times, 6 Oct 2009) - For nearly three decades, the Federal Trade Commission’s rules regarding the relationships between advertisers and product reviewers and endorsers were deemed adequate. Then came the age of blogging and social media. On Monday, the F.T.C. said it would revise rules about endorsements and testimonials in advertising that had been in place since 1980. The new regulations are aimed at the rapidly shifting new-media world and how advertisers are using bloggers and social media sites like Facebook and Twitter to pitch their wares. The F.T.C. said that beginning on Dec. 1, bloggers who review products must disclose any connection with advertisers, including, in most cases, the receipt of free products and whether or not they were paid in any way by advertisers, as occurs frequently. The new rules also take aim at celebrities, who will now need to disclose any ties to companies, should they promote products on a talk show or on Twitter. A second major change, which was not aimed specifically at bloggers or social media, was to eliminate the ability of advertisers to gush about results that differ from what is typical — for instance, from a weight loss supplement. For bloggers who review products, this means that the days of an unimpeded flow of giveaways may be over. More broadly, the move suggests that the government is intent on bringing to bear on the Internet the same sorts of regulations that have governed other forms of media, like television or print. “It crushes the idea that the Internet is separate from the kinds of concerns that have been attached to previous media,” said Clay Shirky, a professor at New York University. Jonathan Zittrain, a professor at Harvard Law School and co-founder of the Berkman Center for Internet and Society, said, “the rules are looking ahead to a quite possible future when there is a market to buy ‘authentic’ public endorsements.” Some marketing groups fought the changes. “If a product is provided to bloggers, the F.T.C. will consider that, in most cases, to be a material connection even if the advertiser has no control over the content of the blogs,” said Linda Goldstein, a partner at Manatt Phelps & Phillips, a law firm that represents three marketing groups, the Electronic Retailing Association, the Promotion Marketing Association and the Word of Mouth Marketing Association. “In terms of the real world blogging community, that’s a seismic shift.” FTC guide here: [Interesting spin on this by Eric Goldman, in the context of 47 USC 230: http://blog.ericgoldman.org/archives/2009/10/do_the_ftcs_new.htm]

AT&T TO ALLOW EXPANDED INTERNET CALLING SERVICES ON APPLE’S IPHONE (SiliconValley.com, 6 Oct 2009) - AT&T said Tuesday that it will begin allowing iPhone owners to use Internet calling services such as Skype on its wireless network. The move represents a big reversal for the carrier, which had previously barred iPhones from using such services on its network. It comes as AT&T and other carriers are under scrutiny from the Federal Communications Commission for the control they exert over what types of devices and applications are allowed on their networks. As a result of the policy change, iPhone owners will soon be able to use programs such as Skype to make Voice over Internet Protocol (VoIP) phone calls using AT&T’s 3G data network. Such programs route calls largely over the Internet rather than through the traditional phone systems. Because they use a data connection rather than a voice connection, calls placed over such programs won’t eat into a customer’s limited number of voice minutes. Previously, iPhone owners could use such programs only to make calls over Wi-Fi hot spots, such as those in homes or at Internet cafes. Although AT&T barred the iPhone from making VoIP calls on its network, it did allow certain phones running the Windows Mobile operating system to make such calls, Balmoris said. In its August letter to the FCC, AT&T said it was worried that allowing iPhone users to place voice calls over its data network would decrease the amount of money it makes from those users. Allowing such services might mean AT&T and Apple would have to raise the price of the iPhone, the company warned. http://www.siliconvalley.com/news/ci_13499179

POST-BREACH FEAR OF IDENTITY THEFT SATISFIES STANDING REQUIREMENTS, BUT FAILS TO SUPPORT NEGLIGENCE AND OTHER CLAIMS (Steptoe & Johnson’s E-Commerce Law Week, 8 Oct 2009) - A federal court in Connecticut has ruled in McLoughlin v. People’s United Bank, Inc., that fear of identity theft following a data breach qualifies as injury-in-fact for Article III standing, but that such fear alone cannot support claims of unfair trade practices, negligence, or breach of fiduciary duty. Courts have split over whether fear of identity theft alone satisfies standing requirements. But courts have been fairly consistent in holding that fear of future harm alone is insufficient to establish damages and therefore to state a tort claim or any other sort of claim commonly raised by plaintiffs in data breach cases. http://www.steptoe.com/publications-6375.html Ruling here: http://www.steptoe.com/assets/attachments/3911.pdf

- and -

AUTUMN BRINGS AMENDMENTS TO DATA BREACH NOTIFICATION LAWS (Steptoe & Johnson’s E-Commerce Law Week, 8 Oct 2009) - Four states have amended their existing data breach notification laws. Montana and Texas have extended their notification requirement to the public sector. Maine has limited the amount of time businesses can delay notification after law enforcement gives a green light. And North Carolina now requires businesses to notify the state attorney general of breaches and to provide free security freezes to data breach victims. The amendments are all now in effect. Alabama, Kentucky, Mississippi, New Mexico, and South Dakota remain the only states without any breach notification requirement on the books. http://www.steptoe.com/publications-6375.html

- and -

GERMANY BROACHES THE BREACH QUESTION IN THE EU (Steptoe & Johnson’s E-Commerce Law Week, 15 Oct 2009) - With amendments to the German Federal Data Protection Law (Bundesdatenschutzgesetz) that took effect last month, Germany has become an early adopter of data breach notification obligations in the European Union. Data breach notification laws are widespread in the United States (now in force in 45 states, plus the District of Columbia, Puerto Rico, and the U.S. Virgin Islands ), but the EU has lagged in this area of regulation. That will almost certainly change, because proposed revisions to the EU electronic communications framework are expected to require all EU member states to introduce data breach notification legislation. However, those revisions stalled this summer due to conflicting views of the European Parliament and Council over other aspects of an overall electronic communications reform package, and it is likely to be at least a year before EU-wide data breach obligations take effect. In the meantime, Germany has taken the lead (although EU neighbor Norway has had such legislation on the books for some time). One upshot of these developments is that companies that suffer a breach involving the data of U.S. as well as EU residents will face an even broader patchwork of differing notification obligations. http://www.steptoe.com/publications-6391.html

COMPANIES SAY NO TO FRIENDING OR TWEETING (Nat’l Law Journal, 8 Oct 2009) - Lawyers are calling it social networking burnout. Back-to-back studies, the most recent issued Tuesday, show a big chunk of corporate America is banning communication wonders like Twitter and Facebook from the workplace. According to the latest survey of more than 1,400 U.S. companies, more than half (54 percent) said they prohibit employees from visiting sites such as Twitter, Facebook and MySpace while on the clock. The survey, by Robert Half Technology, a provider of information technology staffing services, was based on telephone interviews with U.S. companies of 100 or more employees. Another recent survey delivered even graver news for the social media world. According to an August survey by ScanSafe, a Web security provider, 76 percent of companies are now choosing to block employees’ use of social networking -- up 20 percent from February -- which is now a more popular category of sites to block than those involving shopping, weapons, sports or alcohol. Law firms have also joined in the trend. Indianapolis-based Barnes & Thornburg has blocked all access to Facebook. Twitter is still available, however. Gunster Yoakley & Stewart of West Palm Beach, Fla., blocks Facebook and Twitter for all its support staff, including secretaries and legal assistants, but lets lawyers use the social media tools. London’s Allen & Overy tried to ban Facebook in 2007, but then lifted the ban after associate backlash. http://www.law.com/jsp/article.jsp?id=1202434373430&rss=newswire

E-DISCOVERY ISSUES WITH DIGITAL VOICEMAIL (Law.com, 9 Oct 2009) - Modern companies are presented with many options for generating, receiving, storing, retrieving and disposing of electronic business communications. Perhaps nowhere is the progression of technology more evident than in the context of voicemail. Where voicemail messages were once stored on analog tapes, many organizations now utilize digital technology, and some opt for “unified” technology in which a company’s telephone and computer systems are integrated. Not surprisingly, such advances raise a number of e-discovery issues. Businesses considering implementation of new voicemail technology should evaluate the effect, if any, that implementation will have on the company’s obligations to preserve, search for and disclose relevant voicemail messages. The purpose of this article is to provide an overview of various digital voicemail arrangements, from very basic to fully unified, and to identify and discuss related e-discovery issues and practical considerations. http://www.law.com/jsp/article.jsp?id=1202434402099&rss=newswire&hbxlogin=1 [Editor: Good, useful survey of technology and legal issues.]

SIDEKICK OUTAGE CASTS CLOUD OVER MICROSOFT (CNET, 10 Oct 2009) - The massive data failure at Microsoft’s Danger subsidiary threatens to put a dark cloud over the company’s broader “software plus services” strategy. A key tenet of that approach is that businesses and consumers can trust Microsoft to reliably store valuable data on their servers. A week ago, though, Microsoft’s Danger unit experienced a huge outage that left many T-Mobile Sidekick users without access to their calendar, address book, and other key data. That’s because the Sidekick keeps nearly all its data in the cloud as opposed to keeping the primary copy on the devices themselves. Things got even worse on Saturday, as Microsoft said in a statement that data not recovered thus far may be permanently lost. It’s not immediately clear how many people lost their data. The outage earlier in the week affected a broad swath of Sidekick users, though many had data return during the week. While outages in the cloud computing world are common (one need only look at recent issues with Twitter or Gmail), data losses are another story. And this one stands as one of the more stunning ones in recent memory. The Danger outage comes just a month before Microsoft is expected to launch its operating system in the cloud--Windows Azure. That announcement is expected at November’s Professional Developer Conference. One of the characteristics of Azure is that programs written for it can be run only via Microsoft’s data centers and not on a company’s own servers. http://news.cnet.com/8301-13860_3-10372525-56.html [Editor: Now Microsoft says it’s going to be able to recover most lost sidekick data. This doesn’t change the fundamental point.]

FBI USES FACIAL-RECOGNITION TECHNOLOGY ON DMV PHOTOS (USA Today, 13 Oct 2009) - In its search for fugitives, the FBI has begun using facial-recognition technology on millions of motorists, comparing driver’s license photos with pictures of convicts in a high-tech analysis of chin widths and nose sizes. The project in North Carolina has already helped nab at least one suspect. Agents are eager to look for more criminals and possibly to expand the effort nationwide. But privacy advocates worry that the method allows authorities to track people who have done nothing wrong. “Everybody’s participating, essentially, in a virtual lineup by getting a driver’s license,” said Christopher Calabrese, an attorney who focuses on privacy issues at the American Civil Liberties Union. Earlier this year, investigators learned that a double-homicide suspect named Rodolfo Corrales had moved to North Carolina. The FBI took a 1991 booking photo from California and compared it with 30 million photos stored by the motor vehicle agency in Raleigh. In seconds, the search returned dozens of drivers who resembled Corrales, and an FBI analyst reviewed a gallery of images before zeroing in on a man who called himself Jose Solis. A week later, after corroborating Corrales’ identity, agents arrested him in High Point, southwest of Greensboro, where they believe he had built a new life under the assumed name. Corrales is scheduled for a preliminary hearing in Los Angeles later this month. “Running facial recognition is not very labor-intensive at all,” analyst Michael Garcia said. “If I can probe a hundred fugitives and get one or two, that’s a home run.” Calabrese said Americans should be concerned about how their driver’s licenses are being used. Licenses “started as a permission to drive,” he said. “Now you need them to open a bank account. You need them to be identified everywhere. And suddenly they’re becoming the de facto law enforcement database.” State and federal laws allow driver’s license agencies to release records for law enforcement, and local agencies have access to North Carolina’s database, too. But the FBI is not authorized to collect and store the photos. That means the facial-recognition analysis must be done at the North Carolina Division of Motor Vehicles. http://www.usatoday.com/tech/news/2009-10-13-fbi-dmv-facial-recognition_N.htm?csp=34

GOV’T UNVEILS NEW SHORT URLS (NationalJournal.com, 13 Oct 2009) - The General Services Administration on Tuesday announced a new application that allows government employees to shorten their Web addresses. Go.USA.gov lets officials create short .gov URLs out of any .gov, .mil, or .si.edu URLs. As of 5:30 p.m., Go.USA.gov has shortened 249 URLs that have been clicked 14,299 times. In related Web news, the White House unveiled a new Spanish site and Twitter feed. http://techdailydose.nationaljournal.com/2009/10/govt-unveils-new-short-urls.php

- and -

WHITE HOUSE CONFRONTS BARRIERS TO GOV 2.0 (Information Week, 14 Oct 2009) - Regulations and technical limitations pose challenges in the federal government’s move to “Government 2.0,” the trend of Web-enabling government data and processes, Andrew McLaughlin, deputy CTO for Internet policy, said in a speech today in Washington, D.C. Several issues come into play as the government increasingly uses popular Web sites such as YouTube, Facebook and Flickr to share information and interact with the public. Advertising on commercial sites is one of them. The U.S. government doesn’t run ads on Web sites because it doesn’t want to be seen as endorsing commercial products, but sites like Flickr and YouTube want to run ads on sites the government uses to host photos and videos. As of now, some sites offer ad-free pages as a public service, but it’s unclear how long they will continue to do so. “Do they offer their sites for free to the government forever?” McLaughlin asked rhetorically. “That’s not a good business model.” The terms-of-use policies of some sites present other concerns for the federal government. Many sites use language that binds their use to the laws of certain states, but the federal government isn’t bound by any one state law, McLaughlin noted. Often such language has to be tweaked for federal use. A third challenge is Section 508, the regulation that requires any technology used by the government to be accessible by the disabled. New technologies often make compliance with Section 508 difficult, McLaughlin said. For example, if a Web site is using Ajax and automatically adds new information to a page, it’s difficult for page readers for the blind or Braille readers to interpret and convey that information. There’s a similar problem with archiving. The government is required to save much information as a matter of public record, but it doesn’t have a good way of digitally archiving things like Facebook comments. For now, the costly work-around is to manually print and store paper copies. In addition, the White House continues to work on a new policy around its use of Web cookies, though it’s unclear when that will come out. McLaughlin noted the government is still assessing the best way to deal with public concerns about what it will do with the Web usage data that cookies collect. http://www.informationweek.com/news/government/info-management/showArticle.jhtml?articleID=220600838&cid=RSSfeed_IWK_News

WEB CONTENT POSTED ABROAD NOT SIMULTANEOUSLY PUBLISHED IN AMERICA (BNA’s Internet Law News, 15 Oct 2009) – BNA’s Electronic Commerce & Law Report reports that the U.S. District Court for the District of Delaware has ruled that posting content to a foreign website, although instantly accessible in the United States, does not amount to simultaneous publication in the United States such that registration is required to pursue an infringement action under the federal Copyright Act. In a case of first impression, the court ruled that the mere act of posting content to the internet does not mean that the content is simultaneously published in every country where it is accessible. Case name is Moberg v. 33T LLC.

LIBRARIES AND READERS WADE INTO DIGITAL LENDING (New York Times, 15 Oct 2009) - Kate Lambert recalls using her library card just once or twice throughout her childhood. Now, she uses it several times a month. The lure? Electronic books she can download to her laptop. Beginning earlier this year, Ms. Lambert, a 19-year-old community college student in New Port Richey, Fla., borrowed volumes in the “Hitchhiker’s Guide to the Galaxy” series, “The Lovely Bones” by Alice Sebold and a vampire novel by Laurell K. Hamilton, without ever visiting an actual branch. Eager to attract digitally savvy patrons and capitalize on the growing popularity of electronic readers, public libraries across the country are expanding collections of books that reside on servers rather than shelves. The idea is to capture borrowers who might not otherwise use the library, as well as to give existing customers the opportunity to try new formats. About 5,400 public libraries now offer e-books, as well as digitally downloadable audio books. The collections are still tiny compared with print troves. The New York Public Library, for example, has about 18,300 e-book titles, compared with 860,500 in circulating print titles, and purchases of digital books represent less than 1 percent of the library’s overall acquisition budget. Most digital books in libraries are treated like printed ones: only one borrower can check out an e-book at a time, and for popular titles, patrons must wait in line just as they do for physical books. After two to three weeks, the e-book automatically expires from a reader’s account. Simon & Schuster, whose authors include Stephen King and Bob Woodward, has also refrained from distributing its e-books to public libraries. “We have not found a business model that works for us and our authors,” said Adam Rothberg, a spokesman. http://www.nytimes.com/2009/10/15/books/15libraries.html?scp=1&sq=kate%20lambert&st=cse

LAW.GOV PROPOSES OPEN-SOURCE STASH OF ALL PRIMARY US LEGAL MATERIALS (ABA Journal, 15 Oct 2009) - An ambitious project to create an open-source authenticated repository of all primary legal materials in the United States is being proposed by Law.Gov. Detailed by Law.Gov, the project is presently in a planning stage. A growing group of individuals and organizations including a number of well-known law schools and law professors expect to meet to discuss how it might be pursued and potentially develop a proposal for doing so. “By primary legal materials,” Law.Gov explains, “we mean all materials that have the force of law and are part of the law-making process, including: briefs and opinions from the judiciary; reports, hearings, and laws from the legislative branch; and regulations, audits, grants, and other materials from the executive branch. Creating the system from open source software building blocks will allow states and municipalities to make their materials available as well.” http://www.abajournal.com/mobile/law.gov_mulls_open_source_repository_for_all_primary_us_legal_materials

**** RESOURCES ****
PRIVACY IN ELECTRONIC COMMUNICATIONS: THE REGULATION OF VOIP IN THE EU AND THE UNITED STATES (SSRN Paper, 1 Sept 2009; by Rebecca Wong and Daniel Garrie) - The growth of internet telephony or Voice over Internet Protocol (VoIP) services has led to questions by policymakers and legislators over the regulation of VoIP. In this article, the authors consider the extent to which VoIP services are protected from an EU/US perspective and the concerns arising from the current legislative framework, mainly from privacy perspective. The second part considers VoIP services in general. The third part examines the European framework and in particular, the current categorisation of VoIP services, before considering the privacy perspective, taking into account the Directive on Privacy and Electronic Communications 2002/58 and the general Data Protection Directive 95/46. The fourth part will consider the US framework in protecting the privacy of communications, asserting that the federal courts and legislatures should act to explicitly protect VoIP oral internet communications. The final part will conclude by discussing the principal areas that still need to be addressed. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1466153

**** BOOK REVIEW ****
BOOK REVIEW: ‘7 STEPS FOR LEGAL HOLDS’ (Law.com, 14 Oct 2009) - I have not applied a legal hold in a corporate or large law firm setting, but John J. Isaza and John J. Jablonski told me how to go about it -- and why -- in “7 Steps for Legal Holds of ESI and Other Documents.” The book explains how to implement a legal hold in seven easy steps and provides the legal and business drivers behind the holds that can be used to create more efficient business processes for an organization of any size. When I first picked up the book, I thought: “What’s the big deal?” Isaza and Jablonski made it clear. Federal and state courts are focusing on the legal duty to preserve potential evidence in litigation or government investigations, especially evidence stored in electronic form. Increasingly, cases are settling during the discovery phase because of the conspicuous absence or abundant presence of relevant electronic evidence. If evidence is absent, there is the chance your organization may face costly sanctions; if evidence is abundant, your organization may face a costly production that will require an expensive preproduction review of documents for privilege. Isaza and Jablonski are honest and cut to the chase in plain English. They readily admit that the legal hold, although a relatively new legal term, incorporates a legal duty to preserve evidence, which is not new. In fact, the legal hold reflects a time-honored public policy that is embedded into law: it is wrong to destroy evidence. They also bring the legal hold down to earth and instantiate it with fundamental concepts that operate on our daily lives, e.g., when implementing a legal hold, “timing is everything.” Although the book is a monograph, it is bound in a tabbed format that makes for an easy reference book to review material at any of the seven steps to the legal hold. It includes appendices loaded with examples of how misunderstandings of ESI lead to large spoliation sanctions, sample legal hold notices, policies and procedures. One index combines both case names and keywords. Isaza and Jablonski don’t have the last word on legal holds, but they certainly have the right ones, in seven, digestible steps, to get your organization started in fashioning a legal hold policy and procedure to respond to an event that triggers the duty to preserve evidence. In the end, you will want to get out there and put a legal hold on something. http://www.law.com/jsp/article.jsp?id=1202434570370&rss=newswire

**** DIFFERENT ****
INTERNETBAR.org PEACETONES WEBSITE - PeaceTones is an InternetBar project created to build peace, and create opportunities for all members of the global community. The selected project participants are artists from developing economies, remote areas, and conflict zones. After selection InternetBar works with students and participants to digitalize their art. This can mean photographing paintings, recording music, capturing local nature sounds, folk tales, etc. Once digitalized the art is then organized into the form of albums which are then sold online. The proceeds are sent back to the participants in their respective countries in intervals, creating revenues for project participants and their communities. During this process participants learn about technology, the internet, rights, and their intellectual property rights in a global market. If you would like more information, the “PeaceTones Overview” link will take you to a page with an in detail explanation of the entire process. http://www.peacetones.org/index.html [Editor: search iTunes for “Peacetones”; the music is rather wonderful.]

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
RINGING IN THE NEW YEAR WITH GREENWICH NET TIME -- January 1 marks the debut of a new time standard that supporters hope will become the online equivalent of the venerable Greenwich Mean Time. Greenwich Net Time will offer ISPs and Internet users a new way to time-stamp electronic documents. Companies involved in the deployment of GNT clocks include the London Internet Exchange (LINX), a nonprofit group of ISPs that share data centers in order to speed Internet traffic within the U.K.; Datum, which is supplying three atomic clocks that will deliver GNT from Greenwich’s zero meridian line; and Enron Communications, an energy and communications firm. LINX members who will support GNT include AT&T, BT Internet Services, France Telecom and Level 3. (Computer Reseller News 29 Dec 99) http://scout.wisc.edu/Projects/PastProjects/net-news/99-12/99-12-30/0001.html

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC. Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note,
8. Steptoe & Johnson’s E-Commerce Law Week,
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.