Saturday, August 06, 2005

MIRLN -- Misc. IT Related Legal News [16 July – 6 August 2005; v8.09]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

HARRY POTTER AND THE RIGHT TO READ (Toronto Star, 18 July 2005) -- Along with millions worldwide who scooped up the latest Harry Potter tome over the weekend, the 41 schools that make up Manitoba’s Frontier School Division no doubt purchased several copies for their students. The link that connects Harry Potter and the school division that serves northern Manitoba extends beyond a mutual interest in children’s books. Both were at the centre of situations last week that illustrate how good news culture and heritage stories can easily be transformed when copyright law goes awry. The Harry Potter incident is widely known since it generated global attention. A grocery store in Coquitlam, British Columbia inadvertently sold 14 copies of the new Harry Potter book prior to its official sale date of July 16, 2005. Reports indicate that Raincoast Books, the Canadian publisher, mistakenly failed to include a notice on the shipping box that the books were not to be sold in advance. When Raincoast was informed of the sales, it joined with author J.K. Rowling and Bloomsbury Publishing, the British publisher, to seek a court order from the British Columbia Supreme Court to keep the book and its contents under wraps. Had Raincoast limited the requested order to stopping Canadian booksellers from selling the book, the issue would have attracted little attention. Rather than adopting that approach, however, Raincoast also directly targeted the 14 purchasers who had lawfully purchased copies of the book. The order compelled anyone with a copy of the book to return it to the publisher along with any notes and other descriptions of its contents. Moreover, it prohibited Canadians from reading or discussing any aspect of the book. [Read on.] http://www.michaelgeist.ca/index.php?option=content&task=view&id=896

-- and --

ONLINE PIRATES POUNCE ON NEW HARRY POTTER BOOK (CNET, 20 July 2005) -- The sixth book in the Harry Potter series, the fastest-selling book of all time, has become among the quickest to fall prey to Internet piracy, with illicit copies available online within hours of its release. Tech-savvy fans of the boy wizard teamed up to scan the entire 607 page book into digital form, with unauthorized e-book copies appearing online less than 12 hours after "Harry Potter and the Half-Blood Prince" went on sale on Saturday. Copies of the audio version of the book were also widespread on file-trading networks such as BitTorrent. http://news.com.com/2100-1030_3-5796511.html

COST OF US CYBER ATTACKS PLUMMETS (The Register, 18 July 2005) -- The cost of individual cyber attacks fell dramatically in the US last year but unauthorised access and the theft of proprietary information remain top security concerns. The 10th annual Computer Crime and Security Survey, put together by the Computer Security Institute (CSI) in conjunction with information security experts at the FBI, shows financial losses resulting from security breaches down for the fourth successive year. The cost of breaches averaged $204,000 per respondent - down 61 per cent from last year's average loss of $526,000. Virus attacks continue as the source of the greatest financial pain, making up 32 per cent of the overall losses reported. But unauthorized access showed a dramatic increase and replaced denial of service as the second most significant contributor to cybercrime losses. Unauthorised access was fingered for a quarter (24 per cent) of losses reported in the CSI/FBI Computer Crime and Security Survey 2005. Meanwhile losses from theft of proprietary information doubled last year, based on the survey of 700 computer security practitioners in various US corporations, universities and government agencies. The study found fears about negative publicity are preventing organisation from reporting cybercrime incidents to the police, a perennial problem the CSI/FBI study reckons is only getting worse. Assuming that this isn't true of what respondents also told CSI's researchers (academics from the University of Maryland), the study presents a picture of reducing cyber crime losses that contrasts sharply with vendor-sponsored studies. [Survey at http://www.gocsi.com/forms/fbi/csi_fbi_survey.jhtml] http://www.theregister.com/2005/07/18/csi_fbi_security_survey/

HAGUE CHOICE OF COURT CONVENTION FINALLY ADOPTED (Steptoe & Johnson’s E-Commerce Law Week, 16 July 2005) -- The long-awaited – and often-doubted – conclusion of negotiations for a multilateral treaty to improve the enforceability of civil judgments has finally arrived after 13 years of negotiations. The Hague Conference on Private International Law reached agreement on June 30 on the Convention on Choice of Courts Agreements ("Convention"). However, despite lobbying efforts by Internet service providers and other technology companies to place so-called clickwrap agreements and other non-negotiated agreements outside the scope of the Convention, the final draft of the 12-page document does not explicitly exclude such agreements. This raises concerns that many companies – including, for example, those that link to a website in a foreign jurisdiction – may unknowingly risk being hauled into a court halfway around the world. Of course, the Convention must still be ratified by any country to which it would apply, and the agreed text includes an option allowing countries to opt out of the Convention on specific matters if they have a “strong interest” in doing so. Therefore, the fight against having the Convention apply to non-negotiated agreements could spread to individual countries around the globe – raising the risk that the Convention may not actually avoid the world-wide jurisdictional muddle that it is designed to avoid. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=10121&siteId=547 [Convention at http://www.steptoe.com/publications/362b.pdf]

CALLING JACKIE CHILES (New York Times, 16 July 2005) -- Groklaw.net features an entry titled "The Stupidest Lawsuit Since the World Began," and it's hard to argue. A French transit company, Transports Schiocchet Excursions, is suing 10 cleaning women in the Moselle region because they carpool to work rather than use the company's buses. The plaintiffs' lawyers charge the women with "unfair and parasitical competition" and want their cars seized. http://www.nytimes.com/2005/07/16/technology/16online.ready.html?ex=1279166400&en=f3ce10695112b660&ei=5090&partner=rssuserland&emc=rss

IN CANADA: CACHE A PAGE, GO TO JAIL? (CNET, 19 July 2005) -- A bill before Canada's Parliament could make it illegal for search engines to cache Web pages, critics say, opening the door to unwarranted lawsuits and potentially hindering public access to information. The legislation in question, Bill C-60, is designed to amend Canada's Copyright Act by implementing parts of the 1996 World Intellectual Property Organization treaty, the treaty that led to the Digital Millennium Copyright Act in the U.S. Set for debate and an initial vote in the House of Commons after Parliament's summer break, C-60 addresses things such as file-sharing, anticopying devices and the liability of Internet service providers and would tighten the Copyright Act in ways favorable to record labels and movie studios. But according to Howard Knopf, a copyright attorney at the Ottawa firm of Macera & Jarzyna, a brief passage in the bill could mean trouble for search engines and other companies that archive or cache Web content. "The way it reads, arguably what they're saying is that the very act of making a reproduction by way of caching is illegal," Knopf said. Michael Geist, a law professor at the University of Ottawa, where he holds the Canada Research Chair in Internet and E-Commerce Law, agreed. http://news.com.com/2100-1028_3-5793659.html

HACKERS GET INTO USC DATABASE (CNET, 19 July 2005) -- A University of Southern California database containing about 270,000 records of past applicants was hacked last month, officials said on Tuesday. The breach of the university's online application database exposed "dozens" of records, which included names and Social Security numbers, to unauthorized individuals, said Katharine Harrington, USC dean of admissions and financial aid. Harrington could not be more specific about the number of people whose personal data may have been viewed by the hacker or hackers, nor about what the motivation had been for the computer break-in. "There was not a sufficiently precise tracking capability," Harrington said, but added that the hackers had not been able to access multiple records at once. Records were also only able to be viewed at random, she said. USC learned of the breach June 20 when it was tipped off by a journalist. http://news.com.com/2100-7349_3-5795373.html

UNIVERSITY R&D SPENDING IS UP (Inside Higher Ed, 21 July 2005) -- Colleges and universities spent $40.1 billion on research and development in the 2003 fiscal year, up 10.2 percent from the previous year and 100 percent from 1993. The data were released by the National Science Foundation, which regularly studies research spending in higher education. A majority of the research funds came from Washington. Federal research and development spending in 2003 was $24.7 billion, up 13 percent from the previous year. Other significant sources of research support include state and local governments, businesses and institutional funds. Industry support for R&D in higher education fell by 1 percent in 2003, to $2.16 billion. Other categories all reported increases. Nearly three-fourths of total research spending is for basic research, but applied research outpaced basic research slightly in the rate of increase, 11 percent to 10 percent. Within the sciences and engineering, the top area of support, by far, is the medical sciences. http://insidehighered.com/news/2005/07/21/nsf

LEGALLY DOWNLOADED MUSIC TRIPLES IN 2005 (AP, 21 July 2005) -- The number of digital music tracks legally downloaded from the Internet almost tripled in the first half of 2005 as the use of high-speed broadband connections surged around the world, the international recording industry said Thursday. The International Federation of Phonographic Industries said that 180 million single tracks were downloaded legally in the first six months of the year, compared to 57 million tracks in the first half of 2004 and 157 million for the whole of last year. The federation credited the increase to a 13 percent rise in the number of broadband lines installed around the world, along with an industry campaign to both prosecute and educate against illegal downloading. It said there was just a 3 percent increase in illegal file-sharing to 900 million in July, from 870 million at the start of the year. "We are now seeing real evidence that people are increasingly put off by illegal file-sharing and turning to legal ways of enjoying music online," said John Kennedy, the IFPI's chairman. "Whether it's the fear of getting caught breaking the law, or the realization that many networks could damage your home PC, attitudes are changing, and that is good news for the whole music industry." The IFPI, which has filed hundreds of lawsuits worldwide accusing people of putting copyright songs onto Internet file-sharing networks and offering them to millions without permission, said that the legitimate market is responding to the increased demand. http://news.yahoo.com/news?tmpl=story&cid=528&e=3&u=/ap/20050722/ap_on_hi_te/britain_music_piracy

-- and --

ONLINE FILE SHARERS 'BUY MORE MUSIC' (The Guardian, 27 July 2005) -- Computer-literate music fans who illegally share tracks over the internet also spend four and a half times as much on digital music as those who do not, according to research published today. The survey confirms what many music fans have informally insisted for some time: that downloading tracks illegally has also led them to become more enthusiastic buyers of singles and albums online. Unlikely to be music to the ears of record companies, who have previously argued the opposite, the results will raise a question mark over the companies' recent drive to pursue individual file sharers through the courts. http://www.guardian.co.uk/online/news/0,12597,1536888,00.html and http://news.bbc.co.uk/2/hi/technology/4718249.stm

POLICE: ORKUT USED AS BRAZILIAN DRUG NETWORK (CNET, 21 July 2005) -- Brazilian police arrested 10 people on Thursday accused of selling drugs using Google's international social networking site Orkut, which is hugely popular in the Latin American country. "We discovered the drug ring first via authorized phone tapping, and later the investigation included monitoring of their activities on the Internet," said a duty officer at the Drugs Enforcement Service in the city of Niteroi, just across the bay from Rio de Janeiro. Orkut allows members to join and set up online communities to discuss everything from doughnuts to quantum physics and schedule events such as community meetings. Narcotics are also discussed, with some groups advocating their legalization. However, most popular Portuguese-language communities touching on the issue are anti-drug groups. Several million Brazilians have become devotees of Orkut since Web search leader Google launched the popular social-networking site in January 2004. They make up more than half of Orkut's 7 million plus members. http://news.com.com/2100-1030_3-5798781.html

CONGRESS: TSA BROKE PRIVACY LAWS (Wired, 22 July 2005) -- The Transportation Security Administration violated privacy protections by secretly collecting personal information on at least 250,000 people, congressional investigators said Friday. The Government Accountability Office sent a letter to Congress saying the collection violated the Privacy Act, which prohibits the government from compiling information on people without their knowledge. The information was collected as the agency tested a program, now called Secure Flight, to conduct computerized checks of airline passengers against terrorist watch lists. TSA had promised it would only use the limited information about passengers that it had obtained from airlines. Instead, the agency and its contractors compiled files on people using data from commercial brokers and then compared those files with the lists. The GAO reported that about 100 million records were collected. The 1974 Privacy Act requires the government to notify the public when it collects information about people. It must say who it's gathering information about, what kinds of information, why it's being collected and how the information is stored. And to protect people from having misinformation about them in their files, the government must also disclose how they can access and correct the data it has collected. Before it began testing Secure Flight, the TSA published notices in September and November saying that it would collect from airlines information about people who flew commercially in June 2004. Instead, the agency actually took 43,000 names of passengers and used about 200,000 variations of those names -- who turned out to be real people who may not have flown that month, the GAO said. A TSA contractor collected 100 million records on those names. Justin Oberman, the TSA official in charge of Secure Flight, said that was a highly instructive test. "When you cannot distinguish one John Smith from another, you're going to get records from John Smiths who aren't boarding flights on an order of magnitude we can't handle," Oberman said. He said the testing is designed to find out what kind of data airlines will need to get -- such as passengers' birthdates --so they can turn it over to the government to check against watch lists. http://www.wired.com/news/privacy/0,1848,68292,00.html

-- and --

BEHIND-THE-SCENES BATTLE ON TRACKING DATA MINING (New York Times, 24 July 2005) -- Bush administration officials are opposing an effort in Congress under the antiterrorism law known as the USA Patriot Act to force the government to disclose its use of data-mining techniques in tracking suspects in terrorism cases. As part of the vote in the House this week to extend major parts of the antiterrorism law permanently, lawmakers agreed to include a little-noticed provision that would require the Justice Department to report to Congress annually on government-wide efforts to develop and use data-mining technology to track intelligence patterns. But a set of talking points distributed among Republican lawmakers as the measure was being debated warned that the Justice Department was opposed to the amendment because it would add to the list of "countless reports" already required by Congress and would take time away from more critical law enforcement activities. The government's use of vast public and private databases to mine for leads has produced several damaging episodes for the Bush administration, most notably in connection with the Total Information Awareness system developed by the Pentagon for tracking terror suspects and the Capps program of the Department of Homeland Security for screening airline passengers. Both programs were ultimately scrapped after public outcries over possible threats to privacy and civil liberties, and some Republicans and Democrats in Congress say they want to keep closer tabs on such computer operations to guard against abuse. "We have wasted millions and millions of dollars on implementing database-mining activities which, when they became public, produced such an outrage they were canceled," Representative Howard L. Berman, a California Democrat who sponsored the amendment requiring a report to Congress, said this week during the House debate. "We do not want to tie the hands of our security agencies in gathering this information," Mr. Berman said. "We simply want to provide a logical mechanism to gather the information so that the American people can feel more comfortable that what is being done is protected." http://www.nytimes.com/2005/07/24/politics/24patriot.html?ex=1279857600&en=fcec9a4f677a46db&ei=5090&partner=rssuserland&emc=rss

NEW YORK JUDGES REFUSE TO SAY INTERNET OBSCENITY LAW IS UNCONSTITUTIONAL (Newsday, 25 July 2005) -- A special three-judge federal panel on Monday refused to find unconstitutional a law making it a crime to send obscenity over the Internet to children. The Communications Decency Act of 1996 had been challenged by Barbara Nitke, a photographer who specializes in pictures of sadomasochistic sexual behavior, and by the National Coalition for Sexual Freedom, a Baltimore-based advocacy organization. They contended in a December 2001 lawsuit brought in U.S. District Court in Manhattan that the law was so broad and vague in its scope that it violated the First Amendment, making it impossible for them to publish to the Internet because they cannot control the forum. A judge from the 2nd Circuit Court of Appeals and two district judges heard the facts of the case and issued a written decision saying the plaintiffs had provided insufficient evidence to prove the law was unconstitutional. The panel noted that evidence was offered to indicate there are at least 1.4 million Web sites that mention bondage, discipline and sadomasochism but that evidence was insufficient to decide how many sites might be considered obscene. The judges said the evidence also was insufficient for them to determine how much the standards for obscenity differ in communities across the United States. The court said it was necessary to know how much the standards vary to decide if those creating Web sites would be graded for obscenity unfairly when compared with those who market traditional pornography and can control how they distribute the material. http://www.newsday.com/news/local/wire/newyork/ny-bc-ny--sexsites-obscenit0725jul25,0,6680266.story

WIRELESS NETWORK HIJACKER FOUND GUILTY (Silicon.com, 22 July 2005) – A UK man has been fined £500 and sentenced to 12 months' conditional discharge for hijacking a wireless broadband connection. On Wednesday, a jury at Isleworth court in London found Gregory Straszkiewicz, 24, guilty of dishonestly obtaining an electronic communications service and possessing equipment for fraudulent use of a communications service. Straszkiewicz was prosecuted under sections 125 and 126 of the Communications Act 2003. Police sources said Straszkiewicz was caught standing outside a building in a residential area holding a wireless-enabled laptop. The Crown Prosecution Service confirmed that Straszkiewicz was 'piggybacking' the wireless network that householders were using. He was reported to have attempted this several times before police arrested him. [See similar story from the U.S. in MIRLN 8.08 at http://mirln.blogspot.com/]
http://management.silicon.com/government/0,39024677,39150672,00.htm

UK POLICE WANT NEW COMPUTER POWERS (Techworld, 26 July 2005) -- The UK Association of Chief Police Officers (ACPO) has called for new powers to allow police to tackle rogue websites, and make withholding encryption keys a criminal offence. The new proposals are buried inside a long and sometimes controversial list of powers the influential body would like the government to consider enacting through legislation in the light of the special demands posed by terrorist investigations. Most of these relate to conventional police powers, but one section of the official release suggests amending part 3 of the Regulation of Investigatory Powers Act (RIPA) with a specific offence of withholding a software encryption key. This is the first time encryption keys have been singled out by UK police in this way, though the problems associated with their use by criminals to secure documents has long been a subject of debate. http://www.techworld.com/security/news/index.cfm?NewsID=4106

ADVISING CLIENTS IN A POST-GROKSTER WORLD (BNA’s Internet Law News, 27 July 2005) - Fred Von Lohmann highlights the challenges facing lawyers as they seek to advise technology clients in the post-Grokster world. Von Lohmann argues that the court's concurring opinions leave innovators and lower courts with precious little guidance on issues such as contributory and vicarious copyright liability. http://www.law.com/jsp/article.jsp?id=1122023112436

-- and --

NEW FILE-SHARING TECHNIQUES ARE LIKELY TO TEST COURT DECISION (New York Times, 1 August 2005) – Briefly buoyed by their Supreme Court victory on file sharing, Hollywood and the recording industry are on the verge of confronting more technically sophisticated opponents. At a computer security conference in Las Vegas on Thursday, an Irish software designer described a new version of a peer-to-peer file-sharing system that he says will make it easier to share digital information anonymously and make detection by corporations and governments far more difficult. Others have described similar efforts to build a so-called darknet that aims to shield the identities of those sharing information. The issue is complicated by the fact that the small group of technologists designing the new systems say their goal is to create tools to circumvent censorship and political repression - not to abet copyright violation. The Irish programmer, Ian Clarke, is a 28-year-old free-speech advocate who five years ago introduced a software system called Freenet that was intended to make it impossible for governments and corporations to restrict the flow of any kind of digital information. The system initially used a secure approach to routing between users and employed encryption to protect the information from eavesdroppers who were not part of the network. Unlike today's open peer-to-peer networks, the new systems like Mr. Clarke's use software code to connect individuals who trust one another. He said he would begin distributing the new version of his program within a few months, making it possible for groups of users to establish secured networks - available only to them and those they choose to include - through which any kind of digital information can be exchanged. Though he says his aim is political - helping dissidents in countries where computer traffic is monitored by the government, for example - Mr. Clarke is open about his disdain for copyright laws, asserting that his technology would produce a world in which all information is freely shared. In June, Ross Anderson, a prominent computer-security researcher who was a pioneer in developing early peer-to-peer networks, published a technical paper detailing how it was possible to resist industry attempts to disable such networks. He also published a second paper trying to anticipate the market reaction to curbs on file sharing like the Grokster ruling. The paper, "The Economics of Censorship Resistance," predicts the emergence of closed networks like the new Freenet, as well as "fan clubs" focused on specific digital content, which would be more difficult for the industry to combat. Legal skirmishes over anonymous peer-to-peer networks have already taken place in both Europe and Asia. In Japan last year, Isamu Kaneko, the developer of a file-sharing program called WinNY, was arrested after two users of the program were charged with sharing copyrighted material through the system. The Kaneko case is pending. On a separate front, the recording industry has sued users of Blubster, a peer-to-peer network designed by Pablo Soto, a Spanish programmer, who built privacy features into his system. http://www.nytimes.com/2005/08/01/technology/01file.html?ex=1280548800&en=2ab1bf4745b327bc&ei=5090&partner=rssuserland&emc=rss

CISCO HITS BACK AT FLAW RESEARCHER (CNET, 27 July 2005) -- Cisco Systems has taken legal action to keep a researcher from further discussing a hack into its router software. The networking giant and Internet Security Systems jointly filed a request Wednesday for a temporary restraining order against Michael Lynn and the organizers of the Black Hat security conference. The motion came after Lynn showed in a presentation how attackers could take over Cisco routers--a problem that he said could bring the Internet to its knees. The filing in U.S. District Court for the Northern District of California asks the court to prevent Lynn and Black Hat from "further disclosing proprietary information belonging to Cisco and ISS," said John Noh, a Cisco spokesman. "It is our belief that the information that Lynn presented at Black Hat this morning is information that was illegally obtained and violated our intellectual property rights," Noh added. Lynn decompiled Cisco's software for his research and by doing so violated the company's rights, Noh said. http://news.com.com/2100-1002_3-5807551.html

-- and --

RESEARCHER, CISCO REACH AGREEMENT (SiliconValley.com, 29 July 2005) -- Cisco Systems reached an agreement Thursday with a defiant computer security researcher who said he would stop revealing the details of a serious flaw in Cisco's software that directs traffic around much of the Internet. Only a day before, Michael Lynn quit his job with an Internet security company in Atlanta to deliver a speech at the Black Hat conference in Las Vegas that revealed details of the Cisco flaw. Cisco sought a court injunction Thursday to silence Lynn and even hired temporary workers to rip information about the software flaw from handouts given to conference-goers. The dispute highlights a hot debate over when and how to disclose vulnerabilities uncovered by security researchers to the software and equipment used to run the world's computer systems. Lynn, who Wednesday resigned from Internet Security Systems, said he had to defy Cisco and his employer to get out information on vital security threats to equipment that helps run the Internet. http://www.siliconvalley.com/mld/siliconvalley/12255870.htm

-- but--

WHISTLE-BLOWER FACES FBI PROBE (Wired, 29 July 2005) -- The FBI is investigating a computer security researcher for criminal conduct after he revealed that critical routers supporting the internet and many networks have a serious software flaw that could allow someone to crash or take control of them. Mike Lynn, a former researcher at Internet Security Systems, or ISS, said he was tipped off late Thursday night that the FBI was investigating him for violating trade secrets belonging to his former employer. Lynn resigned from ISS Wednesday morning after his company and Cisco threatened to sue him if he spoke at the Black Hat security conference in Las Vegas about a serious vulnerability he found while reverse-engineering the operating system in Cisco routers. He said he conducted the reverse-engineering at the request of his company, which was concerned that Cisco wasn't being forthright about a recent fix it had made to its operating system. Lynn spoke anyway, discussing the flaw in Cisco IOS, the operating system that runs on Cisco routers, which are responsible for transferring data over much of the internet and private networks. Although Lynn demonstrated for the audience what hackers could do to a router if they exploited the flaw, he did not reveal technical details that would allow anyone to exploit the bug without doing the same research he did to discover it. Both companies knew in advance about Lynn's plan to talk and originally supported it. But at the last minute, the companies tried to halt the presentation or force Lynn to allow Cisco representatives to speak as well. http://www.wired.com/news/privacy/0,1848,68356,00.html

-- and --

HACKERS RACE TO EXPOSE CISCO ROUTER FLAW (CNET, 31 July 2005) -- Computer hackers worked through the weekend to expose a flaw that could allow an attacker to take control of the Cisco Systems routers that direct traffic across much of the Internet. Angered and inspired by Cisco's attempts to suppress news of the flaw earlier in the week, several computer security experts at the Defcon computer-security conference worked past midnight Saturday to discover and map out the vulnerability. Cisco's routers direct traffic across at least 60 percent of the Internet and the security hole has dominated a pair of conferences that draw thousands of security researchers, U.S. government employees and teenage troublemakers to Las Vegas each summer. The hackers said they had no intention of hijacking e-commerce payments, reading private e-mail, or launching any of the other malicious attacks that could be possible by exploiting the flaw. Rather, they said they wanted to illustrate the need for Cisco customers to update their software to defend against such possibilities. Many Cisco customers have postponed the difficult process because it could require them to unplug entirely from the Internet. http://news.com.com/2100-1002_3-5812611.html

STATE ANTI-SPAM LAW IS NOT PREEMPTED BY CAN-SPAM ACT (BNA’s Internet Law News, 28 July 2005) -- BNA's Electronic Commerce & Law Report reports that a federal court in Washington has ruled that a state anti-spam law creating a civil cause of action against those who send commercial e-mails containing false header information and/or misleading subject lines is not preempted by the federal CAN-SPAM Act. Although the CAN-SPAM Act generally preempts state regulation of commercial e-mail, the court acknowledges, the law expressly permits state regulation of false or misleading commercial e-mail practices. Case name is Gordon v. Impulse Marketing Group Inc. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b1d7n7y4

READING BETWEEN THE LINES OF USED BOOK SALES (New York Times, 28 July 2005) -- THE Internet is a bargain hunter's paradise. Ebay is an easy example, but there are many places for deals on used goods, including Amazon.com. While Amazon is best known for selling new products, an estimated 23 percent of its sales are from used goods, many of them secondhand books. Used bookstores have been around for centuries, but the Internet has allowed such markets to become larger and more efficient. And that has upset a number of publishers and authors. In 2002, the Authors Guild and the Association of American Publishers sent an open letter to Jeff Bezos, the chief executive of Amazon.com, which has a market for used books in addition to selling new copies. "If your aggressive promotion of used book sales becomes popular among Amazon's customers," the letter said, "this service will cut significantly into sales of new titles, directly harming authors and publishers." But does it? True, consumers probably save a few dollars while authors and publishers may lose some sales from a used book market. Yet the evidence suggests that the costs to publishers are not large, and also suggests that the overall gains from such secondhand markets outweigh any losses. Consider a recent paper, "Internet Exchanges for Used Books," by Anindya Ghose of New York University and Michael D. Smith and Rahul Telang of Carnegie-Mellon. (The text of the paper is available at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=584401.) The starting point for their analysis is the double-edged impact of a used book market on the market for new books. When used books are substituted for new ones, the seller faces competition from the secondhand market, reducing the price it can set for new books. But there's another effect: the presence of a market for used books makes consumers more willing to buy new books, because they can easily dispose of them later. http://www.nytimes.com/2005/07/28/technology/28scene.html?ex=1280203200&en=33765024cbf62d4c&ei=5090&partner=rssuserland&emc=rss

REALLY OPEN SOURCE (Inside Higher Ed, 29 July 2005) -- Few projects in academe have attracted the attention and praise in recent years of OpenCourseWare, a program in which the Massachusetts Institute of Technology is making all of its course materials available online — free — for anyone to use. In the four years since MIT launched the effort, use of the courseware has skyrocketed, and several other universities have created similar programs, assembling material from their own courses. With less fanfare than MIT, Rice University has also been promoting a model for free, shared information that could be used by faculty members and students anywhere in the world. But the Rice program — Connexions — is different in key respects. It is assembling material from professors (and high school teachers) from anywhere, it is offering free software tools in addition to course materials, and it is trying to reshape the way academe uses both peer review and publishing. The project also has hopes of becoming a major curricular tool at community colleges. http://www.insidehighered.com/news/2005/07/29/open

BUSH SIGNS LAW THAT CREATES MEDICAL ERROR DATABASES (Government Health IT, 29 July 2005) -- The Patient Safety and Quality Improvement Act of 2005 that President Bush signed today will require the establishment of a network of databases to hold data on medical errors that patient safety organizations and health care providers voluntarily report. Sen. Jim Jeffords (I-Vt.) first introduced a patient safety bill in 2000. He said the syringing of the bill today “will go a long way in reducing patient deaths and injuries that result from preventable errors.” The bill ensures legal protection by calling for the voluntary reporting of medical errors, keeping patient and provider information anonymous. The bill requires the Department of Health and Human Services to set up and maintain an interactive, evidence-based management resource that can analyze the reports. Don Woodlock, general manager of inpatient clinical at GE Healthcare Information Technologies, said the removal of provider information could help spur reporting of medical errors. Before passage of the bill, which guarantees anonymity, providers were reluctant to report errors due to fear of litigation. Dr. J. Edward Hill, president of the American Medical Association, said the patient safety law “is the catalyst we need to transform the current culture of blame and punishment into one of open communication and prevention.” http://govhealthit.com/article89736-07-29-05-Web

ROBOTS TAKE SCIENTISTS INTO SEA DEPTHS (Seattle P-I, 29 July 2005) -- Think of it as the Mars Rover but at the bottom of the ocean, remotely exploring our own planet's most alien landscape for scientists back at mission control. "This is how the science is going to be done," said Deborah Kelley, a University of Washington oceanographer. In 2000, Kelley led an expedition using a manned submersible to explore the deep Atlantic Ocean. Her team stumbled upon something never seen before. The researchers discovered a startlingly massive collection of limestone towers located miles away from the tectonic "spreading" cracks in the seafloor that typically produce such structures. Some of these hydrothermal vent towers were hundreds of feet high, prompting the scientists to call the unprecedented find the "Lost City" after the myth of Atlantis. Yesterday, Kelley and her colleagues were in Seattle and also "virtually" back at the Lost City to demonstrate how robotics and information technology can transform deep-ocean exploration. What once required dangerous and time-limited manned exploits can now be done by remote control on a ship deck or in an office thousands of miles away. In a darkened room on the UW campus, the makeshift, temporary command center featured Kelley and her colleagues surrounded by video screens depicting Ballard along with the remote-controlled submersible Hercules poised alongside one of the stark, shimmering white towers of the Lost City. http://seattlepi.nwsource.com/local/234479_lostcity29.html

WILL THE ADWARE INDUSTRY BEAT SPITZER? (CNET, 2 August 2005; article by Prof. Eric Goldman) -- New York Attorney General Elliott Spitzer's recent enforcement action against adware vendor Intermix Media has opened up a new front in the battle against this type of software. Though Intermix claims to have settled the matter for $7.5 million, any disposition leaves open a number of issues regarding Spitzer's ultimate plan for a possible sweep against the entire adware industry. In particular, Spitzer has repeatedly threatened advertisers who run ads with adware vendors. These threats have created a conundrum for advertisers. On one hand, adware offers advertisers a cost-effective way to reach consumers who derive value from the advertisements. On the other hand, no advertiser wants to get on Spitzer's hit list. Thus, if Spitzer's threat is real, many advertisers will simply forgo adware advertising. But amid the commotion, a critical, substantive question remains ignored: What legal doctrine holds advertisers liable for advertising via adware? We have yet to hear a coherent theory from Spitzer--or anyone else--explaining how this liability arises. In fact, advertiser liability for adware vendors' actions would represent a novel and unprecedented application of current law. In other words, to hold advertisers liable, Spitzer will need to create new law. Advertiser liability for adware vendors' actions would represent a novel and unprecedented application of current law. We can better understand the radical nature of these assertions through some analogies to other advertising contexts. Imagine The New York Times runs a libelous story or illegally obtains consumer subscriptions through deceptive trade practices. Or imagine a Yellow Pages vendor illegally trespasses by throwing copies of its book onto homeowners' land. Are advertisers liable in these circumstances? Generally, the answer is emphatically no. Advertisers have no more responsibility for the media partner's actions than any other customer or vendor. Indeed, such expansive liability might generate First Amendment concerns. http://news.com.com/2010-1071_3-5808481.html

CALLING ALL LUDDITES (New York Times, 3 August 2005; op-ed piece by Tom Friedman) -- I've been thinking of running for high office on a one-issue platform: I promise, if elected, that within four years America will have cellphone service as good as Ghana's. If re-elected, I promise that in eight years America will have cellphone service as good as Japan's, provided Japan agrees not to forge ahead on wireless technology. My campaign bumper sticker: "Can You Hear Me Now?" I began thinking about this after watching the Japanese use cellphones and laptops to get on the Internet from speeding bullet trains and subways deep underground. But the last straw was when I couldn't get cellphone service while visiting I.B.M.'s headquarters in Armonk, N.Y. But don't worry - Congress is on the case. It dropped everything last week to pass a bill to protect gun makers from shooting victims' lawsuits. The fact that the U.S. has fallen to 16th in the world in broadband connectivity aroused no interest. Look, I don't even like cellphones, but this is not about gadgets. The world is moving to an Internet-based platform for commerce, education, innovation and entertainment. Wealth and productivity will go to those countries or companies that get more of their innovators, educators, students, workers and suppliers connected to this platform via computers, phones and P.D.A.'s. [Article continues, and discusses the virtues of municipalities providing free WiFi.] http://www.nytimes.com/2005/08/03/opinion/03friedman.html?ex=1280721600&en=18d4a862134f2aae&ei=5090&partner=rssuserland&emc=rss

FCC PUTS DSL ON SAME FOOTING AS CABLE SERVICE (CNET, 5 August 2005) -- The Federal Communications Commission on Friday did away with old rules that require phone companies to share their infrastructure with Internet service providers. The new framework puts DSL service in line with cable modem services. Recently, the U.S. Supreme Court upheld the FCC's interpretation of cable modem service as an "information" service, which means it isn't required to share its infrastructure with competitors. The new rules could hurt ISPs such as EarthLink, which will be forced to negotiate wholesale deals with existing DSL providers. But DSL providers won't get off scott free. DSL providers will still be required to comply with wire tapping rules and disability requirements. And DSL providers will still contribute to the Universal Service Fund, at least for the next 270 days until the FCC can figure out another way to keep USF funded. http://news.com.com/2061-10785_3-5820294.html?part=rss&tag=5820294&subj=news

‘GUNS, GERMS, AND STEEL’ RECONSIDERED (Inside Higher Ed, 3 August 2005) -- Guns, Germs, and Steel: The Fates of Human Societies has had the kind of impact that most scholarly authors can only dream about for their works. First published by W.W. Norton in 1997, the book won a Pulitzer Prize the next year for its author, Jared Diamond, a professor of geography at the University of California at Los Angeles. Almost immediately, the book sold much better than most serious works (more than 1 million copies) and started to turn up on college reading lists — in courses on world history, anthropology, sociology and other fields. By 1999, the book was one of 12 recommended to freshmen at the University of California at Berkeley (along with some works that had been around a while longer, like Genesis and Exodus from the Bible). In 2001, Cornell University had all of its freshmen read the book. This summer, PBS broadcast a series based on the book, with Diamond explaining many of his ideas. And in the last week, a relatively new blog in anthropology — Savage Minds — has set off a huge debate over the book. Two of the eight people who lead Savage Minds posted their objections to the book, and things have taken off from there, with several prominent blogs in the social sciences picking up the debate, and adding to it. Hundreds of scholars are posting and cross-posting in an unusually intense and broad debate for a book that has been out for eight years. http://insidehighered.com/news/2005/08/03/ggs

NET POSTS DIRECTED TO FORUM RESIDENTS SUPPORT JURISDICTION (BNA’s Internet Law News, 4 August 2005) -- BNA's Electronic Commerce & Law Report reports that a federal court in Massachusetts has ruled that postings on a Yahoo! message board, though readable by those outside the forum, are nonetheless a "contact" with the forum in instances in which the posts are directed to the forum's residents. The court reasoned that the postings, which it said showed the defendant "engaged in direct dialogue" with forum residents, are analogous to e-mail sent to state residents. Case name is Abiomed v. Turnbull. Decision at http://pacer.mad.uscourts.gov/dc/opinions/gorton/pdf/abiomed.pdf

BOSTON AIRPORT BATTLES WITH FREE WI-FI (CNET, 4 August 2005) -- A free Wi-Fi service that competes with Logan Airport's paid-for service poses an 'unacceptable potential risk' to security forces gear, according to airport authorities. Boston's Logan International Airport is attempting to pull the plug on Continental Airlines' free Wi-Fi node, which competes with the airport's $7.95 (£4.48) per day pay service. In an escalating series of threatening letters sent over the last few weeks, airport officials have pledged to "take all necessary steps to have the [Wi-Fi] antenna removed" from Continental's frequent flyer lounge. Continental's free service poses an "unacceptable potential risk" to communications gear used by the state police and the Transportation Security Administration, the letters claim. For its part, Continental says that a 1996 law prevents local officials from meddling with wireless service and has asked the Federal Communications Commission to intervene. Its letter to the FCC argues that the agency has "exclusive jurisdiction" over Wi-Fi and should keep local authorities at bay. "We believe that offering free Wi-Fi at Boston's Logan airport is consistent with the FCC's regulations and its prior rulings on similar issues and that it is permissible under the terms of our lease," Continental spokeswoman Julie King said Wednesday. The airline provides free wireless access at all of its Presidents Club lounges worldwide. http://uk.news.yahoo.com/050804/152/fous1.html

**** RESOURCES ****

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Friday, July 15, 2005

MIRLN -- Misc. IT Related Legal News [18 June – 15 July 2005; v8.08]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

TROJAN E-MAILS SUGGEST TREND TOWARD TARGETED ATTACKS (Computerworld, 17 June 2005) -- A report on Trojan e-mail attacks against critical-infrastructure systems in the U.K. highlights an emerging trend away from mass-mailing worms and viruses to far more targeted ones, analysts said. The U.K.’s National Infrastructure Security Co-Ordination Center yesterday released a report (PDF format) disclosing that more than 300 government departments and businesses were targeted by a continuing series of e-mail attacks designed to covertly gather sensitive and economically valuable information (see story). Unlike with phishing and mass-mailing worms, the attackers appear to be going after specific individuals who have access to commercially or economically privileged information, the report said. The attacks involved the use of e-mails containing so-called Trojan programs or links to Web sites containing Trojan files. Once installed on a user’s system, Trojans covertly run in the background and perform a variety of functions, including collecting usernames, passwords and system information; scanning of drives; and uploading of documents and data to remote computers. “The e-mails use social engineering to appear credible, with subject lines often referring to news articles that would be of interest to the recipient,” the report said. “In fact, they are ‘spoofed,’ making them appear to originate from trusted contacts, news agencies or government departments.”The report highlights how hackers are starting to tailor their attacks and go after specific high-value targets instead of simply launching mass-mailing worms and viruses, said Mark Sunner, chief technology officer at MessageLabs Ltd., a New York-based provider of e-mail security services. http://www.computerworld.com/printthis/2005/0,4814,102595,00.html and http://www.securityfocus.com/news/11222 Report at http://www.niscc.gov.uk/niscc/docs/ttea.pdf

FIVE FINNS GET SUSPENDED SENTENCES IN SONERA TELEPHONE RECORD CASE (Helsingin Salomat, 17 June 2005) – The Helsinki District Court handed down suspended sentences to five defendants in the case involving unauthorised use of mobile telephone records by executives of the telecommunications service provider Sonera. All five were found guilty of violating telecommunications privacy. Although the sentences were less severe than the prosecution had called for, the court generally agreed with the prosecutors’ assertion that there had been extensive misuse of telecommunications information at Sonera from 1998 to 2001. The harshest sentence was handed down to former Information Security Manager Juha E. Miettinen, who got a ten-month suspended jail term. Two other defendants, an investigator for the National Bureau of Investigation, as well as Ari Uutinen, a former security chief at the Council of State (government), were fined for incitement to the main crime in the case, and for violating their official duties. The court found a number of both aggravating and mitigating circumstances in the case. One aggravating factor was the large number of targets of the illegal investigations. Another factor was the high position of the defendants in the company, their roles as initiators in the case, and their attempts to break the confidentiality between journalists and their sources. http://www.helsinginsanomat.fi/english/article/1101979719153

MIX BRIX, CLIX? FACE TAX TO MAX, SAYS CAL. COURT (Steptoe & Johnson’s E-Commerce Law Week, 18 June 2005) -- Hatfields and McCoys have nothing on the feud between distance sellers and state revenue authorities. States have long sought to collect sales tax on mail order sales. After bitter litigation the Supreme Court has held and reheld that distance sellers can’t be forced to collect the tax unless those sellers have sufficient contacts with the state to become subject to state law. Then bricks-and-mortar companies got into the act, creating “clicks and mortar” companies to sell their products over the Internet -- without collecting taxes. As long as the Internet company was formally separate from the “bricks and mortar” company, the Internet company could not be forced to collect taxes because it didn’t have any assets in the taxing jurisdiction. That was the theory, anyway. But now a California court has thrown a brick of its own right through that notion. In Borders Online, LLC v. State Board of Equalization, a California Court of Appeal has upheld a trial court’s ruling that although “Borders” and “Borders Online” were two separate companies, Borders’ activities in the state “on behalf” of Borders Online were sufficient for the online retailer to be subject to California’s tax code. Further, the appeals court held that the online retailer had a “sufficient physical presence” in California -- by virtue of the presence of brick-and-mortar Borders stores -- to satisfy the commerce clause of the US Constitution. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9917&siteId=547 Decision at http://www.steptoe.com/publications/358a.pdf

-- and --

STATES MOVE FORWARD ON INTERNET SALES TAX (Washington Post, 1 July 2005) -- Tax officials, state lawmakers and industry representatives agreed Thursday to establish an 18-state network for collecting taxes on Internet sales, a compact they hope will encourage online retailers and Congress to endorse a mandatory national program. Meeting in Chicago under the auspices of the Streamlined Sales Tax Project, the officials agreed that 11 states will oversee the project and outlined incentives to encourage retailers to participate. Forty states have been negotiating since 2000 to create a framework for collecting sales taxes on all remote transactions, whether through regular mail or online. “The vote is a culmination of over five years of hard work by states, local governments and businesses interested in seeing the complexity in sales tax [reduced],” said Stephen Kranz, tax counsel for the Council on State Taxation, an industry trade association. Starting Oct. 1, software vendors contracted by the Streamlined Sales Tax Project will begin providing free tax collection and remittance software and services to online merchants who voluntarily agree to collect taxes on all online sales on behalf of the 18 participating states. Under the states’ plan, Internet retailers that agree to collect and remit taxes will do so for online sales originating in any of 11 states that have amended their state laws to fully comply with standards developed by the sales tax project. In the other seven states, the Internet sales tax collection would be optional until their tax codes are brought into full compliance. In both cases, any taxes the retailer collected would be based on the rates in effect where the buyer lives, and the retailers would be compensated for the cost of collecting and remitting that revenue to the states. As an incentive, the states will offer a one-year amnesty for e-commerce companies that may owe taxes on past online sales to any of the participating states. The amnesty offer could prove attractive for several major retailers that are currently involved in legal disputes over whether they owe taxes on Internet sales. http://www.washingtonpost.com/wp-dyn/content/article/2005/07/01/AR2005070101475.html

APPEALS COURT LIMITS CALIFORNIA’S FINANCIAL PRIVACY LAW (Timesleader.com, 20 June 2005) -- A federal appeals court blocked a portion of California’s landmark financial privacy law Monday, ruling that banks have a right to sell their customers’ private information to affiliated companies. The 9th U.S. Circuit Court of Appeals ruled that federal law pre-empts a portion of California’s 2003 privacy law, the toughest in the nation, but leaves most of it intact. The part of the California law at issue is a section that gives consumers the right to block banks from selling their personal information to affiliates that are not in the same line of business. That could include a bank sharing data with an insurance company owned by the same corporation. Three trade associations challenged that aspect of the law, but it was upheld in July by a federal judge in Sacramento. That judge ruled that a 1999 federal financial-privacy law allows states to enact stricter rules. The American Bankers Association, the Financial Services Roundtable and the Consumer Bankers Association appealed. They said the federal 2003 Fair and Accurate Credit Transactions Act pre-empts California’s restrictions on how affiliated companies can share customer data. The 9th Circuit agreed, reversing the lower court ruling and sending the case back to the district judge. The lower court judge, U.S. District Judge Morrison C. England Jr., will be asked to determine whether any aspects of the California law dealing with this kind of information swapping might still be legal in light of the 2003 federal law. Specifically, England will determine whether any consumer information can be shielded from affiliated companies under the state law. Given that the appeals court sent the case back for further review, Monday’s ruling is not the “smashing pre-emption victory” that bankers had sought, said Tom Dresslar, spokesman for state Attorney General Bill Lockyer, who defended the state law. http://www.timesleader.com/mld/timesleader/business/11942397.htm Decision at http://caselaw.findlaw.com/data2/circs/9th/0416334p.pdf

L.A. TIMES SUSPENDS ‘WIKITORIALS’ (AP, 21 June 2005) -- A bold Los Angeles Times experiment in letting readers rewrite the paper’s editorials lasted all of three days. The newspaper suspended its “Wikitorial” Web feature after some users flooded the site over the weekend with foul language and pornographic photos. The paper had posted on its Web site Friday an editorial urging a better-defined plan to withdraw troops from Iraq. Readers were invited to add their thoughts. Dozens did, with some adding hyperlinks and others adding opposing views. One reader split the long editorial in two, something that pleased Michael Kinsley, the Times’ editorial and opinion editor. But the number of “inappropriate” posts soon began to overwhelm the editors’ ability to monitor the site. On Sunday, editors decided to remove the feature. The newspaper’s Web page was to show the original editorial and interim versions along with the readers’ final product. “The result is a constantly evolving collaboration among readers in a communal search for truth,” the paper said in its Friday edition. “Or that’s the theory.” The Times said it might be creating a new form of opinion journalism — or an embarrassing failure. In a statement Monday, the Times said the feature would stay offline indefinitely while it looked at what happened and how to fix it. “We thank the thousands of people who logged onto the Wikitorial in the right spirit,” the paper said. http://news.yahoo.com/news?tmpl=story&cid=528&e=5&u=/ap/20050621/ap_on_bi_ge/la_times_wikitorials

EMPLOYEE WHISTLEBLOWER HOTLINES FOUND ILLEGAL IN FRANCE AND GERMANY (Hunton & William’s Privacy & E-Commerce Alert, 22 June 2005) -- In its session of May 26, 2005, the plenary of the French DPA (CNIL) refused to authorize the use of anonymous whistleblower hotlines operated by McDonalds France and CEAC (an affiliate of Exide Technologies) that would enable employees to alert their headquarters or managers (by phone, fax e-mail of mail) of their colleagues’ possible misconduct. These hotlines were set up by the companies in order to comply with the requirements of the US Sarbanes-Oxley law, which requires such anonymous complaint mechanisms. In two separate decisions, the CNIL expressed particular concern over: (1) anonymous reporting that could lead to slanderous denunciation; (2) disproportionality between the purpose and the risk of malicious reporting; (3) the fact that suspected staff would not be informed of a complaint or investigation in the early stage of the process; and (4) the period of data retention. Both decisions are available (in French) on the CNIL web site: Decision 2005/110 at http://www.cnil.fr/index.php?id=1833 (McDonalds); and Decision 2005/111 at http://www.cnil.fr/index.php?id=1834 (CEAC).

FTC OPPOSES MANDATORY “ADV” LABELING OF EMAIL (BNA’s Internet Law News, 233 June 2005) -- BNA’s Electronic Commerce & Law Report reports that the FTC has believes that federal legislation mandating the inclusion of “ADV” in the subject line of unsolicited commercial e-mail messages would be ineffective in combatting spam. The FTC’s views were informed by the belief that so-called “outlaw spammers” would not obey the law, that “ADV” labelling proved ineffective at the state level, and that anti-spam filters and other emerging e-mail technologies hold more promise as anti-spam tools than an “ADV” label. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b0z2n5c7
SHOULD CITIES BE ISPS? (CNET, 23 June 2005) -- When Philadelphia’s city government decided to sell wireless access to downtown residents last year, a furious political fight in the state capital erupted. Verizon stridently opposed the plan, liberal advocacy groups just as emphatically endorsed it, and politicians in Harrisburg ended up approving a compromise bill that effectively let the city of brotherly love do what it wanted. Now this politechnical dispute is bubbling up from states to Washington, D.C., where lobbyists are pressuring Congress to resolve the question of whether governments or private companies do a better job as Internet service providers. “Our focus is that 75 to 85 percent of our population in our low-income and minority areas that don’t have access,” said Dianah Neff, Philadelphia’s chief information officer. “When we talked to them and we did surveys with them, they said 76 percent of the time that cost was the No. 1 reason why they didn’t have access to the Internet.” But if reaching low-income people is the primary goal, said Jim Speta, an associate professor at the Northwestern University School of Law, then cities could keep costs down by relying on “consumer demand pull”--that is, handing vouchers to poorer consumers, who could use them to pay for private sector broadband. http://news.com.com/2100-1034_3-5758262.html

PEER-TO-PEER FILE SHARING COMES WITH RISKS, SAYS FTC (Information Week, 23 June 2005) -- Peer-to-peer file-sharing technology offers both benefits and risks, according to a report issued today by the Federal Trade Commission. The report, based on comments from the FTC’s P2P workshop last December, cites benefits such as fast file transfers, bandwidth conservation, and reduced storage needs. It also warns of risks related to data security, spyware and adware, viruses, copyright infringement, and pornography. How significant are those risks compared with general Internet use? The FTC doesn’t know. “Workshop participants submitted little empirical evidence concerning whether the risks arising from P2P file sharing are greater than, equal to, or less than these risks from other Internet-related activities,” the report finds. The report comes at an odd time. The Supreme Court is expected to soon decide the future of peer-to-peer technology when it rules in the case of Metro-Goldwyn Mayer Studios v. Grokster Ltd. As the FTC says, “Because [this case] likely will clarify the legal framework applicable to P2P file sharing and may have a profound effect on the future structure and impact of P2P file-sharing programs, FTC staff does not believe that it would be prudent at this time to make specific recommendations regarding the intellectual-property issues raised by P2P file sharing.” http://informationweek.com/story/showArticle.jhtml?articleID=164902381 Report at http://www.ftc.gov/reports/p2p05/050623p2prpt.pdf

DATABASE TARGETS TEENS AS RECRUITS FOR MILITARY (Houston Chronicle, 23 June 2005) -- The Defense Department began working Wednesday with a private marketing company to create a database of all U.S. college students and high school students between 16 and 18 years old, to help the military identify potential recruits in a time of dwindling enlistment in some branches. The new database will include an array of personal information including birth dates, Social Security numbers, e-mail addresses, grade-point averages, ethnicity and what subjects the students are studying. The data will be managed by BeNOW Inc. of Wakefield, Mass., one of many marketing companies that use computers to analyze large amounts of data to target potential customers based on their personal profiles and habits. “The purpose of the system ... is to provide a single central facility within the Department of Defense to compile, process and distribute files of individuals who meet age and minimum school requirements for military service,” according to the official notice of the program. Privacy advocates said the plan appeared to be an effort to circumvent laws that restrict the government’s right to collect or hold citizen information by turning to private firms to do the work. Some data on high school students already is given to military recruiters in a separate program under provisions of the 2002 No Child Left Behind Act. Under the new system, additional data will be collected from commercial data brokers, state driver’s license records and other sources, including information already held by the military. The Pentagon’s statements added that anyone can “opt out” of the system by providing detailed personal information that will be kept in a separate “suppression file.” That file will be matched with the full database regularly to ensure that those who do not wish to be contacted are not, according to the Pentagon. But privacy advocates said using database marketers for military recruitment is inappropriate. Chris Hoofnagle, West Coast director of the Electronic Privacy Information Center, called the system “an audacious plan to target-market kids, as young as 16, for military solicitation.” He added that collecting Social Security numbers was not only unnecessary but posed a needless risk of identity fraud. Theft of Social Security numbers and other personal information from data brokers, government agencies, financial institutions and other companies is rampant. BeNOW’s Web site does not have a published privacy policy, nor does it list either a chief privacy officer on its executive team. http://www.chron.com/cs/CDA/ssistory.mpl/nation/3237413

ALMOST ALL LIBRARIES IN U.S. OFFER FREE ACCESS TO INTERNET (New York Times, 24 June 2005) -- Nearly all libraries around the country have free public Internet access and an increasing number are offering wireless connections, according to a study released Thursday by the American Library Association here. The study, which was conducted by researchers at Florida State University, found that 98.9 percent of libraries offer free public Internet access, up from 21 percent in 1994 and 95 percent in 2002. It also found that 18 percent of libraries have wireless Internet access and 21 percent plan to get it within the next year. The study found that rural areas were more likely to have slower connections and fewer workstations and training opportunities. Arkansas, California, Idaho, New Hampshire, Virginia and West Virginia had the lowest levels of access. Urban areas, which also had some of the highest poverty rates, tended to have high levels of connectivity, bandwidth and wireless access. Hazel Williams, 50, of Chicago said she started going to the library for Internet research two years ago while she was earning her high school equivalency diploma. People like Ms. Williams who go to the library for Internet access might be one reason that the number of annual library visits has increased from 500 million in the early 1990’s to 1.2 billion today, said Carol Brey-Casiano, president of the American Library Association. The study also reported that almost 40 percent of public libraries filter public Internet access to prevent minors from gaining access to sexually related materials. State library systems in Georgia and West Virginia put filters on all public libraries, the study reported. http://www.nytimes.com/2005/06/24/national/24library.html?ex=1277265600&en=844132cc8d3c7fe3&ei=5090&partner=rssuserland&emc=rss

AT PARTYGAMING, EVERYTHING’S WILD (New York Times, 26 June 2005) -- As a rule, companies don’t often draw attention to business practices that could land their executives in jail. But for PartyGaming PLC, potential illegalities aren’t just a secret hidden in its business plan - they are the centerpiece of its business plan. A giant in the online gambling business, PartyGaming is an often-overlooked megasurvivor from the dot-com crash of the late 1990’s. As hundreds of profitless commercial sites disappeared into the digital ether, PartyGaming’s popular gambling sites - like PartyPoker.com - soared, with revenues and profits growing exponentially year after year. This week, the company will go public in what is expected to be the largest offering in years on the London Stock Exchange, one that will make billionaires out of its ragtag assortment of founders and major stockholders - including a California lawyer who earned her first fortune in online pornography and phone-sex lines. All told, as much as $9 billion is expected to be raised, with all of the cash going to private shareholders selling portions of their stakes. PartyGaming, based in Gibraltar, has no assets in the United States, and its officers or directors could risk being served with a civil suit - or an arrest warrant - if they came to the United States on business. The reason? The Justice Department and numerous state attorneys general maintain that providing the opportunity for online gambling is against the law in the United States - and PartyGaming does it anyway. Indeed, of its $600 million in revenue and $350 million in profit in 2004, almost 90 percent came from the wallets and bank accounts of American gamblers. To justify this, PartyGaming walks a very thin line. Providing online gambling is not illegal per se in the United States, the company argues - federal prosecutors just say it is. The company’s prospectus - a British document that is not available in the United States - at times reads something like a legal brief, citing American case law to support the company’s position that no prosecution would ever take place. Still, in its offering documents, PartyGaming makes no secret of the fact that even if the company’s view of the law proves wrong, it is banking on its executives’ belief that there is little that law enforcement can do - or will do - to prosecute. “In many countries, including the United States, the group’s activities are considered to be illegal by the relevant authorities,” PartyGaming says in its offering document. “PartyGaming and its directors rely on the apparent unwillingness or inability of regulators generally to bring actions against businesses with no physical presence in the country concerned.” [Editor: Lengthy, interesting piece (with a too-long digression into 1990s internet pornography). Particularly interesting: the “offshore” move to avoid U.S. jurisdiction.] http://www.nytimes.com/2005/06/26/business/yourmoney/26poker.html?ex=1277438400&en=a47371cd660556db&ei=5090&partner=rssuserland&emc=rss

THE VOICEMAIL MESSAGE THAT HAS GCs TALKING (Law.com, 27 June 2005) -- There are dumb mistakes, and then there are really dumb mistakes. Four years ago Matthew Gloss, the general counsel of Marvell Semiconductor Inc., and two of his colleagues phoned the legal chief of a rival company, Jasmine Networks Inc. The call went straight to voicemail, so Gloss left a message and hung up. At least, he thought he did. Though the Marvell officials didn’t know it, the Jasmine lawyer’s voicemail was still taping them as they continued to talk on speakerphone -- allegedly about how they were stealing their rival’s trade secrets. Gloss’ little boo-boo has turned into a major headache, not just for Marvell but potentially for in-house lawyers everywhere. That’s because when Jasmine filed its inevitable lawsuit against Marvell, it tried to enter the voicemail as evidence. Marvell moved to exclude the tape, arguing that it was protected by attorney-client privilege, since two company lawyers took part in the conversation. The trial judge sided with Marvell, but a California appellate court backed Jasmine. By failing to disconnect his phone, Gloss had waived privilege, the appellate court ruled last year. Moreover, since he is also a company officer -- he holds the title of vice president for business affairs -- Gloss had the authority to waive privilege on Marvell’s behalf. The appellate decision so worried the Association of Corporate Counsel that it asked the California Supreme Court to review the case. The justices agreed, and Marvell and Jasmine are currently preparing their briefs. ACC is also backing a proposed state law that says privilege can only be waived intentionally and not inadvertently. http://www.law.com/jsp/article.jsp?id=1119603919501

US SUPREME COURT REVERSES GROKSTER DECISION (BNA’s Internet Law News, 28 June 2005) -- The US Supreme Court has ruled against file-swapping companies Grokster and StreamCast Networks in their high profile battle with the content indusries. The court sought to leave the 1984 Sony Betamax decision untouched, but added the notion of active inducement. Although the 9-0 decision was a loss for Grokster, the court provided a potential roadmap for future P2P services by ruling that there is no liability for knowledge of potential or actual infringement; no liability for product support or technical updates, and (absent other evidence of intent) no liability for failure to take affirmative steps to prevent infringement. Decision at http://laws.findlaw.com/us/000/04-480.html Media coverage at http://news.com.com/2100-1030_3-5764998.html http://news.com.com/2100-1028_3-5764787.html http://www.wired.com/news/digiwood/0,1412,68018,00.html

-- and --

THE COURT HAS RULED SO ENTER THE GEEKS (New York Times, 29 June 2005) -- The Supreme Court’s unanimous decision Tuesday in the Grokster case means trouble and potentially ruinous judgments against commercial file-sharing services, but it has also established a new standard for software innovation: don’t ask, don’t sell. That is, don’t ask for or gather information on what users are doing with the software you write, and don’t sell ads that profit from access to copyrighted material. The court found that the file-sharing companies Grokster and Streamcast could be sued for copyright infringement because they offered marketing and technical advice that clearly induced their customers to share files illegally, so the companies could attract larger numbers of users and thus more advertising. But the court did not give the movie and recording businesses much ammunition to attack the Robin Hoods of the Internet: those software geeks and culture fans who really just want to share. They are online right now building Web sites that don’t make a dime and spending hours writing and editing “mp3 blogs” - Web page collections of downloadable songs. They hook people up, basically because they can and because people want access to art. The court’s decision may torpedo the parasitical, ad-pumping services like Grokster, Kazaa and Morpheus, but no one’s going to miss them much. There are plenty of geek alternatives that were devised not as business startups, but for the programmers’ satisfaction and the users’ sense of connection. It’s a completely alien mentality for profit-focused companies that still dream of being paid every time someone hears a song. Reality has never exactly worked that way, from radio to the Internet. In the United States, songwriters are paid for radio air play, but performers and recording companies are not, on the theory that having a song broadcast sells recordings and concert tickets. [Editor: The entire story is worthwhile.] http://www.nytimes.com/2005/06/29/arts/music/29pare.html?ex=1277697600&en=a4e8e6f3cc33bd23&ei=5090&partner=rssuserland&emc=rss

-- and --

REFLECTING ON THE GROKSTER DECISION (BNA’s Internet Law News, 29 June 2005) -- Several articles focus on the fallout from the Grokster decision. The Toronto Star features a special edition of my Law Bytes column which comments on Monday’s Grokster decision. The column argues that the case is a mirror image of the recent Canadian file sharing case as despite the unanimous verdict, it provides a roadmap for file sharing services to avoid future liability. Larry Lessig warns of chilled innovation in a Business Week interview, while other articles include reaction from industry players on both sides of the issue. Geist Toronto Star column at http://geistgrokster.notlong.com/ http://www.michaelgeist.ca/resc/html_bkup/june292005.html Reaction articles at http://news.com.com/2100-1027_3-5767277.html http://www.nytimes.com/2005/06/29/arts/music/29pare.html Lessig interview at http://www.businessweek.com/technology/content/jun2005/tc20050629_2928_tc057.htm

BLOGGERS FIGHTING GOVERNMENT REGULATIONS (AP, 28 June 2005) -- Bloggers who built their Internet followings with anti-establishment prose are now lobbying the establishment to protect their livelihoods from federal regulations. Some are even working with lawyers, public-relations consultants and a political action committee to do it. “I like to think of myself as just a guy with a blog, but it’s clear that ‘just a guy with a blog’ is different today than it was when I started three years ago,” said Markos Moulitsas Zuniga, founder of the Web log www.DailyKos.com. “One sign of having arrived is when government regulators start wanting to poke their fingers into what you do.” Moulitsas was to testify Tuesday at a hearing on a Federal Election Commission proposal that would extend some campaign finance rules to the Internet, including bloggers. Moulitsas also is working with a lawyer who volunteered to help bloggers fight new government regulations and whose efforts were promoted in a PR firm press release Monday. He is prepared to lobby Congress himself if necessary, and he is the treasurer of BlogPac, a political action committee formed last year by bloggers. Duncan Black — who founded the www.atrios.blogspot.com blog — featured a headline Monday on his Web site, “Bite me, Congressman,” that linked to a diatribe against a Republican House committee chairman over global warming. Asked whether the use of hearing testimony and PACs is a sign that bloggers are succumbing to mainstream political techniques, Black said he and his colleagues have no choice. “I think once you do achieve a certain degree of traffic, influence, notoriety — however you want to call it — eventually the outsider label is not perfectly applicable anymore,” said Black, who describes himself as a “recovering economist.” He too planned to testify before the FEC. http://news.yahoo.com/news?tmpl=story&cid=528&e=1&u=/ap/20050628/ap_on_hi_te/bloggers_lobby

CONGRESS MODIFIES FCC RULING ON UNSOLICITED FAXES (SiliconValley.com 28 June 2005) -- Congress approved junk fax legislation Tuesday that allows businesses to send out unsolicited faxes in certain circumstances while protecting the rights of consumers to stop receiving them. The legislation, passed by the House on a voice vote and now headed for President Bush’s signature, reinstates a 1992 Federal Communications Commission ruling that permits businesses and associations to send unsolicited faxes to those with whom they have an ``established business relationship.” It would eliminate a new FCC ruling, first drawn up in 2003, that required businesses and organizations to obtain prior written approval before sending a commercial fax. That rule was supposed to go into effect on Friday, but the FCC on Tuesday announced it would further delay its new junk fax rule until Jan. 9, 2006, ``in light of the ongoing developments in Congress.” The agency said the delay would also give more time to respond to petitions to reconsider the rule. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/12005819.htm

PUBLISHING MAKES SHIFT TO DIGITAL (BBC, 29 June 2005) -- The vast majority of UK research material will be available in electronic form by 2020. According to a study commissioned by the British Library, 90% of newly published work will be available digitally by this time. Only half of this will also be available in print form, with just 10% of new titles available only in print. It represents a “seismic shift” in the world of publishing said British Library chief executive Lynne Brindley. For its part, the British Library aims to spend the next three years developing the infrastructure necessary to store, manage, preserve and provide access to digital material. “In many ways digital material is more fragile than physical material and if we don’t manage it effectively it won’t survive for future generations,” said Ms Brindley. http://news.bbc.co.uk/2/hi/technology/4633423.stm

THEFT FEARS RULE OUT NATIONAL AUSTRALIAN CARD (AustralianIT, 29 June 2005) -- Australia will not introduce a national identification card because of the fear of identity theft by criminals, Attorney-General Philip Ruddock said. Mr Ruddock today rejected media reports that the federal Government was considering introducing a national ID card. His comments come as the British government legislates to introduce the country’s first national ID card since World War II. The UK cards, which Prime Minister Tony Blair says are necessary to fight terrorism, fraud and illegal immigration, will include biometric details such as iris scans and fingerprints. But Mr Ruddock told a security technology conference in Sydney today a national ID card could actually compromise Australians’ security. “We haven’t supported an approach where all personal information is centralised on one database and a single form of identification is used,” Mr Ruddock told the gathering of government, security and business leaders. “Such an approach could actually increase the risk of identity fraud because only one document would need to be counterfeited to establish an identity.” Outside the forum, Mr Ruddock said the government wanted to step up security of existing personal identification documents such as passports, birth certificates and drivers’ licences. “We are not about developing a national ID card, we are about improving identity security arrangements - that’s the approach we’re taking,” he told reporters. http://australianit.news.com.au/articles/0,7204,15767261%5E15319%5E%5Enbv%5E15306,00.html

ONE FIFTH OF JAPANESE BUSINESSES USING OPEN SOURCE OS (Info World, 5 July 2005) -- The use of open-source operating systems in enterprise servers is growing in Japan, with companies citing low introduction costs as the main factor for adoption, according to a recent report by the Japanese government. So far, 21 percent of Japanese companies have already introduced open-source operating systems including Linux, FreeBSD, and OpenBSD systems, while 22 percent either have plans to deploy, or are considering plans to deploy, an open-source operating system, according to an annual white paper released by Japan’s Ministry of Internal Affairs and Communications (MIC). By contrast, 33 percent of U.S. companies have adopted open-source operating systems in at least some of their servers, MIC said. Among the companies polled by the MIC, 66 percent said open-source operating systems have low initial costs, while 47.8 percent said the software has low operating costs. Of those companies that have so far adopted open-source operating systems, major uses for these servers include Web, mail, and file servers. Open-source operating systems are used with much less frequency in applications for financial, payment, distribution and customer service applications, the report said. http://www.infoworld.com/article/05/07/05/HNjapaneseopensource_1.html

MAN CHARGED WITH STEALING WI-FI SIGNAL (Forbes, 6 July 2005) -- Police have arrested a man for using someone else’s wireless Internet network in one of the first criminal cases involving this fairly common practice. Benjamin Smith III, 41, faces a pretrial hearing this month following his April arrest on charges of unauthorized access to a computer network, a third-degree felony. Police say Smith admitted using the Wi-Fi signal from the home of Richard Dinon, who had noticed Smith sitting in an SUV outside Dinon’s house using a laptop computer. The practice is so new that the Florida Department of Law Enforcement doesn’t even keep statistics, according to the St. Petersburg Times, which reported Smith’s arrest this week. Innocuous use of other people’s unsecured Wi-Fi networks is common, though experts say that plenty of illegal use also goes undetected: such as people sneaking on others’ networks to traffic in child pornography, steal credit card information and send death threats. http://www.forbes.com/business/feeds/ap/2005/07/06/ap2126874.html [Editor: There must be more to this story. Smith has been charged with unauthorized access to a computer network, a third-degree felony.]

E-VOTE GUIDELINES NEED WORK (Wired, 7 July 2005) -- In an effort to keep pace with changing technology and address widespread security concerns about electronic voting machines, the federal government has released new guidelines for voting systems. The guidelines, published in late June, call for vendors to follow better programming practices and make some suggestions for addressing problems with vote integrity. Computer security experts say the guidelines are a step in the right direction, but fall short of making voting systems secure. They also don’t require systems to produce a voter-verified paper audit trail, which would allow voters to confirm their vote. The government is accepting public comment on the guidelines for 90 days, after which it will revise them, if needed, and release them for states to adopt. But there has been some confusion on whether these should be considered final guidelines, or simply a first step toward more permanent guidelines. Avi Rubin, a Johns Hopkins University computer science professor and technical director of the university’s Information Security Institute, said the new guidelines are an improvement but contain some serious security red flags. He also said they have some requirements that, had they been included in previous versions of voting system guidelines, would have prevented voting systems made by Diebold Election Systems from being certified. http://www.wired.com/news/evote/0,2645,68116,00.html?tw=wn_4polihead

GOOGLE WINS COPYCAT WEB DOMAIN DISPUTE (Reuters, 8 July 2005) -- The National Arbitration Forum said on Friday that Google Inc. has rights to the Internet domain names googkle.com, ghoogle.com, gfoogle.com and gooigle.com, which are similar to its own google.com domain. The Web search leader filed a complaint with the NAF on May 11, claiming legal rights to Web addresses bearing a close resemblance to google.com, which it registered in late 1999. Sergey Gridasov, of St. Petersburg, Russia, registered googkle.com, ghoogle.com, gfoogle.com and gooigle.com between December 2000 and January 2001 through Computer Services Langenbach GmbH, which did business as Joker.com. He did not respond to charges levied against him. Because Gridasov failed to answer, the arbitrator was entitled to accept all reasonable allegations and inferences in the complaint from Google as true, unless the evidence was clearly contradictory. The NAF arbitrator, Paul Dorf, found that Gridasov did not have legitimate rights to the Web addresses, and the Web addresses were confusingly similar to Google’s trademark rights to its own name. Further, the arbitrator found that Gridasov was using them in bad faith by presumably profiting from the use of domains. http://today.reuters.com/business/newsArticle.aspx?storyID=nN78398318

DOWNLOADING TROUBLE AT THE BBC (BBC, 10 July 2005) -- The BBC has been lambasted by classical music labels for making all nine of Beethoven’s symphonies available for free download over the Internet. This week the BBC will announce there have been more than a million downloads of the symphonies during the month-long scheme. But the initiative has infuriated the bosses of leading classical record companies who argue the offer undermines the value of music and that any further offers would be unfair competition. http://news.independent.co.uk/media/article298067.ece

WILL THE U.N. RUN THE INTERNET? (CNET, 11 July 2005) -- An international political spat is brewing over whether the United Nations will seize control of the heart of the Internet. U.N. bureaucrats and telecommunications ministers from many less-developed nations claim the U.S. government has undue influence over how things run online. Now they want to be the ones in charge. While the formal proposal from a U.N. working group will be released July 18, it’s already clear what it will contain. A preliminary summary of governmental views claims there’s a “convergence of views” supporting a new organization to oversee crucial Internet functions, most likely under the aegis of the United Nations or the International Telecommunications Union. Beyond the usual levers of diplomatic pressure and public kvetching, Brazil and China could choose what amounts to the nuclear option: a fragmented root. At issue is who decides key questions like adding new top-level domains, assigning chunks of numeric Internet addresses, and operating the root servers that keep the Net humming. Other suggested responsibilities for this new organization include Internet surveillance, “consumer protection,” and perhaps even the power to tax domain names to pay for “universal access.” This development represents a grave political challenge to the Internet Corporation for Assigned Names and Numbers (ICANN), which was birthed by the U.S. government to handle some of those topics. A recent closed-door meeting in Geneva convened by the U.N.’s Working Group on Internet Governance offers clues about the plot to dethrone ICANN. As these excerpts from a transcript show, dissatisfaction and general-purpose griping is rampant * * * http://news.com.com/2010-1071_3-5780157.html

UK LOBBIES FOR DATA RENTENTION (ZDnet, 11 July 2005) -- Charles Clarke wants email and phone records kept for up to three years to aid police investigations, but critics have claimed the scheme is expensive and unwieldy. Britain will renew its efforts this week to get fellow European Union members to agree to the introduction of new controls for the retention of telecommunications data, following last week’s bombings in London. Under the proposals, telecoms operators and Internet service providers would have to keep records of emails, telephone calls and text messages for between 12 months and three years. Law enforcement agencies would be able to see who had sent and received these communications, although the content of these communications would not be stored. Home secretary Charles Clarke claims that the powers would help to establish links between individuals. “Telecommunications records, whether of telephones or of emails, which record what calls were made from what number to another number at what time are of important use for intelligence,” said Clarke, according to reports. The UK is one of several countries advocating the introduction of such measures over recent months. Other EU members have opposed them, fearing they would erode civil liberties. Back in June the European Parliament rejected draft legislation introduced by France, Ireland, Sweden and the UK, amid fears that the proposals were illegal. http://uk.news.yahoo.com/050711/152/fn318.html

NEW BATTLE BREWS OVER UCITA, SOFTWARE LICENSING TERMS (Computer World, 11 July 2005) -- A new legislative battle is looming over the controversial UCITA software licensing law. But this time, it’s software users, not vendors, who are poised to attack. The push for state-by-state adoption of the Uniform Computer Information Transactions Act was abandoned nearly two years ago because of widespread opposition. But the group of software users that led that opposition has since been quietly drafting its own model software-licensing law. Its concern is that courts may use UCITA as a reference point in legal disputes, giving vendors a victory through the legal system that they couldn’t gain in state legislatures. “That battle against UCITA is still going on; it’s just taken another form,” said Riva Kinstlick, vice president of government relations at Prudential Financial in Newark, N.J. “People are starting to be concerned about it,” said Kinstlick, who maintained that stopping UCITA wasn’t enough. “If there is a void and UCITA is the only thing to take the place of the void, this could end up being the model almost by default rather than choice,” she said. UCITA is a software licensing law that specifies terms and conditions for licensing contracts. Under the act, unless the parties agree otherwise, the default terms apply. Its supporters argued that UCITA would provide a legal framework for online commerce. Opponents said the default rules favored vendors and created potential perils for corporate users, such as allowing vendors to knowingly ship defective products. Virginia approved the law in 2000, and Maryland quickly followed. But opponents—especially those in the financial services industry—joined the state-by-state battle to block further adoptions. In August 2003, the law’s legislative sponsor, the Chicago-based National Conference of Commissioners on Uniform State Laws (NCCUSL), suspended efforts to win state adoption. But UCITA can still be used as a contract model, said Jean Braucher, a University of Arizona law professor who is working with Americans for Fair Electronic Commerce Transactions (AFFECT) to develop a model bill. “Eventually, we need an alternative,” she said. http://www.computerworld.com/softwaretopics/software/story/0,10801,103065,00.html

GIVING NEW MEANING TO ‘SPYWARE’ (Wired, 12 July 2005) -- Supreme Court Justice Potter Stewart famously said that he couldn’t define obscenity, but that he knew it when he saw it. The same has long been the case with spyware. It’s not easy to define, but most people know it when parasitic programs suck up resources on their computer and clog their browsers with pop-up ads. Recognizing that one person’s search toolbar is another’s spyware, a coalition of consumer groups, ISPs and software companies announced on Tuesday that it has finally come up with a mutually agreeable definition for the internet plague. Spyware impairs “users’ control over material changes that affect their user experience, privacy or system security; use of their system resources, including what programs are installed on their computers; or collection, use and distribution of their personal or otherwise sensitive information,” according to the Anti-Spyware Coalition, which includes Microsoft, EarthLink, McAfee and Hewlett-Packard. The group hopes the definitions will clear the way for anti-spyware legislation and help create a formal, centralized method for companies to dispute or change their software’s classification. http://www.wired.com/news/privacy/0,1848,68167,00.html

BUSH PICKS TECH LAWYER FOR SECURITY POST (CNET, 13 July 2005) -- President Bush has chosen Stewart Baker, one of Washington’s most influential technology lawyers, to be assistant secretary for policy in the Homeland Security Department. Baker’s new job, which requires Senate confirmation, would place him in the prominent position of shaping policy on topics from data mining to the department’s planning for “what if” scenarios far off in the future. It also could include evaluating existing department functions for efficiency and creating a national strategy to prevent terrorists from entering the United States. The nomination, announced Wednesday, is part of a sweeping reorganization of the department that Secretary Michael Chertoff announced Wednesday. “Creation of a DHS policy shop has been suggested by members of Congress, (former Secretary Tom Ridge), and numerous outside experts,” Chertoff said. “Now is the time to make this a reality.” Baker is currently a partner at the Steptoe and Johnson law firm--which counts many technology companies as clients--and has been an important but polarizing fixture in many privacy debates during the last 15 years. Baker served as the general counsel of the National Security Agency--the bane of many civil libertarians--during the early 1990s. “For the civil liberties community, this could be a troubling appointment,” said Marc Rotenberg, director of the Electronic Privacy Information Center. “Stu Baker often stood on the other side of important national debates on protecting privacy and preserving open government.” [Editor: I don’t share Marc’s concerns. I find Stewart to be a careful, thoughtful, and well-informed lawyer who also possesses rarer attributes: he’s open-minded and an excellent listener. For me, he’s the ideal person for this new position. I *AM* sad that he’ll no longer be able to concoct the snappy headlines I’ve come to love in Steptoe & Johnson’s E-Commerce Law Week report!] http://news.com.com/2100-7348_3-5787520.html


**** RESOURCES ****
EFF: LEGAL GUIDE FOR BLOGGERS (8 June 2005) -- Like all journalists and publishers, bloggers sometimes publish information that other people don’t want published. You might, for example, publish something that someone considers defamatory, republish an AP news story that’s under copyright, or write a lengthy piece detailing the alleged crimes of a candidate for public office. The difference between you and the reporter at your local newspaper is that in many cases, you may not have the benefit of training or resources to help you determine whether what you’re doing is legal. And on top of that, sometimes knowing the law doesn’t help - in many cases it was written for traditional journalists, and the courts haven’t yet decided how it applies to bloggers. But here’s the important part: None of this should stop you from blogging. Freedom of speech is the foundation of a functioning democracy, and Internet bullies shouldn’t use the law to stifle legitimate free expression. That’s why EFF created this guide, compiling a number of FAQs designed to help you understand your rights and, if necessary, defend your freedom. To be clear, this guide isn’t a substitute for, nor does it constitute, legal advice. Only an attorney who knows the details of your particular situation can provide the kind of advice you need if you’re being threatened with a lawsuit. The goal here is to give you a basic roadmap to the legal issues you may confront as a blogger, to let you know you have rights, and to encourage you to blog freely with the knowledge that your legitimate speech is protected. http://www.eff.org/bloggers/lg/

A MODEL REGIME OF PRIVACY PROTECTION (by Daniel Solove, GW Law School, and Chris Hoofnagle, EPIC) -- Privacy protection in the United States has often been criticized, but critics have too infrequently suggested specific proposals for reform. Recently, there has been significant legislative interest at both the federal and state levels in addressing the privacy of personal information. This was sparked when ChoicePoint, one of the largest data brokers in the United States with records on almost every adult American citizen, sold data on about 145,000 people to fraudulent businesses set up by identity thieves. Other companies announced security breaches, including LexisNexis, from which personal information about 32,000 people was improperly accessed. Senator Schumer criticized Westlaw for making available to certain subscribers personal information including Social Security Numbers (SSNs). In the aftermath of the ChoicePoint debacle and other major information security breaches, both of us have been asked by Congressional legislative staffers, state legislative policymakers, journalists, academics, and others about what specifically should be done to better regulate information privacy. In response to these questions, we believe that it is imperative to have a discussion of concrete legislative solutions to privacy problems. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=699701

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.