Saturday, April 01, 2017

MIRLN --- 12 March – 1 April 2017 (v20.05)

MIRLN --- 12 March - 1 April 2017 (v20.05) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | RESOURCES | LOOKING BACK | NOTES

France drops electronic voting for citizens abroad over cybersecurity fears (Fortune, 6 March 2017) - France's government has dropped plans to let its citizens abroad vote electronically in legislative elections in June because of concern about the risk of cyber attacks, the Foreign Ministry said on Monday. The National Cybersecurity Agency believed there was an "extremely high risk" of cyber attacks. "In that light, it was decided that it would be better to take no risk that might jeopardise the legislative vote for French citizens residing abroad," the ministry said in a statement. Since 2012, French citizens abroad had been allowed to vote electronically in legislative elections, but not in the presidential vote. France will elect a new president in a two-round ballot in April and May.

top

DHS finalizing best practices for notifying victims of major cyber breaches (Federal News Radio, 6 March 2017) - The Homeland Security Department is finalizing best practices that agencies, state and local governments and other organizations involved in a cyber breach can use to notify victims. The guidance lends suggestions on the decision-making process for notifying impacted individuals, preparing and delivering notices, concerns about "over-notifying" and additional support for victims. The DHS Data Privacy and Integrity Advisory Committee drafted the document after former DHS Chief Privacy Officer Karen Neuman asked the committee in September 2015 to develop written best practices for notifying data breach victims. The committee made minor changes to and approved a final draft of best practices at a committee meeting Feb. 21.

top

Home Depot to pay $25M in breach settlement (SC Magazine, 10 March 2017) - Following a massive breach, retailer Home Depot has agreed to pay off a settlement of $25 million for damages resulting from the incursion in 2014 that exposed personal information of more than 50 million customers. Hackers managed to infiltrate the chain store's self check-out terminals to purloin email and credit card data Under terms of the agreement, Home Depot also must improve its cybersecurity implementations, including tighter oversight of its vendors. Home Depot is already out of pocket some $134.5 million which it paid in compensation to card brands and financial institutions. As well, it agreed last year to compensate affected customers to the tune of $19.5 million. The cost of the breach is currently running around $179 million, based on figures in court documents, Fortune reported. But, that figure is expected to rise considerably factoring in legal fees and other charges.

top

Judge says cops can search BitTorrent shared files without a warrant (Motherboard, 10 March 2017) - A judge in Baton Rouge, Louisiana, has ruled that an alleged child pornographer had no expectation of privacy in the files he shared via BitTorrent because those files were accessible to anyone on the popular peer-to-peer file-sharing network. In 2015, a police detective in Louisiana used a piece of software called Torrential Downpour, which is sold exclusively to law enforcement, to scan the BitTorrent network for child pornography. That's how the cops found Justin Landry, a 36-year-old from Prairieville, who allegedly had videos of children being raped on his BitTorrent shared folder, which allows users to make their own files available for download to others on the internet. Judge John W. deGravelles, of the United States District Court for the Middle District in Baton Rouge ruled on Thursday that the undercover cop investigating the case didn't need a warrant to search Landry's files, because Landry wasn't protected by the 4th Amendment's prohibition against unreasonable search and seizure when it came to the videos and pictures he was sharing on BitTorrent. "Files which an individual voluntarily places in a shared folder on a peer-to-peer network are considered publicly available," the judge wrote in the ruling, which denied Landry's request to suppress the evidence gathered in the search, and was spotted by USA Today investigative reporter Brad Heath.

top

- and -

Microsoft pulls then revives Docs.com search after complaints of exposed sensitive files (ZDnet, 26 March 2017) - Microsoft has quietly removed a feature on its document sharing site Docs.com that allowed anyone to search through millions of files for sensitive and personal information. Users had complained over the weekend on Twitter that anyone could use the site's search box to trawl through publicly-accessible documents and files stored on the site, which were clearly meant to remain private. Among the files reviewed by ZDNet, and seen by others who tweeted about them , included password lists, job acceptance letters, investment portfolios, divorce settlement agreements, and credit card statements -- some of which contained Social Security and driving license numbers, dates of birth, phone numbers, and email and postal addresses. The company removed the site's search feature late on Saturday, but others observed that the files were still cached in Google's search results, as well as Microsoft's own search engine, Bing.

top

Malware found preinstalled on 38 Android phones used by 2 companies (ArsTechnica, 10 March 2017) - A commercial malware scanner used by businesses has recently detected an outbreak of malware that came preinstalled on more than three dozen Android devices. An assortment of malware was found on 38 Android devices belonging to two unidentified companies. This is according to a blog post published Friday by Check Point Software Technologies, maker of a mobile threat prevention app. The malicious apps weren't part of the official ROM firmware supplied by the phone manufacturers but were added later somewhere along the supply chain. In six of the cases, the malware was installed to the ROM using system privileges, a technique that requires the firmware to be completely reinstalled for the phone to be disinfected. Most of the malicious apps were info stealers and programs that displayed ads on the phones. One malicious ad-display app, dubbed "Loki," gains powerful system privileges on the devices it infects. Another app was a mobile ransomware title known as "Slocker," which uses Tor to conceal the identity of its operators.

top

Facebook says police can't use its data for 'surveillance' (WaPo, 13 March 2017) - Facebook is cutting police departments off from a vast trove of data that has been increasingly used to monitor protesters and activists. The move, which the social network announced Monday, comes in the wake of concerns over law enforcement's tracking of protesters' social media accounts in places such as Ferguson, Mo., and Baltimore. It also comes at a time when chief executive Mark Zuckerberg says he is expanding the company's mission from merely "connecting the world" into friend networks to promoting safety and community. Although the social network's core business is advertising, Facebook, along with Twitter and Facebook-owned Instagram, also provides developers access to users' public feeds. The developers use the data to monitor trends and public events. For example, advertisers have tracked how and which consumers are discussing their products, while the Red Cross has used social data to get real-time information during disasters such as Hurricane Sandy. But the social networks have come under fire for working with third parties who market the data to law enforcement. Last year, Facebook, Instagram and Twitter cut off access to Geofeedia, a start-up that shared data with law enforcement, in response to an investigation by the American Civil Liberties Union. The ACLU published documents that made references to tracking activists at protests in Baltimore in 2015 after the death of a black man, Freddie Gray, while in police custody and also to protests in Ferguson, Mo., in 2014 after the police shooting of Michael Brown, an unarmed black 18-year-old. On Monday, Facebook updated its instructions for developers to say that they cannot "use data obtained from us to provide tools that are used for surveillance." The company also said, in an accompanying blog post, that it had kicked other developers off the platform since it had cut ties with Geofeedia.

top

Phone searches now default mode at the border; more searches last month than in all of 2015 (TechDirt, 14 March 2017) - The Constitution -- which has always been malleable when national security interests are in play -- simply no longer applies at our nation's borders. Despite the Supreme Court's finding that cell phone searches require warrants, the DHS and CBP have interpreted this to mean it doesn't apply to searches of devices entering/leaving the country. For the past 15 years, the government has won 9/10 constitutional-violation edge cases if they occurred within 100 miles of our borders -- a no man's land colloquially referred to as the "Constitution-free zone." But the pace of device searches has increased exponentially over the last couple of years. The "border exception" is no longer viewed as an "exception" -- something to be deployed only when customs officers had strong suspicions about a person or their devices. Now, it's the rule, as NBC News reports: Data provided by the Department of Homeland Security shows that searches of cellphones by border agents has exploded, growing fivefold in just one year, from fewer than 5,000 in 2015 to nearly 25,000 in 2016. According to DHS officials, 2017 will be a blockbuster year. Five-thousand devices were searched in February alone, more than in all of 2015.

top

20,000 worldclass university lectures made illegal, so we irrevocably mirrored them (LBRY, 15 March 2017) - Today, the University of California at Berkeley has deleted 20,000 college lectures from its YouTube channel. Berkeley removed the videos because of a lawsuit brought by two students from another university under the Americans with Disabilities Act. We copied all 20,000 and are making them permanently available for free via LBRY. This makes the videos freely available and discoverable by all, without reliance on any one entity to provide them (even us!). The full catalog is over 4 TB and will be synced over the next several days. Until LBRY launches to the public in April, the videos are only accessible to technical users via the command line. If you already have access to LBRY, go to lbry://ucberkeley to see the full catalog. If you want to be notified as soon as the videos are made public to everyone, sign up here . If you're command-line-capable but new to LBRY, follow this guide , then access lbry://ucberkeley . The vast majority of the lectures are licensed under a Creative Commons license that allows attributed, non-commercial redistribution. The price for this content has been set to free and all LBRY metadata attributes it to UC Berkeley. When publishing the lectures to LBRY, the content metadata is written to a public blockchain, making it permanently public and robust to interference. Then, the content data itself is hosted via a peer-to-peer data network that offers economic incentives to ensure the data remains viable. This is superior to centralized or manual hosting, which is vulnerable to technical failure or other forms of attrition. [ see also , 'No plans' to delete free content (InsideHigherEd, 14 March 2017)]

top

U.S. judge rejects Google email scanning settlement (Reuters, 16 March 2017) - A federal judge rejected Google's proposed class-action settlement with non-Gmail users who said it illegally scanned their emails to Gmail users to create targeted advertising. In a decision on Wednesday night, U.S. District Judge Lucy Koh in San Jose, California, said it was unclear that the accord, which provided no money for plaintiffs but up to $2.2 million in fees and expenses for their lawyers, would ensure Google's compliance with federal and state privacy laws. Koh called the proposed disclosure notice inadequate. She said this was because it did not clearly reveal any technical changes that Google would make, or that Google scans non-Gmail users' emails to create ads for Gmail users. The judge also said the notice did not make clear that Google could still extract data for the "dual purpose" of creating targeted ads and detecting spam and malware, and then use that data once emails went into storage after being transmitted. "In sum, based on the parties' current filings, the court cannot conclude that the settlement is fundamentally fair, adequate, and reasonable," Koh wrote.

top

- and -

Google starts flagging offensive content in search results (USA Today, 16 March 2017) - With growing criticism over misinformation in search results, Google is taking a harder look at potentially "upsetting" or "offensive" content, tapping humans to aid its computer algorithms to deliver more factually accurate and less inflammatory results. The humans are Google's 10,000 independent contractors who work as what Google calls quality raters. They are given searches based on real queries to score the results, and they operate based on guidelines provided by Google. On Tuesday they were handed a new one: to hunt for "Upsetting-Offensive" content such as hate or violence against a group of people, racial slurs or offensive terminology, graphic violence including animal cruelty or child abuse or explicit information about harmful activities such as human trafficking, according to guidelines posted by Google. The goal: to steer people with queries such as "did the Holocaust happen" to trustworthy websites and not to websites that engage in falsehoods or hate speech. How it works: Google, for example, advises its quality raters that a search result from white supremacist website Stormfront that denies the Holocaust happened should be flagged as upsetting or offensive content while a result from the History Channel describing what happened during the Holocaust should not. Quality raters don't have the ability to change how search results are ranked but feedback from these contractors is used by engineers and machine learning systems to improve search results, according to Google. It declined to comment on the new guideline.

top

Blockchain & corporate records: DGCL amendments would open the door (Corporate Counsel, 17 March 2017) - Posted in our "Blockchain" Practice Area , this Cooley memo notes that this year's proposed DGCL amendments would grant statutory authority for the use of "blockchain" or "distributed ledger" technology for the administration of corporate records. Last year, Broc blogged about a possible move by Delaware in this direction. Blockchain technology allows for the creation of an "open ledger" shared among a network of participants, instead of relying on a single, central ledger. Information is stored in "blocks" that record all network transactions and permit the ownership and existence of assets to be independently validated. Advocates of the technology see great potential for using it to address the shortcomings of the current stock transfer and record-keeping process. The amendments would allow a Delaware corporation to rely on the contents of a distributed ledger as its stock ledger. But the memo points out that the distributed ledger must meet several requirements: * * *

top

- and -

Treatment of bitcoin under US property law (Perkins Coie whitepaper, 29 March 2017) - In this recently published Perkins Coie whitepaper, the authors analyze the treatment of bitcoin under applicable U.S. property law. The authors conclude that property interests should exist in bitcoin under such law, and that multiple sources of persuasive authority provide additional support for that conclusion. The paper is divided into 5 parts: (1) Treatment of bitcoin under U.S. state property law - an illustrative analysis using California law; (2) Scholarly consideration of bitcoin ownership rights under property law generally; (3) Treatment of bitcoin as property under other U.S. legal regimes; (4) Possible challenges to treating bitcoin as property; and (5) Property interest in bitcoins held in custody. Each part offers an in-depth analysis of legal issues. For example, under the discussion of property interests in bitcoins held in custody, the authors discuss the differences between specific and general deposits and how these concepts could be applied to deposited bitcoin in a custodial arrangement.

top

Behind Booz Allen's effort to get carmakers to work together against hackers (WaPo, 19 March 2017) - As the idea of a mass-marketed driverless car nudges closer to reality, automakers are increasingly coming to terms with the need to address the threat that onboard technology could be targeted by hackers. So far there has not been a catastrophic attack, but the growing array of potential connections for cars to the Internet - and at least one hacking-related recall - have pushed the industry toward taking action. One company that sees a potentially lucrative new market is McLean, Va.-based Booz Allen Hamilton, whose employees have long teamed with the intelligence community on classified cybersecurity work. The 103-year-old management and technology consulting firm has been tapped by an auto industry trade group to set up a system for companies to share potential vulnerabilities, an operation that is being run out of Booz Allen's new innovation center in downtown Washington. Booz Allen said that nearly all major car manufacturers are working with the Automotive Information Sharing and Analysis Center, known as Auto-ISAC. The chief challenge is reaching out to the vast network of suppliers that provide parts for what is coming to be called "the connected car" - components of the modern automobile that send and/or receive information over the Internet. That list is surprisingly long. Some bumpers and engine parts have sensors that communicate with other parts of the car or with other automobiles. Even tires have small pressure sensors, which security researchers have used to take control of other parts of the car. Taking inventory of all these possible access points and understanding their potential vulnerabilities is likely to become increasingly important. Last month, seven more suppliers said they were joining the program: Bosch Mobility Solutions, Cooper Standard, Honeywell, Hyundai, Lear Corp., LG Electronics, NXP Semiconductors, and Japanese manufacturer Sumitomo Electric Industries. All of them produce electronic parts. Bosch makes car systems that communicate electronically from one vehicle to the next, as well as vehicle safety systems. Cooper Standard makes fuel and brake lines, and Hyundai is working on self-driving car systems.

top

Hacking tools get peer reviewed, too (The Atlantic, 20 March 2017) - In September 2002, less than a year after Zacarias Moussaoui was indicted by a grand jury for his role in the 9/11 attacks, Moussaoui's lawyers lodged an official complaint about how the government was handling digital evidence. They questioned the quality of the tools the government had used to extract data from some of the more than 200 hard drives that were submitted as evidence in the case-including one from Moussaoui's own laptop. When the government fired back, it leaned on a pair of official documents for backup: two reports produced by the National Institute of Standards and Technology (NIST) that described the workings of the software tools in detail. The documents showed that the tools were the right ones for extracting information from those devices, the government lawyers argued, and that they had a track record of doing so accurately. In September 2002, less than a year after Zacarias Moussaoui was indicted by a grand jury for his role in the 9/11 attacks, Moussaoui's lawyers lodged an official complaint about how the government was handling digital evidence. They questioned the quality of the tools the government had used to extract data from some of the more than 200 hard drives that were submitted as evidence in the case-including one from Moussaoui's own laptop. When the government fired back, it leaned on a pair of official documents for backup: two reports produced by the National Institute of Standards and Technology (NIST) that described the workings of the software tools in detail. The documents showed that the tools were the right ones for extracting information from those devices, the government lawyers argued, and that they had a track record of doing so accurately. In addition to setting standards for digital evidence-gathering, the reports help users decide which tool they should use, based on the electronic device they're looking at and the data they want to extract. They also help software vendors correct bugs in their products. Today, the CFTT's decidedly retro webpage -emblazoned with a quote from an episode of Star Trek: The Next Generation-hosts dozens of detailed reports about various forensics tools. Some reports focus on tools that recover deleted files, while others cover "file carving," a technique that can reassemble files that are missing crucial metadata. * * *

top

Bill would compel firms to say if cybersec expert sits on board (BankInfoSecurity, 20 March 2017) - Legislation introduced in the Senate would require publicly traded companies to disclose to regulators whether any members of their boards of directors have cybersecurity expertise. The Cybersecurity Disclosure Act of 2017 , or S. 536, would not require companies to have a cybersecurity expert on their boards. Instead, it would require them to explain in its filings with the Securities and Exchange Commission whether such expertise exists on their boards and, if not, why this expertise is unnecessary because of other steps taken by the company. The bill's sponsors - Democrats Mark Warner of Virginia and Jack Reed of Rhode Island and Republican Susan Collins of Maine - characterize the legislation as a consumer- and shareholder-protection measure. * * * According to a 2015 report published by the Georgia Institute of Technology , fewer than one-quarter of boards of directors had a member with cybersecurity expertise. The report's author, Jody Westby, says she believes that percentage likely has not changed much since the report was published.

top

Google vows to fight search warrant seeking the names of everyone who Googled crime victim (ABA Journal, 20 March 2017) - Google says it will fight a search warrant seeking information about anyone who searched the name of a financial crime victim on the search engine in December and early January. Judge Gary Larson of Hennepin County, Minnesota, issued the warrant in February, report the Minneapolis Star Tribune , Ars Technica and TonyWebster.com , which was first to publicize the warrant. Police in Edina, Minnesota, told the judge they found that a fake photo used in a phony passport was available through Google images, but not through Yahoo or Bing. The fraudster used the passport to obtain $28,500 through a line of credit with the crime victim's credit union. The warrant application is here . The photo on the passport wasn't the crime victim's image, but it was an image of someone who is similar in age. Police believe the fraudster believed the photo he or she obtained was that of the victim. The fraudster transferred the line of credit money into the victim's savings account, and then into another account at Bank of America. Police want the internet address for people conducting the search, as well as their Social Security numbers and account and payment information. Police obtained the search warrant from the judge after Google objected to an administrative subpoena seeking the information.

top

GitHub now lets its workers keep the IP when they use company resources for personal projects (Quartz, 21 March 2017) - If it's on company time, it's the company's dime. That's the usual rule in the tech industry-that if employees use company resources to work on projects unrelated to their jobs, their employer can claim ownership of any intellectual property (IP) they create. But GitHub is throwing that out the window. Today the code-sharing platform announced a new policy , the Balanced Employee IP Agreement (BEIPA). This allows its employees to use company equipment to work on personal projects in their free time, which can occur during work hours, without fear of being sued for the IP. As long as the work isn't related to GitHub's own "existing or prospective" products and services, the employee owns it. * * * GitHub's new agreement doesn't explicitly state that employees can use company time to develop their own IP, but does say employees can own any work they produce in their "free time." According to Mike Linksvayer, head of open source policy at GitHub, that can include downtime during work hours. As long as the work doesn't step on the company's toes, Linksvayer said, "we don't want to restrain creativity if it's not something we're interested in."

top

New paper on encryption workarounds (Bruce Schneier, 22 March 2017) - I have written a paper with Orin Kerr on encryption workarounds. Our goal wasn't to make any policy recommendations. (That was a good thing, since we probably don't agree on any.) Our goal was to present a taxonomy of different workarounds, and discuss their technical and legal characteristics and complications. Abstract: The widespread use of encryption has triggered a new step in many criminal investigations: the encryption workaround. We define an encryption workaround as any lawful government effort to reveal an unencrypted version of a target's data that has been concealed by encryption. This essay provides an overview of encryption workarounds. It begins with a taxonomy of the different ways investigators might try to bypass encryption schemes. We classify six kinds of workarounds: find the key, guess the key, compel the key, exploit a flaw in the encryption software, access plaintext while the device is in use, and locate another plaintext copy. For each approach, we consider the practical, technological, and legal hurdles raised by its use. The remainder of the essay develops lessons about encryption workarounds and the broader public debate about encryption in criminal investigations. First, encryption workarounds are inherently probabilistic. None work every time, and none can be categorically ruled out every time. Second, the different resources required for different workarounds will have significant distributional effects on law enforcement. Some techniques are inexpensive and can be used often by many law enforcement agencies; some are sophisticated or expensive and likely to be used rarely and only by a few. Third, the scope of legal authority to compel third-party assistance will be a continuing challenge. And fourth, the law governing encryption workarounds remains uncertain and underdeveloped. Whether encryption will be a game-changer or a speed bump depends on both technological change and the resolution of important legal questions that currently remain unanswered. The paper is finished, but we'll be revising it once more before final publication. Comments are appreciated.

top

Walmart's Vudu app now converts your physical movies to digital for $2 each (TechCrunch, 23 March 2017) - Want to build a movie library without having to re-purchase all the DVDs and Blu-rays you already purchased? Walmart's streaming video service Vudu has you covered, with a new feature available via its iPhone and Android mobile apps. The new "Disc-to-Digital" feature allows users to scan the barcode on the case for their DVD or Blu-Ray movies, pay a $2 per movie fee for the transfer, and optionally upgrade DVD titles to HD quality for $5 per title. It's a smart feature that offers a deep discount to users versus buying digital copies of these movies all over again, and the upgrade option is still cheaper than it'll be in most cases to buy a new HD-quality copy of a film. The service is available for around 8,000 movies from a variety of studios, including Paramount, Sony, Twentieth Century Fox, Universal and Warner Bros., and Walmart says more movies will be added to the library over time, too. Digitized movies are loaded into a user's library automatically, and then made available wherever they can access the Vudu service. There's a catch that prevents you from just running around scanning all the DVDs and Blu-rays you can find, however: The Disc-to-Digital option is only available when the app can determine via geolocation that it's at the user's home billing address, so kill that plan to hop over to Best Buy's video section before it develops any further.

top

Amazon will collect sales taxes nationwide on April 1 (CNBC, 24 March 2017) - Amazon , the online merchandise juggernaut, will collect sales taxes from all states with a sales tax starting April 1. Tax-free shopping will be over as of next month in Hawaii, Idaho, Maine and New Mexico, the four remaining holdouts. Since the beginning of this year, Amazon has added a number of states to its roster of jurisdictions where it collects sales taxes . After April, the only states in which Amazon won't collect taxes are Alaska, Delaware, Oregon, Montana and New Hampshire. These five states don't have sales levies.

top

Court says posting Georgia's official annotated laws is not fair use, and thus infringing (TechDirt, 27 March 2017) - We've written a number of times about Carl Malamud and his organization Public.Resource.org, a nonprofit that focuses on making the world's laws more readily accessible to the people governed by those laws. You'd think that people would be excited about this, but instead, Carl just keeps getting sued. All the way back in 2013, the state of Georgia first threatened Carl for daring to publish online the "Official Code of Georgia Annotated." Two years later the state did, in fact, sue Carl for copyright infringement . The case is, at least somewhat tricky and nuanced -- even if it shouldn't be. The key issue is the annotations and other additions to the official laws created by the legislature (the state of Georgia claims that "names of titles, chapter, articles, parts and subparts, history lines, editor notes, Code Commission notes, annotations, research references, cross-references, indexes and other such materials" are all covered by copyright). Obviously, it's crazy to think the underlying law itself is covered by copyright and unpublishable, but this has to focus on the annotations -- which are the various notes and links to relevant case law that add important context to the code itself. As people studying the law quickly learn, "the law" is not just the regulations written down by legislators, but also the relevant caselaw that interprets the laws and sets key standards and makes decisions that influence what the written code actually means. I don't think anyone disagrees that a private party who develops useful and creative works as annotations could potentially hold a copyright on the creative elements of that work (merely listing relevant cases, probably not, but a deeper explanation, sure...). And here, these annotations are developed by a private company: LexisNexis. The issue is the "official" part. Under contract with the state, LexisNexis creates the annotations, gets the copyright, and then assigns the copyright to the state of Georgia on those annotations, with Georgia releasing it as "the Official Code of Georgia Annotated." Also, as noted above, it's not just the "annotations" here -- but as the state claims, the "Code Commission" notes. That seems like fairly relevant information created by the government. Either way, the state of Georgia views the entire "Official Code of Georgia Annotated" as its one true source of law, and it's not available to the public. While the state has responded that (via LexisNexis) it does offer a website with the unannotated code, that website requires that you agree to LexisNexis' overly broad terms and conditions, which include all sorts of crazy demands, including insisting that if they ask you not to link to them, you have to stop linking. Also, even though this is Georgia's state laws, you agree that any dispute over the website will be in a New York jurisdiction. Oh, and the actual website with the law is basically unusable. Malamud and his legal team argued that (1) due to the nature of this odd relationship, the work cannot be covered by copyright and (2) that, if it was covered by copyright, republishing this annotated code was fair use. Unfortunately Judge Richard Story, in the federal district court in Atlanta, has rejected both these arguments and found that the posting of the work was infringing.

top

Apple finally approved an app for tracking drone strikes, then immediately deleted it (Mashable, 28 March 2017) - Five years ago, Josh Begley , a data artist and editor at The Intercept , created a straightforward news app for iOS. It sent a push notification to your device each time a U.S. drone strike was reported by a news outlet. There's a map that shows you where the drone strikes occurred and a log that keeps track of each one. That's it. No pictures, no interviews. And yet, it was censored by Apple for years. Begley attempted to bring Metadata+, which was originally called Drones+, to the App Store a dozen times. It finally became available for download on Tuesday, and then was abruptly removed again five hours later. Begley received an email from Apple Tuesday afternoon, notifying him that his app was removed for containing content that "many users would find objectionable."

top

UW professor: The information war is real, and we're losing it (Seattle Times, 29 March 2017) - It started with the Boston marathon bombing, four years ago. University of Washington professor Kate Starbird was sifting through thousands of tweets sent in the aftermath and noticed something strange. Too strange for a university professor to take seriously. "There was a significant volume of social-media traffic that blamed the Navy SEALs for the bombing," Starbird told me the other day in her office. "It was real tinfoil-hat stuff. So we ignored it." Same thing after the mass shooting that killed nine at Umpqua Community College in Oregon: a burst of social-media activity calling the massacre a fake, a stage play by "crisis actors" for political purposes. "After every mass shooting, dozens of them, there would be these strange clusters of activity," Starbird says. "It was so fringe we kind of laughed at it. "That was a terrible mistake. We should have been studying it." Starbird is in the field of "crisis informatics," or how information flows after a disaster. She got into it to see how social media might be used for the public good, such as to aid emergency responders. Starbird argues in a new paper , set to be presented at a computational social-science conference in May , that these "strange clusters" of wild conspiracy talk, when mapped, point to an emerging alternative media ecosystem on the web of surprising power and reach. There are dozens of other conspiracy-propagating websites such as beforeitsnews.com, nodisinfo.com and veteranstoday.com. Starbird cataloged 81 of them, linked through a huge community of interest connected by shared followers on Twitter, with many of the tweets replicated by automated bots. [Starbird's paper is here .]

top

Cybersecurity guidance for law firms is nothing to argue about (BNA, 30 March 2017) - Lawyers are the gatekeepers of client information including corporate clients put great trust in-and spend countless dollars on-both their inside and outside counsel to protect confidential communications and trade secrets. Corporate intellectual property and confidential communications aren't just valuable to organizations but also to hackers. It is one of the reasons why companies tell their corporate counsel that cybersecurity "chief concerns" when sharing sensitive data with their attorneys, according recent data security guidance from the Association of Corporate Counsel (ACC). The aim of the guidance is to help in-house counsel use data security controls when interacting with outside counsel and other third-party vendors, the report said. The guidelines for "outside counsel who have access to sensitive company data" encompass topics such as "information retention/return/destruction, data handling and encryption, data breach reporting, physical security, employee background screening, and cyber liability insurance," the ACC said in a statement. For example, the guidance calls for the use of the encryption solutions for data at-rest, data transmitted over non-secure channels and mobile devices certified against the National Institute of Standards and Technology's (NIST) Federal Information Processing Standard (FIPS) 140-2. The guidelines will put in-house counsel and outside counsel in the position to take "the lead on sharing established best practices to promote data security," Amar D. Sarway, vice president and chief legal strategist at ACC said in a statement.

top

RESOURCES

Law, Virtual Reality, and Augmented Reality (Mark Lemley and Eugene Volokh, 17 March 2017) - Abstract: Virtual Reality (VR) and Augmented Reality (AR) are going to be big -- not just for gaming but for work, for social life, and for evaluating and buying real-world products. Like many big technological advances, they will in some ways challenge legal doctrine. In this Article, we will speculate about some of these upcoming challenges, asking: (1) How might the law treat "street crimes" in VR and AR -- behavior such as disturbing the peace, indecent exposure, deliberately harmful visuals (such as strobe lighting used to provoke seizures in people with epilepsy), and "virtual groping"? Two key aspects of this, we will argue, are the Bangladesh problem (which will make criminal law very hard to practically enforce) and technologically enabled self-help (which will offer an attractive alternative protection to users, but also a further excuse for real-world police departments not to get involved). (2) How might the law handle tort lawsuits, by users against users, users against VR and AR environment operators, outsiders (such as copyright owners whose works are being copied by users) against users, and outsiders against the environment operators? (3) How might the law treat users' alteration of other users' avatars, or creation of their own avatars that borrow someone else's name and likeness? (4) How might privacy law deal with the likely pervasive storage of all the sensory information that VR and AR systems present to their users, and that they gather from the users in the course of presenting it? (5) How might these analyses reflect on broader debates even outside VR and AR, especially order without law and the speech-conduct distinction?

top

Fishman on Music as a Matter of Law (Harvard Law Review, March 2017) - Joseph Fishman, Vanderbilt University Law School, is publishing Music as a Matter of Law in volume 131 of the Harvard Law Review. Here is the abstract: What is a musical work? Philosophers debate it, but for judges the answer has long been simple: music means melody. Though few recognize it today, that answer goes all the way back to the birth of music copyright litigation in the nineteenth century. Courts adopted the era's dominant aesthetic view identifying melody as the site of originality and, consequently, the litmus test for similarity. Surprisingly, music's single-element test has persisted as an anomaly within the modern copyright system, where typically multiple features of eligible subject matter are eligible for protection. Yet things are now changing. Recent judicial decisions are beginning to break down the old definitional wall around melody, looking elsewhere within the work to find protected expression. Many have called this increasing scope problematic. This Article agrees-but not for the reason that most people think. The problem is not, as is commonly alleged, that these decisions are unfaithful to bedrock copyright doctrine. A closer inspection reveals that, if anything, they are in fact more faithful than their predecessors. The problem, rather, is that the bedrock doctrine itself is misguided. Copyright law, unlike patent law, has never shown any interest in trying to increase the predictability of its infringement test, leaving second comers to speculate as to what might or might not be allowed. But the history of music copyright offers a valuable look at a path not taken, an accidental experiment where predictability was unwittingly achieved by consistently emphasizing a single element out of a multi-element work. As a factual matter, the notion that melody is the primary locus of music's value is a fiction. As a policy matter, however, that fiction has turned out to be useful. While its original, culturally-myopic rationale should be discarded, music's unidimensional test still offers underappreciated advantages over the "everything counts" analysis that the rest of the copyright system long ago chose.

top

LOOKING BACK - MIRLN TEN YEARS AGO

(note: link-rot has affected about 50% of these original URLs)

Apple introduced iTunes U (InsideHigherEd, 31 May 2007) -- Apple introduced iTunes U, a new section within its music software where universities can publish lecture audio, promotional videos and other downloadable media for current and prospective students. Top downloads on Wednesday included a "What Is Existentialism?" lecture from the University of California at Berkeley and another called "Technical Aspects of Biofuel Development" at Stanford University. Unlike traditional podcasts, not just anyone can post material to iTunes U - universities control the content, and institutions can sign up to publish their own media relatively easily, according to Chris Bell, Apple's director of worldwide marketing for iTunes. The new initiative to bring content from institutions of higher learning together into a unified interface stemmed in part from a program that began with Stanford in 2005, in which colleges could offer course content available only to their students. iTunes U was developed in collaboration with many of those colleges and universities, Bell added. "It's free to the university, it's free to the end user, and we think it's a great way to take the assets that universities have and really serve the public," he said.

top

Site plans to sell hacks to highest bidder (Washington Post, 12 July 2007) - A Swiss Internet start-up is raising the ire and eyebrows of the computer security community with the launch of an online auction house where software vulnerabilities are sold to the highest bidder. The founders of WabiSabiLabi.com (pronounced wobby-sobby-lobby) say they hope the service presents a legitimate alternative for security researchers who might otherwise be tempted to sell their discoveries to criminals. Several established vulnerability management companies already purchase information about software flaws from researchers, yet the terms of those deals are private and generally set by the companies. Letting all interested parties bid on security vulnerabilities in an "eBay"-style auction assures that researchers receive the fair market value for the work they do in finding the flaws, said Herman Zampariolo, WabiSabiLabi's chief executive.

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, http://www.sans.org/newsletters/newsbites/

4. Aon's Technology & Professional Risks Newsletter

5. Crypto-Gram, http://www.schneier.com/crypto-gram.html

6. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/

7. The Benton Foundation's Communications Headlines

8. Gate15 Situational Update Notifications, http://www.gate15.us/services.html

9. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top

Saturday, March 11, 2017

MIRLN --- 19 Feb - 11 March 2017 (v20.04)

MIRLN --- 19 Feb - 11 March 2017 (v20.04) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | RESOURCES | LOOKING BACK | NOTES

Software helps assemble social media posts from a specific event or point in time (ABA Journal, 1 Feb 2017) - Before he became a trial lawyer (and an advocate on behalf of the wrongfully convicted), Sean MacDonald in Toronto worked as a private investigator. His experiences on both sides of the coin taught him all too well how time-consuming and expensive it could be to locate eyewitnesses months or years after the fact. Then he saw a demo of LifeRaft , a cloud-based program that uses geolocation technology and data mining to monitor social media. It can re-create a scene based on public posts on social media. LifeRaft was marketed primarily toward law enforcement officials to maintain public safety and monitor potential threats. But MacDonald saw other uses. "When I first saw it, it struck me like a bolt of lightning," says MacDonald, a solo practitioner who sits on the board of directors at Innocence Canada. "I knew this would be unbelievably useful for lawyers preparing for trial." Social media contains a potential treasure trove of information. It seems people's first instinct nowadays is to reach for the smartphone while they witness a fight, traffic crash or crime, then log on to spill the details. The problem was trying to comb through all the selfies, pet portraits and other irrelevant information in a quick, cost-effective way. With TrialDrone , which launched in late February 2016, MacDonald thinks lawyers now have the ability to go back in time and see who witnessed an event and what he or she said about it. TrialDrone, a sibling company to LifeRaft that uses the same software, claims to be able to re-create an event by identifying everyone who posts publicly to social media at a given time and location. * * *

top

Judge Gorsuch on copyright and technology (James Grimmelmann, 17 Feb 2017) - I've done a quick pass through Judge Gorsuch's opinions in the fields I know something about (mainly IP and Internet law) and I'm impressed by what I've found. His writing style is designed to make his conclusions sound reasonable and sensible, and in these cases at least, they are. A few highlights: * * *

top

Federal agency begins inquiry into auto lenders' use of GPS tracking (NYT, 19 Feb 2017) - They can figure out when you leave town and see where you parked your car. They can see how many times you went to the grocery store or the health clinic. Auto loans to Americans with poor credit have been booming, and many finance companies, credit unions and auto dealers are using technologies to track the location of borrowers' vehicles in case they need to repossess them. Such surveillance, lenders say, allows them to extend loans to more low- income Americans, knowing that they can easily locate the car. Lenders are also installing devices that enable them to remotely disable a car's ignition after a borrower misses a payment. Now, federal regulators are investigating whether these devices unfairly violate a borrower's' privacy. The auto lender Credit Acceptance Corporation said this month in a securities filing that it had received a civil investigative demand from the Federal Trade Commission asking for its "policies, practices and procedures" related to so-called GPS starter interrupter devices, which are used to disable an ignition. Industry lawyers say the action is part of a broader inquiry by the agency into tracking technologies used in the subprime auto lending market.

top

- and -

If your TV rats you out, what about your car? (Autoblog, 24 Feb 2017) - Vizio, the TV manufacturer, recently had to pay a $2.2-million fine to the FTC recently because it was discovered that its sets were collecting data about viewers' watching habits and then using the information for its own benefit. Last year, it was revealed the Samsung smart TVs were busy listening to what was being said, even if the conversations in question had absolutely nothing with switching the channel away from the Matt LeBlanc Gear. Nowadays, auto manufacturers seem to be tripping over each other pointing out that they offer Apple CarPlay and Google Android Auto. And more recent phenomenon are announcements-from companies including Ford and Hyundai-that they are offering Amazon Alexa capabilities. You talk. It listens. In late January, General Motors said it is releasing a next-generation infotainment software development kit (NGI SDK) to software developers to write apps for GM cars. The NGI SDK includes native Application Program Interfaces (APIs) that allow access to expected things - like oil life and tire pressure and whether lightbulbs are burned out - but unexpected things, as well. Like the presence of passengers in the vehicle. In making the announcement of the NGI SDK, GM pointed out that it has the largest connected fleet on the road, some 12-million vehicles. The company also noted: "From 2015 to 2016, GM has seen data usage by customers increase nearly 200 percent. Mobile app use for GM vehicles also hit an all-time high in 2016, with more than 225 million interactions." Is it not plausible that they know more those interactions than simply the number of them? GM's privacy agreement is like most privacy policies, which boils down to: You use it (the device, software, etc.), you potentially give up a portion of your privacy. * * *

top

- and -

China orders every vehicle in region troubled by ethnic unrest to be fitted with Satnav tracker (Techdirt, 27 Feb 2017) - Techdirt stories on China tend to paint a fairly grim picture of relentless surveillance and censorship, and serve as a warning of what could happen in the West if government powers there are not constrained. But if you want to see how a real dystopian world operates, you need to look at what is happening in the north-western part of China's huge domain. Xinjiang was originally a turkic-speaking land, but the indigenous Uyghur population is increasingly swamped by Chinese-speaking immigrants, which has caused growing unrest. Violent attacks on the Chinese population in the region have led to a harsh crackdown on the Uyghurs, provoking yet more resentment, and yet more attacks. Last November, we noted that the Chinese authorities in Xinjiang were describing censorship circumvention tools as "terrorist software." Now the Guardian reports on an ambitious attempt by the Chinese government to bring in a new kind of surveillance for Xinjiang: Security officials in China's violence-stricken north-west have ordered residents to install GPS tracking devices in their vehicles so authorities are able to keep permanent tabs on their movements. The compulsory measure, which came into force this week and could eventually affect hundreds of thousands of vehicles, is being rolled out in the Bayingolin Mongol Autonomous Prefecture of Xinjiang, a sprawling region that borders Central Asia and sees regular eruptions of deadly violence. The rollout is already underway -- those who refuse to install the trackers will not be allowed to refuel their vehicles * * *

top

Verizon cuts Yahoo deal price by $350 million (CNN, 21 Feb 2017) - Verizon is moving forward with its deal to buy Yahoo, but at a lower price. The two companies have agreed to cut the acquisition price by $350 million following Yahoo's disclosures in recent months of two massive security breaches affecting more than one billion users. Verizon's new price tag for buying Yahoo's core Internet assets is $4.48 billion, all in cash. The deal is expected to close in the second quarter of this year. Verizon and Yahoo have also agreed to split the cost of any legal liabilities resulting from the security breaches. Yahoo has already been hit with multiple lawsuits from customers claiming the company was negligent. The U.S. Senate has also begun probing Yahoo over the breach. [ Polley : SANS' John Pescatore writes : " [This] essentially means Yahoo's failures in security cost the company at least $700M in revenue from the sale and that is on top of the costs they have already incurred in dealing with the breach, which likely at least doubles the impact - a $1.5B hard cost. That will definitely get the attention of Boards of Directors - making this news item a good opportunity for CISOs to advance strategies and plans for changes needed to make sure it doesn't happen to their companies. "]

top

- and -

Yahoo's top lawyer resigns, CEO Marissa Mayer loses bonus in wake of hack (NYT, 1 March 2017) - Yahoo's top lawyer, Ronald S. Bell, has resigned, and its chief executive, Marissa Mayer, lost her 2016 bonus after a board investigation of the 2014 theft of information on more than 500 million user accounts. Senior executives, company lawyers and information security staff were aware of the hack in 2014 and also knew about subsequent attempts to break into the affected accounts in 2015 and 2016, but failed to 'properly comprehend or investigate' the situation, the company's board of directors said in a securities filing on Wednesday. The board "did not conclude that there was an intentional suppression of relevant information." The company's filing, which it said concluded its investigation, avoided naming any individuals responsible for Yahoo's security woes, and it left many important questions unanswered. The board offered no new information about the company's apparent failure to notice a separate theft in 2013 of the account information of one billion users. Mr. Bell, a longtime lawyer at Yahoo, appears to be taking the blame for the company's security failures. Yahoo said he resigned on Wednesday and would receive no payments in connection with his departure. The company's chief information security officer at the time of the 2014 breach, Alex Stamos, left for Facebook in 2015 after repeated battles with Ms. Mayer over security priorities.

top

Appeals court says filming the police is protected by the First Amendment (TechDirt, 21 Feb 2017) - In news that will surprise no one , police officers decided they must do something about someone filming the police department building from across the street. That's where this Fifth Circuit Court of Appeals decision begins: with a completely avoidable and completely unnecessary assertion of government power. Phillip Turner was filming the police department. He was accosted by two officers (Grinalds and Dyess). Both demanded he provide them with identification. He refused to do so. The officers arrested him for "failure to identify," took his camera, and tossed him in the back of a squad car. Given the circumstances of the initial interaction, it's surprising the words "contempt of cop" weren't used on the official police report. * * * First, the court asks whether the right to film police was "clearly established" at the time the incident took place (September 2015). It can't find anything that says it is. * * * The court doesn't leave it there, although it could have. The court notes that there's a circuit split on the issue, but just because the issue's far from decided doesn't mean courts have not recognized the right exists. It points to conclusions reached by the First and Eleventh Circuit Appeals Courts as evidence the right to film police has been acknowledged. Even so, there's not enough clarity on the issue to remove the officers' immunity. * * * This is where the opinion gets interesting. While many judges would leave a trickier, somewhat tangential issue open and unanswered, the Fifth Circuit Appeals Court decides it's time for it to set some precedent: We conclude that First Amendment principles, controlling authority, and persuasive precedent demonstrate that a First Amendment right to record the police does exist , subject only to reasonable time, place, and manner restrictions.

top

The police can't just share the contents of a seized iPhone with other agencies, court rules (Orin Kerr, 21 Feb 2017) - If a police agency gets a search warrant and seizes a target's iPhone, can the agency share a copy of all of the phone's data with other government agencies in the spirit of "collaborative law enforcement among different agencies"? Not without the Fourth Amendment coming into play, a federal court ruled last week in United States v. Hulscher , 2017 WL 657436 (D.S.D. February 17, 2017) . Here's a summary of the new case, together with my reactions. * * *

top

Google's new project aims to clean up comment sections (TechCrunch, 23 Feb 2017) - If you read stuff on the internet (and obviously you do because hi, you're reading a blog) then you know the golden rule: never read the comments. Scrolling past the end of a story is an adventure into a realm of racism, conspiracy theories and ad hominem attacks that will quickly make you lose your faith in humanity. But instead of encountering Godwin's Law in the comments, you might start encountering Google instead. Google's internet safety incubator Jigsaw launched new technology today called Perspective, intended to clean up comment sections. Perspective reviews comments and assigns them a toxicity rating that reflects the likelihood that the comment is intended to be harmful. Jigsaw's goal is to keep people engaged in the conversation, so it assesses "harm" as something that would drive other commenters away. How to interpret and react to a toxicity rating is up to publishers. Jigsaw won't do anything except provide the score, so the comments can be flagged for human review or hidden behind a warning so readers have to click through to see them. Commenters can also be confronted with their own toxicity rating so they can make a choice about whether that's really what they want to say. Media outlets have been struggling to come up with solutions to the comment problem on their own. Outlets like Reuters have deleted their comment sections outright, while BuzzFeed is experimenting with curated comments. The New York Times partnered with Jigsaw to help develop Perspective - the paper receives 11,000 comments per day, which Jigsaw used to feed its machine learning model.

top

Pentagon launches open-source experiment (Nextgov, 24 Feb 2017) - With a new website showcasing federal software code, the Pentagon is the latest government entity to join the open-source movement. The Defense Department this week launched Code.mil, a public site that will eventually showcase unclassified code written by federal employees. Citizens will be able to use that code for personal and public projects. Code written by government employees can be shared with the public because that material usually isn't covered by copyright protections in the U.S., according to the Pentagon. The site, which redirects to code repository GitHub, currently features a draft "open source license agreement" that includes stipulations such as "[i]n places where DoD has no copyright protections in this Work, it is licensed under the terms and conditions in this Agreement and the License as a contract between DoD and You."

top

Why Trump's election scares data scientists (CNN, 25 Feb 2017) - When Donald Trump was elected, most people probably weren't concerned about the future of data. But for some groups, that was top of mind. Data Refuge was founded after the election, with a goal of tracking and safeguarding government data. The volunteer group of hackers, writers, scientists and students collects federal data about climate change in order to preserve the information and keep it publicly accessible. "When things like science are politicized, scientific information will be less accessible," said Dr. Bethany Wiggin, co-director of Data Refuge. "If you can keep knowledge out of the hands of your political opponents, that's an effective win." In the past three months, Data Refuge has hosted 17 events where hundreds of volunteers figure out how to copy and publish research-quality data. The group, which grew out of the Penn Program in Environmental Humanities, also monitors scientific research that depends on government funding because there's concern this could dry up. These fears are stoked by the fact that some content has already been removed from agencies' websites. For instance, ProPublica found that the Energy Information Administration edited an educational website for kids to significantly downplay the negative impacts of coal. The White House also removed all of the data from its portal of searchable federal data. The site previously included data on everything from budgets to climate change to LGBT issues. It now displays a message telling people to: "Check back soon for new data." Additionally, some USDA data on animal testing, puppy mill cruelty and company audits has been completely removed since Trump's inauguration. * * *

top

Top bank executives required to vouch for cyber attack defences (Financial Times, 26 Feb 2017) - Top executives at some of the world's biggest banks and insurers will have to vouch for their companies' resilience to cyber attacks, under tough rules laid down by New York's state regulator. A new regulation, which takes effect on March 1, requires companies supervised by New York's Department of Financial Services to establish and maintain a cyber security programme that can protect consumers' private data and "ensure the safety and soundness" of the state's financial services industry. Executives will be made to submit an annual certification that the company is complying with the various requirements, and agree to notify the DFS of any serious breaches within 72 hours of their discovery. "This has gone further than any other regulation I've seen, and is the most prescriptive," said Joe Nocera, Chicago-based leader of PwC's cyber security practice. * * * Analysts say the protocols are mostly in line with those adopted by the Federal Financial Institutions Examination Council, an inter-agency body that sets uniform standards for examinations by regulators including the Federal Reserve and the Office of the Comptroller of the Currency. But the requirement for an executive to testify that the company's systems are up to scratch, could expose that individual to liability if the company's cyber security programme is later found to be non-compliant. For now, no other US state "comes anywhere close" to New York's level of scrutiny, said Jim Halpert, Washington-based co-chair of the cyber security practice at DLA Piper, a law firm.

top

Open link to file-sharing site was like leaving legal file on a bench, judge says; privilege waived (ABA Journal, 27 Feb 2017) - An insurance company has waived any claim of privilege to materials uploaded to an unprotected file-sharing site, a federal magistrate judge in Virginia ruled earlier this month. U.S. Magistrate Judge Pamela Meade Sargent said in a Feb. 9 decision that the Harleysville Insurance Co. waived its privilege in documents uploaded to a site where they were accessible to anyone who had the hyperlink, according to the ABA BNA Lawyers' Manual on Professional Conduct . "In essence," Sargent wrote, "Harleysville has conceded that its actions were the cyber world equivalent of leaving its claims file on a bench in the public square and telling its counsel where they could find it. It is hard to imagine an act that would be more contrary to protecting the confidentiality of information than to post that information to the world wide web." According to the Lawyers' Manual, the decision "should make lawyers think twice before putting confidential documents in a file-sharing site without password protection." Harleysville was not the only litigant criticized in the opinion. Its opponent also acted improperly, Sargent said, by accessing the drop-box materials and using them without notifying lawyers for Harleysville.

top

American Bar Association to offer cybersecurity insurance to law firms (Cyberscoop, 28 Feb 2017) - After a year which saw multiple law firms end up in the headlines for data breaches, the American Bar Association expanded its insurance program Tuesday to offer cybersecurity coverage . Chubb Limited, the world's largest publicly traded property and casualty insurer, will underwrite the policy. "The American Bar Association has been educating lawyers about cyber security and the risks to their clients and their practices for a number of years. ABA Insurance is a new program though, developed by the Association within the last year to provide members with access to affordable coverage from top-quality carriers," ABA Deputy Executive Director James Dimos told CyberScoop.

top

- and -

Law firms must manage cybersecurity risks (ABA Journal, 1 March 2017) - It's another busy day at the office when you receive an email with an attached memo. You don't remember asking for the memo, but you download the attachment anyway. Alarm bells! It's not an attachment. It's malware that's now infecting your computer and every other computer in your law firm. This was the situation that Jessica Mazzeo and Fran Griesing faced. In July 2016, the computer system for their small Philadelphia firm of 12 lawyers was infected with malware. They contacted Integrated Micro Systems, their outsourced information technology provider. * * * That incident changed the way the law firm dealt with websites, emails and mobile devices. As a small firm, Griesing Law leans on outside providers for help. The firm uses Workshare, a cloud-based program that allows users to send files securely online, and Trend Micro to quarantine suspicious emails. It also made firewall changes to block certain websites from being accessed by employees because of the risk of malware. A new policy was implemented last year on internal email: If the source is unknown or if you're not expecting the email, don't open it. * * * Cybersecurity is evolving. This is more than just a technology issue or an added clause in the retainer agreement-it's the biggest risk that law firms face in 2017. * * * [ Polley : This is a long, thoughtful article, for which I was interviewed. The ABA's Cybersecurity Legal Task Force is working on a 2nd edition of the Cybersecurity Legal Handbook , for publication this summer.]

top

- and -

6 major law firm hacks in recent history (ABA Journal, 1 March 2017) - Law firms have been victims of some of the most damaging hacks in recent history. Here's a list of the major law firm hacks in the past five years: * * * [ Polley : I thought it was unclear how the Mossack Fonseca documents were leaked; the last I remember, it was attributed to a former employee. Not sure I'd call that a "hack".]

top

"Proof Mode" for your smartphone camera (Bruce Schneier, 1 March 2017) - ProofMode is an app for your smartphone that adds data to the photos you take to prove that they are real and unaltered: On the technical front, what the app is doing is automatically generating an OpenPGP key for this installed instance of the app itself, and using that to automatically sign all photos and videos at time of capture. A sha256 hash is also generated, and combined with a snapshot of all available device sensor data, such as GPS location, wifi and mobile networks, altitude, device language, hardware type, and more. This is also signed, and stored with the media. All of this happens with no noticeable impact on battery life or performance, every time the user takes a photo or video. This doesn't solve all the problems with fake photos, but it's a good step in the right direction.

top

Something amazing from JSTOR labs (InsideHigherEd, 2 March 2017) - A quick note: I've been working with an intern to track some research down, but the keywords are slushy and the controlled vocabulary in the databases we're using just hasn't been cutting it. Mostly, we've been able to make some progress by seeing who is citing the articles that seem most relevant, but even that traditional citation-tracing method isn't producing quite as much as I hoped. But then I happened on a nifty new tool today, the JSTOR Labs Text Analyzer , thanks to the kind of serendipity my Twitter community seems to promote. Basically, you upload a document (something you wrote, a text you're reading, an article PDF, a syllabus, even) and . . . something magical happens. The analyzer finds patterns in the text and looks for similar documents. The words used in the pattern appear on one side. There are sliders for how much you want to emphasize some concepts. There's a collection of keywords roughly sorted by type, and you choose which ones are most relevant to your interests or decide which ones aren't of interest. You can even add your own words. If you want your results to emphasize current content, there's a checkbox for that. Results can be limited to the JSTOR content your library subscribes to, or you can search it all to see what you might want to obtain through interlibrary loan. It only surfaces JSTOR content, but that's a lot of good material.

top

The government's secret wiki for intelligence (The Atlantic, 3 March 2017) - During the final weeks of the Obama administration, officials began to worry that the results of ongoing investigations into Russia's election-related hacking might get swept under the rug once President Trump took office. They decided to leave a trail of breadcrumbs for congressional investigators to find later, according to a report from The New York Times . In another age, the paper trail may have taken the form of notes stuffed into a box in a forgotten archive. But this being the 21st century, some of the breadcrumbs were submitted to an online wiki. According to the Times, intelligence officers in various agencies rushed to complete analyses of intelligence about Russian hacking and file the results, at low classification levels, in a secret Wikipedia-like site for intelligence analysts. There, the information would be widely accessible among the intelligence community. That site, called Intellipedia, has been around for more than a decade. It's made up of three different wikis, at different classification levels: one wiki for sensitive but unclassified information, another for secret information, and a third for top secret information. Each wiki can only be accessed by employees in the U.S. intelligence community's 17 agencies who have the appropriate clearance level. Intellipedia was formally launched in 2006, but grew slowly at first. "It was received skeptically by most," said Carmen Medina, the former CIA director for the study of intelligence and one of the first officials to green-light the project. "Analysts were not really rewarded for contributing to Intellipedia." Since then, the wikis have grown steadily. According to a release celebrating the site's second anniversary, the system housed nearly 50,000 articles by March 2008. In January 2014, the National Security Agency responded to a Freedom of Information Act request with the latest statistics: The three domains had just over 269,000 articles, more than 40 percent of which were found on the top secret wiki. (It's not clear whether articles are duplicated across the wikis.)

top

Excellent nominations for CIA GC and DoD GC (John Bellinger on Lawfare, 7 March 2017) - This evening, President Trump nominated Courtney Elwood to be CIA General Counsel and John Sullivan to be DoD General Counsel. These are excellent appointments and good news for the national security law community. Courtney and John are both superb lawyers-both former Supreme Court clerks, for Chief Justice Rehnquist and Justice Souter, respectively-with extensive national security experience in the Bush Administration. The country will be well-served by both of them. * * *

top

Uber's 'Greyball' program puts new focus on legal dept (Inside Counsel, 7 March 2017) - Uber Technologies Inc. has used software to evade law enforcement and public officials in cities where the company faced opposition from regulators, The New York Times reported Friday , and legal ethics professionals said the company may be steering into the wrong lane. While the program may not be illegal, ethics professionals said, it does appear to skirt ethical standards. And if in-house counsel approved the program knowing that Uber would use it to break the law, then disbarment could be in store for the lawyers who signed off on it, they said. The New York Times report said Uber's legal department, led by general counsel Salle Yoo, approved use of the program. "For lawyers, the legal ethics issue is did they approve of the program so that Uber could act illegally?" Wayne State University professor of law Peter Henning said. "That could put a license at risk to practice law."

top

Facebook parking chatbot now turns lawyer helping refugees claim asylum (IBT, 7 March 2017) - A Facebook chatbot called DoNotPay that helped overturn over 160,000 parking fines is now helping refugees claim asylum. The chatbot, which described itself as the "world's first robot lawyer", was created by Stanford student Joshua Browder, designed to provide free legal advice via a user-friendly chat interface. New updates to the chatbot now allow it to help refugees file immigration applications in the US and Canada, as well as aid refugees apply for asylum support. The chatbot asks users a list of questions to determine which application should be filled out for the refugee and to ascertain whether the user is eligible for asylum protection under international law. The chatbot then collects information required for the appropriate application. In case of users based in the UK, the bot helps them fill out an ASF1 form for asylum support, informing them that they are required to file the application in person. Browder claimed that once the application form is filled and sent out the "details are deleted" from his end. However, Browder acknowledged that there are some drawbacks to the Messenger. For instance, it doesn't come with end-to-end encryption, which is now available in most other chat apps. [ Polley : Spotted by MIRLN reader Corinne Cooper - @ucc2]

top

Zero days, thousands of nights (Rand, 9 March 2017) - Zero-day vulnerabilities - software vulnerabilities for which no patch or fix has been publicly released - and their exploits are useful in cyber operations - whether by criminals, militaries, or governments - as well as in defensive and academic settings. This report provides findings from real-world zero-day vulnerability and exploit data that could augment conventional proxy examples and expert opinion, complement current efforts to create a framework for deciding whether to disclose or retain a cache of zero-day vulnerabilities and exploits, inform ongoing policy debates regarding stockpiling and vulnerability disclosure, and add extra context for those examining the implications and resulting liability of attacks and data breaches for U.S. consumers, companies, insurers, and for the civil justice system broadly. The authors provide insights about the zero-day vulnerability research and exploit development industry; give information on what proportion of zero-day vulnerabilities are alive (undisclosed), dead (known), or somewhere in between; and establish some baseline metrics regarding the average lifespan of zero-day vulnerabilities, the likelihood of another party discovering a vulnerability within a given time period, and the time and costs involved in developing an exploit for a zero-day vulnerability. * * * [ Polley : pretty interesting.]

top

RESOURCES

Digital Privacy at the U.S. Border: Protecting the Data On Your Devices and In the Cloud (EFF, 9 March 2017) - The U.S. government reported a five-fold increase in the number of electronic media searches at the border in a single year, from 4,764 in 2015 to 23,877 in 2016. Every one of those searches was a potential privacy violation. Our lives are minutely documented on the phones and laptops we carry, and in the cloud. Our devices carry records of private conversations, family photos, medical documents, banking information, information about what websites we visit, and much more. Moreover, people in many professions, such as lawyers and journalists, have a heightened need to keep their electronic information confidential. How can travelers keep their digital data safe? The U.S. Constitution generally places strong limits on the government's ability to pry into this information. At the U.S. border, however, those limits are not as strong, both legally and practically. As a matter of the law, some legal protections are weaker - a fact EFF is working to change. As a matter of practice, border agents may take a broad view of what they are permitted to do. Border agents may attempt to scrutinize the content stored on your phones, laptops, and other portable electronic devices. They may try to use your devices as portals to access your cloud content, including electronic communications, social media postings, and ecommerce activity. Moreover, agents may seek to examine your public social media postings by obtaining your social media identifiers or handles. As of this writing, the federal government is considering requiring disclosure from certain foreign visitors of social media login credentials, allowing access to private postings and "friend" lists. This guide (updating a previous guide from 2011) helps travelers understand their individual risks when crossing the U.S. border, provides an overview of the law around border search, and offers a brief technical overview to securing digital data.

top

State Data Security Breach Notification Laws (Mintz Levin, 15 Feb 2017) - This chart is for informational purposes only and does not constitute legal advice or opinions regarding any specific facts relating to specific data breach incidents. You should seek the advice of experienced legal counsel when reviewing options and obligations in responding to a particular data security breach. Laws and regulations change quickly in the data security arena. This chart is current as of February 15, 2017.

top

Copyrighted Laws: Enabling and Preserving Access to Incorporated Private Standards (U. Minn. Law Review) - Traditional laws-statutes, judicial opinions, and regulations-are not eligible for copyright protection. This principle is firmly established in over one hundred years of case law, despite the Copyright Code not expressly addressing the eligibility of laws. This has caused little controversy. In the last few decades, however, federal agencies have increasingly given legal force to privately authored copyrighted works by incorporating them verbatim by reference into regulations. The authors of those works continue to exercise their exclusive right to control reproduction and distribution by charging the compliance-seeking public fees to obtain transfer-restricted copies. Concealing legal obligations from the public and controlling access to them with fees and threats of litigation raises significant concerns. This practice does not fit within the case-law analysis of traditional laws because incorporated private standards are copyrighted works that later obtain legal force. With little case law on point and silence from the Copyright Code, this Note examines whether any other copyright doctrines can be used to enable public access to copyrighted works that are subsequently given legal force. This Note argues that none of the proposed copyright doctrines would prevent incorporated copyrighted works from maintaining their copyright. This Note proposes a two-part legislative solution that adds laws to the Copyright Code's subject-matter exclusions and provides a special section for neutralizing the copyright of private works that are subsequently given legal force.

top

LOOKING BACK - MIRLN TEN YEARS AGO

(note: link-rot has affected about 50% of these original URLs)

Insurance company refuses to cover law firm's blog (Computerworld, 22 March 2007) -- A law firm in New Jersey has temporarily halted plans to launch a blog because its insurance company would not cover the blog under an existing malpractice insurance policy. James Paone, a partner at Lomurro, Davison, Eastman and Munoz in Freehold, N.J., said that the firm's insurer -- The Chubb Corp. -- said several weeks ago that it would not add the blog to the existing policy. "We were in the process of beginning to set up a blog, having internal discussions about what areas of law would be the subjects," he said. "We wanted to cover the first base, which is [Chubb's] coverage. Our insurance carrier said [a blog] is not a risk they were interested in insuring. The entire discussion stopped." Paone said his firm contacted Chubb to ask about insurance coverage in case someone tried to sue it over content in the blog. Now, the law firm is in the process of setting up a meeting with Chubb "so we can understand what their rationale is for saying they weren't interested in covering that kind of risk," Paone said. Chubb did not immediately respond to a request for comment.

top

Greece Fines Ericsson Hellas in tapping case (Reuters, 6 Sept 2007 - Greece's privacy watchdog has fined the Greek unit of telecom equipment maker Ericsson more than 7 million euros over a wiretapping scandal that rocked the country last year. In 2006 the Greek government revealed that more than 100 people, including the prime minister, senior ministers, journalists and activists, had their mobile phones tapped for about a year around the Athens 2004 Olympics. "The Hellenic Authority for Information and Communication Security and Privacy (ADAE) decided to fine Ericsson Hellas 7.36 million euros ($10 million) in relation to the wiretap issue," ADAE said in a statement released late on Wednesday. It gave no further details. ADAE has said Ericsson Hellas's equipment was used in the phone tapping. Ericsson Hellas said it planned to appeal the decision. In December 2006 ADAE also fined the Greek unit of Vodafone (VOD.L: Quote, Profile, Research) 76 million euros for a "number of infringements attributed to the company", also without giving details. Vodafone Hellas has rejected the decision, saying it considers the fine illegal and is appealing the decision. The bugged phones were found to have been tapped mostly before and during the Athens Games by unknown eavesdroppers. The case became public after Vodafone Greece informed the government of its concerns when it suspected its equipment was being used. The government went public with the case almost a year after it was informed by Vodafone, prompting questions in the media about whether foreign intelligence services were involved. At the time, the Greek government said Ericsson-supplied software was used to tap phones from June 2004 until March 2005. Calls were relayed to unknown destinations via four mobile phone antennas in central Athens. The bugging stopped when Vodafone Greece discovered the software and removed it from the system. [Editor in 2007: Excellent technical discussion of the yet-unsolved wiretapping techniques employed: http://www.spectrum.ieee.org/jul07/5280 ]

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, http://www.sans.org/newsletters/newsbites/

4. Aon's Technology & Professional Risks Newsletter

5. Crypto-Gram, http://www.schneier.com/crypto-gram.html

6. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/

7. The Benton Foundation's Communications Headlines

8. Gate15 Situational Update Notifications, http://www.gate15.us/services.html

9. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top