Saturday, October 15, 2016

MIRLN --- 25 Sept - 15 Oct 2016 (v19.14)

MIRLN --- 25 Sept - 15 Oct 2016 (v19.14) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | RESOURCES | LOOKING BACK | NOTES

HP inkjet printers refuse to accept third-party ink cartridges after stealth firmware update (Extreme Tech, 20 Sept 2016) - The inkjet printer market has been a ridiculously profitable racket for HP and its ilk for decades, and manufacturers have fought tooth and nail to keep it that way. HP launched the latest salvo in this effort earlier this month, when a six-month-old firmware update suddenly kicked in and locked out third-party ink cartridges. Multiple models in HP's OfficeJet, OfficeJet Pro, and OfficeJet Pro X were all affected, even though none of these models had seen a firmware update in the past six months. The consensus is that HP actually baked this response into the March 2016 update it released, but told no one it was coming. This ensured more people would adopt the firmware and report that it worked without incident. In a statement to the BBC , HP noted that some devices had been updated with this functionality via firmware, while others had shipped with the necessary chips and capabilities from Day 1. "The purpose of this update is to protect HP's innovations and intellectual property," HP said in a statement. "In many cases, this functionality was installed in the HP printer and in some cases it has been implemented as part of an update to the printer's firmware." Dutch ink cartridge manufacturer 123inkt noted it had received more than 1,000 complaints in a single day as a result of its cartridges suddenly failing to work in HP hardware. Refilled cartridges with an HP security chip should still function, though this requires that the user still purchase an original set of HP cartridges at significantly higher prices.

top

- and -

HP blinked! Let's keep the pressure on! (BoingBoing, 3 Oct 2016) - Only three days after EFF's open letter to HP over the company's deployment of a stealth "security update" that caused its printers to reject third-party cartridges, the company issued an apology promising to let customers optionally install another update to unbreak their printers. That's good for starters, but it's a long way from making up for one of the most egregious abuses of a security update in recent memory. With HP on the run, it's time to push for real, meaningful reassurances and remedies about this bad conduct -- not just to make sure HP does right by its customers, but also to put other companies on notice about the kind of drubbing they can expect if they follow HP's lead. EFF's open letter has more than 10,000 signatures, and there's more flooding in as I type these words. If you haven't signed the letter, please do -- and then tell your friends. Even if you don't have an HP printer, we all share the same internet with tens of millions of these things, and the last thing we can afford is for HP to be giving its customers reasons not to run security updates, especially as these kinds of devices are being hijacked to perform unprecedented attacks on the net . * * *

top

Microsoft's new datacenters aim to put customer data beyond the reach of US snooping (ZDnet, 21 Sept 2016) - Microsoft has started offering its Azure cloud services from two new German datacenters , which have been set up to make it much harder for US authorities -- and others -- to demand access to the customer data stored there. Microsoft Cloud Germany is different to the company's existing European cloud services: the customer data in the datacenters is under the control of a "data trustee", T-Systems International , which is an independent German company and subsidiary of Deutsche Telekom. Microsoft's cloud and enterprise corporate vice president Takeshi Numoto described the new datacenters as a "first-of-its-kind model". Microsoft cannot access data at the sites without the permission of customers or the data trustee -- and if permission is granted by the latter, the company can only do so under its supervision.

top

ABA launches free virtual legal advice clinic (ABA Journal, 22 Sept 2016) - The ABA has unveiled a free Q&A-style program to allow income-eligible users to ask civil law-related questions to pro bono attorneys. The ABA formally launched ABAFreeLegalAnswers.org on Thursday. According to a press release , the site will function as a virtual legal advice clinic that will serve low-income individuals and communities. The service will also help lawyers by giving them a more convenient, flexible option for performing pro bono work. Free Legal Answers is currently available in eight states - Connecticut, Louisiana, Mississippi, New York, Oklahoma, Tennessee, Virginia and Wyoming, and the ABA hopes to expand the service to a majority of the country by the end of the year. "Free Legal Answers is a no-cost, online version of the walk-in clinic model where clients request brief advice and counsel about a specific civil legal issue from a volunteer lawyer," ABA President Linda Klein said in the press release. "It is an important part of the ABA's efforts to expand access to legal services to low-income communities. With our partner states, the program also provides significant pro bono opportunities for lawyers. It's a real win-win." Free Legal Answers has existed, in some form, in Tennessee for six years, the press release stated. Meanwhile, Virginia recently implemented a similar service and received interest from over 170 lawyers across the state to participate. According to the press release, Free Legal Answers will contain some similarities with these existing programs. The ABA Standing Committee on Pro Bono and Public Service created Free Legal Answers while software developers at Baker, Donelson, Bearman, Caldwell & Berkowitz built the website. Baker Donelson, alongside with another law firm, Nelson Mullins Riley & Scarborough, will provide support for the initiative, along with companies from other industries such as AT&T, FedEx, International Paper, Pilot Travel Centers and Wal-Mart, as well as the ABA sections on Business Law and Litigation.

top

Four states expanded employer data breach notification obligations in 2016 (Littler, 23 Sept 2016) - With over 680 security breaches reported so far in 2016,1 more employers are being forced to confront the issue of how to respond to a breach. All states except Alabama, North Dakota and New Mexico now require notification when information commonly maintained by employers, such as Social Security numbers and driver's license numbers, is compromised. While many of these breach notification laws were initially modeled after California's pioneering 2002 breach notification statute, more and more states are amending their notice laws in different ways, increasing the complexity of security incident response for multi-state employers. Following on amendments by eight states in 2015,2 four states-Illinois, Tennessee, California, and Nebraska-reinforced their data breach notification statutes in 2016. For employers, the net impact of these amendments is an increased number of circumstances in which they must inform employees, customers, or other state residents whose personal information has been compromised (and, in some cases, the state's attorney general) of a data breach. The following Insight highlights the key amendments to these laws in Illinois, Tennessee, California and Nebraska, of which employers should be aware. * * * In March, Tennessee made its data breach notification law the strictest in the country by requiring Tennessee residents to be informed of a data breach, regardless of whether the compromised information is encrypted. Effective July 1, 2016, the Tennessee Code now defines a breach as any "unauthorized acquisition of computerized data that materially compromises the security, confidentiality, or integrity of personal information maintained by the information holder."3 Personal information is defined as an individual's first name or first initial and last name, in combination with the individual's: (1) Social Security number (SSN); (2) driver's license number; or (3) information that would permit access to a financial account. Prior to this amendment, Tennessee, like all other states with data breach laws, required notification of a data breach only if the compromised personal information was unencrypted. Tennessee is now the only state in the country that requires notification of a breach of encrypted personal information. * * *

top

Cybersecurity disclosures: not happening much in SEC filings (Corporate Counsel, 27 Sept 2016) - Here's an excerpt from this " D&O Diary Blog " about how few companies are disclosing cybersecurity & data breach incidents in their SEC filings (which could be a concern for investors - and for D&O underwriters): According to a September 19, 2016 Wall Street Journal article entitled "Corporate Judgment Call: When to Disclose You've Been Hacked," notwithstanding the long-standing SEC disclosure guidelines, companies are being hacked more frequently but are not disclosing these incidents in their periodic reports to the SEC. The article cites a recent Audit Analytics report, in which the firm reviewed the filings of nearly 9,000 reporting companies during the period January 2010 to the present. The report found that only 95 of these companies had informed the SEC of a data breach. However, according to the Privacy Rights Clearinghouse, the number of data breaches during that period experienced by all U.S. businesses - including both public and private companies - totaled 2,642. The most important consideration accounting for this apparent discrepancy is the question of "materiality." If the company believes that the incident or incidents it experienced are not "material" within relevant reporting obligation standards, then, many companies apparently are concluding that they have no obligation to report the incident. Significantly, while only a small number of companies have reported cyber incidents in their periodic reports, a greater number are reporting data breaches and other incidents to other regulators. The Journal article cites the Audit Analytics report as stating that about 300 publicly traded U.S. companies have reported cybersecurity incidents to a state regulator or directly to affected consumers over the past six years. Obviously, whether or not any potentially reportable item is "material" and therefore subject to disclosure is a judgment call of a type that corporate officials have long been called upon to make. The concern is that these types of judgment calls can be subject to hindsight scrutiny. In that regard, it is probably worth noting that to date the SEC has not yet brought a regulatory enforcement action against a company that failed to disclose a cyberincident - but, the Journal article notes, SEC officials "have not ruled out doing so."

top

Father sues for copyright infringement after live-streaming baby's birth (Mandour & Associates, 29 Sept 2016) - It seems each day more people are willing to share ever more personal things on the Internet. Along these lines, in May of this year Kali Kanongataa a California resident used Facebook to live stream his wife giving birth. After portions the live stream ended up on television and publicized on the Internet, he sued ABC and Yahoo for allegedly infringing his copyright by displaying the video. The day after the live stream, ABC's "Good Morning America" ran a short segment about the live stream and showed a brief excerpt from the video that was up loaded by Mr. Kanogataa which had been widely viewed online since this airing. The clip also appeared on Yahoo, which has a partnership with ABC. Mr. Kanogataa explained to People magazine that he has family in the Polynesia island Tonga and by using Facebook Live he was hoping to easily share the birth of his son with them and other family members who were not able to be present. He expressed he never expected it to been seen by the public at large. "There's a lot of negative stuff on Facebook and so I thought this would be positive," he reportedly told People magazine in May. He alleges in a complaint filed in federal court in Manhattan that "Good Morning America" and Yahoo never obtained his permission to show the video, which he registered with the U.S. Copyright Office. "Defendants infringed plaintiff's copyright in the video by reproducing and publicly displaying the video on the GMA Website, Yahoo Website, and on GMA," he alleges in a petition filed Thursday.

top

Should you call in the feds after a cyber breach? (PropertyCasulaty360.com, 30 Sept 2016) - After a business is affected by a cyber breach, any number of decisions need to be made for the well-being of the company, its customers and other stakeholders. One of the major questions for many companies is whether to involve the authorities, and there are several considerations surrounding this action. Bryan Rose, managing director with the New York City-based business consulting firm Stroz Friedberg , told an audience at ALM's cyberSecure conference in New York City this week that a company must consider whether reporting the breach to the government will hurt or benefit the company in any way. "There are benefits to reporting to law enforcement, but it depends on the company," Rose said, adding that the company will likely be viewed as a victim of the breach. "They (the FBI and Secret Service) are dealing with national security, and will make decisions based on that perspective." Nicole Friedlander, special counsel at the New York City law firm of Sullivan & Cromwell LLP , said that other considerations around reporting the breach include the type of information affected (such as personal identifiable information or personal health information), and whether the breach will generally affect public health or safety. Richard Jacobs, assistant special agent in charge of the cyber branch in New York for the FBI said they would like to be notified any time a company suffers a breach. "We would like a phone call," he said. "Your breach might be connected to a dozen others and help us paint a picture of the criminals. The FBI's role is to get the bad guys out from behind the keyboard and into jail. If we don't neutralize those responsible, they will come back and attack again and again." [ Polley : There are other important considerations, too. This is a tricky area.]

top

Florida is 25th state to adopt duty of technology competence (Bob Ambrogi, 30 Sept 2016) - Just last week, I reported that Oklahoma had adopted the duty of technology competence for lawyers, becoming the 24th state on my ongoing tally of states that have adopted the ABA Model Rule. Now there is another. Yesterday, the Supreme Court of Florida ordered adoption of the duty of tech competence for that state, effective Jan. 1, 2017. From the court's order: The comment to rule 4-1.1 (Competence) is amended to add language providing that competent representation may involve a lawyer's association with, or retention of, a non-lawyer advisor with established technological competence in the relevant field. Competent representation may also entail safeguarding confidential information related to the representation, including electronic transmission and communications. Additionally, we add language to the comment providing that, in order to maintain the requisite knowledge and skill, a lawyer should engage in continuing study and education, including an understanding of the risks and benefits associated with the use of technology. In adopting the rule, the Supreme Court went farther than other states have done, adding two separate comments pertaining to technology competence. One is based on the ABA Model Rule on maintaining competence, but varies slightly: To maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, engage in continuing study and education, including an understanding of the benefits and risks associated with the use of technology , and comply with all continuing legal education requirements to which the lawyer is subject. (Emphasis added.) The language is the same as the ABA rule except for the addition of the words "an understanding of." I'll leave it to scholars to debate why the court added those three words and what their significance may be. In addition, the Supreme Court added language that other states rules do not have: Competent representation may also involve the association or retention of a non-lawyer advisor of established technological competence in the field in question. Competent representation also involves safeguarding confidential information relating to the representation, including, but not limited to, electronic transmissions and communications.

top

- and -

Florida becomes first state to mandate tech CLE (Bob Ambrogi, 3 Oct 2016) - Talk about burying the lede. On Friday, I reported that Florida had become the 25th state to adopt the duty of technology competence for lawyers. That was notable news, for sure, but I skipped over the even-bigger story - the same rule change also made Florida the first state to mandate technology CLE for lawyers. The rule change, ordered by the Supreme Court of Florida on Thursday, added a requirement that Florida lawyers must complete three hours of CLE every three years "in approved technology programs." The rule raises the state's minimum credit hours from 30 to 33 to accommodate the tech requirement.

top

10 Questions: Raj De's career has taken him from 9/11 Commission to White House to NSA (ABA Journal, 1 Oct 2016) - Nearly 20 years ago, a young Harvard Law School student named Raj De sat in his mentor's office and explained why he'd decided to bypass BigLaw for the Department of Justice. The older lawyer understood completely. "You should always go where the action is," he counseled. De took this advice-and then some. Leadership roles at the DOJ? Check. 9/11 Commission? He was a part of it, serving as counsel and contributing to its historic final report. U.S. Senate? Check that off, too: De was counsel to the committee charged with drafting and implementing intelligence reform legislation. Then came two dizzyingly busy years at the White House, where De worked directly with President Barack Obama as staff secretary. The follow-up? Three years as general counsel to the National Security Agency, where he helped steer the agency through perhaps its biggest crisis-the leak of countless classified documents by former contractor Edward Snowden. De left the NSA last March for the private sector, returning to the Washington, D.C., office of Mayer Brown-the law firm where he was a partner before working with the NSA-to direct the firm's global cybersecurity and data privacy practice. * * * [ Polley : interesting Q&A]

top

J&J warns diabetic patients: Insulin pump vulnerable to hacking (Reuters, 4 Oct 2016) - Johnson & Johnson is telling patients that it has learned of a security vulnerability in one of its insulin pumps that a hacker could exploit to overdose diabetic patients with insulin, though it describes the risk as low. Medical device experts said they believe it was the first time a manufacturer had issued such a warning to patients about a cyber vulnerability, a hot topic in the industry following revelations last month about possible bugs in pacemakers and defibrillators. "The probability of unauthorized access to the OneTouch Ping system is extremely low," the company said in letters sent on Monday to doctors and about 114,000 patients who use the device in the United States and Canada. "It would require technical expertise, sophisticated equipment and proximity to the pump, as the OneTouch Ping system is not connected to the internet or to any external network." The Animas OneTouch Ping, which was launched in 2008, is sold with a wireless remote control that patients can use to order the pump to dose insulin so that they do not need access to the device itself, which is typically worn under clothing and can be awkward to reach. Jay Radcliffe, a diabetic and researcher with cyber security firm Rapid7 Inc, said he had identified ways for a hacker to spoof communications between the remote control and the OneTouch Ping insulin pump, potentially forcing it to deliver unauthorized insulin injections. The system is vulnerable because those communications are not encrypted, or scrambled, to prevent hackers from gaining access to the device, said Radcliffe, who reported vulnerabilities in the pump to J&J in April and published them on the Rapid7 blog on Tuesday.

top

New York to test facial recognition cameras at 'crossing points' (Vocativ, 6 Oct 2016) - New York will soon test facial recognition technology around Manhattan. In a 35-minute speech detailing a landmark $100 billion investment into state infrastructure, largely focused on New York City and Long Island, Governor Andrew Cuomo made a number of promises that would thrill New Yorkers, like the promise of a renovated Penn Station, called Penn-Farley, a direct train from there to LaGuardia Airport, and the completion of the long-awaited Second Avenue Line. Oh, and facial recognition cameras around the city, he said: "At each crossing, and at structurally sensitive points on bridges and tunnels, advanced cameras and sensors will be installed to read license plates and test emerging facial recognition software and equipment." "We're going to be using this in Penn-Farley and we also want to be testing it in bridges and crossings system," he added. On the matter of facial recognition cameras, Cuomo was shy on details. It's unclear how many cameras will be deployed, which agencies will have access to them, what defines a crossing, how citizens' photos will be stored, and what photo databases will be used to compare against the faces of the millions of people who drive into the city. In his speech, Cuomo referenced the cameras as necessary for New York to adapt to 21st century security threats. "In this age of terrorist activity and lone wolves, if you look at points of vulnerability you'll go to our tunnels and to our bridges. So really they have to be reimagined for a new reality," he said.

top

- and -

Remotely accessing an IP address inside a target computer is a search (Orin Kerr, 7 Oct 2016) - Last week, I wrote a post on the Playpen warrant currently being litigated in federal courts around the country. My post included a section, "Retrieving IP Addresses is Clearly a Search," that said the following: A significant amount of media attention about the Playpen cases has focused on a curious argument. A minority of the judges have held that the Playpen searches were constitutional because they weren't searches at all. According to this argument, a person has no Fourth Amendment rights in IP addresses. Because the most important information obtained by the NIT was IP addresses, use of the NIT was not a search and no Fourth Amendment rights were violated. As far as I can tell, the government has not actually made this argument. Rather, it is a position introduced by one judge and then adopted by some others. This argument is clearly wrong, though. Individuals have Fourth Amendment rights in information stored inside their computers unless they voluntarily share the information. A person using Tor has not voluntarily shared his IP address with the websites he visits. Indeed, the absence of voluntarily sharing is precisely what led the government to surreptitiously obtain the information using the NIT. Given that a Tor user has not voluntarily shared his IP address, it doesn't matter that obtaining an IP address from a third party or a visited website would not be a search in other circumstances that did involve voluntarily sharing. Put another way, it's the way of obtaining information that makes the act a search, not the information itself in the abstract. This point is obvious in the physical world. See Arizona v. Hicks, 480 U.S. 321 , 325 (1987) ("A search is a search, even if it happens to disclose nothing but the bottom of a turntable."). It should be equally obvious with computers. If the police want to read today's newspaper, they can't break into my house and open my desk drawer to find my copy without committing a search. The fact that they could have read the newspaper by finding a copy in public doesn't mean they can break into my house to read mine. Similarly, the fact that IP addresses may be available without searching a target in some cases doesn't mean they can break into his computer to find the IP address without committing a search. Here's a follow-up. First, several readers pointed out that the government actually has made this argument. You can read the government's argument here in the Michaud case (pages 6-7) and here in the Lemus case (pages 8-12). My apologies for the misstatement, and thanks to reader Jonathan Mayer for sending on the briefs. Second, some readers argued that a Tor user loses a reasonable expectation of privacy in IP addresses because the user must disclose his true IP address to Tor. This is essentially the argument the government (briefly) makes in Michaud : By using Tor, you are sending your IP address to Tor, which is ultimately hosted by "an unknowable collection of strangers" who are running Tor exit nodes. You have put out your IP address to lots of people, which means that you have no expectation of privacy in it. That argument doesn't work. Fourth Amendment law regulates how the government learns information, not what information it learns. * * *

top

- and -

Feds convinced police to use license plate-scanning tech at gun shows (SlashDot, 8 Oct 2016) - Long-time Slashdot reader SonicSpike quotes the Wall Street Journal: Federal agents have persuaded police officers to scan license plates to gather information about gun-show customers , government emails show, raising questions about how officials monitor constitutionally protected activity. Emails reviewed by The Wall Street Journal show agents with the Immigration and Customs Enforcement agency crafted a plan in 2010 to use license-plate readers -- devices that record the plate numbers of all passing cars -- at gun shows in Southern California, including one in Del Mar, not far from the Mexican border. Agents then compared that information to cars that crossed the border, hoping to find gun smugglers, according to the documents and interviews with law-enforcement officials with knowledge of the operation... [T]he officials didn't rule out that such surveillance may have happened elsewhere. The agency has no written policy on its use of license-plate readers and could engage in similar surveillance in the future, they said. Jay Stanley, a lawyer at the American Civil Liberties Union, said the gun-show surveillance "highlights the problem with mass collection of data." He said law enforcement can take two entirely legal activities, like buying guns and crossing the border, "and because those two activities in concert fit somebody's idea of a crime, a person becomes inherently suspicious."

top

- and -

Police use surveillance tool to scan social media, ACLU says (NYT, 11 Oct 2016) - A Chicago company has marketed a tool using text, photos and videos gleaned from major social media companies to aid law enforcement surveillance of protesters, civil liberties activists say. The company, called Geofeedia , used data from Facebook , Twitter and Instagram , as well as nine other social media networks, to let users search for social media content in a specific location, as opposed to searching by words or hashtags that would be less likely to reveal an exact location. Geofeedia marketed its abilities to law enforcement agencies and has signed up more than 500 such clients, according to an email obtained by the American Civil Liberties Union . In one document posted by the organization , as part of a report released on Tuesday, the company appears to point to how officials in Baltimore, with Geofeedia's help, were able to monitor and respond to the violent protests that broke out after Freddie Gray died in police custody in April 2015. Geofeedia appears to have used programs that Facebook, Twitter and other social media companies offered that allow app makers or advertising companies to create third-party tools, like ways for publishers to see where their stories are being shared on social media. Facebook, Twitter and Instagram say they have cut off Geofeedia's access to their information. But civil liberties advocates criticized the companies for lax oversight and challenged them to create better mechanisms to monitor how their data is being used.

top

Most Comcast customers now have a 1TB home internet data cap (The Verge, 6 Oct 2016) - Comcast's home internet data caps are going live for a majority of customers starting November 1st, the company announced today . Called the "Xfinity Terabyte Internet Data Usage Plan," the cap restricts the amount of data you consume in your home to 1TB per month regardless of the speed of your plan. Comcast claims 99 percent of customers use less than 1TB per month, but it does now offer an unlimited option for $50 more per month. Back in April, Comcast bumped its data cap from 300GB to 1TB after consumer backlash and renewed regulatory concern from the FCC. And until today, the plan has been active in select markets for 16 states. But starting November 1st, the list will add 18 new markets, bringing the total number of states with the terabyte data cap to around 30. Notable exceptions include New York and nearly the entire northeast. For a full list of included markets, check Comcast's online FAQ . Comcast says it will never throttle customers who go over the cap, but it will automatically add 50GB to your plan at a cost of $10. The company will continue to charge you $10 in 50GB intervals up to $200 a month. To notify customers, the company will use in-browser, email, and text notifications starting at the 50 percent point, and a usage meter is available on your online account. Comcast says customers will get two grace months every year, meaning you won't be charged unless you exceed the cap a third time in any given 12-month period.

top

Clearing up the fog of cloud service agreements (LinkedIn post by Dan Solove, 10 Oct 2016) - Contracting with cloud service providers has long been a world shrouded in fog. Across various organizations, cloud service agreements (CSAs) are all over the place, and often many people entering into these contracts have no idea what provisions they should have to protect their data. According to a recent survey by Forrester Research , "cloud agreements are often missing key considerations." In the survey of 467 small and medium-sized businesses and government entities, 48% said that they wished they would have included more security requirements in their CSAs and 41% said they wished they would have included more requirements to protect privacy. The Forrester survey involves more sophisticated actors who already realize that something might be missing from their CSAs. There are many out there who don't even know what might be missing and who think their CSAs are just fine when, in fact, their CSAs are woefully inadequate. Significant guidance is needed to improve this landscape and bring more order to the chaos. Fortunately, a new standard -- ISO/IEC 19086 - provides this much-needed guidance. * * *

top

Aon announces agreement to acquire risk management firm, Stroz Friedberg (AON, 11 Oct 2016) - As the complexity and severity of cyber risk continues to expand, threatening organizations across all industries, Aon Risk Solutions , the global risk management business of Aon plc , today announced it has entered into an agreement to acquire all of Stroz Friedberg Inc., a leading global risk management firm based in New York City, with offices across the U.S. and in London, Zurich, Dubai and Hong Kong. Financial terms were not disclosed and the acquisition is subject to customary closing conditions. The combination of Aon and Stroz Friedberg will extend Aon's industry-leading position in cyber risk brokerage and creates a comprehensive Cyber Risk Management Advisory Group with distinct client value, including standards-based cyber assessments and industry-leading risk transfer solutions. Integrating Stroz Friedberg's cyber security governance and advisory services, including its penetration testing, incident response, digital forensics, eDiscovery and due diligence capabilities, will position Aon as the global leader in cyber risk management.

top

Comcast in middle of Oregon fight over taxes and censorship (The Hill, 11 Oct 2016) - Comcast has blocked versions of an advertisement backing a hike in Oregon's corporate tax, which the cable giant opposes, from appearing on its video-on-demand service. The versions that raised red flags specifically mention Comcast as one of the out-of-state corporations that would have to pay higher taxes as a result of Measure 97, which would raise income taxes on corporations across the state. New versions of all three advertisements initially flagged by Comcast are back on air and do not mention the cable giant, but the initial decision has rankled supporters of the tax.

top

- and -

Facebook helped drive a voter registration surge, election officials say (NYT, 12 Oct 2016) - A 17-word Facebook reminder contributed to substantial increases in online voter registration across the country, according to top election officials. At least nine secretaries of state have credited the social network's voter registration reminder, displayed for four days in September, with boosting sign-ups, in some cases by considerable amounts. Data from nine other states show that registrations rose drastically on the first day of the campaign compared with the day before. In California, 123,279 people registered to vote or updated their registrations on Friday, Sept. 23, the first day that Facebook users were presented with the reminder. That was the fourth-highest daily total in the history of the state's online registration site. Indiana similarly recorded its third-highest daily online registration total ever. Minnesota, meanwhile, broke its record for the most online voter registrations in a single week, thanks at least in part to the Facebook campaign, which continued through Monday, Sept. 26. Those were among the nine states where election administrators extolled the social network in official statements. In nine others, online registration rose as Facebook began its effort, according to a review of data collected by the nonprofit Center for Election Innovation & Research . In those states, registration increased anywhere from two- to 23-fold on the first day the reminder went up, compared with the previous day. Facebook's effort is notable not just for boosting voter registration, but also for the kinds of voters it may have helped to enlist. While Facebook could not provide demographic breakdowns of the users who registered, the social network is more popular among female internet users than male users, and the same is true for young users compared with older users, according to 2015 data from the Pew Research Center .

top

Signal is a free, secure, easy-to-use client communication tool (Lawyerist, 12 Oct 2016) - Lawyers need a way to communicate securely with clients , if not about everything, then about especially sensitive matters. It's just too easy for a spouse, coworker, employer, or malicious hacker to intercept email. If you don't have one or you have had trouble getting clients to use your existing communication portal, try Signal . Signal is a free messaging app for iPhone and Android. If you've texted or used iMessage, Hangouts, Facebook Messenger, WhatsApp, or any of a dozen other messaging utilities, you know what it's like. Everyone knows how to install apps, and everyone knows how to use messaging apps. Like most messaging apps now do, Signal also supports voice calls. Signal is pretty similar to other messaging apps, with one big difference: Signal uses zero-knowledge, end-to-end encryption to that nobody outside the conversation can get your messages. Signal is pretty similar to other messaging apps, with one big difference: Signal uses zero-knowledge, end-to-end encryption to that nobody outside the conversation can get your messages. * * * [ Polley : This is how I use Signal - for secure key/password distribution. See also , This app [Signal] promises privacy through encrypted messaging, but a U.S. subpoena puts it to test (LA Times, 4 Oct 2016), and Facebook rolls out opt-in encryption for 'secret' Messenger chats (ZDnet, 5 Oct 2016)]

top

HHS imposes $400k fine for outdated BAA (Steptoe, 13 Oct 2016) - Last month, Care New England Health System (CNE) settled with the Department of Health and Human Services (HHS) on behalf of the covered entities under its common ownership or control related to alleged violations of HIPAA and agreed to pay a $400,000 penalty. The allegations stem from the business associate agreement (BAA) between the Woman & Infants Hospital of Rhode Island (WIH), one of CNE's subsidiary covered entities, and CNE, which acted as a "business associate" for WIH and its other subsidiary covered entities by providing centralized corporate support. HHS concluded that the BAA between WIH and CNE had not been updated since March 2005, and thus did not incorporate the revisions required by the HITECH Act of 2009 and HHS's implementing regulations. That's a stiff fine for forgetting to update the paperwork.

top

RESOURCES

Adler on Fair Use and the Future of Art (MLPB, 29 Sept 2016) - Amy Adler, New York University School of Law, is publishing Fair Use and the Future of Art in volume 91 of the New York University Law Review (2016). Here is the abstract: Twenty-five years ago, in a seminal article in the Harvard Law Review, Judge Leval changed the course of copyright jurisprudence by introducing the concept of "transformativeness" into fair use law. Soon thereafter, the Supreme Court embraced Judge Leval's new creation, calling the transformative inquiry the "heart of the fair use" doctrine. As Judge Leval conceived it, the purpose of the transformative inquiry was to protect the free speech and creativity interests that fair use should promote by offering greater leeway for creators to build on preexisting works. In short, the transformative standard would ensure that copyright law did not "stifle the very creativity which that law [was] designed to foster." This Article shows that the transformative test has not only failed to accomplish this goal; the test itself has begun to "stifle the very creativity which that law was designed to foster." In the realm of the arts, one of the very areas whose progress copyright law is designed to promote, the transformative standard has become an obstacle to creativity. Artistic expression has emerged as a central fair use battleground in the courts. At the same time that art depends on copying, the transformative test has made the legality of copying in art more uncertain, leaving artists vulnerable to lawsuits under a doctrine that is incoherent and that fundamentally misunderstands the very creative work it governs. The transformative test has failed art. This Article shows why and what to do about it, turning to the art market itself as a possible solution to the failure of the transformative use test.

top

Animated map reveals the 550,000 miles of cable hidden under the ocean that power the internet (Business Insider, 8 Oct 2016; 2 minute video) - Every time you visit a web page or send an email, data is being sent and received through an intricate cable system that stretches around the globe. Since the 1850s, we've been laying cables across oceans to become better connected. Today, there are hundreds of thousands of miles of fiber optic cables constantly transmitting data between nations.

top

LOOKING BACK - MIRLN TEN YEARS AGO

(note: link-rot has affected about 50% of these original URLs)

2005 worst year for breaches of computer security (USA Today, 28 Dec 2005) -- Data breaches disclosed at Marriott International, Ford Motor, ABN Amro Mortgage Group and Sam's Club this month capped what computer experts call the worst year ever for known computer-security breaches. At least 130 reported breaches have exposed more than 55 million Americans to potential ID theft this year. Security experts warn that wayward personal data, such as Social Security and credit card numbers, could end up in the hands of criminals and feed a growing problem. An adviser for the Treasury Department's Office of Technical Assistance estimates cybercrime proceeds in 2004 were $105 billion, greater than those of illegal drug sales. The breaches come at a time when the Department of Homeland Security's research budget for cybersecurity programs was cut 7%, to $16 million, for 2005. ID theft-related bills are stalled in Congress, and data brokers such as ChoicePoint, itself a victim of fraud this year, remain unregulated, "so it is likely that many more serious breaches have gone unreported," says Avivah Litan, a security analyst at Gartner. As a result, the Bush administration has drawn the ire of the Cyber Security Industry Alliance, which represents high-tech heavyweights Symantec, McAfee and RSA Security. "Attacks are taking place every day," says Paul Kurtz, a former Bush administration cybersecurity official who is executive director of CSIA.

top

New breach notification laws springing up all over (Steptoe & Johnson's E-Commerce Law Week, 1 April 2006) -- After a relatively quiet winter, data security legislation is once again brewing in state legislatures. And, with the advent of Spring, new laws are blooming across the country. Three more states have jumped on the "breach notification law" bandwagon. Since our last update, the governors of Utah (S.B. 69), Wisconsin (Act 138), and Indiana (H.B. 1101) signed data security bills with breach notification provisions. The Utah law is the broadest of the three, with its breach notification sections accompanied by provisions requiring businesses to "implement and maintain" reasonable security procedures. And both Utah and Indiana have requirements regarding the destruction of personal information, which is an important but often overlooked element of any good security policy.

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, http://www.sans.org/newsletters/newsbites/

4. Aon's Technology & Professional Risks Newsletter

5. Crypto-Gram, http://www.schneier.com/crypto-gram.html

6. Steptoe & Johnson's E-Commerce Law Week

7. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/

8. The Benton Foundation's Communications Headlines

9. Gate15 Situational Update Notifications, http://www.gate15.us/services.html

10. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top

Saturday, September 24, 2016

MIRLN --- 4-24 September 2016 (v19.13)

MIRLN --- 4-24 September 2016 (v19.13) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | PODCASTS/MOOCS | BOOK REVIEW | LOOKING BACK | NOTES

NIST publishes major revisions to digital authentication guidance (Federal News Radio, 30 August 2016) - Hoping to balance today's requirements with future needs, the National Institute of Standards and Technology released a major update to Special Publication 800-63 for digital authentication. The third version was published Aug. 30, and divides the digital authentication document into four sections, ranging from credentials that are tied to a specific person to the process of sending those authentication results to the party who needs know that certification. The third revision has already received more than 200 comments. Unlike the original special publication, the third version is split into four documents: digital authentication guidelines, enrollment and identity proofing, authentication and lifecycle management, and federation and assertions. Garcia said identity proofing is "a complete re-write," based off good practices guidance like the kind seen in Canada and the UK.

top

- and -

NIST releases Baldridge-based tool for cybersecurity excellence (NIST, 15 Sept 2016) - The US Commerce Department's National Institute of Standards and Technology (NIST) released today the draft Baldridge Cybersecurity Excellence Builder , a self-assessment tool to help organizations better understand the effectiveness of their cybersecurity risk management efforts. NIST is requesting public comments on the draft document, which blends the best of two globally recognized and widely used NIST resources: the organizational performance evaluation strategies from the Baldridge Performance Excellence Program and the risk management mechanisms of the Cybersecurity Framework .

top

New Mexico high court urges judges to be discreet on social media (ABA Journal, 1 Sept 2016) - For most of its 37-page opinion in State v. Thomas, issued June 20, the New Mexico Supreme Court explained its finding that the convictions of Truett Thomas for murder and kidnapping violated the confrontation clause. The supreme court reversed the convictions and remanded the case for a new trial only on the murder charge because there was insufficient evidence to support the kidnapping conviction. It wasn't until page 31 of the opinion that the justices turned to an issue that might have been a more important factor in the case, if not for the confrontation clause violation. During the trial, Judge Samuel L. Winder of the District Court of Bernalillo County, which encompasses Albuquerque, posted the following statement on a Facebook page created for his unsuccessful re-election campaign: "I am on the third day of presiding over my 'first' first-degree murder trial as a judge." While this was a seemingly innocuous post, Winder later posted the following message after trial but before sentencing: "In the trial I presided over, the jury returned guilty verdicts for first-degree murder and kidnapping just after lunch. Justice was served. Thank you for your prayers." On appeal, "defendant argues that social media postings by the district court judge demonstrate judicial bias," wrote Chief Justice Charles W. Daniels in his opinion for a unanimous court (with one abstention). "During the pendency of the trial, the district court judge posted to his election campaign Facebook page discussions of his role in the case and his opinion of its outcome. Although we need not decide this issue because we reverse on confrontation grounds, we take this opportunity to discuss our concerns over the use of social media by members of our judiciary." Judges "should expect to be the subject of public scrutiny that might be viewed as burdensome if applied to other citizens," stated Daniels, citing Rule 21-102 of the New Mexico Code of Judicial Conduct. "Judges must avoid not only actual impropriety but also its appearance, and judges must 'act at all times in a manner that promotes public confidence in the independence, integrity and impartiality of the judiciary.' These limitations apply with equal force to virtual actions and online comments and must be kept in mind if and when a judge decides to participate in electronic social media." Daniels emphasized that the court was sounding a note of caution to judges. "While we make no bright-line ban prohibiting judicial use of social media," the opinion states, "we caution that 'friending,' online postings and other activity can easily be misconstrued and create an appearance of impropriety. Online comments are public comments, and a connection via an online social network is a visible relationship, regardless of the strength of the personal connection." The New Mexico Supreme Court's opinion echoes the view expressed by the ABA Standing Committee on Ethics and Professional Responsibility in Formal Ethics Opinion 462, issued Feb. 21, 2013. "A judge may participate in electronic social networking," states the committee in Opinion 462, "but as with all social relationships and contacts, a judge must comply with relevant provisions of the Code of Judicial Conduct and avoid any conduct that would undermine the judge's independence, integrity or impartiality, or create an appearance of impropriety."

top

- and -

Florida Bar Social Media presence leads the nation (Future Lawyer, 9 Sept 2016) - Florida Bar social media efforts connect with members and the public . Do you want to change the perception of lawyers in society? Go where the people are. Do you want to communicate with a diverse group of lawyers and keep them up to date daily on news and events that are important to them? Go where they are. Do you want to let the world know that lawyers are ordinary people doing extraordinary things? Go where the world is. Nowadays, the bulletin board is on the Internet, and people, including lawyers, interact on social media; whether it be Twitter, Facebook, Pinterest, Google+, or elsewhere. This article shows why the Florida Bar's social media team has become the national leader in this area. Social media is where everyone goes to get news, and to have conversations about current affairs. Not only should lawyers follow the Florida Bar; but, everyone else can see lawyers in a positive light. Too often the only contact regular citizens have with lawyers and the legal system are sensational stories on the news, or negative interactions with the system. As my mom used to say: "If you don't toot your own horn, no one else will." Congratulations to the Florida Bar social media team. They get it.

top

Military supermarket chain's encryption setup is 'unacceptable,' commissary says (NextGov, 2 Sept 2016) - The Defense Department's $6 billion supermarket chain needs tighter security for the secret keys fastening its hundreds of databases, Pentagon officials say. Currently, those keys-lengthy, computer-generated passwords-essentially are stored underneath the doormat, beside personal and financial data, contracting documents show. "In today's solutions, the keys reside with the data and that is not acceptable," Defense Commissary Agency officials said in a recent request for information from vendors. The data at stake includes encrypted payment card industry, or PCI, data and personally identifiable information, or PII, agency spokesman Kevin Robinson told Nextgov . Scrambled in code indecipherable to hackers, the records contain credit card numbers and security codes from the back of the card, he said. The commissary agency's proposed system would make it possible, say, to deposit keys at DeCA's Fort Lee, Virginia, headquarters for locking and unlocking remote databases at a server farm "in the cloud," the contracting papers said. Beyond using encryption to protect grocery store operations, the military deploys the data-scrambling feature in handheld radios, missile system data links and other communications devices to hide information from foes. While the 250-store grocery chain has not committed to buying anything, officials Aug. 24 said there's a possibility an acquisition will take place in fiscal 2017 . The system, formally dubbed the Enterprise Encryption and Key Management Solution, would consist of commercial, currently available technology that stows encryption keys in a different location than the data in the agency's 629 database environments, officials said.

top

World map shows countries requiring open source software (Slashdot, 3 Sept 2016) - "Europe and South America are the biggest hotspots for open-source use in government," reports Network World, while Bulgaria requires all software written for the government to be FOSS . Slashdot reader alphadogg quotes their report: It's become increasingly common over the past decade or so to see laws being passed to either mandate the use of open-source software or, at the very least, encourage people in government who make procurement decisions to do so. Here's a map of the status of open-source laws around the world .

top

Go to court without leaving home (ABA Journal, 7 Sept 2016) - A few years ago, J.J. Prescott went to court to deal with a traffic ticket. The University of Michigan Law School professor waited four hours to have a very short informal hearing. "Imagine if I lived in a rural area where the courthouse was two hours away," he says. "And as a result, I had to miss an entire day of work to go to court, which, if I were paid by the hour, would equate to $100 or more in lost wages. All of that aggravation, all to come over to have that conversation. "I can't believe that in 50 years, that's how our courts will operate." They might not, and Prescott's work could be a reason why. The U-M Online Court Project, which began with his collaboration with former student Ben Gubernick, created an online platform allowing citizens to resolve smaller legal matters-civil infractions, plus minor warrants and misdemeanors-without having to go to court. Users submit their side of the story and other information, answer questions and eventually hear from a decision-maker. Prescott says at least half of court cases are minor matters that could be resolved simply: "It can happen the way you request an increase in the credit limit on your credit card-at 11 p.m. from your couch." Online interactions have a lot of advantages over the traditional model, Prescott says. They remove barriers caused by poverty, disability and personal obligations; reduce time spent on cases; avoid the intimidation and fear some people feel in courthouses; and sidestep the possibility that the defendant's appearance could create perceived or actual bias. The project was in the beginning stages when Prescott got the ticket. With a grant from the University of Michigan, he had a prototype made and convinced the Michigan state court administrative office to give the project access to court data. Through the university's Office of Technology Transfer, which helps academics build businesses out of their ideas, Prescott launched a startup, Court Innovations Inc., to market the technology and give it a permanent home. He now has the software, Matterhorn, in 15 Michigan district courts and is in talks with other states.

top

EFF to Court: Public's right to access the law should not be blocked by bogus copyright case (EFF, 8 Sept 2016) - On Monday, September 12, Electronic Frontier Foundation (EFF) Legal Director Corynne McSherry will urge a federal court to confirm that the public has a right to access and share the laws, regulations, and standards that govern us and cannot be blocked by overbroad copyright claims. The court in Washington, D.C., is hearing arguments in two cases against EFF client Public.Resource.Org , an open records advocacy website. In these suits , several industry groups claim they own copyrights on written standards for building safety and educational testing they helped develop, and can deny or limit public access to them even after the standards have become part of the law. Standards like these that are legal requirements-such as the National Electrical Code-are available only in paper form in Washington, D.C., in expensive printed books, or through a paywall. By posting these documents online, Public.Resource.Org seeks to make these legal requirements more available to the public that must abide by them. The industry groups allege the postings infringe their copyright, even though the standards have been incorporated into government regulations and, therefore, must be free for anyone to view, share, and discuss. McSherry and co-counsel Andrew Bridges at Fenwick & West will argue at the hearing that our laws belong to all of us and private organizations shouldn't be allowed to abuse copyright to control who can read, excerpt, or share them. They will be assisted by EFF Senior Staff Attorney Mitch Stoltz and Fenwick & West Associate Matthew Becker. [ Polley : see also Carl Malamud has standards (Backchannel, 12 Sept 2016)]

top

Now you can buy a USB stick that destroys anything in its path (ZDnet, 8 Sept 2016) - For just a few bucks, you can pick up a USB stick that destroys almost anything that it's plugged into. Laptops, PCs, televisions, photo booths -- you name it. Once a proof-of-concept, the pocket-sized USB stick now fits in any security tester's repertoire of tools and hacks, says the Hong Kong-based company that developed it. It works like this: when the USB Kill stick is plugged in, it rapidly charges its capacitors from the USB power supply, and then discharges -- all in the matter of seconds. On unprotected equipment, the device's makers say it will "instantly and permanently disable unprotected hardware".

top

Court finds violation of TCPA itself constitutes concrete injury (Steptoe, 8 Sept 2016) - Last month, the U.S. District Court for the Northern District of Illinois held, in Aranda v. Caribbean Cruise Line, Inc. , that a violation of the Telephone Consumer Protection Act (TCPA) constituted a concrete injury that conferred standing without any additional allegations of harm. In doing so, it engaged in an extensive analysis of the Supreme Court's decision in Spokeo, Inc. v. Robins and expressly disagreed with the Central District of California's decision, in Smith v. Aitima Medical Equipment , which had found no standing in similar circumstances. The decision marks an important interpretation of the Supreme Court's muddled decision in Spokeo , which could influence how courts approach standing in cases alleging statutory violations in the future.

top

CFTC imposes cybersecurity rules for U.S. commodities, derivatives firms (SC Magazine, 9 Sept 2016) - The Commodity Futures Trading Commission (CFTC) Thursday approved a set of rules that will require frequent testing of information technology at U.S. commodities and derivatives firms, including exchanges and clearinghouses. Systems will undergo vulnerability testing, penetration testing, controls testing, security incident response testing, and enterprise technology risk assessment, according to a government fact sheet . Key elements of the rules include, specified cybersecurity testing, minimum testing frequency, use of independent contractors, testing scope, and internal reporting, review and remediation. The CFTC's comprehensive approach to this new regulation demonstrates a clear appreciation of the reality that between 40 and 70 percent of data breaches originate from third party vendors and partners, Jeff Hill, director of product management for the security firm Prevalent told SCMagazine.com via emailed comments.

top

- and -

Cybersecurity enhancements proposed for financial firms in New York (SC Magazine, 15 Sept 2016) - Banks and insurance companies in New York will soon be required to adhere to new cybersecurity guidelines, including appointing CISOs. In a statement , Gov. Andrew Cuomo called the proposed new regulations a "first-in-the-nation" initiative to bolster cybersecurity policies at financial institutions licensed in the state. Cuomo's long-awaited guidance for institutions overseen by the New York State Department of Financial Services (NYDFS) will first face a 45-day notice and a request for public comment before adoption procedures commence. The proposed rules are intended to guard consumer data and financial systems from terrorist organizations and other criminal enterprises. They mandate that regulated financial institutions adhere to five principal requirements: * * * [ Polley : John Pescatore of SANS writes : " The proposed regulation sets a very low bar: covered entities must have written policies, a designated CISO, annual pen tests, etc. A few requirements bump it up a bit: CISO must brief the board at least twice per year, for example. However, a requirement for encrypting sensitive data at rest allows compensating controls to be substituted for the first 5 years. Biggest lack: no prioritization of requirements - would be good to see that included or the Critical Security Controls referenced for prioritization. "]

top

This Bill Gates-backed tech startup is on a mission to fundamentally change the way scientists work (Business Insider, 10 Sept 2016) - Meet Ijad Madisch. He's a Berlin-based entrepreneur on a mission to change the way scientists go about their research. The computer science graduate and qualified doctor set up a company called ResearchGate in 2008 when he realised that scientists were making the same mistakes over and over again as a result of not sharing their work publicly. "It's one of the biggest problems we have in the world, especially if we are repeating mistakes made by other scientists that cost us a lot of time and money," Madisch told Business Insider. ResearchGate can be described as a social network for scientists. It started off as a free-to-use platform for academics but it's become increasingly popular with scientists working in corporates, including tech firms like Google and Facebook. There are currently 1,145 Google employees registered on the platform and 199 Facebook employees . In total, ResearchGate boasts over 10 million users. "ResearchGate has become the biggest and most active scientific social network in the world over the last couple of years," claims Madisch. "From the beginning, the focus was on convincing scientists to share publication data." The company claims not to have any competitors but it's worth noting that it was compared to London's Mendeley and San Francisco's Academia.edu in a Times Higher Education article that was published in April. Over the last eight years, tens of millions of pieces of scientific information have been uploaded onto ResearchGate's platform and today more than two million scientific publications are uploaded every month. In addition to publications, scientists are also uploading general articles, conference papers, and raw data. Now the company wants to make it even easier for scientists to collaborate on chunky problems like climate change and illnesses like HIV and cancer. "Recently we launched a 'Project' feature where scientists can collaborate in real time and document what they have found within the experiment," said Madisch.

top

Apple came up with 'AirPods' in 2015 - here's how it kept it under wraps (Business Insider, 12 Sept 2016) - Earlier this week, Apple announced a new type of wireless headphones at a media event in San Francisco. It called them "AirPods." That name would have sounded familiar if you read Apple trademark applications. In fact, it was hiding in plain sight since at least early 2015, when an Apple-aligned holding company first registered the trademark. However, "AirPods" was registered under a dummy corporation called "Entertainment in Flight." In the run-up to Apple's big reveal, Rennick Solicitors trademark lawyer Brian Conroy definitively linked Entertainment in Flight to Apple - and discovered a few other names Apple wanted to make sure it could name future products after, like Beats' EP headphones , which were announced shortly after the event. He also highlighted a number of trademarks Apple didn't announce, but might one day, including "Today at Apple," "Apple Touch Bar," and "Apple Smart Button." "If Apple had just filed all their applications in the US, or wherever, the intrigue [before the iPhone launch] wouldn't be nearly as palpable," Controy told Business Insider. But Conroy is quick to warn that just because a company files a trademark doesn't mean it's planning a product. Here's how Apple hides its trademarks around the world, and how Conroy sleuthed them out. * * *

top

Long-secret Stingray manuals detail how police can spy on phones (The Intercept, 12 Sept 2016) - Harris Corp's Stingray surveillance device has been one of the most closely guarded secrets in law enforcement for more than 15 years. The company and its police clients across the United States have fought to keep information about the mobile phone-monitoring boxes from the public against which they are used. The Intercept has obtained several Harris instruction manuals spanning roughly 200 pages and meticulously detailing how to create a cellular surveillance dragnet. Harris has fought to keep its surveillance equipment, which carries price tags in the low six figures, hidden from both privacy activists and the general public, arguing that information about the gear could help criminals. Accordingly, an older Stingray manual released under the Freedom of Information Act to news website TheBlot.com last year was almost completely redacted. So too have law enforcement agencies at every level, across the country, evaded almost all attempts to learn how and why these extremely powerful tools are being used - though court battles have made it clear Stingrays are often deployed without any warrant. The San Bernardino Sheriff's Department alone has snooped via Stingray, sans warrant, over 300 times . Richard Tynan, a technologist with Privacy International, told The Intercept that the "manuals released today offer the most up-to-date view on the operation of" Stingrays and similar cellular surveillance devices, with powerful capabilities that threaten civil liberties, communications infrastructure, and potentially national security. He noted that the documents show the "Stingray II" device can impersonate four cellular communications towers at once, monitoring up to four cellular provider networks simultaneously, and with an add-on can operate on so-called 2G, 3G, and 4G networks simultaneously. * * * [ Polley : Bruce Schneier linked to this story, with the note: " It's an impressive surveillance device." ]

top

MoMA will make thousands of exhibition images available online (NYT, 14 Sept 2016) - The Museum of Modern Art, which has defined Modernism more powerfully than perhaps any other institution, can often seem monolithic in the mind's eye, essentially unchanged since its doors opened in 1929: a procession of solemn white-box galleries, an ice palace of formalism, the Kremlin (as the artist Martha Rosler once called it) of 20th-century art. But a more complicated story has always been told by the hundreds of thousands of documents and photographs in the museum's archives, a vast accumulation of historical detail that has been accessible mainly to scholars. Beginning Thursday, after years of planning and digitizing, much of that archive will now be available on the museum's website, moma.org , searchable so that visitors can time-travel to see what the museum looked like during its first big show ("Cézanne, Gauguin, Seurat, van Gogh," in the fall of 1929); during seminal exhibitions (Kynaston McShine's " Information " show in 1970, one of the earliest surveys of Conceptual art); and during its moments of high-minded glamour (Audrey Hepburn, in 1957, admiring a Picasso with Alfred H. Barr Jr., the museum's domineering first director). Michelle Elligott, chief of the museum's archives, who undertook the project with Fiona Romeo, the director of digital content and strategy, said that translating documents from the physical to the virtual yielded some real-world historical discoveries. Yes, as the museum has long suspected but could never quite say definitively, Picasso is the artist who has been included in the most exhibitions (more than 320). The digital archive project will include almost 33,000 exhibition installation photographs, most never previously available online, along with the pages of 800 out-of-print catalogs and more than 1,000 exhibition checklists, documents related to more than 3,500 exhibitions from 1929 through 1989. (The project, supported by the Leon Levy Foundation, will continue to add documents from more recent years and also plans to add archives from the museum's film and performance departments.) One of the surprises for regular museum visitors will undoubtedly be the highly varied forms the galleries and exhibition programs have taken since the museum first opened in rented offices on Fifth Avenue and then grew, on 53rd Street, into the shiny, streamlined version that the architects Edward Durell Stone and Philip Johnson helped create.

top

Avvo wins First Amendment fight, as judge compares it to Sports Illustrated (Bob Ambrogi, 14 Sept 2016) - A federal court has dismissed a putative class action against Avvo under the Illinois Right of Publicity Act, ruling that Avvo's lawyer listings are comparable to the editorial content in Sports Illustrated and deserving of the same First Amendment protection. This is the second time in six weeks in which a right-of-publicity class action against Avvo has been dismissed. Lawyer John Vrdolyak filed the lawsuit in the Northern District of Illinois, alleging that Avvo was using his identity for commercial purposes without his consent, in violation of Illinois law. It did this by listing his profile without his consent and by placing paid advertising on his profile page, including advertising by competing lawyers, he contended. But in granting Avvo's motion to dismiss, U.S. District Judge Robert W. Gettleman found that Avvo's lawyer listings constituted non-commercial speech fully protected by the First Amendment. (The full decision is embedded below.)

top

Ninth Circuit tells FTC to back off common carriers (Steptoe, 15 Sept 2016) - The U.S. Court of Appeals for the Ninth Circuit dismissed a case brought by the FTC against AT&T for allegedly violating Section 5(a) of the FTC Act by reducing internet speeds for customers with unlimited data plans once they exceeded certain usage levels (called "data throttling"). At issue in the case was the scope of the exemption to the FTC Act for "common carriers." The FTC argued that while a substantial part of AT&T's activity constitutes common carrier activity, data service was not a common carrier activity at the time AT&T engaged in the alleged activities, so the exemption did not apply to these activities. The Ninth Circuit, however, held that the common carrier exemption is "status-based," not "activity-based"; thus, AT&T, due to its "status" as a common carrier, was exempt from the FTC Act.

top

IP lawyer learns the hard way: Copying Newegg appellate brief is not fair use (Reuters, 15 Sept 2016) - Just a few years ago, the New Jersey intellectual property lawyer Ezra Sutton was on the same side as the online retailer Newegg. Newegg and Sutton's client, the electronics company Sakar International, were among dozens of defendants sued in Texas federal district court by Adjustacam, a patent plaintiff often described as a "troll." Newegg and Sakar refused to settle with Adjustacam, which ended up dropping its case. Sutton worked with Newegg lawyers on separate motions for attorneys' fees from Adjustacam. When the trial judge denied the fee requests, Newegg and Sutton's client both decided to appeal the fee ruling to the Federal U.S. Circuit Court of Appeals. That is when Sutton discovered that Newegg - which is known as a warrior against what it considers unwarranted patent claims - is just as tough on its erstwhile allies as it is on its sworn enemies. As Newegg general counsel Lee Cheng recounts the story, he told Sutton early on that Newegg would be willing to file a joint brief with Sakar if Sakar paid a share of the legal fees. Sutton said no thanks, but, as the filing deadline approached, he came back to Newegg. Cheng agreed to show Sutton a draft of the brief Newegg intended to submit to the Federal Circuit to help him write a complementary brief for Sakar. Instead, the day before Newegg's brief was due, Sutton filed a brief that was largely copied from Newegg's draft. When Newegg realized what he'd done and protested the filing, Sutton withdrew the brief and subsequently filed a shorter version focused on Sakar's argument. That wasn't good enough for Newegg. In February 2015, the company sued Sutton for copyright infringement in Los Angeles federal district court. On Tuesday, U.S. District Judge Terry Hatter ruled that Sutton's copying was not fair use, despite Sutton's arguments that Newegg wasn't harmed by the copying. The judge held Sutton liable for copyright infringement. Damages are to be determined at a trial in December. I've never before seen a case in which a lawyer is on the hook for copying a co-defendant's brief. And after talking Thursday to Sutton and Newegg general counsel Cheng, I have mixed feelings about the outcome. * * *

top

FBI restricts impersonation of journalists (The Hill, 15 Sept 2016) - The FBI is imposing new restrictions making it more difficult for investigators to impersonate journalists, following scrutiny over a 2007 episode in which the bureau posed as a reporter to track a suspected criminal. The FBI did not violate its internal policy during that controversial incident, the Justice Department's Office of the Inspector General claimed in a 30-page report. Yet this June, it implemented an interim policy barring impersonation of a journalist without approval from the FBI's deputy director, the watchdog revealed. The changes are the result of a 2007 incident when FBI investigators wrote a fake AP story and placed it on a website designed to mimic the Seattle Times in order to infect a suspect's computer. A link to the story bearing the headline "Bomb threat at high school downplayed by local police department" was sent to the MySpace page of a student suspected of making multiple threats against the school and launching cyberattacks against its computer network. In followup emails to the student, Charles Jenkins, an FBI investigator portrayed himself as an "AP staff publisher" in order to get Jenkins to click on the link and links to other photographs. The operation became public in 2014 and was immediately attacked by news organizations claiming that it eroded the public's trust in journalists.

top

EU Court: Wi-Fi providers not responsible for illegal downloads (Deutsche Welle, 15 Sept 2016) - The Court of Justice of the European Union (CJEU) issued a decision freeing businesses that provide free Wi-Fi internet access to their customers from being held responsible for copyright infringement committed by their patrons. The decision by the European Court of Justice in Luxembourg serves as a new precedent in case law across the European Union. In 2010, Sony had brought legal proceedings against a shopkeeper in Germany after a customer used free internet access to illegally download a music album covered by Sony's copyright stipulations. The court found that the owner of the business had no say in the perpetrator's decision to illegally download the data in question. The European Court of Justice did concede, however, that those providing free online access could be obliged secure their networks with a password or to have users sign in with their names to establish their identities. The district court in Munich, which initially was in charge of the case, had turned to the CJEU to ask for assistance in the case, as the alleged copyright infringement was covered by European law. The owner of the shop meanwhile commented that he found the court decision to be "disappointing" because it would serve as a further hindrance to establishing free Wi-Fi across Europe. He referred to the ruling as a "partial win."

top

When Alexa is listening, what do you tell houseguests? (Christian Science Monitor, 16 Sept 2016) - Earlier this week, Amazon unveiled its $50 internet-connected personal assistant "so you can add Alexa to any room in your home." Alexa is the online giant's artificial-intelligence powered bot that listens to what you say and answers your commands and questions: What's the weather? How's traffic? Can you order me a large pepperoni pizza? And the low priced Echo Dot, about the size of a hockey puck, means many more homes will soon have on-command digital listening devices that eavesdrop on - and store - family conversations, holiday celebrations, and even off-color comments (and also bickering siblings or quarreling spouses). Sure, it has its conveniences and Star Trek-like appeal and maybe you're OK with potential privacy implications. But what happens if your houseguests aren't? What if your friends think your robot assistant is creepy? Maybe your in-laws worry about the device's Orwellian implications, or your babysitter is concerned about his privacy. So, what are the manners when it comes to connected homes? Are we approaching a time when we'll warn guests, "Be careful what you say, Alexa is listening." Trevor Hughes, chief executive of the International Association of Privacy Professionals (IAPP), says that moment is fast approaching. "We don't have the social norms for someone to say, 'Oh hey, I have my Amazon Echo on, just so you know.' That's not happening," says Mr. Hughes. "Society will have to decide, what are the right norms? What are the right ways to set the dials so we can maintain privacy and also enjoy these new technologies? We can foresee that there will be flash points, but they haven't happened yet." This confusion isn't exclusive to devices such as Echo. Anything connected to the internet and equipped with a microphone poses quandaries of etiquette. Consider connected toys such as the talking Barbie doll that records and stores its conversations with children. Should parents warn their child's playmates that the dolls could be listening in? [ Polley : see also Google backs off on previously announced Allo privacy feature (The Verge, 21 Sept 2016)]

top

Indian court says 'copyright is not an inevitable, divine, or natural right' and photocopying textbooks is fair use (TechDirt, 19 Sept 2016) - Last week there was a big copyright ruling in India, where a court ruled against some big academic publishers in ruling that a photocopying kiosk that sold photocopied chapters from textbooks was not infringing on the copyrights of those publishers . We wrote about this case over three years ago, when it was first filed . It's actually fairly similar to a set of cases in the US that found college copyshops to be infringing -- leading to a massive increase in educational material for college students. The Indian court went the other way. The full ruling takes a fair use-style look at the question, and recognizes that educational purposes are more important than padding the bank account of some big publishers. The ruling is pretty long, but there are a number of good points in there. Here's the one that a bunch of people have been quoting, noting that copyright is not inevitable, divine or a natural right: Copyright, specially in literary works, is thus not an inevitable, divine, or natural right that confers on authors the absolute ownership of their creations. It is designed rather to stimulate activity and progress in the arts for the intellectual enrichment of the public. Copyright is intended to increase and not to impede the harvest of knowledge. It is intended to motivate the creative activity of authors and inventors in order to benefit the public.

top

Lloyd's of London survey reveals nine out of 10 businesses have suffered a major cyber attack (ITProPortal, 20 Sept 2016) - According to a new survey, nine out of 10 big business in Europe have fallen victim to a significant cyber attack during the last five years, though less than half are concerned regarding the possibility of future breaches.

Lloyd's of London conducted a survey of chief executives and senior bosses at 346 European companies with a turnover of €250 million or more. The boss of the company, Inga Beale believes that the results of the survey show that European businesses are "complacent" when it comes to cyber attacks and the damage they could cause their business and brands.

top

- and -

Verizon's statement on Yahoo's data breach is about as rough as it gets (Mashable, 22 Sept 2016) - You don't see corporate statements like this every day. On Thursday, Yahoo admitted that a data breach in 2014 ended up with the theft of far more user data than had been previously thought. By Yahoo's count, some 500 million user accounts had at least some information stolen. That's news to Verizon, the company that acquired Yahoo's core business in July for $4.83 billion but has not yet finalized the acquisition. When reached for comment, Verizon released a pretty stunning statement, claiming it had not been aware of the breach until very recently. "Within the last two days, we were notified of Yahoo's security incident. We understand that Yahoo is conducting an active investigation of this matter, but we otherwise have limited information and understanding of the impact. We will evaluate as the investigation continues through the lens of overall Verizon interests, including consumers, customers, shareholders and related communities. Until then, we are not in position to further comment." Among the surprising details, Verizon is claiming that Yahoo only provided notification of the breach in the last two days. TWO DAYS. Yahoo has had a deal with Verizon for an acquisition for two months. Next, Verizon said that even now, the company doesn't really know what's going on. I'm sure it knows more than we do at this point, but you'd imagine that with almost $5 billion on the line, there would be a healthy amount of transparency.

top

University may remove online content to avoid disability law (InsideHigherEd, 20 Sept 2016) - The University of California, Berkeley, has announced that it may eliminate free online content rather than comply with a U.S. Justice Department order that it make the content accessible to those with disabilities. The content in question is all free and is for the general public to use. "The department's findings do not implicate the accessibility of educational opportunities provided to our enrolled students," said a statement on the situation by Cathy Koshland, vice chancellor for undergraduate education. While the university has not made a final decision, she said, it may not be able to afford complying with the Justice Department's recommendations on how to make the online material accessible. The material in question involves courses provided by Berkeley through the edX platform for massive open online courses, and videos on YouTube and iTunes University. The Department of Justice found that much of this online material is in violation of the Americans With Disabilities Act, which requires colleges to make their offerings accessible to people with disabilities. The department investigation followed complaints by two individuals who are deaf -- one of them a faculty member at Gallaudet University and one at its school for elementary and secondary school students. Both said that they are unable to use Berkeley online material because it has not been formatted for use by people with hearing disabilities. Berkeley released the Justice Department letter finding the university in violation of ADA. The letter outlined numerous concerns about issues related to those who are deaf as well as those who have visual disabilities: * * *

top

Court: With 3D printer gun files, national security interest trumps free speech (ArsTechnica, 21 Sept 2016)) - A federal appeals court ruled Tuesday against Defense Distributed, the Texas organization that promotes 3D-printed guns, in a lawsuit that it brought last year against the State Department. In a 2-1 decision, the 5th Circuit Court of Appeals was not persuaded that Defense Distributed's right to free speech under the First Amendment outweighs national security concerns. As Ars reported in February 2016 , the lawsuit, Defense Distributed v. Department of State , centers on whether a website that publishes CAD files-which would enable foreigners outside the US to print a firearm-violates munitions export laws. Fearing a possible lawsuit by the State Department or prosecution by the government, Defense Distributed took the files down three years ago , but they have since reappeared on BitTorrent sites. The federal civil suit originated three years ago when Cody Wilson and his group, Defense Distributed, published designs for the " Liberator ," the world's first 3D-printed handgun. Within months, Defense Distributed received a letter from the United States Department of State's Office of Defense Trade Controls Compliance , stating that 10 files, including the designs of the Liberator, were in violation of the International Traffic in Arms Regulations (ITAR). This letter came despite the fact that these files had already been downloaded hundreds of thousands of times and continue to circulate online. Defense Distributed then re-submitted a "commodity jurisdiction request" to the Department of State, which they hoped would clear the way for the publication of the files. After waiting for two years, Defense Distributed, along with the Second Amendment Foundation, sued the Department of State and argued that the government's action constituted "prior restraint"-preventing publication before it occurs. In the United States, the Supreme Court has generally rejected the concept of prior restraint. However, one member of the 5th Circuit, District Judge Edith Jones, directly disagreed with her colleagues. In a scathing dissent, she called it an "irrational representation" of the export regulations. She also described the government's actions as "pure content-based regulation."

top

A new service just launched that allows voters in key states to register to vote via text message (Business Insider, 22 Sept 2016) - Registering to vote may now be a lot easier for a portion of the roughly 90% of Americans who own a cellphone. The nonprofit group Fight For The Future launched HelloVote on Thursday morning with the goal of boosting voter registration in several key battleground states by allowing voters to register directly via text message or Facebook Messenger. Backed by brands like MTV, Genius, and the Latino Victory Project, the tool is the first major service to offer voter registration through text messaging, a process the company hopes will boost voter registration rolls, particularly among young voters. HelloVote today can register people to vote via SMS or Facebook in six states: Arizona, California, Colorado, Georgia, Massachusetts, and Virginia. HelloVote is only partially operational in other states. Each state maintains its own election laws, and many still require that voters mail in paper registration forms. In these instances, HelloVote's text system fills out the registration form via SMS and creates a printer-friendly version for voters to print out and submit.

top

NOTED PODCASTS/MOOCS

Crypto arg: CA3 judges seemed on board that being forced to enter passcode only testifies to knowing the passcode. (Orin Kerr on Twitter, 8 Sept 2016) - Oral argument here: http://www2.ca3.uscourts.gov/oralargument/audio/15-3537USAv.AppleMacProComputer.mp3

top

BOOKS

Weapons of Math Destruction: The Dark Side of Big Data (review in InsideHigherEd, 21 Sept 2016) - So often when someone starts a Twitter message with the label "Must read" I get defensive. You're not my teacher. I'm a grown up. I get to decide what I'm going to read, thank you very much. But I'm really tempted to start this post with "Must read" because Cathy O'Neil's book, Weapons of Math Destruction: How Big Data Increases Inequality and Threatens Democracy is important and covers issues everyone should care about. Bonus points: it's accessible, compelling, and - something I wasn't expecting - really fun to read. O'Neil is a data scientist who taught at Barnard before being seduced by the excitement of applying mathematics to finance, working for a Wall Street hedge fund before the crash of 2008. One of the things she quickly learned was different from academic mathematics was that employees were treated like members of an Al Qaida cell: the amount of information they could share was strictly limited so that if anyone was captured by a competing firm, they couldn't reveal too much. Also, the scale of their collective if obscure work was ginormous. Subprime mortgages were a three trillion dollar market, but the markets created around them through credit default swaps, synthetic CDOs, and other weird financial inventions based on math and baloney was twenty times that size. As it all began to collapse, the damage cascaded, and people, lots of people, got hurt. These risky financial instruments, like many other proprietary big data projects - what O'Neil calls "weapons of math destruction" - have features in common. They are opaque (few people could understand them even if they weren't trade secrets that cannot be examined by those who are subject to the decisions they make); they work at large scale, and because they are sealed systems, they can't learn from their mistakes. They can do a lot a damage and are bizarrely unaccountable for it, often claiming greater objectivity than the fallible humans who encode them. Her experience in high finance is a cautionary tale because the features that crashed the world economy are present in big data systems that affect our lives in myriad ways, from education to jobs to the criminal justice system to how we are persuaded to vote. * * *

top

LOOKING BACK - MIRLN TEN YEARS AGO

(note: link-rot has affected about 50% of these original URLs)

Free calls from AIM (InternetNews.com, 8 May 2006) -- First came free e-mail addresses, and then came free IM accounts. Later this month, Dulles, Va.-based AOL plans to offer free phone numbers through its instant messenger (AIM). AIM Phoneline brings Internet phone calling to the more than 40 million AOL instant messenger users. Slated to begin May 16 in 50 U.S. markets, the service will offer a free base of features along with a $14.95 fee-based premium option, according to an AOL spokesperson. Based on AIM Triton, AIM Phoneline augments AOL's TotalTalk VoIP offering. AOL will offer Phoneline users free local phone numbers enabling unlimited inbound calls from traditional phones, cell phones and PCs. Cell phone users can receive text messages alerting them when an IM-based call is received, as well as listen to Phoneline voicemail. Along with free phone numbers, AOL will provide AIM users free voicemail. Calls not answered are saved as MP3 files and sent to an AOL or AIM mailbox, according to a company statement. While the differences between AOL's VoIP plans "are kind of subtle," the company wants to be sure all its bases are covered, according to Joe Laszlo, analyst with JupiterResearch.

top

Proposed FEC rules would exempt most political activity on internet (Washington Post, 25 March 2006) -- The Federal Election Commission last night released proposed new rules that leave almost all Internet political activity unregulated except for the purchase of campaign ads on Web sites. "My key goal in this rule-making has been to make sure that the commission establish clear rules to exempt individuals who engage in online politics from campaign finance laws," said Chairman Michael E. Toner, a Republican. "We tried to craft a regulation that would allow the maximum amount of freedom for people as possible," said Commissioner Ellen L. Weintraub, a Democrat. Most bloggers, individual Web users, and such Web sites as Drudge Report and Salon.com are exempted from regulation and will be free to support and attack federal candidates, much as newspapers are allowed. For the most part, leading advocates of the blogger community welcomed the proposed rules. "As a whole, these are rules that I think those who have been fighting regulations are going to be cheering," said Richard L. Hasen, a professor at Loyola Law School in Los Angeles, who runs the Election Law blog. The rules provide "broad exemptions for most political activity on the Internet, and expand the media exemption to the Internet," he said. Hasen and others noted that as technology advances, the regulations will have to be modified. In particular, Hasen said, "as the Internet and TV converge, the FEC or Congress will eventually need to rethink these rules to see if they make sense." "Generally, it's in line with what I think bloggers ask for," said Jerome Armstrong, the founder of the liberal blog MyDD, an adviser to the Howard Dean for president campaign in 2004 and currently an adviser to former Virginia governor Mark R. Warner's political action committee. "They give bloggers the media exemption." Armstrong voiced concern, however, over potential difficulties that could result from a requirement that campaign ads have disclaimers. "The size of a Web ad and the size of blog ad is so small that having to put a disclaimer on it is going to take up all the space," he said.

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, http://www.sans.org/newsletters/newsbites/

4. Aon's Technology & Professional Risks Newsletter

5. Crypto-Gram, http://www.schneier.com/crypto-gram.html

6. Steptoe & Johnson's E-Commerce Law Week

7. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/

8. The Benton Foundation's Communications Headlines

9. Gate15 Situational Update Notifications, http://www.gate15.us/services.html

10. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top