Saturday, September 26, 2009

MIRLN --- 6-26 September 2009 (v12.13)

• Court Says Court Reporters do not Retain Copyright on Transcripts they Prepare
o Twitter Confirms User Ownership of Tweets
• Court Allows Suit against Bank for Lax Security
o How to Measure Security? NIST Maps out the Emerging Field of IT Metrology
• Web-Monitoring Software Gathers Data on Kid Chats
• “Anonymized” Data Really Isn’t—And Here’s Why Not
• New Jersey Courts Employ Social Media
o A Legal Battle: Online Attitude vs. Rules of the Bar
o Jurors Required to Sign Promises not to Google Details of Case
o Substantial Growth in Online Social Networking by Lawyers over the Past Year
o New Jersey Appellate Court Provides Guidance on How Company Email Policies Should Be Crafted
o Employers Grappling with Social Network Use
• The Sunlight Foundation Names Apps-For-America2 Winners
o White House Takes a Big Step into the Cloud with Apps.Gov
• HHS and FTC Issue Rulemakings on HITECH Breach Notification Provisions
• Times Reporter Blogs His Own Kidnapping
• US Court of Appeals for the Ninth Circuit Establishes Protocols for Searches of Electronically Stored Information
• Court Rules Overstock Can’t Enforce ‘Browsewrap’ Agreement
• Seyfarth Shaw Says Six Sigma Method has Cut Client Fees by up to 50%
• Five Major Research Universities Endorse Open-Access Journals
o Higher Ed. And TED
o From Ivory Tower to Iron Bars: Scientists Risk Jail Time for Violating Export Laws
o The Mobile Campus
o A Library Address
• Airplane Liquid Bombers
• Sears Told to Destroy Data Gathered by Online Tracking Software
• Govt Review: No Privacy Problems in Cyber Security
• National Security Threats in Cyberspace - ABA Workshop Report
• Google Confirms that Keyword Metatags Don’t Matter
o EU Adviser: Google Ads Don’t Infringe Trademarks
• Federal Courts now Offer Hearings Online as Mp3 Files
• If The Army Can Put its Doctrine up on a WiKi, You’ve Got No Excuse
• 3rd Circuit Says Corporations May Take Info Requests ‘Personally’

NEWS | DIFFERENT | COMMENTARY | LOOKING BACK | NOTES

**** NEWS ****
COURT SAYS COURT REPORTERS DO NOT RETAIN COPYRIGHT ON TRANSCRIPTS THEY PREPARE (TechDirt, 27 August 2009) - In a world where almost every new expression is automatically covered by copyright once set in fixed form, you get some really odd situations -- highlighted by a recent ruling pointed out by Michael Scott. Apparently, in a lawsuit between bunch of plaintiffs and the city of Albuquerque, the city paid for a court reporter to record transcripts of some hearings. An attorney for the plaintiffs who wanted to use the transcripts did the smart thing and used New Mexico’s Inspection of Public Records Act to gain access to the transcripts. The problem? The city and the court reporter who recorded the transcripts would have charged a much higher fee for a copy of the transcripts, and felt that the lawyer’s use of the law to gain access was somehow unfair. The court then ordered the lawyer to pay the court reporter over $4,000 to make up the “difference.” The lawyer, however, appealed, and the appeals court has thrown out the lower court ruling, saying that forcing the lawyer to pay the higher fee would mean that the court reporter effectively was given a copyright to the transcripts: “In broad terms, [the court reporter’s] fee claim rests on the tacit premise that court reporters in some legal sense own the content of the transcripts they prepare, such that they are entitled to remuneration whenever a copy of a transcript is made (even if they played no role in making the copy). To accept this premise would effectively give court reporters a “copyright” in a mere transcription of others’ statements, contrary to black letter copyright law. See 2 William F. Patry, Patry on Copyright, Ch. 4 Noncopyrightable Material, § 4.88 (Updated Sept. 2008) (court reporters are not “authors of what they transcribe and therefore cannot be copyright owners of the transcript of court proceedings”).” http://techdirt.com/articles/20090827/0231116015.shtml

- and -

TWITTER CONFIRMS USER OWNERSHIP OF TWEETS (Information Week, 11 Sept 2009) - Twitter co-founder Biz Stone on Thursday said that the popular online messaging site had updated its Terms of Service to clarify what users can expect from the service, though the announcement appears to be more about reassuring users than delineating substantive rights. The move suggests a desire not to repeat the controversy that Facebook found itself in when, in February, the social network altered its Terms of Service and users read the language as a claim of ownership over all user-submitted content. “The revisions [of Twitter’s Terms of Service] more appropriately reflect the nature of Twitter and convey key issues such as ownership,” said Stone in a blog post. “For example, your tweets belong to you, not to Twitter.” This does not appear to be much of a change, however. Twitter’s Terms of Service from October 2007 state, “We claim no intellectual property rights over the material you provide to the Twitter service. Your profile and materials uploaded remain yours.” Such assurances may mollify twittering authors of note but they’re not particularly meaningful. “The vast majority of tweets are likely to be too short and lacking in creativity to qualify for copyright,” said Fred von Lohmann, senior staff attorney for the Electronic Frontier Foundation, in an e-mail. “So they are not ‘owned’ by anyone, much like your idle chatter while walking down the street isn’t ‘owned’ by anyone.” Lohmann however grants that there are exceptions, such as a carefully-crafted haiku that was tweeted. http://www.informationweek.com/news/internet/social_network/showArticle.jhtml?articleID=220000033&cid=RSSfeed_IWK_News

COURT ALLOWS SUIT AGAINST BANK FOR LAX SECURITY (ComputerWorld, 2 Sept 2009) - A couple whose bank account was breached can sue their bank for its alleged failure to implement the latest security measures designed to prevent such compromises. In a ruling issued last month, Judge Rebecca Pallmeyer, of the District Court for the Northern District of Illinois, denied a request by Citizens Financial Bank to dismiss a negligence claim brought against it by Marsha and Michael Shames-Yeakel. The Crown Point, Ind. couple -- customers of the bank -- alleged that Citizens’ failure to implement up-to-date user authentication measures resulted in the theft of more than $26,000 from their home equity line of credit. The negligence claim was one of several claims brought against Citizens by the couple. Although, Pallmeyer dismissed several of the other claims, she allowed the negligence claim against Citizens to stand. She noted that the couple had shown that a “reasonable finder of fact could conclude that the bank breached its duty to protect Plaintiffs’ account against fraudulent access.” The ruling highlights an issue that security analysts have been talking about for a long time: the need by companies to show due diligence in protecting customer data against malicious and accidental compromise. Security analysts have warned that companies that can’t prove they took adequate measures to protect data could find themselves exposed to legal liability after a data breach. http://www.computerworld.com/s/article/9137451/Court_allows_suit_against_bank_for_lax_security?source=CTWNLE_nlt_dailyam_2009-09-03

- and -

HOW TO MEASURE SECURITY? NIST MAPS OUT THE EMERGING FIELD OF IT METROLOGY (GCN, 10 Sept 2009) - Information technology security is a hot topic, but attention usually focuses on the lack of it. What is missing is an objective, quantifiable way to effectively measure it. “Security can be looked at in different ways by different people,” said Wayne Jansen, a computer scientist at the National Institute of Standards and Technology’s IT Laboratory. There is quality control for code developers, the process of deploying a system, and its maintenance by users. “These are all different aspects,” and they do not lend themselves to traditional methods of measurement used in physical science, he said. Jansen has examined the status of efforts to develop security metrics, identified challenges and suggested a course for future research in a recent NIST report, “Directions in Security Metrics Research.” There have been a number of efforts to establish metric systems for security, including the international Common Criteria, the Defense Department’s Trusted Computer System Evaluation Criteria, the European Communities’ Information Technology Security Evaluation Criteria, and the International Systems Security Engineering Association’s Systems Security Engineering Capability Maturity Model. http://gcn.com/Articles/2009/09/14/Update-1-Security-metrics-lacking-for-IT-systems.aspx?s=gcndaily_110909&Page=1

WEB-MONITORING SOFTWARE GATHERS DATA ON KID CHATS (AP, 4 Sept 2009) - Parents who install a leading brand of software to monitor their kids’ online activities may be unwittingly allowing the company to read their children’s chat messages — and sell the marketing data gathered. Software sold under the Sentry and FamilySafe brands can read private chats conducted through Yahoo, MSN, AOL and other services, and send back data on what kids are saying about such things as movies, music or video games. The information is then offered to businesses seeking ways to tailor their marketing messages to kids. “This scares me more than anything I have seen using monitoring technology,” said Parry Aftab, a child-safety advocate. “You don’t put children’s personal information at risk.” The company that sells the software insists it is not putting kids’ information at risk, since the program does not record children’s names or addresses. But the software knows how old they are because parents customize its features to be more or less permissive, depending on age. Five other makers of parental-control software contacted by The Associated Press, including McAfee Inc. and Symantec Corp., said they do not sell chat data to advertisers. http://tech.yahoo.com/news/ap/20090904/ap_on_hi_te/us_tec_internet_monitoring_kids_3

“ANONYMIZED” DATA REALLY ISN’T—AND HERE’S WHY NOT (ArsTechnica, 8 Sept 2009) - The Massachusetts Group Insurance Commission had a bright idea back in the mid-1990s—it decided to release “anonymized” data on state employees that showed every single hospital visit. The goal was to help researchers, and the state spent time removing all obvious identifiers such as name, address, and Social Security number. But a graduate student in computer science saw a chance to make a point about the limits of anonymization. Latanya Sweeney requested a copy of the data and went to work on her “reidentification” quest. It didn’t prove difficult. Law professor Paul Ohm describes Sweeney’s work: “At the time GIC released the data, William Weld, then Governor of Massachusetts, assured the public that GIC had protected patient privacy by deleting identifiers. In response, then-graduate student Sweeney started hunting for the Governor’s hospital records in the GIC data. She knew that Governor Weld resided in Cambridge, Massachusetts, a city of 54,000 residents and seven ZIP codes. For twenty dollars, she purchased the complete voter rolls from the city of Cambridge, a database containing, among other things, the name, address, ZIP code, birth date, and sex of every voter. By combining this data with the GIC records, Sweeney found Governor Weld with ease. Only six people in Cambridge shared his birth date, only three of them men, and of them, only he lived in his ZIP code. In a theatrical flourish, Dr. Sweeney sent the Governor’s health records (which included diagnoses and prescriptions) to his office.” Boom! But it was only an early mile marker in Sweeney’s career; in 2000, she showed that 87 percent of all Americans could be uniquely identified using only three bits of information: ZIP code, birthdate, and sex. http://arstechnica.com/tech-policy/news/2009/09/your-secrets-live-online-in-databases-of-ruin.ars [Editor: Paul Ohm has a coming article tentatively titled “The Probability of Privacy”; early drafts are provoking. See also https://www.eff.org/deeplinks/2009/09/what-information-personally-identifiable]

NEW JERSEY COURTS EMPLOY SOCIAL MEDIA (Robert Ambrogi, 8 Sept 2009) - Thanks to the blog Social Media Law Student for the heads-up about the announcement from the New Jersey judiciary that it is adopting an array of social-media tools to keep lawyers, litigants and the public better informed of court developments. The court system now has a Twitter feed and uses text messages to send out breaking news alerts. These cover unscheduled court closings and other high priority information. The courts also now have three RSS feeds -- one for news releases, one for notices to the bar, and a third for Supreme and Appellate Court opinions. In addition, the court system has set up a Facebook page, where it will post press releases, court information and photos of court events, and a YouTube page, where it will post videos that offer lessons in using the courts. http://www.legaline.com/2009/09/new-jersey-courts-employ-social-media.html

- and -

A LEGAL BATTLE: ONLINE ATTITUDE VS. RULES OF THE BAR (New York Times, 13 Sept 2009) - Sean Conway was steamed at a Fort Lauderdale judge, so he did what millions of angry people do these days: he blogged about her, saying she was an “Evil, Unfair Witch.” But Mr. Conway is a lawyer. And unlike millions of other online hotheads, he found himself hauled up before the Florida bar, which in April issued a reprimand and a fine for his intemperate blog post. Mr. Conway is hardly the only lawyer to have taken to online social media like Facebook, Twitter and blogs, but as officers of the court they face special risks. Their freedom to gripe is limited by codes of conduct. “When you become an officer of the court, you lose the full ability to criticize the court,” said Michael Downey, who teaches legal ethics at the Washington University law school. And with thousands of blogs and so many lawyers online, legal ethics experts say that collisions between the freewheeling ways of the Internet and the tight boundaries of legal discourse are inevitable — whether they result in damaged careers or simply raise eyebrows. Mr. Conway initially consented to a reprimand from the bar last year, but the State Supreme Court, which reviews such cases, demanded briefs on First Amendment issues. The American Civil Liberties Union of Florida argued that Mr. Conway’s statements were protected speech that raised issues of legitimate public concern. Ultimately the court affirmed the disciplinary agreement and Mr. Conway paid $1,200. That penalty is light compared with the price paid by Kristine A. Peshek, a lawyer in Illinois who lost her job as an assistant public defender after 19 years of service over blog postings and who now faces disciplinary hearings as well. http://www.nytimes.com/2009/09/13/us/13lawyers.html?_r=1&hp

- and -

JURORS REQUIRED TO SIGN PROMISES NOT TO GOOGLE DETAILS OF CASE (TechDirt, 16 Sept 2009) - There have been plenty of stories concerning judges warning jurors not to research any additional items about a case online, but JJ points us to what is apparently a first (at least in California). A judge has ordered the jury to sign a document that they will not use the internet to research the case, and they can face perjury charges if they’re caught doing so. http://techdirt.com/articles/20090915/0412536196.shtml

- and -

NEW JERSEY APPELLATE COURT PROVIDES GUIDANCE ON HOW COMPANY EMAIL POLICIES SHOULD BE CRAFTED (Duane Morris, 21 Sept 2009) - In light of a recent New Jersey appellate court decision, employers may want to review and update company email policies to ensure that employees are properly made aware that employers have the right to access and review certain private emails that may be generated through a company-sponsored computer system. In Stengart v. Loving Care Agency, Inc.,1 the New Jersey Superior Court, Appellate Division, clarified how an employer should craft email policies to ensure that employees understand that, while they may consider certain emails to be private, the employer nonetheless retains the right to access the materials by virtue of the employee’s use of company technology. http://www.duanemorris.com/alerts/NJ_Employment_Email_Stengart_3408.html

- and -

SUBSTANTIAL GROWTH IN ONLINE SOCIAL NETWORKING BY LAWYERS OVER THE PAST YEAR (BeSpacific, 20 Sept 2009) - 2009 Networks for Counsel Study - A Global Study of the Legal Industry’s Adoption of Online Professional Networking, Preferences, Usage and Future Predictions - Sample Composition: “The survey was administered to 1,474 counsel – 764 private practice lawyers and 710 corporate counsel –in May and June of 2009; 33 countries were represented. Financial Services, Manufacturing and Healthcare were the top three industries represented.” Key Findings: “Networking remains critical to the legal industry, yet resource constraints make it more difficult than ever; Use of social networking sites has grown significantly over the past year, with three‐quarters of all counsel now reporting they are members of a social or professional network..” http://www.bespacific.com/mt/archives/022366.html#022366 Study here: http://www.leadernetworks.com/documents/Networks_for_Counsel_2009.pdf

- and -

EMPLOYERS GRAPPLING WITH SOCIAL NETWORK USE (CNET, 24 Sept 2009) - Social networking is on the rise, both on and off the job, leaving companies uncertain how to monitor their use by employees, reports new survey. More than 50 percent of companies questioned said they have no policy to address the use of social networking by employees outside the workplace, according to a survey released Wednesday by the Society of Corporate Compliance and Ethics and the Health Care Compliance Association. Typically, companies shy away from restricting an employee’s actions off the job. But businesses are concerned about employees who use social networking and reveal private details or post inappropriate pictures that could embarrass the company. Some organizations, such as the U.S. Marines, have already banned their recruits from using Facebook and Twitter. But the survey found that many businesses aren’t sure what to do to restrict or monitor such usage. Of the companies questioned in the survey, 34 percent said they have a general employee policy that addresses all online activity, including the use of social networking, both on and off the job. Only 10 percent said they have a policy specifically geared toward social networks. http://news.cnet.com/8301-10797_3-10360849-235.html [Editor: This is my area of concentration – see http://www.knowconnect.com/policies/ and the various articles and presentations available there.]

THE SUNLIGHT FOUNDATION NAMES APPS FOR AMERICA2 WINNERS (press release, 9 Sept 2009) - The Sunlight Foundation awarded Datamasher.org with the grand prize of $10,000 for Sunlight’s Apps for America 2: The Data.gov Challenge. Datamasher.org is a Web application designed by Forum One Communications that lets anyone—no programming background required—choose different government data sets and mash them up to create visualizations and compare results on a state by state basis. Clay Johnson, director of Sunlight Labs, announced the winners and distributed over $25,000 in awards late yesterday at the Gov 2.0 Expo hosted by O’Reilly Media and TechWeb. Sunlight created the Apps for America 2: The Data.gov Challenge to solicit creative Web applications based on the information available at Data.gov, the new central depository for government data created by Federal Chief Information Officer Vivek Kundra. It was inspired by the Sunlight’s commitment to use new tools to make the work of the federal government more transparent. The $5,000 second prize went to GovPulse, which allows viewers to quickly search the Federal Register in a variety of ways, including by agency or date. Sunlight awarded the third place award of $2,500 to ThisWeKnow.org, which lets users type in their zip code and get back a wealth of information about their neighborhood drawn from different agencies. Additionally, QuakeSpotter.org won the bonus prize of $2,500 for best data visualization. QuakeSpotter.org, a cross-platform desktop application shows where earthquakes are happening and matches that to mentions of the earthquake on the popular social network, Twitter. http://sunlightfoundation.com/presscenter/releases/2009/09/09/sunlight-names-apps-america2-winners/

- and -

WHITE HOUSE TAKES A BIG STEP INTO THE CLOUD WITH APPS.GOV (ArsTechnica, 21 Sept 2009) - “The Cloud” may not mean what you think it means, but the White House is hitching a ride on this fluffy bandwagon with Apps.gov. The site is essentially a White House-sanctioned App Store of social media services approved for government agencies, made possible largely because of some unique TOS amendments. Run by the US General Services Administration (GSA), Apps.gov arranges quite a few social media services under categories like Business, Productivity, Social Media, and Cloud IT, with the latter listing services like storage, Web hosting, and virtualization as “coming soon.” Almost every commercial and free service that you have (and have not) heard of is here, ranging from Facebook, Scribd, Vimeo, and Google Apps. The site also offers a market-speak crash course in the cloud’s advantages of reduced cost, less overhead, going green, and adopting modern technologies and trends more quickly. Agency representatives can learn about each service and, once logged in, submit a department request or purchase order. The entire process seems deceptively App Store-simple (at least the publicly accessible portion), especially since most of the red tape around adopting such services is summarized in the FAQs. In a way, the GSA is treating Apps.gov like high schools now treat Wikipedia: it’s OK to use as research springboard, but agencies should consult their respective higher powers before diving into the deep end. http://arstechnica.com/web/news/2009/09/white-house-takes-a-big-step-into-the-cloud-with-appsgov.ars?utm_source=microblogging&utm_medium=arstch&utm_term=Main%20Account&utm_campaign=microblogging

HHS AND FTC ISSUE RULEMAKINGS ON HITECH BREACH NOTIFICATION PROVISIONS (Sidley Austin, 9 Sept 2009) - The U.S. Department of Health and Human Services (“HHS”) and Federal Trade Commission (“FTC”) recently issued separate rules implementing the groundbreaking breach notification provisions of the Health Information Technology for Economic and Clinical Health Act (“HITECH”). HHS’ breach notification interim final rule applies to entities that meet the definition of “covered entity” or “business associate” under the privacy and security regulations promulgated under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). FTC’s breach notification final rule applies to entities – other than covered entities or business associates – that offer or maintain personal health records (“PHR vendors”), certain entities offering products or services through PHR Web sites or providing services to PHR vendors, and third-party service providers of such entities. Although HHS and FTC each stated that they consulted closely to harmonize the two rules, the agencies’ regulations contain at least two major differences. Under the HHS interim final rule, a reportable breach occurs only if there is a significant risk of harm to the individual. In contrast, the FTC final rule presumes unauthorized acquisition when there is unauthorized access to data unless the entity that discovers the incident can rebut the presumption with “reliable evidence” showing there has not been, or could not reasonably have been, unauthorized acquisition of such data. Additionally, the HHS interim final rule applies to protected health information (“PHI”) in any form (paper or electronic) whereas the FTC rule applies only to electronic information. The HHS and FTC rules take effect 30 days after publication in the Federal Register (September 23, 2009, for the HHS interim final rule with request for comments, and September 24, 2009, for the FTC final rule). Significantly, however, HHS and FTC have stated that they will not enforce the notification requirements for breaches that are discovered within 180 days from the date of publication in the Federal Register (February 22, 2010). http://www.sidley.com/files/News/7a96572a-07f5-4b1f-a20c-82d59fc159ce/Presentation/NewsAttachment/546dc18d-8ed9-4bf0-a4dc-8601afae4653/Healthcare_Privacy_Update_09.09.09.pdf#page=1 See also: http://www.steptoe.com/publications-6321.html

TIMES REPORTER BLOGS HIS OWN KIDNAPPING (Danger Room, 10 Sept 2009) - If you haven’t read it yet, go read New York Times At War blogger Stephen Farrell’s first-person account of his kidnapping by the Taliban — and the death of his Afghan colleague, Sultan Munadi. It’s heartbreaking stuff. But equally important, Farrell’s involuntary “embed” provides a glimpse of the insurgent organization in northern Afghanistan. With a keen eye for detail, Farrell notes everything from the Taliban’s operational security (abysmal), their equipment and financing (marginal) and their control of parts of Kunduz Province (near absolute). http://www.wired.com/dangerroom/2009/09/ny-times-reporter-blogs-his-own-kidnapping/

US COURT OF APPEALS FOR THE NINTH CIRCUIT ESTABLISHES PROTOCOLS FOR SEARCHES OF ELECTRONICALLY STORED INFORMATION (Mayer Brown, 10 Sept 2009) - The long-running BALCO steroid investigation that led to the indictment of Major League Baseball (MLB) star Barry Bonds has resulted in a potentially landmark decision related to the manner in which government agents apply for and execute search warrants for electronically stored information (ESI). In United States v. Comprehensive Drug Testing, Inc., No. 15-10067 (9th Cir. Aug. 26, 2009), the en banc Ninth Circuit affirmed a lower court ruling ordering the government to return an overbroad set of electronic data seized under a search warrant. This decision will force the Department of Justice to adjust its procedures for using ESI search warrants—a common tool for gathering evidence—in the midst of the government’s recent efforts to step up enforcement of federal laws. http://www.mayerbrown.com/publications/article.asp?id=7498&nid=6

COURT RULES OVERSTOCK CAN’T ENFORCE ‘BROWSEWRAP’ AGREEMENT (OnlineMediaDaily, 14 Sept 2009) - A federal judge has ruled that Internet retailer Overstock can’t enforce the mandatory arbitration agreement set out in its online terms and conditions because there is no evidence that consumers read the policy. The ruling, issued last week by U.S. District Court Judge Sterling Johnson, Jr., grew out of a dispute about a restocking fee between customer Cynthia Hines and the online retailer. Hines sued Overstock for charging her a $30 fee after she returned a vacuum cleaner. Overstock countered that the case should not be in court because the site’s terms and conditions provided for mandatory arbitration. A link at the bottom of Overstock’s home page took visitors to a page that spelled out those terms. But Johnson found that the “browsewrap” agreement did not adequately notify Hines about the provision. Hines “lacked notice of the terms and conditions because the website did not prompt her to review the terms and conditions and because the link to the terms and conditions was not prominently displayed,” he wrote. “When courts think something is so important that a consumer might not have purchased if the details of the deal were more visible, they will impose a higher bar to ensure users are informed,” Jules Polonetsky, co-chair and director of the think tank Future of Privacy Forum, said in an email to Online Media Daily. Polonetsky adds that the Overstock ruling is “in sync with thinking at the FTC and on the Hill, where increasingly the view is that behavioral advertising matters enough to users that sites need to be truly up front about it.” http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=113404 See also http://newmedialaw.proskauer.com/2009/09/articles/contracts/arbitration-provision-unenforceable-where-online-retailers-link-to-browsewrap-terms-and-conditions-was-not-prominently-displayed/

SEYFARTH SHAW SAYS SIX SIGMA METHOD HAS CUT CLIENT FEES BY UP TO 50% (ABA Journal, 14 Sept 2009) - Seyfarth Shaw has embraced Six Sigma to such an extent that press releases announcing lawyer promotions or additions extol its virtues. The law firm even has a name for its Six Sigma approach: SeyfarthLean. Six Sigma emphasizes rigorous measuring and perfecting of processes, but also can squelch innovation, according to critics. Many companies that can’t afford to cut any more employees are embracing Six Sigma in an effort to improve the bottom line, Business Week reports. Seyfarth managing partner Stephen Poor is a believer, as is Robert Reynolds Jr., a lawyer joining the firm from Alston & Bird who labeled the firm’s Six Sigma accomplishments “extraordinary” in a press release. Poor called Six Sigma Poor “a very powerful tool” in a Business Week interview. Seyfarth says on its website that it is using Six Sigma to eliminate inefficiencies that can push legal bills higher, resulting in cost savings to clients ranging from 13 percent to 50 percent. In an e-mail interview with the ABA Journal, Poor didn’t name a specific client that has saved 50 percent on legal bills. Instead, he mentioned a “summary judgment project” at the law firm that eliminated inefficiencies and bottlenecks, “resulting in a 50 percent savings from the usual costs.” Poor told the ABA Journal that Seyfarth uses its tailor-made version of Six Sigma to set prices for legal work in a collaborative process with clients. As an example of Six Sigma in action, he points to the law firm’s efforts to work with 7-Eleven in its quest to ramp up store openings. Seyfarth helped by developing processes to “reduce cycle time” for store leases. Using Six Sigma, the law firm introduced “consistency, standardization, quality control [and] efficiency” into the process. http://www.abajournal.com/weekly/seyfarth_shaw_says_six_sigma_has_cut_client_fees_by_up_to_50_percent [Editor: Bah! This seems like simple process-control, such as practiced by most real businesses for 15 years. For example, BP did something similar in routinizing the creation of retail service stations in Asia in the middle 1990s. Knowledge Management processes yield even better results, but are nearly impossible to deploy in law firm cultures. The “news” here is that it’s taken law firms so long to take such baby-steps.]

FIVE MAJOR RESEARCH UNIVERSITIES ENDORSE OPEN-ACCESS JOURNALS (Chronicle of Higher Ed, 14 Sept 2009) - In an effort to support alternatives to traditional scholarly publishing, five major research universities announced their joint commitment to open-access journals on Monday. The institutions—Cornell University, Dartmouth College, Harvard University, the Massachusetts Institute of Technology, and the University of California at Berkeley—signed a compact agreeing to the “timely establishment” of mechanisms for providing financial support for free open-access journals. While conventional journals require institutions to pay subscription fees to access articles, open-access publications make their material free to the public, thus aiding libraries forced to cut back during difficult financial times, officials at the universities believe. John M. Saylor, associate university librarian for scholarly resources and special collections at Cornell, says it is a much healthier research environment when the financial burden is taken off the reader and everyone has access to the same research. Mr. Saylor says, however, that the challenge now is to develop a system that pays for the operation of journals that give away the store. “We just don’t know if it’s going to be too expensive,” he said. http://chronicle.com/blogPost/5-Major-Research-Universities/8042/

- and -

HIGHER ED. AND TED (InsideHigherEd, 16 Sept 2009) - TED talks pose all sorts of challenges and opportunities for those of us in higher education. The quality of the freely available content gives lie to the notion that the best lectures occur within the gates of academe. The format of the talks can teach us a thing or two about the optimal length, timing, pace and content of the lecture. And the conversations around the online lectures remind us that the degree to which learning is social. Perhaps the biggest lesson from http://www.ted.com/ for learning technology is the method in which TED makes its videos available to the world. Two characteristics of the TED media strategy stand out:
1. TED talks are released under the Creative Commons license. http://www.ted.com/index.php/help#talks5 The Creative Commons variant that TED chooses allows the videos to be freely shared and reposted. The license does not allow TED talks to be remixed. This strategy strikes a good balance between facilitating the diffusion of the content while protecting the integrity of the narrative. Institutions of higher education should follow this strategy for as much of the content produced on campus as possible, with Creative Commons permissions included in all (taped) speaker release forms.
2. TED talks are made available in multiple formats, including a streaming version, video to desktop (MP4) and video to ITunes (MP4). Embed code is always provided to allow the reposting of the talks. The multiple formats encourage the audience to download and consume the media on the device that is most convenient. I download TED talks to iTunes and copy them over to my iPod touch. Having TED talks on a mobile platform allows the viewing of these talks when I have a few free moments and in small chunks. http://www.insidehighered.com/blogs/technology_and_learning/higher_ed_and_ted [Editor: the TED talks are generally quite good: http://www.ted.com/]

- and -

FROM IVORY TOWER TO IRON BARS: SCIENTISTS RISK JAIL TIME FOR VIOLATING EXPORT LAWS (Danger Room, 17 Sept 2009) - John Reece Roth never thought he’d be going to prison for his research on plasma physics. But that’s precisely where the 72-year old University of Tennessee professor will likely spend the next four years. Roth was sentenced last month for sharing his research with foreign graduate students and taking a laptop with his research to China. Along with his university research, he was working on an unclassified contract from the U.S. Force looking at ways to reduce drag on drones using plasma actuators. The case has been closely watched by university professors working in areas that deal with controlled technical information, particularly satellite technology, which is classified as a munition. As I write in a recent article for Nature (apologies, behind a paywall): “Concerns over prosecution have even led some academics to self-censor when teaching, particularly in the area of satellites, which have been under the control of the state department since 1999. That shift, which was prompted by a satellite manufacturer illegally sharing technical data with China about the failure of a Long March rocket, had an immediate effect on university work in the area. “There are things I was once comfortable talking about in class, and I’m not comfortable with anymore,” says Thomas Zurbuchen, a professor of space science and aerospace engineering at the University of Michigan in Ann Arbor.” It’s a difficult subject: many people I interviewed felt Roth showed blatant disregard for the law — he was warned his work fell under the State Department’s munitions list — but they expressed deep frustration with the ambiguity of the laws. Clif Burns, a lawyer at Bryan Cave, who contributes to the equally amusing and educational Export Law Blog, believes the Roth case is an anomaly — at least so far. Burns also told me that part of Roth’s particular problem was that he was sharing research with graduate students from the two countries of most concern to the United States: China and Iran. http://www.wired.com/dangerroom/2009/09/from-ivory-tower-to-iron-bars-academics-risk-jail-time-for-violating-export-laws/

- and -

THE MOBILE CAMPUS (InsideHigherEd, 21 Sept 2009) - Last fall, Abilene Christian University gave out free iPhones or iPod Touches to its first-year undergraduates as part of an attempt by the Texas college to transform its campus into a 200-acre Petri dish for studying the intersection of mobile technology and higher education. Now, the reviews from the first year of the experiment are in — and they are glowing. In the university’s 2008-2009 Mobile-Learning Report — a 24-page glossy prepared for the university’s board of trustees — Scott Perkins, a psychology professor and director of research for the mobile initiative, writes that “iPhones present a more attractive platform for learning” than current classroom tools, and “learning activities can be successfully transitioned to mobile-device platforms.” Furthermore, 89 percent of students and 87 percent of faculty polled called the program successful. The Abilene Christian project has been viewed by some as a gimmick, similar to Duke University’s widely publicized 2004 decision to give each member of its incoming class an iPod -- a program it quickly changed to encompass only certain students, then changed again to a partially subsidized purchase opportunity. Although Rankin said he thinks the Duke experiment was a success, it left many stones unturned. “Duke gave out the devices like they were sowing seeds in a field,” Rankin said, “saying, ‘Let’s see who does something with them.’” Abilene Christian’s approach is more active: Give students the mobile devices, then have professors integrate the machines and their tools into the way courses are taught, and measure the changes. Chemistry instructor Cynthia Powell, for example, created a special section of 25 iPhone users to whom she delivered laboratory preparation and safety lectures via podcast, rather than giving them in the classroom. Then she tracked the performance of that section relative to her 109 other students in the five categories she uses to determine grades. While the higher scores of the mobile group were not outside the substantial margin of error, Perkins said the mere fact that there was no decrease in score was evidence that such instruction “can transition to a mobile platform with no loss in student mastery of content.” http://www.insidehighered.com/news/2009/09/21/iphones

- and -

A LIBRARY ADDRESS (InsideHigherEd, 24 Sept 2009) - One of the best things about my job in learning technology is that I get to work in a library. How many of you have your physical offices inside your campus library? The future, I believe, will be the intermingling and merging of the academic library and academic technology disciplines. Even if academic technology and academic library services remain organizationally independent, our daily work and strategic goals will become increasingly intertwined. EDUCAUSE has a great page of resources on IT-Library Mergers -- and I’d appreciate any pointers folks have around best practices in collaboration. 5 of the best things about having an office inside the college library: * * * http://www.insidehighered.com/blogs/technology_and_learning/a_library_address

AIRPLANE LIQUID BOMBERS (CryptoGram, 15 Sept 2009) - Perfectly legal (obtained with a FISA warrant) NSA intercepts used to convict liquid bombers.
http://www.schneier.com/blog/archives/2009/09/nsa_intercepts.html
The BBC has a video demonstration of a 16-ounce bottle of liquid blowing a hole in the side of a plane. I know no more details than what’s in the video.
http://news.bbc.co.uk/2/hi/uk_news/7536167.stm [Editor: very, very impressive detonation. I’m convinced.]

SEARS TOLD TO DESTROY DATA GATHERED BY ONLINE TRACKING SOFTWARE (The Register, 16 Sept 2009) - US retailer Sears has been ordered to destroy all the customer data it collected from a piece of online tracking software that consumer regulator the Federal Trade Commission (FTC) said was unfairly used. The FTC said that while customers had been warned that, once downloaded, software would track their browsing, it had in fact tracked browsing on third party websites, secure browsing including banking and transactions and even some non-internet computer activity. “The FTC charged… that the software also monitored consumers’ online secure sessions – including sessions on third parties’ Web sites – and collected consumers’ personal information transmitted in those sessions, such as the contents of shopping carts, online bank statements, drug prescription records, video rental records, library borrowing histories, and the sender, recipient, subject, and size for web-based e-mails,” said an FTC statement. Sears has been ordered to make notification of any future tracking clearer, and to delete all the information gathered through the use of the software. “Only in a lengthy user license agreement, available to consumers at the end of a multi-step registration process, did Sears disclose the full extent of the information the software tracked,” said an FTC statement. “The [FTC] complaint charged that Sears’s failure to adequately disclose the scope of the tracking software’s data collection was deceptive and violates the FTC Act.” Sears, which owns KMart, has settled the case with the FTC, the regulator said. Sears paid some visitors to sears.com and kmart.com $10 to participate in a scheme to monitor their browsing via “research software”. The full extent of the monitoring was only made clear in a long user agreement visible after the downloading of the software. Sears has agreed to tell users more clearly and prominently what activity will be recorded, and to do so before any software is downloaded. The case resulted from an administrative complaint from the FTC itself. http://www.theregister.co.uk/2009/09/16/sears_to_destroy_tracking_software_data/ FTC’s Order here: http://www.ftc.gov/os/caselist/0823099/090604searsdo.pdf

GOVT REVIEW: NO PRIVACY PROBLEMS IN CYBER SECURITY (Washington Post, 18 Sept 2009) - The Justice Department has concluded that a beefed-up surveillance program that monitors federal employees’ Internet traffic does not violate their rights or those of private citizens who communicate with them. But the review of the Einstein 2 program was limited and leaves important questions unanswered, said the vice president of an Internet freedom watchdog group. Einstein 2 is a second-generation automated program designed to detect cyber attacks on government computer networks. The review, completed last month and released Friday, said the system addresses potential privacy concerns by warning employees when they log in that their communications may be monitored. Such warnings “eliminate federal employees’ legitimate expectations of privacy” on government computers, acting Assistant Attorney General David J. Barron wrote. http://www.washingtonpost.com/wp-dyn/content/article/2009/09/18/AR2009091802905.html

NATIONAL SECURITY THREATS IN CYBERSPACE - A WORKSHOP REPORT (ABA’s Standing Committee on Law & National Security, 21 Sept 2009) - The last few years have seen a remarkable surge in the degree of concern publicly expressed by government officials regarding “national security threats” in cyberspace. The Bush Administration began development of a Comprehensive National Cybersecurity Initiative (CNCI) in January 2008. The Obama Administration has followed with a Cyberspace Policy Review and a promise to appoint a “Cyber Czar” to coordinate a federal government response. Funding for initiatives to protect the cyber domain is likely to increase significantly. The ferment of ideas is substantial, even by Washington “crisis” standards. Some question whether a threat exists at all while others deem the threat existential. Novel issues of policy and law surface on an almost daily basis as technological innovation runs headlong forward, leaving policy‐makers and concerned legislators trailing in its wake. As the United States continues the development of its cybersecurity policy, the time is ripe for reflection and an examination of first principles. To that end the American Bar Association Standing Committee on Law and National Security, the McCormick Foundation, and the National Strategy Forum sponsored a two‐day workshop in Annapolis, Maryland on June 4‐5, 2009. The workshop brought together more than two dozen experts with diverse backgrounds: physicists; telecommunications executives; Silicon Valley entrepreneurs; Federal law enforcement, military, homeland security, and intelligence officials; Congressional staffers; and civil liberties advocates. For those two days they engaged in an open‐ended discussion of cyber policy as it relates to national security. The discussion was under Chatham House Rules – their comments were for the public record, but they were not for attribution. Full report here: http://www.abanet.org/natsecurity/threats_%20in_cyberspace.pdf [Compare, good article on the exaggerated fears of cyberwar: http://bostonreview.net/BR34.4/morozov.php]

GOOGLE CONFIRMS THAT KEYWORD METATAGS DON’T MATTER (Eric Goldman’s blog, 22 Sept 2009) - Few Internet technologies have horked [sic] cyberlaw as much as keyword metatags. Back in the 1990s, some search engines indexed keyword metatags, which encouraged some websites to stuff their keyword metatags as a way of gaming the rankings. Judges took a dim view of this practice, largely because the surreptitious nature of keyword metatags seemed inherently sinister, regardless of their efficacy. In the interim, search engines wizened up. Some search engines stopped indexing keyword metatags, and others greatly diminished the credit they assigned to keyword metatags. As a result, for the better part of this century, keyword metatags have had either zero or de minimis effect on search engine placement. However, the anti-keyword metatag legal doctrines developed in the 1990s have persisted, even as the technology changed. Although occasionally judges have gotten it right (see, e.g., Standard Process v. Banks). most courts still treat the presence of a third party trademark in keyword metatags as essentially a per se trademark infringement--even if the keyword metatags didn’t (and couldn’t) change the search results ordering or any consumer’s behavior. For a quick sense of the ridiculous state of keyword metatag jurisprudence, take a look at my recent blog posts on the topic. The current state of nature has put keyword metatag defendants in a bind. On the one hand, the law treats the inclusion of third party trademarks as per se trademark infringement. On the other hand, everyone in the industry knows they are irrelevant but search engines have been less than forthcoming about the components of their search engine algorithms, leaving scanty citable material to support that proposition. And judges, deciding between the weight of a dozen years of anti-keyword metatag legal precedence and not-from-the-horse’s-mouth assessments of keyword metatag efficacy, not surprisingly continue to stick with the outdated legal precedent. This makes Google’s announcement yesterday so exciting. Google’s star techie Matt Cutts says in plain language that Google’s core search algorithm ignores keyword metatags. This isn’t news in the sense that we’ve known this about Google for years, but I believe this is Google’s first public confirmation of keyword metatag’s irrelevancy. Matt’s short video clip goes so far to tell trademark owners to quit suing over keyword metatags. Amen! http://blog.ericgoldman.org/archives/2009/09/google_confirms.htm

- and -

EU ADVISER: GOOGLE ADS DON’T INFRINGE TRADEMARKS (SiliconValley.com, 22 Sept 2009) - A European Union court adviser said Tuesday that Google does not violate luxury goods makers’ trademarks when it sells brand names as search keywords that trigger its lucrative advertisements. The adviser’s legal opinion will now be studied by judges at the European Court of Justice, which has been asked to tell a French appeals court how to apply EU trademark law in a dispute between Google and several French luxury goods companies over the Internet search engine’s ad system. Although Maduro’s recommendation is nonbinding, legal adviser opinions are followed by the court in about 80 percent of cases. Google has been repeatedly sued for trademark violations in courts around the world, and it generally prevails or settles cases without changing its practices. In the United States and most other countries, Google typically accepts trademarks used as those keyword triggers, but it places limits on what can appear in ads themselves. But in many European countries, including France, Italy and the Netherlands, Google does restrict the use of trademarks as keywords. It will typically strike ads, however, only after receiving a complaint from the trademark owner and conducting a review. The EU court adviser said neither Google nor advertisers are at fault for initially placing or accepting an ad using a brand keyword. Google isn’t to blame either for displaying the keyword ads because Maduro said a keyword linking to a site isn’t likely to lead customers into mistaking a brand name item for a counterfeit. But users are likely to make decisions when they see the content of the ad or visit the advertised sites — and the adviser warns that Google may be held liable for the ad content. That could potentially lead to Google facing legal action in national courts if brand owners could prove that such an ad damaged sales of genuine goods. http://www.siliconvalley.com/news/ci_13393205?nclick_check=1

FEDERAL COURTS NOW OFFER HEARINGS ONLINE AS MP3 FILES (ArsTechnica, 23 Sept 2009) – US federal courts are in the midst of a fascinating pilot program that could eventually bring MP3 digital audio recordings of court proceedings in a Montana federal building to an investigative journalist working in Boca Raton. The courts already run the PACER system, which offers Public Access to Court Electronic Records. Theses are generally PDF copies of all documents (except those under seal) filed in federal courts across the country. As a tool, it’s an amazing time and money saver for lawyers, journalists, and the public, despite the 8¢ per page charge for most documents which has proved controversial. These documents include the complaints that launch lawsuits and the procedural motions along the way, but what actually happens when lawyers get in front of the judge? If you want to know, you generally have to get yourself down to a particular courtroom in a particular courthouse in a particular state at a particular time. Quite a primitive system, especially when one considers that many such proceedings are already recorded digitally and made available (on audio CD) to anyone who treks down to a courthouse and hands over $26. The pilot program, run by the Administrative Office of the federal courts, began in late 2007 and has been extended through the end of 2009. It allows judges, at their sole discretion, to upload these audio files into the PACER system, where they can be downloaded for... 16 cents each. The files generally go up within 24 hours, so lawyers and journalists who truly need to follow a case as it happens still need to get themselves down to court. But for everyone else, these trial recordings are a fantastically convenient, cheap way to follow legal proceedings across the country. Nine courts are currently testing the technology, including US District Courts in Nebraska and the Eastern District of Pennsylvania. While the availability of such recordings sounds like an incredible step forward, problems have arisen. Criminal hearings are not covered by the pilot program at the moment, due to worries that it could expose sensitive witnesses, and judges have to make sure that private information such as Social Security numbers, dates of birth, and the names of children are not said aloud in court. Also, all-day court proceedings simply generate files that are too large; the Administrative Office has decided to break such recordings into morning and afternoon sessions. http://arstechnica.com/tech-policy/news/2009/09/federal-courts-now-offer-hearings-online-as-mp3-files.ars?utm_source=rss&utm_medium=rss&utm_campaign=rss

- and -

IF THE ARMY CAN PUT ITS DOCTRINE UP ON A WIKI, YOU’VE GOT NO EXCUSE (Nancy Dixon, 23 Sept 2009) - A few weeks ago I had the privilege of watching an astounding event - a room full of Soldiers typing Army doctrine onto a wiki so that Soldiers in the field could make changes as they were discovering new and better tactics in the midst of fighting a war. There were a couple of amazing things about this event. One was that it was happening at all, because to the Army, doctrine is close to sacred. It is written by doctrine specialists and then verified and authenticated at many levels within the hierarchy. So opening doctrine up to Soldiers is a very big deal. The second amazing thing was how quickly it happened – just three weeks after the General said, “Make it happen.” the first eight manuals went up. A hierarchical organization, of one million plus employees, just shouldn’t be able to move that fast! But let me begin at the beginning of the story… http://www.nancydixonblog.com/2009/09/if-the-army-can-put-its-doctrine-up-on-a-wiki-youve-got-no-excuse.html

3RD CIRCUIT SAYS CORPORATIONS MAY TAKE INFO REQUESTS ‘PERSONALLY’ (Law.com, 24 Sept 2009) - Lawyers for AT&T have won a court battle with the Federal Communications Commission that turned on a question largely of semantics -- whether corporations are entitled to assert claims of “personal” privacy. In an appeal before the 3rd U.S. Circuit Court of Appeals, the FCC argued that when Congress crafted the exemptions clauses of the Freedom of Information Act, it intended the phrase “personal privacy” to extend only to human beings. But AT&T begged to differ, arguing that the FOIA specifically defines the term “person” to include corporations, and therefore that “Congress’s choice of the adjectival form of that word -- ‘personal’ -- should be understood to refer to that definition.” By contrast, AT&T argued, “where Congress intends to refer to natural persons and to exclude corporations -- both in the FOIA itself and in the closely related Privacy Act of 1974 -- it uses the term ‘individual.’” Now the 3rd Circuit has ruled that AT&T’s lawyer, Colin S. Stretch of Kellogg Huber Hansen Todd Evans & Figel in Washington, D.C., had the better argument, and that the FCC was therefore wrong to block AT&T from invoking the personal privacy protections in FOIA Exemption 7(C). http://www.law.com/jsp/article.jsp?id=1202434019429&rss=newswire&hbxlogin=1

**** DIFFERENT ****
HORRIFICALLY BAD SOFTWARE DEMO BECOMES PERFORMANCE ART (ArsTechnica, 23 Sept 2009) - For software developers, live product demonstrations are a way of life, and that means that “live product demos gone horribly awry” are also a fact of life. But what if the world’s most disastrous software demo was faked, foisted on a set of unsuspecting computer science students as a piece of performance art? That thought is what led University of California-San Diego student Tristan Newcomb to produce a half-hour of surreptitious theater that he calls “The Last Lecture.” Students stare at the stage in disbelief, amusement, and horror as a software developer comes to class with his two assistants and proceeds to demonstrate a new videogame in spectacular fashion—software crashes, lag problems, puppet videos, and falling computers all coincide with the presenter’s personal breakdown in which he questions his life’s work and worries ceaselessly about his death (a death in which no Kermit the Frog will welcome him to the afterlife). Only after 30 minutes of increasingly bizarre personal confessions and technical glitches is the gag revealed; credits suddenly begin to scroll up the gigantic demonstration screen at the front of the classroom. The audience slowly realizes that it has been watching not a software demonstration, but a half-hour prerecorded video fronted by three actors. http://arstechnica.com/web/news/2009/09/horrifically-bad-software-demos-become-performance-art.ars?utm_source=rss&utm_medium=rss&utm_campaign=rss This “Last Lecture” is here: http://www.lumalin.com/lumalin_films/last_lecture.php [Editor: at least he’s not using a Macintosh. The first 5 minutes are painful, but the guy falling off the cliff at 15m10s is priceless; what a wonderful waste of time.]

**** COMMENTARY ****
FROM MAC PORTABLE TO MACBOOK PRO: 20 YEARS OF APPLE LAPTOPS (ArsTechnica, 21 Sept 2009) - 20 years ago, Apple introduced its first portable Mac—we hesitate to say laptop because of its size—the Macintosh Portable. Ars looks back at some of the best Mac laptops to come out of Cupertino over the past two decades—and a couple of clunkers. http://arstechnica.com/apple/news/2009/09/from-portable-to-pro-best-mac-laptops-of-the-past-20-years.ars?utm_source=rss&utm_medium=rss&utm_campaign=rss [Editor: looking at these is a trip down memory lane (with some nightmares) – I’ve owned most of the machines pictures (plus a half-dozen PCs).]

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
READING THE FINE PRINT: YAHOO INADVERTENTLY THREATENS CONTENT COPYRIGHT -- The fine print in the terms of service agreement Yahoo posted to GeoCities (a web page hosting service) members last week seemed to indicate that Yahoo held the copyright for all their site content. Angry members emailed Yahoo. The company issued a clarifying statement saying it never intended to usurp content copyright. Other web page hosting services have similar clauses in their terms of service agreements. Yahoo purchased GeoCities in January of this year. http://www.sjmercury.com/svtech/news/breaking/merc/docs/083171.htm

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, September 05, 2009

MIRLN --- 16 August – 5 September 2009 (v12.12)

• Internet Materials in Opinions: Citations and Hyperlinking
• Judge Strikes Down La. Restrictions on Lawyer Internet Ads
• Firefox Plug-In Frees Court Records, Threatens Judiciary Profits
• Second Life’s Economy Nearly Doubles
• U.C. Professors Seek Changes to Google Books Deal
• FCC Launches a Blog, Joins Twitter Stream
• FTC Finalizes Rules on Health Care Breach Disclosure
• E-Discovery Fears May Explain Why Recession Didn’t Spur Litigation
• Teaching the Quarantined
• Massachusetts Modifies its New Information Security Rules for Businesses and Extends the Compliance Deadline Again
• 45% of Employers Now Screen Social Media Profiles
• D.C. Appeals Court Adopts Five-Step Inquiry for Unmasking Anonymous Internet Speakers
• Forcing Employee to Provide Access to Password-Protected Website Violates SCA
• Judge: Defunct Airport Fast Pass Company Can’t Sell Customer Data
• Federal Agencies Pursue Cybersecurity Common Ground
o DHS and Information Technology Sector Coordinating Council Release Information Technology Sector Baseline Risk
• Cyber-Attack Strategy: Part of Russian Attack on Georgian Pipelines, Report Finds
• Court Rules U.S. Seized 2003 Tests Improperly
• Dozens of Judges are Getting LinkedIn, Blogger Notes
• Tighter Oversight on Border Laptop Searches
o Protect Your Laptop Data from Everyone, Even Yourself
• For Intelligence Officers, a Wiki Way to Connect Dots
• Augmented Reality Comes to the iPhone
• The Government Domain: Tracking Congress 2.0
• Harvard's Dash for Open Access
• Online Terms Presented with Three Blue Hyperlinks are Conspicuous, Conscionable
• Fox Adds On-Air Tweets to `Fringe' Reruns

NEWS | PODCASTS | LOOKING BACK | NOTES

**** NEWS ****
INTERNET MATERIALS IN OPINIONS: CITATIONS AND HYPERLINKING (U.S. Courts, July 2009) - The Judicial Conference has issued a series of “suggested practices” to assist courts in the use of Internet materials in opinions. The recommendations follow a pilot project conducted by circuit librarians who captured and preserved webpages cited in opinions over a six-month period. The Internet often seems to pervade everyday life, giving us answers, matches, recommendations, definitions, and citations. But the information on the Internet can be as ephemeral as yesterday’s blog entry. Websites can change or disappear altogether. “Judges are citing to and using Internet-based information in their opinions with increasing frequency,” Judicial Conference Secretary Jim Duff wrote recently to chief judges. “Unlike printed authority, Internet information is often not maintained at a permanent location, and a cited webpage can be changed or deleted at any time. Obviously, this has significant implications for the reliability of citations in court opinions.” The Judicial Conference Committee on Court Administration and Case Management (CACM) began the pilot project, conducted by circuit libraries, and received and endorsed the recommendations of an ad hoc working group of circuit librarians. In approving those recommendations in March 2009, the Judicial Conference agreed that all Internet materials cited in final opinions be considered for preservation, while each judge should retain the discretion to decide whether the specific cited resource should be captured and preserved. The Conference directed the Administrative Office to work with the CACM Committee to develop guidelines “to assist judges in making the determination of which citations to preserve.” The guidelines suggest that, if a webpage is cited, chambers staff preserve the citation by downloading a copy of the site’s page and filing it as an attachment to the judicial opinion in the Judiciary’s Case Management/Electronic Case Files System. The attachment, like the opinion, would be retrievable on a non-fee basis through the Public Access to Court Electronic Records system. When considering whether to cite Internet sources, judges are reminded that some litigants, particularly pro se litigants, may not have access to a computer. http://www.uscourts.gov/ttb/2009-07/article09.cfm?WT.cg_n=TTB&WT.cg_s=July09_article09_newsroom [Editor: There are two interesting studies/projects that speak to link rot and the need for preservation. One is the Chesapeake Project:
http://www.legalinfoarchive.org/. The other was a study done by a librarian in Washington: Ching, Tina. “The Next Generation of Legal Citations: A Survey of Internet Citations in the Opinions of the Washington Supreme Court and Washington Appellate Courts, 1999-2005″ http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1305277. The ABA’s Catherine Sanders Reach participated in a related program discussion earlier this month -- http://www.abanet.org/tech/ltrc/presentations/authentication.pdf]

JUDGE STRIKES DOWN LA. RESTRICTIONS ON LAWYER INTERNET ADS (ABA Journal, 4 August 2009) - A federal judge has upheld most of the new restrictions on advertising by Louisiana lawyers, but struck down two rules regulating Internet advertising. U.S. District Judge Martin Feldman said Louisana’s Internet restrictions don’t account for differences between ads online and those in traditional media such as television, the Associated Press reports. “The Internet presents unique issues related to advertising, which the state simply failed to consider in formulating this rule,” Feldman wrote in his opinion. As a result, the Internet ad restrictions violate the First Amendment, he ruled. Feldman upheld most other restrictions, saying the state can regulate ads that promise results, portray a judge or jury, or use client testimonials, according to AP. The Wolfe Law Group had challenged the Internet rules, claiming they would restrict the firm’s right to comment on Twitter, Facebook, online bulletin boards and blogs. The firm also argued the rules would subject each of the firm’s online posts to a cost-prohibitive evaluation and $175 fee. The law firm had provided an example: It spent $160 on 12 different Google pay-per-click ads over a three-month period; the cost of the ad review would have been about $2,100. Name partner Scott Wolfe Jr. said in a press release that Feldman’s ruling is important to lawyers who advertise online. “The court not only noted that states must have a reason to regulate Internet speech, but it also recognized that the Internet media is different from broadcast media, and is entitled to unique protection,” he said. http://www.abajournal.com/news/judge_strikes_down_la._restrictions_on_lawyer_internet_ads

FIREFOX PLUG-IN FREES COURT RECORDS, THREATENS JUDICIARY PROFITS (Wired, 14 August 2009) - Access to the nation’s federal law proceedings just got a public interest hack, thanks to programmers from Princeton, Harvard and the Internet Archive, who released a Firefox plug-in designed to make millions of pages of legal documents free. Free as in beer and free as in speech. The Problem: Federal courts use an archaic, document-tracking system known as PACER as their official repository for complaints, court motions, case scheduling and decisions. The system design resembles a DMV computer system, circa 1988 — and lacks even the most basic functionality, such as notifications when a case gets a new filing. But what’s worse is that PACER charges 8 cents per page (capped at $2.40 per doc) and even charges for searches — an embarrassing limitation on public access to information, especially when the documents are copyright-free. The Solution: RECAP, a Firefox-only plugin, that rides along as one usually uses PACER — but it automatically checks if the document you want is already in its own database. The plug-in’s tagline, ‘Turning PACER around,’ alludes to the fact that its name comes from spelling PACER backwards. RECAP’s database is being seeded with millions of bankruptcy and Federal District Court documents, which have been donated, bought or gotten for free by open-government advocate Carl Malamud and fellow travelers such as Justia. And if the document you request isn’t already in the public archive, then RECAP adds the ones you purchase to the public repository. The plug-in was released by Princeton’s Center for Information Technology Policy, coded by Harlan Yu and Tim Lee, under the direction of noted computer science professor Ed Felten. http://www.wired.com/threatlevel/2009/08/firefox-plug-in-frees-court-records-threatens-judiciary-profits/

SECOND LIFE’S ECONOMY NEARLY DOUBLES (NPR, 14 August 2009) - I don’t know how I missed this key, crucial and totally critical piece of news: The economy in Second Life has grown by 94 percent over the past 12 months, with activity that equates to $144 million in the second quarter. Granted, the real people and their groovy avatars in the 3D virtual reality world are trading in Linden dollars, except when they’re not, like the woman who made a million U.S. dollars selling virtual real estate. Beam me up, I guess. Oh, wait -- wrong world. http://www.npr.org/blogs/money/2009/08/second_lifes_virtual_economy_g.html?sc=nl&cc=pmb-20090814

U.C. PROFESSORS SEEK CHANGES TO GOOGLE BOOKS DEAL (New York Times, 17 August 2009) - A group of prominent faculty representatives from the University of California, one of Google’s earliest and closest allies in its plan to digitize books from major libraries, is the latest to raise concerns about important aspects of a high-profile class-action settlement between Google and groups representing authors and publishers. The professors include members of the university’s Academic Council (the executive committee of the much larger Academic Senate) as well as the chair of the Academic Senate’s Committee on Libraries and Scholarly Communication. Their views suggest something of a break between representatives of the university’s faculty and its administration, which has endorsed the settlement. But the group also suggests that the Authors Guild, which sued Google for copyright infringement over its scanning project and played a central role in negotiating the settlement, did not appropriately represent the interests of academic authors, many of whom want their works to be widely accessible. “We are concerned that the Authors Guild negotiators likely prioritized maximizing profits over maximizing public access to knowledge, while academic authors would have reversed those priorities,” the group wrote. “We note that the scholarly books written by academic authors constitute a much more substantial part of the Book Search corpus than the Authors Guild members’ books.” However, the group does not oppose the settlement, but rather suggests a number of changes to address its concerns. http://bits.blogs.nytimes.com/2009/08/17/uc-professors-seek-changes-to-google-books-deal/

FCC LAUNCHES A BLOG, JOINS TWITTER STREAM (GigaOm, 18 August 2009) - The Federal Communications Commission is looking to overhaul itself, hiring more technically astute people and entrepreneurs. It’s also trying to become an agency for the people, and as part of that attitude change, has launched a blog: Blogband. In a press release (and the first blog post) FCC Chairman Julius Genachowski wrote: “To foster public dialogue about the National Broadband Plan, we’re tapping the power of the Internet to launch a new FCC blog…Blogband will keep people up-to-date about the work the FCC is doing and the progress we’re making. But we want it to be a two-way conversation. The feedback, ideas, and discussions generated on this blog be critical in developing the best possible National Broadband Plan.” http://gigaom.com/2009/08/18/fcc-blog-twitter-fccdotgov/

FTC FINALIZES RULES ON HEALTH CARE BREACH DISCLOSURE (DarkReading, 18 August 2009) - The Federal Trade Commission yesterday issued a final rule that will require Web-based businesses to notify consumers when the security of their electronic health information has been breached. The new rule was put into place by Congress as part of the American Recovery and Reinvestment Act of 2009. The rule applies to both vendors of personal health records “ which provide online repositories that people can use to keep track of their health information “ and entities that offer third-party applications for personal health records. Many organizations that offer these types of services are not subject to the privacy and security requirements of the Health Insurance Portability and Accountability Act (HIPAA), the FTC explained. Under the Recovery Act, the Department of Health and Human Services has been assigned to conduct a study and report by February 2010 on potential privacy, security, and breach-notification requirements for vendors of personal health records and related entities that are not subject to HIPAA. In the meantime, the Recovery Act requires the FTC to issue a rule requiring these entities to notify consumers if the security of their health information is breached. The Commission announced a proposed rule in April 2009, collected public comments until June 1, and issued the final rule yesterday. The Final Rule requires vendors of personal health records and related entities to notify consumers following a breach involving unsecured information. In addition, if a service provider to one of these entities has a breach, it must notify the entity, which in turn must notify consumers. http://www.darkreading.com/security/government/showArticle.jhtml?articleID=219400484

E-DISCOVERY FEARS MAY EXPLAIN WHY RECESSION DIDN’T SPUR LITIGATION (ABA Journal, 18 August 2009) - Litigation usually increases during recessions, but this one appears to be different. Several surveys show that litigation is flat or declining, the National Law Journal reports. One of the major reasons, the story says, is that general counsel don’t want to spend money on litigation, partly because they fear the increasing cost of electronic discovery. “Right now, general counsel are trying to operate in zero-risk mode, and this is something we have not seen in many, many years,” said Michael Rynowecer, president of the BTI Consulting Group, in an interview with the publication. A survey of general counsel at Fortune 1000 companies by BTI found that legal departments spent an average of 1 percent less on litigation during the first half of this year. Elizabeth Scully, a partner at Baker Hostetler experienced in e-discovery, told the NLJ that the discovery process is much more expensive than just a few years ago. “It makes logical sense that the cost associated with e-discovery may be one of the things changing the numbers.” The article cited this evidence of a declining appetite for litigation. http://www.abajournal.com/news/e-discovery_fears_may_explain_why_recession_didnt_spur_litigation Law.com story here: http://www.law.com/jsp/ihc/PubArticleIHC.jsp?id=1202433112312&hbxlogin=1

TEACHING THE QUARANTINED (InsideHigherEd, 19 August 2009) - H1N1 flu may have two surprising symptoms: innovation and empathy. At least that’s the hope of University of Michigan officials, who are encouraging faculty to make broader use of technology to help sick students keep up with class work. As faculty create syllabuses for the coming semester, Michigan officials want them to consider the possibility of an outbreak infecting large numbers of students in the coming months. That means finding ways to work with students who may be absent for days by putting greater emphasis on distance learning tools like listservs, e-mail and Web-based teaching platforms. To that end, the university’s Center for Research on Learning and Teaching has laid out a series of guidelines to help faculty prepare for what could be a challenging year of illness. “[The guidelines] may or may not be helpful, but what we’re trying to do is encourage them to think about it in advance of the school year so it doesn’t take them by surprise,” said Constance Cook, vice provost for academic affairs and executive director of the learning and teaching center. “Then we rely on their good judgment to make accommodations that make sense for them.” The guidelines reflect growing concerns that the fall semester will be a season of H1N1, commonly called swine flu, on college campuses. Michigan is also working to address the somewhat counter-intuitive medical advice being provided by the Centers for Disease Control, which suggests those with the flu stay home an extra day, even if they feel well enough to work. To avoid spreading the flu, the CDC has advised people with influenza-like illness stay isolated until at least 24 hours after they are free of fever without the aid of fever-reducing medications. As such, there may be students who feel able to do work but who really shouldn’t be in class. http://www.insidehighered.com/news/2009/08/19/flu Guidelines here: http://www.crlt.umich.edu/flu/index.php

MASSACHUSETTS MODIFIES ITS NEW INFORMATION SECURITY RULES FOR BUSINESSES AND EXTENDS THE COMPLIANCE DEADLINE AGAIN (Duane Morris, 19 August 2009) - The Massachusetts Office of Consumer Affairs and Business Regulation issued a press release on August 17, 2009, extending the deadline for compliance with the state’s new information security regulations from January 1, 2010, to March 1, 2010, and updating the regulations to implement a more risk-based approach. The regulations had required all businesses, regardless of size, that own, license, store or maintain personal information about a resident of Massachusetts to encrypt that information when stored on portable devices or transmitted wirelessly or on public networks, and adopt a comprehensive, written information security program. New language in the regulations now recognizes that the size of a business and the amount of personal information it handles is a factor in the data security plan the business creates. Hence, the regulations were modified so that the safeguards are appropriate to the size, scope and type of business handling the information; the amount of resources available to the business; the amount of stored data; and the need for security and confidentiality of both consumer and employee information. http://www.duanemorris.com/alerts/alert3378.html

45% OF EMPLOYERS NOW SCREEN SOCIAL MEDIA PROFILES (Mashable, 19 August 2009) - We all know that employers are getting savvy to social networking sites and the information we share online. But what you may not know is that a recently conducted survey shows that nearly 1 in 2 companies are doing their online due diligence for prospective job candidates. This according to research firm Harris Interactive, who was commissioned by CareerBuilder.com and surveyed 2,667 HR professionals, finding that 45% of them use social networking sites to research job candidates, with an additional 11% planning to implement social media screening in the very near future. According to the study, “thirty-five percent of employers reported they have found content on social networking sites that caused them not to hire the candidate.” http://mashable.com/2009/08/19/social-media-screening/

D.C. APPEALS COURT ADOPTS FIVE-STEP INQUIRY FOR UNMASKING ANONYMOUS INTERNET SPEAKERS (BNA’s Internet Law News, 20 August 2009) - BNA’s Electronic Commerce & Law Report reports that the District of Columbia Court of Appeals held that a defamation plaintiff seeking to identify an anonymous defendant must first submit sufficient evidence to establish a genuine issue of material fact for all claim elements within its control. The court ultimately adopted a five-part test it said was similar to the summary judgment standard set forth in Doe v. Cahill. Case name is Solers Inc. v. Doe.

FORCING EMPLOYEE TO PROVIDE ACCESS TO PASSWORD-PROTECTED WEBSITE VIOLATES SCA (Steptoe & Johnson’s E-Commerce Law Week, 20 August 2009) - A recent jury verdict suggests that an employer that gains access to an employee’s social networking site by pressuring the employee to provide it with credentials for access may thereby violate the Stored Communications Act. In Pietrylo v. Hillstone Restaurant Group, several former employees of Houston’s restaurants in New Jersey alleged that Houston’s owner, the Hillstone Restaurant Group, accessed without authorization the employees’ private and password-protected MySpace group website -- used to make comments and jokes about Houston’s management, customers, and customer service standards. The employees were subsequently fired, and they then brought a wrongful termination suit claiming violations of their right to privacy, the Stored Communications Act (SCA) and a similar New Jersey statute, and other laws. Last July, a federal court in New Jersey denied defendants’ motion for summary judgment on the claims for violations of the SCA, the parallel state statute, and two invasion of privacy claims, finding that “testimony regarding whether [] consent was voluntary demonstrate[d] a material issue of disputed fact.” Notably, however, the court also concluded that if “consent was only given under duress, then the Defendants were not ‘authorized’ under the terms of the statute.” Last month, a jury found that Houston’s “knowingly or intentionally or purposefully access[ed] [the site] without authorization” on five occasions, in violation of the SCA and the parallel New Jersey statute. The jury also found the violations to be “malicious.” http://www.steptoe.com/publications-6300.html

JUDGE: DEFUNCT AIRPORT FAST PASS COMPANY CAN’T SELL CUSTOMER DATA (ComputerWorld, 20 August 2009) - A federal judge in New York has issued an order banning the operator of a now-defunct registered air traveler program from selling any of the highly personal data it collected on tens of thousands of people who signed up for the program. The order enjoins Verified Identity Pass Inc. (VIP) of New York from selling, transferring or disclosing to any third-party the data it collected while operating the Clear service, which was designed to help air travelers get through airport security checks faster. The judge noted that the Clear program’s membership agreement expressly forbade VIP from selling the information to third parties. As a result, the court found an immediate need for “preliminary injunctive relief” preventing the transfer or disclosure of the information. The ruling noted the circumstances under which the program closed and said there was a risk of the data being disclosed because of a lack of accountability and oversight over how the data is stored. http://www.computerworld.com/s/article/9136878/Judge_Defunct_airport_fast_pass_company_can_t_sell_customer_data?source=CTWNLE_nlt_dailyam_2009-08-20

FEDERAL AGENCIES PURSUE CYBERSECURITY COMMON GROUND (Information Week, 24 August 2009) - The National Institute of Standards and Technology’s recently released recommendations for cybersecurity are the first step in a plan to create a common security framework for civilian, military, and intelligence agencies. The 237-page final version of NIST’s Special Publication 800-53, “Recommended Security Controls for Federal Information Systems and Organizations,” was released earlier this month. In parallel with that, NIST has been working with defense and intelligence agencies on certification and accreditation, enterprise-wide risk management, procedures to assess cybersecurity controls, and risk assessment. Documents addressing those areas are due over the next few months. NIST only has a mandate to create security standards for civilian federal agencies, but the intelligence and defense communities have been working with civilian agencies in recent years. In doing so, they’re collaborating to create a common set of cybersecurity controls that, among other things, would provide a more consistent market for the industry. “This way we can work off a single playbook,” says NIST senior computer scientist and information security researcher Ron Ross, who drives cybersecurity standards as the lead of NIST’s Federal Information Security Management Act implementation project. Coordination among NIST and the intelligence and defense communities began three years ago when former Department of Defense CIO John Grimes and former Office of the Director of National Intelligence CIO Dale Meyerrose worked together on transforming the certification and accreditation processes for technology products. NIST got involved and suggested that the three constituencies broaden the scope of their work to include higher-level security controls. Prior to that, the Department of Defense, the federal intelligence community, and NIST were accustomed to developing their own security control recommendations. In pursuing common standards, Ross says, the government can create standard ways to share information and partner on IT projects, including cybersecurity. He sees standardization as a potential catalyst for developing new cybersecurity products and services for the government market, as vendors would be working from one set of requirements. The next document NIST will release with help from the intelligence and defense communities will be a revision of Special Publication 800-37, certification and accreditation guidelines published in 2004. A draft of that revision was published 12 months ago. The new document makes certification and accreditation of IT systems more of a continuous process than a one-time activity. Ross expects a final draft of 800-37 in September. After that, NIST will release what Ross calls a “capstone document” that defines and requires enterprise risk management at various levels within government agencies, including information systems. The document will require that agencies have an individual or board that carries out risk management. A draft of that document will likely be out by the end of the year. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=219401209&cid=RSSfeed_IWK_News

- and -

DHS AND INFORMATION TECHNOLOGY SECTOR COORDINATING COUNCIL RELEASE INFORMATION TECHNOLOGY SECTOR BASELINE RISK ASSESSMENT (DHS, 25 August 2009) - The Department of Homeland Security (DHS) and the Information Technology Sector Coordinating Council (IT SCC) today released the IT Sector Baseline Risk Assessment (ITSRA) to identify and prioritize national-level risks to critical sector-wide IT functions while outlining strategies to mitigate those risks and enhance national and economic security...The ITSRA validates the resiliency of key elements of IT sector infrastructure while providing a process by which public and private sector owners and operators can continually update their risk management programs. The assessment links security measures to concrete data to provide a basis for meaningful infrastructure protection metrics. http://www.dhs.gov/ynews/releases/pr_1251249275263.shtm Report here: http://www.dhs.gov/xlibrary/assets/nipp_it_baseline_risk_assessment.pdf

CYBER-ATTACK STRATEGY: PART OF RUSSIAN ATTACK ON GEORGIAN PIPELINES, REPORT FINDS (Energy Bulletin, 24 August 2009) - John Bumgarner, a former cyber-security expert for the CIA and other U.S. intelligence agencies, is attracting much attention for his report concluding that Russia’s military offensive in Georgia last year was coordinated with a pre-arranged civilian cyber-attack on the country. What appears to have gone unreported is Bumgarner’s conclusion that the region’s oil apparatus was a strategic target of the overall conventional-and-cyber offensive. The 100-page report, conducted for the U.S. Cyber-Consequences Unit, where Bumgarner is director of research, was distributed to U.S. officials and security experts. Its chief takeaway is that the Russian cyberattack -- which disabled 54 Georgian websites in banking, communications and media with the apparent aim of reducing Georgia’s capability of responding to the Russian offensive -- was prepared well in advance. Bumgarner writes: “Many of the cyber attacks were so close in time to the corresponding military operations that there had to be close cooperation between people in the Russian military and the civilian cyber attackers. When the cyber attacks began, they did not involve any reconnaissance or mapping stage, but jumped directly to the sort of packets that were best suited to jamming the websites under attack. This indicates that the necessary reconnaissance and the writing of attack scripts had to have been done in advance. Many of the actions the attackers carried out, such as registering new domain names and putting up new Web sites, were accomplished so quickly that all of the steps had to be prepared earlier.” http://www.energybulletin.net/node/49938 Report here: http://www.registan.net/wp-content/uploads/2009/08/US-CCU-Georgia-Cyber-Campaign-Overview.pdf

COURT RULES U.S. SEIZED 2003 TESTS IMPROPERLY (New York Times, 26 August 2009) - A federal appeals court in California ruled Wednesday that prosecutors improperly seized the drug tests for the roughly 100 major league baseball players who tested positive for performance-enhancing drugs in 2003. “This was an obvious case of deliberate overreaching by the government in an effort to seize data as to which it lacked probable cause,” Chief Judge Alex Kozinski wrote in support of a 9-to-2 decision by the United States Court of Appeals for the Ninth Circuit, in San Francisco. The ruling is a significant victory for the Major League Baseball Players Association, which has been fighting in the courts since 2004, when authorities from the United States attorney’s office for the Northern District of California seized the tests as part of a wider investigation into the distribution of performance-enhancing drugs. The tests were supposed to be conducted as an anonymous survey. Not even the players were supposed to know the results. If more than 5 percent tested positive, the program would continue the following season with penalties imposed for those who tested positive. Ultimately, more than 5 percent tested positive, and players began facing suspensions for steroids in 2004. But for reasons never made clear, the test results were not immediately destroyed after the 2003 season. The prosecutors wanted the test results to determine whether 10 players — the most prominent being Barry Bonds, Jason Giambi and Gary Sheffield — had been truthful when they testified before a grand jury investigating the Bay Area Laboratory Co-operative. The prosecutors secured search warrants to seize the 10 tests, and when agents raided the companies overseeing the testing, they found the results for the 10 players on a computer mixed with the results of the roughly 100 players who tested positive. The agents took all the drug-testing information, and the union filed court papers challenging the seizure. At issue in the case is what prosecutors can legally take from a computer when they use a warrant to search it.
http://www.nytimes.com/2009/08/27/sports/baseball/27doping.html?_r=1&hp [Some commentators observe that this essentially is a ruling that the so-called “plain view
doctrine,” under which evidence may be seized if it is within plain view
during a legitimate search, does not apply to electronic searches. – see http://www.computerworld.com/s/article/9137209/Court_ruling_limits_electronic_searches?source=rss_security]

DOZENS OF JUDGES ARE GETTING LINKEDIN, BLOGGER NOTES (ABA Journal, 26 August 2009) - Dozens of judges have posted profiles on the professional networking site LinkedIn, including seven federal appeals judges. Blogger Robert Ambrogi found the judges through his own search, and wrote about them on Legal Blog Watch. Among the federal appeals judges with public profiles are Richard Clifton of the 9th Circuit, Deborah Cook of the 6th Circuit, Jennifer Elrod of the 5th Circuit, John Ferren of the D.C. Circuit and Edith Jones of the 5th Circuit. Two others kept their profiles private. Ambrogi also found two federal district judges, two bankruptcy judges and one U.S. magistrate judge, as well as 16 state appeals judges and several more state trial judges. The judge with the most connections was Milwaukee Municipal Court Judge Derek Mosley, who had 419 connections. Ambrogi considers whether there are ethical pitfalls for judges who post online profiles. Online comments could draw fire, he notes. He also wonders whether the identity of connections could pose a problem. “Could a judge’s connections on LinkedIn or Facebook create the potential for conflicts of interest?” Ambrogi writes. “Should litigants routinely vet a judge’s social-networking profile in advance of a trial? Should judges be required to make public disclosures of the individuals and groups they connect to online?” He also wonders if it is appropriate for judges to list that they are open to “career opportunities” and “business deals.” http://www.abajournal.com/news/blogger_finds_dozens_of_judges_with_linkedin_profiles

TIGHTER OVERSIGHT ON BORDER LAPTOP SEARCHES (AP, 27 August 2009)) - The Obama administration on Thursday put new restrictions on searches of laptops at U.S. borders to address concerns that federal agents have been rummaging through travelers’ personal information. The long-criticized practice of searching travelers’ electronic devices will continue, but a supervisor now would need to approve holding a device for more than five days. Any copies of information taken from travelers’ machines would be destroyed within days if there were no legal reason to hold the information. The new directive, effective immediately, put more restrictions on the searches:
• A supervisor must be present during these searches.
• As before, Customs and Border Protection officials can keep the electronic device or information on it only if they have probable cause to believe it is connected to a crime. But now if there is no legal reason to hold the information, it must be destroyed within seven days.
• Officers must consult agency lawyers if they want to view a traveler’s sensitive legal material, medical records or a journalist’s work-related information.
• Immigration and Customs Enforcement agents cannot keep property for more than 30 days, depending on the circumstances of each case.
Marcia Hofmann, a lawyer with the Electronic Frontier Foundation, a ditigal civil rights advocacy group, said in an interview the new rules are an improvement. But they don’t go far enough, she said. She said travelers should be told if information is copied from their devices. The new directive states that federal agents must tell travelers if they are looking at their property. But if officials copy the hard drive during this search, the traveler will not know. http://news.yahoo.com/s/ap/20090828/ap_on_go_ca_st_pe/us_laptop_searches_3

- and -

PROTECT YOUR LAPTOP DATA FROM EVERYONE, EVEN YOURSELF (Wired essay by Bruce Schneier, 15 July 2009) - Last year, I wrote about the increasing propensity for governments, including the U.S. and Great Britain, to search the contents of people’s laptops at customs. What we know is still based on anecdote, as no country has clarified the rules about what their customs officers are and are not allowed to do, and what rights people have. Companies and individuals have dealt with this problem in several ways, from keeping sensitive data off laptops traveling internationally, to storing the data -- encrypted, of course -- on websites and then downloading it at the destination. I have never liked either solution. I do a lot of work on the road, and need to carry all sorts of data with me all the time. It’s a lot of data, and downloading it can take a long time. Also, I like to work on long international flights. There’s another solution, one that works with whole-disk encryption products like PGP Disk (I’m on PGP’s advisory board), TrueCrypt, and BitLocker: Encrypt the data to a key you don’t know. http://www.wired.com/politics/security/commentary/securitymatters/2009/07/securitymatters_0715 [Editor: fairly extreme technique, but it should work.]

FOR INTELLIGENCE OFFICERS, A WIKI WAY TO CONNECT DOTS (Washington Post, 27 August 2009) - Intellipedia, the intelligence community’s version of Wikipedia, hummed in the aftermath of the Iranian presidential election in June, with personnel at myriad government agencies updating a page dedicated to tracking the disputed results. Similarly, a page established in November immediately after the terrorist attack in Mumbai provided intelligence analysts with a better understanding of the scope of the incident, as well as a forum to speculate on possible perpetrators. “There were a number of things posted that were ahead of what was being reported in the press,” said Sean Dennehy, a CIA officer who helped establish the site. Intellipedia is a collaborative online intelligence repository, and it runs counter to traditional reluctance in the intelligence community to the sharing of classified information. Indeed, it still meets with formidable resistance from many quarters of the 16 agencies that have access to the system. But the site, which is available only to users with proper government clearance, has grown markedly since its formal launch in 2006 and now averages more than 15,000 edits per day. It’s home to 900,000 pages and 100,000 user accounts. “About everything that happens of significance, there’s an Intellipedia page on,” Dennehy said. Intellipedia sprung from a 2004 paper by CIA employee Calvin Andrus titled “The Wiki and the Blog: Toward a Complex Adaptive Intelligence Community.” http://www.washingtonpost.com/wp-dyn/content/article/2009/08/26/AR2009082603606.html?wprss=rss_technology

AUGMENTED REALITY COMES TO THE IPHONE (Macworld, 31 August 2009) - If you’re traveling to Paris, France anytime soon, consider taking Metro Paris Subway 3.0 along for the trip. This 99-cent iPhone app integrates an augmented reality feature (called Your New Eye) that will show you where the closest Paris subway stations are, relative to your current location, as an overlay atop a live video feed from the iPhone’s built-in camera. The app’s developer, Presselite, posted a video demo of its new app. The video is in French, but it’s visual enough that you should get the idea of how the app works. A pair of upcoming apps from iPhone developer Acrossair for navigating the New York City Subway and London Underground will use augmented reality in a similar manner. http://www.macworld.com/article/142503/2009/08/augmented_reality.html?lsrc=rss_main [Editor: fabulous, if it works well.]

THE GOVERNMENT DOMAIN: TRACKING CONGRESS 2.0 (LLRX.com, 31 August 2009) - The 111th Congress of the United States reconvenes on September 8th. Get ready with these new tools and sources for following the action. GovTrack.us, a free and independent legislative database, has just released a number of new features:
• Pages for individual bills now show industry supporters and opponents as determined by MAPLight.org, another free and independent site. (New to MAPLight? See the MAPLight FAQ.)
• Bills affected by a cloture vote link to yet another free website, Filibusted.us, which specializes in explaining and tracking Senate filibusters.
• Pages for members of Congress now show their latest tweets if they are on Twitter.
• The login accepts your existing GovTrack ID or--recommended for new users--your account ID for Google, Yahoo, AOL, or OpenID. (Logging in allows you to establish “trackers,” email or RSS alerts for action on a bill, or new information on a member of Congress or committee.)
• GovTrack also has upgraded hardware to handle its growing popularity.
For information on all of the changes at Govtrack, see the blog posting Summer Site Updates. This is not new, but Govtrack also has a few widgets allowing you to embed content such as a bill’s status or a congressional district map on your web page; for details, see the Widgets page. Others have developed Facebook apps based on Govtrack’s database; for these, see the Tracking and Sharing Tools page. http://www.llrx.com/columns/govdomain42.htm [There’s much more here.]

HARVARD'S DASH FOR OPEN ACCESS (Harvard, 1 Sept 2009) - Harvard's leadership in open access to scholarship took a significant step forward this week with the public launch of DASH—or Digital Access to Scholarship at Harvard—a University-wide, open-access repository. More than 350 members of the Harvard research community, including over a third of the Faculty of Arts and Sciences, have jointly deposited hundreds of scholarly works in DASH. "DASH is meant to promote openness in general," stated Robert Darnton, Carl H. Pforzheimer University Professor and Director of the University Library. "It will make the current scholarship of Harvard's faculty freely available everywhere in the world, just as the digitization of the books in Harvard's library will make learning accumulated since 1638 accessible worldwide. Taken together, these and other projects represent a commitment by Harvard to share its intellectual wealth." http://hul.harvard.edu/news/2009_0901.html Dash is here: http://dash.harvard.edu/

ONLINE TERMS PRESENTED WITH THREE BLUE HYPERLINKS ARE CONSPICUOUS, CONSCIONABLE (BNA’s Internet Law News, 3 Sept 2009) – BNA’s Electronic Commerce & Law Report reports that the U.S. District Court for the Central District of Illinois held Aug. 25 that blue underlined hyperlinks to additional contract terms appearing three times during an online ordering process were sufficiently conspicuous to become part of the sale contract, turning back an unconscionability argument. The court upheld the validity of what it called a “hyperwrap” contract on finding that a combination of three hyperlinks and a specific reference to the contract before checkout rendered it binding. Case name is PDC Laboratories Inc. v. Hach Company.

FOX ADDS ON-AIR TWEETS TO `FRINGE' RERUNS (AP, 4 Sept 2009) - Summer reruns are ho-hum television, but Fox is trying out a possible solution: Add Twitter. On the network's repeat broadcast of its supernatural drama "Fringe" on Thursday night, tweets were added on-screen to the show. The tweets (messages of 140 characters or less from the microblogging Web site Twitter) ran throughout the show on the bottom third of the screen. The tweets were from executive producers Jeff Pinkner (whose handle on Twitter is JPFringe) and J.H. Wyman (JWFringe), and cast members Peter Bishop (peterbishop2) and John Noble (labdad1). http://tech.yahoo.com/news/ap/20090904/ap_on_hi_te/us_tv_twittering_tube_3

**** NOTED PODCASTS ****
ETHICS AND CLOUD COMPUTING (August 2, 2009) – At the ABA annual meeting, I moderated a panel on lawyer-ethics issues associated with cloud computing: Head in the Cloud - Feet in the Code of Professional Responsibility -- Managing the Ethical Risks to Lawyers from Web 2.0 Technologies, Portable Devices and Wireless Access”. We had excellent panelists, including Chris Kelly (on leave as CPO for Facebook and candidate for California Attorney General). The podcast of this event is here: http://files.knowconnect.com/public/Head_in_the_Cloud_Feet_in_the_Code.mp3

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
BIG BLUE OFFERS LINUX SUPPORT... -- IBM has announced it will offer the same level of customer support for Linux as it now offers for Microsoft NT on certain models of IBM servers. “This is not a flash in the pan,” says an executive in IBM’s NetFinity-server unit. “For us, Linux is a long-term plan that’s constantly building.” Support for Linux software is generally considered somewhat problematic, because there are several different versions that are popular today, making it both tricky and expensive for computer makers. “If they support them all, it’s a mess,” says an analyst with Dataquest. “There needs to be a de facto standard, because supporting all of them is crazy.” (Investor’s Business Daily 28 Jul 99) http://www.investors.com/

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, August 15, 2009

MIRLN --- 26 July – 15 August 2009 (v12.11)

• NYT Co.’s Top Lawyer Doubts that Aggregation is a Copyright Issue
• Will Bloggers be at Risk in AP Content Crackdown?
• 15 Top Privacy Policies, Analyzed
• Expert: iPhone 3GS Crypto is Easily Crackable
• Great .GOV Web Sites
• Study: Who’s On Which Social Nets
• Eleven-Word Snippets can Infringe Copyright, Rules ECJ
• Monitoring Employees’ Personal Emails? Not So Fast, Says New Jersey Court
• Finding Accurate Law Text Online Nearly Impossible, Panelists Say
• Serendipity, Lost in the Digital Deluge
• NIST Releases ‘Historic’ Final Version of Special Publication 800-53
o NIST Lab Director Tackles Cybersecurity, Cloud Computing
• Legal Ethics of Facebook, Twitter & Cloud Computing
o Facebooking Judge Catches Lawyer in Lie, Sees Ethical Breaches
o Study Reveals High Levels of Twitter Use at Conferences
o UK Government Advice Urges Tweeting
o NSO to Try Beethoven’s Tweet Suite
o The N.F.L. Has Identified the Enemy and it is Twitter
o DOD Rethinking Social-Media Access
• Data Security Breach Notification Law Update
• Heartland Says Breach has Cost it $32 Million this Year
• Cyber Attackers Empty Business Accounts in Minute
• Publicis Groupe to Buy Microsoft’s Razorfish
• Bank Will Allow Customers to Deposit Checks by iPhone
• Care to Write Army Doctrine? With ID, Log On

NEWS | PODCASTS | DIFFERENT | LOOKING BACK | NOTES

**** NEWS ****
NYT CO.’S TOP LAWYER DOUBTS THAT AGGREGATION IS A COPYRIGHT ISSUE (Nieman Journalism Lab, 22 July 2009) - It’s been four months since Josh predicted that a news organization would sue The Huffington Post for copyright violation over its aggregation of headlines, ledes, and article summaries. The interim has been marked by saber-rattling, settlements, and dubious proposals for changes to federal law. But I’m still hoping to see that lawsuit — not because I think The Huffington Post is necessarily in the wrong but because a major case of that sort could begin to clarify the increasingly muddled issues of copyright on the Internet. For instance, how do you apply a 91-year-old legal doctrine known as “hot news” to a website that never heard of news that isn’t sizzling? Well, I’m no copyright lawyer, but UCLA professor Doug Lichtman is, and he just released a wonderful, hourlong podcast on what intellectual property means in the context of news reporting. Most of the program focuses on the dueling lawsuits over Shepard Fairey’s use of an Associated Press photograph in his iconic Obama “Hope” poster. Lichtman interviews lawyers from both sides and offers a more thoughtful discussion of the case than I’ve seen anywhere else. But my interest was really piqued by his chat with The New York Times Co.’s general counsel, Ken Richieri, who considers whether news aggregators are protected by “fair use,” the legal standard that permits reproduction of copyrighted material under guidelines that, as Richieri says, “work a lot better in the analog world than they do in a digital world.” http://www.niemanlab.org/2009/07/nyt-cos-top-lawyer-doubts-that-aggregation-is-a-copyright-issue/

- and -

WILL BLOGGERS BE AT RISK IN AP CONTENT CRACKDOWN? (ABA Journal, 24 July 2009) - The Associated Press plans to add software to its articles to track how they are used online. The aim is for those who use AP articles to pay for them, AP president and chief executive Tom Curley told the New York Times. AP maintains that just publishing an article headline and a link requires a licensing agreement, the story says. The Times notes that headlines and links are often used by search engines like Google, news aggregators and blogs. Google has argued in the past that its use of AP articles is protected by the doctrine of fair use, according to the blog Today @ PC World. But Curley apparently expects payment. “If someone can build multibillion-dollar businesses out of keywords, we can build multihundred-million businesses out of headlines, and we’re going to do that,” he told the Times. Today @ PC World questions whether bloggers will be targeted. Jane Seagrave, senior vice president for global product development at AP, told Information Week that the intent was to deter those who engage in large-scale copying of AP content rather than bloggers who use too many paragraphs from an AP story. “It’s not aimed at people who use part of stories periodically,” Seagrave told Information Week. “It’s aimed at being affirmative about how we allow our content to be used.” http://www.abajournal.com/news/ap_to_crack_down_on_use_of_its_content/

15 TOP PRIVACY POLICIES, ANALYZED (ReadWriteWeb, 23 July 2009) - We all know no one reads privacy policies. What do the top websites really include in them? In its mission to get anonymous public data, The Common Data Project a New York City-based non-profit, is on a mission to eliminate the barriers that privacy policies pose. In a new report, they analyzed ten of the most popular Web properties on the Internet, and several more emerging ones. Here’s how what they put in their policies affects your privacy, and how other enterprises can imitate their best practices. Regardless of any similarities or differences within policies, one thing is absolutely clear: tons of data is being collected about you, though some of it may already be incidental enough to be private (such as the popularity of search terms). Privacy is certainly not an issue limited to the Web, but it facilitates the nearly limitless ability to gather data by the boatload. The question at this point isn’t if companies will acquire your data. It’s what they’ll do with it. The 15 privacy policies studied encompasses both some of the biggest online portals and retailers, non-profits, and scrappy startups. The full list includes: Google, Yahoo!, Wikipedia, Microsoft, AOL, Amazon, eBay, Facebook, Craigslist, Photobucket, NYT, WebMD, Ask, Cuil, and Ixquick. Out of the analysis, Common Data Project asked seven pointed questions about what companies will or won’t do. Here are some of the red flags found in existing privacy policies. http://www.readwriteweb.com/enterprise/2009/07/15-top-privacy-policies-analyz.php

EXPERT: IPHONE 3GS CRYPTO IS EASILY CRACKABLE (CNET, 24 July 2009) - The encryption functionality of the iPhone 3GS is so easy to crack that it is essentially “broken” as far as protecting sensitive personal data like credit card and social security numbers, according to a forensics expert and iPhone developer. “I don’t think any of us [developers] have ever seen encryption implemented so poorly before, which is why it’s hard to describe why it’s such a big threat to security,” Jonathan Zdziarski told Wired. With physical access to a 3GS iPhone and some free software data can be extracted within two minutes and an image of the entire raw disk in about 45 minutes, he said. The iPhone decrypts the data on its own once the extraction has begun, he explains in a video demonstration. Apple has been touting the encryption and other features to entice corporate users to the device. And it seems to be working. Nearly 20 percent of Fortune 100 companies have purchased 10,000 or more iPhones per company. http://news.cnet.com/8301-27080_3-10295348-245.html

GREAT .GOV WEB SITES (GCN, 27 July 2009) - Anyone who doubts the central role that the Web has taken in government life should consider all the attention paid to Recovery.gov. The General Services Administration created the site earlier this year to show the public how federal economic stimulus money was being disbursed. But the first iteration of the site proved to be too inscrutable for the public. So the agency contracted with a company to redesign the site — to the tune of $18 million over the next five years. The days of a Web presence being an optional component for agencies are long gone. For most citizens, the primary way of interacting with their government is through Web sites. By and large, agencies have responded to that demand by creating richer, more interactive sites. What follows is a compendium of 10 government Web sites that are meeting and exceeding those goals. This is not a definitive list of the 10 best government sites. The field is way too broad for any such superlatives. But they are sites that embrace the Web’s full potential, and they can offer ideas for other agencies seeking to improve their own sites:
• Data.Gov sets the tone for transparent government
• Forge.mil brings net-centric speed to software development
• Transit511 combines public transportation systems in the Bay Area
• State puts social networking to diplomatic use
• FDsys makes America’s documents current and permanent
• Utah takes its site to higher ground
• Science.gov breaks down stovepipes of research
• USPS extends its virtual post office
• HHS delivers health info users can trust
• The Web site on building better Web sites
http://gcn.com/articles/2009/07/27/gcn-great-gov-web-sites-2009.aspx

STUDY: WHO’S ON WHICH SOCIAL NETS (MediaPost, 27 July 2009) - Marketers that are frustrated with targeting specific age groups or demographics in Facebook, MySpace, Twitter and LinkedIn could glean insight from a recent study by Anderson Analytics. The study suggests that Twitter has become more popular than LinkedIn, more than half of U.S. consumers who tap social networks belong to more than one, and that those who belong to a social net are four times more vocal about products and services than those who don’t. Anderson Analytics CEO Tom Anderson says the biggest surprise from the study reveals that Twitter has become more popular than LinkedIn among social network users in the United States. Aside from posting tweets, Twitter users tend to blog frequently. In fact, more than 20% have their own blog, many of which trumpet social causes. These consumers make good evangelists for brands, he says. Anderson’s study aims to help marketers understand the type of people who frequent each social network. For example, it debunks the myth that Facebook attracts only kids. In fact, the Anderson study suggests that the ideal age group for Facebook spans from 15 to 34, but 44% of 35- to 44-year-olds and 30% of 45- to-54-year-olds say they have profiles, too. And while more people are experimenting on social networks, only 10% of users report having ever created a duplicate or experimental profile. More than half of social network users have associated their profiles with a brand, company or product. While much has been written about negative nature of Web 2.0 and blog posts, social network users are more likely to say positive things about brands, companies or products. The average user logs into a social network account about four times daily, five days a week, and spends about one hour per day on the network. About 31.8% are business users; followed by 26.3%, fun seekers; 21.8%, social media mavens; and 10.1%, leisure followers. http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=110517

ELEVEN-WORD SNIPPETS CAN INFRINGE COPYRIGHT, RULES ECJ (Outlaw.com, 27 July 2009) - The copying and reproduction of just 11 words of a news article can be copyright infringement, the European Court of Justice (ECJ) has ruled. Europe’s highest court has said that a clippings service’s copying could be unlawful. Danish clippings service Infopaq was taken to court by Danish newspaper industry body Danske Dagblades Forening (DDF) over its reproduction of 11-word snippets of news for sale to clients. The agency would scan in newspaper pages and use software to turn the image of the page into text. If pre-determined keywords that clients wanted monitored appeared in text then that word and the five words on either side of it were kept and the rest of the text thrown away. Clients were then sent the 11 words and the details of what page of what publication on what date the words appeared as well as an indication of how far into the article the words came. Infopaq conceded that acts of copying and reproduction took place in the process, but said that the use was legal because of exceptions in the European Union’s Copyright Directive for ‘transient’ copying of material and lawful copying. The ECJ said that while some parts of Infopaq’s processing could be called transient, as soon as it had printed out the 11 words on to paper the copying became too permanent to qualify for the law’s exception. “The possibility cannot be ruled out at the outset that in the first two acts of reproduction at issue in those proceedings, namely the creation of [image] files and text files resulting from the conversion of [image] files, may be held to be transient as long as they are deleted automatically from the computer memory,” said the ECJ ruling. “By the last act of reproduction in the data capture process, Infopaq is making a reproduction outside the sphere of computer technology. It is printing out files containing the extracts of 11 words and thus reproduces those extracts on a paper medium,” it said. “Once the reproduction has been affixed onto such a medium, it disappears only when the paper itself is destroyed.” “Since the data capture process is apparently not likely itself to destroy that medium, the deletion of that reproduction is entirely dependent on the will of the user of that process. It is not at all certain that he will want to dispose of the reproduction, which means that there is a risk that the reproduction will remain in existence for a longer period, according to the user’s needs,” said the judgment. Though the Court conceded that “words as such do not…constitute elements covered by the protection”, it said that copyright law would apply to extracts even if they contained just 11 words. “The possibility may not be ruled out that certain isolated sentences, or even certain parts of sentences in the text in question, may be suitable for conveying to the reader the originality of a publication such as a newspaper article, by communicating to that reader an element which is, in itself, the expression of the intellectual creation of the author of that article,” it said. “Such sentences or parts of sentences are, therefore, liable to come within the scope of the protection provided for in Article 2(a) of that directive.” http://www.out-law.com/default.aspx?page=10205

MONITORING EMPLOYEES’ PERSONAL EMAILS? NOT SO FAST, SAYS NEW JERSEY COURT (Steptoe & Johnson’s E-Commerce Law Week, 30 July 2009) - A New Jersey appellate court recently ruled that although a company may examine an employee’s personal emails where necessary to serve “a legitimate business interest,” such a policy cannot permit “an intrusion into communications otherwise shielded by the attorney-client privilege.” In Stengart v. Loving Care Agency, Inc., Marina Stengart brought an employment discrimination claim against her former employer, the Loving Care Agency (LCA). While still employed at LCA, Stengart used her work-issued laptop to send several emails pertaining to her anticipated suit to her attorneys through her “personal, web-based, password-protected Yahoo email account.” After she filed suit, attorneys for LCA obtained access to these emails and produced some of them in response to her interrogatories. Stengart’s attorneys requested that LCA’s attorneys return all such emails. They refused, prompting Stengart to apply for a temporary restraining order. The trial judge denied the motion, finding that “the emails were not protected by the attorney-client privilege because the company’s electronic communications policy put plaintiff on sufficient notice that her emails would be viewed as company property.” On appeal, the Superior Court of New Jersey, Appellate Division, reversed, finding that “[a] policy imposed by an employer, purporting to transform all private communications into company property -- merely because the company owned the computer used to make private communications or used to access such private information during work hours -- furthers no legitimate business interest.” Significantly, the court’s rationale was not limited to emails concerning the attorney-client privilege. In reaching its decision, the court announced an extremely privacy-protective rule, holding that, regardless of the wording of a company’s monitoring policy, “an employer’s rules and policies must be reasonable to be enforced,” and that the policy may be enforced by courts only if “the regulated conduct … concern[s] the terms of employment” and the policy “reasonably further[s] the legitimate business interests of the employer.” http://www.steptoe.com/publications-6267.html Ruling here: Stengart v. Loving Care Agency -- http://lawlibrary.rutgers.edu/courts/wordperfect/appellate/A3506-08.DOC [Editor: The decision is an odd one, but distinguishable on the facts. All in all, not the end of the story for permitted employer monitoring, especially if the policy is well written and communicated.]

FINDING ACCURATE LAW TEXT ONLINE NEARLY IMPOSSIBLE, PANELISTS SAY (ABA Journal, 31 July 2009) - Federal Reserve Bank of New York’s counsel, Denley Chew, slapped down some $2 bills and challenged a room of lawyers and legal researchers with laptops and iPhones to find the authoritative text of the landmark Fugitive Slave Act online. “Authoritative” was the catch. The money remained untouched. Panelists declared that finding accurate text of a law—on government websites, LexisNexis, Westlaw—is almost impossible. The recession forced state and federal governments to post laws online rather than print them. But Mary Alice Baish, government relations director for the American Association of Law Libraries, says there is no national or international body that ensures those online postings are accurate or updated with amendments. The AALL conducted a 2007 survey that discovered that eight states and the District of Columbia refer lawyers and judges seeking the text of a law to official sources so different that the versions conflict. States that posted laws online only had no consistent way of maintaining older versions of an amended law or showing errors had been corrected. “The history of law is disappearing; older versions of a law, amendments, show the thought process of a people and how they evolved,” observed ABA Legal Technology Research Center director Catherine Reach. Global Legal Information Network at the Law Library of Congress provided the hopeful glimmer. Trusted officers of the court in dozens of jurisdictions, from the Congo to Canada, authenticate legal documents from their countries with an encrypted certificate. GLIN director Janice Hyde proudly said over 170,000 legal instruments have been authenticated. http://www.abajournal.com/news/finding_accurate_law_text_online_nearly_impossible_panelists_say_abachicago/

SERENDIPITY, LOST IN THE DIGITAL DELUGE (New York Times, 1 August 2009) – We’ve gained so much in the digital age. We get more entertainment choices, and finding what we’re looking for is certainly fast. Best of all, much of it is free. But we’ve lost something as well: the fortunate discovery of something we never knew we wanted to find. In other words, the digital age is stamping out serendipity. When we walk into other people’s houses, we peruse their bookshelves, look at their CD cases and sneak a peek at their video collections (better that than their medicine cabinets). It gives us a measure of the owner’s quirky tastes and, more often than not, we find a singer, a musician or a documentary we’d never known before. But CDs have disappeared inside the iPod. And shelves of videos are rarely seen as we get discs in the mail from Netflix or downloaded from Vudu. And, one day soon, book collections may end up inside a Kindle. With an e-book reader, the person on the subway seat across from you will never know what you are reading. Ah, the techies say, no worries. We have Facebook and Twitter, spewing a stream of suggestions about what to read, hear, see and do. We come to depend on it to lead us to the funny article on TheOnion.com or the roving food cart serving goat curry. It’s useful. But that isn’t serendipity. It’s really group-think. Everything we need to know comes filtered and vetted. We are discovering what everyone else is learning, and usually from people we have selected because they share our tastes. It won’t deliver that magic moment of discovery that we imagine occurred when Elvis Presley first heard the blues, or when Michael Jackson followed Fred Astaire’s white spats across the dance floor. Many software developers are trying to recreate serendipity. StumbleUpon is a Web service that steers users toward content they are likely to find interesting. Readers tell the service about their professional interests or hobbies, and it serves up sites to match them. It’s a good try, but it is still telling readers what they want to know. http://www.nytimes.com/2009/08/02/business/02ping.html?emc=eta1

NIST RELEASES ‘HISTORIC’ FINAL VERSION OF SPECIAL PUBLICATION 800-53 (GCN, 3 August 2009) - The National Institute of Standards and Technology has collaborated with the military and intelligence communities to produce the first set of security controls for all government information systems, including national security systems. The controls are included in the final version of Special Publication 800-53, Revision 3 “Recommended Security Controls for Federal Information Systems and Organizations,” released Friday. NIST called the document historic. “For the first time, and as part of the ongoing initiative to develop a unified information security framework for the federal government and its contractors, NIST has included security controls in its catalog for both national security and non-national security systems,” the agency said. “The updated security control catalog incorporates best practices in information security from the United States Department of Defense, Intelligence Community and Civil agencies, to produce the most broad-based and comprehensive set of safeguards and countermeasures ever developed for information systems.” A draft version of the document was released in June for public comment. This is the final version of the guidelines. NIST also has released a draft of SP 800-126, “The Technical Specification for the Security Content Automation Protocol (SCAP),” for public comment. SCAP comprises specifications for the standardized organization and expression of security-related information. SP 800-126 provides an overview of SCAP, focusing on how software developers can integrate SCAP technology into their product offerings and interfaces. SP 800-53 is part of a series of documents setting out standards, recommendations and specifications for implementing the Federal Information Security Management Act. This revision is the first major update of these guidelines since its initial publication in December 2005. It specifies the baseline security controls needed to meet the mandatory requirements of Federal Information Processing Standards 199, “Standards for Security Categorization of Federal Information and Information Systems,” and FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems.” http://gcn.com/Articles/2009/08/03/NIST-release-of-800-53-rev-3-080309.aspx 800-53 here: http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf

- and -

NIST LAB DIRECTOR TACKLES CYBERSECURITY, CLOUD COMPUTING (Information Week, 7 August 2009) - The National Institute of Standards and Technology’s IT Laboratory plays a key role in government cybersecurity, setting standards that federal agencies are required to follow. InformationWeek discussed NIST’s role, including the fine line between setting standards and setting policy, with Cita Furlani, director of NIST’s IT Lab. http://www.informationweek.com/news/government/enterprise-architecture/showArticle.jhtml?articleID=219100346&cid=RSSfeed_IWK_News [Editor: Interesting Q&A.]

Editor: Earlier this month I moderated an ABA panel in Chicago on lawyer-ethics issues associated with Cloud Computing. We had excellent panelists, including Chris Kelly (on leave as CPO for Facebook and candidate for California Attorney General). Here’s the ABA Journal’s blurb on the session:
LEGAL ETHICS OF FACEBOOK, TWITTER & CLOUD COMPUTING (ABA Journal, 2 August 2009) - The legal ethics challenges that will be posed by lawyer use of Facebook, Twitter and other forms of “cloud computing” services are almost as revolutionary as the services themselves, according to experts speaking at a discussion hosted Sunday by the Cyberspace Law Committee of the ABA Business Law Section. Cloud computing services store a user’s data–messages, photos, documents or any other kind of information–on a computer that is not under the user’s control. Facebook, Twitter, Flickr, YouTube, and Google Docs are all examples of the growing trend, which is sometimes also referred to as “software as a service.” The services allow users to access information from any computer connected to the Internet and to share that information either with a limited number of people or the public at large. They are quickly gaining popularity among lawyers and the clients they serve, both for their technological benefits and low cost, as reported in the August issue of the ABA Journal. But lawyers should carefully consider the legal ethics implications of that trend, according to Roland L. Trope, a partner in New York’s Trope and Schramm. He noted there’s a dramatic difference between what Google Docs–a service for creating and sharing text documents, spreadsheets and slide presentations–says in its marketing materials, and what is in its legally binding terms of service. When promoting the service, Google says it backs up users’ information almost as fast as they create it, so users always have access to their saved content. But the terms of service say Google does not guarantee any defects in the product will be fixed, and the company reserves the right to disable a user’s account without providing copies of the data the user has stored on Google’s computers. And because many cloud computer companies don’t store a user’s data in one location, or even in one country, what will happen when information from a client that is subject to U.S. export control restrictions is stored on a computer in a foreign country, Trope asked. Firms ought to disclose to clients how their data will be stored, so issues like this can be dealt with before they become a crisis, he said. http://www.abajournal.com/news/legal_ethics_of_facebook_twitter_cloud_computing_abachicago/

- and -

FACEBOOKING JUDGE CATCHES LAWYER IN LIE, SEES ETHICAL BREACHES (ABA Journal, 31 July 2009) - Galveston, Texas-area lawyers on Facebook may want to double-check their friends list, especially if they’re about to appear before Judge Susan Criss. That’s because Criss, a state court judge who is learning to adapt to social media as a way to connect with long-lost friends and is leveraging Facebook as a judicial campaign tool, has also learned a few things she didn’t expect. Biggest surprise: Even lawyers don’t fully grasp how public social media is, even when privacy controls are in place. “Anyone can cut and paste,” said Criss, who was part of a Friday ABA Annual Meeting program “Courts and Media in the 21st Century: Twitterers, Bloggers, the New Media, the Old Media, and What’s a Judge to Do?” sponsored by the ABA’s Judicial Division. Criss recalled one time that a lawyer asked for a continuance because of the death of her father. The lawyer had earlier posted a string of status updates on Facebook, detailing her week of drinking, going out and partying. But in court, in front of Criss, she told a completely different story. Then there was the lawyer who complained about having to handle a motion in Criss’s court. Criss playfully zinged her, too—on Facebook, of course. Criss has seen lawyers on the verge of crossing, if not entirely crossing, ethical lines when they complain about clients and opposing counsel. And she admonished one family member who jeopardized her own tort case by bragging online about how much money she would get from a lawsuit. http://www.abajournal.com/news/facebooking_judge_catches_lawyers_in_lies_crossing_ethical_lines_abachicago/

- and -

STUDY REVEALS HIGH LEVELS OF TWITTER USE AT CONFERENCES
(ReadWriteWeb, 27 July 2009) - A group of scholars from Germany, Austria, and the U.K. recently put together a case study about the tweeting habits of conference attendees. Entitled “How People are using Twitter during Conferences,” this research report (available on Scribd.com), reveals some interesting, although not altogether shocking, insights into the role the microblogging service plays during major events. Most notable of their findings is the number of individuals who actively use the service during conferences - a figure showing high participation levels among attendees. According to the report, the researchers were motivated to find out if using Twitter could actually help improve the interactions among the learners and enhance their learning experience when attending presentations in large groups. They looked into the motives of Twitter users, contents of tweets, and how this impacted the user’s network. The researchers found that the majority of conference attendees already had a Twitter account (95.1%) and many of those who did actively used it to tweet during the conference (67.5%). 74.1% of the attendees send between 11 and 20 messages per day and 51.2% discussed topics via @ replies and DMs. [N]early half the tweets were simple plain text messages while tweets with links to web sites only accounted for 10% of the messages. In other words, the Twitterers were using the medium to share the information they were learning at the present moment as opposed to posting links to information already available on the web. The participants were also asked open-ended questions like “Why do you think Twitter encouraged the discussion about topics?” and what the added value of Twitter at conferences was. In response, the survey participants answered that Twitter gave conference goers a greater sense of community and encouraged discussion in the backchannel, often allowing them to discuss things in more detail than the “guys on the stage.” Other participants noted that Twitter helps you connect with people who have similar interests, provides networking potential, and allows those who could not attend to gain value from your experience. Unfortunately, the data collected comes from only five conferences and forty-one different attendees, so the sample size isn’t what we would consider to be large enough to draw any definite conclusions. http://www.readwriteweb.com/archives/study_reveals_high_levels_of_twitter_use_at_conferences.php Study here: http://www.scribd.com/doc/15855075/09edumedia

- and -

UK GOVERNMENT ADVICE URGES TWEETING (BBC, 27 July 2009) - New government guidance has been published urging civil servants to use the micro-blogging site Twitter. Launched on the Cabinet Office website, the 20-page document is calling on departments to “tweet” on “issues of relevance or upcoming events”. The website is already used by Downing Street, the Foreign Office and many individual MPs. Neil Williams, of the Department for Business, Innovation and Skills (BIS), published the “template” strategy. Writing on the Cabinet Office’s digital engagement blog, Mr Williams - who is BIS’s head of corporate digital channels - conceded that 20 pages was a “a bit over the top for a tool like Twitter” but added: “I was surprised by just how much there is to say - and quite how worth saying it is.” The template had been written for BIS to consider using Twitter but could be used by other departments, he said. Publishing tweets, replying to incoming messages and monitoring the account would take less than an hour a day, according to the strategy. There would be an “add-on” to “business as usual” activity due to quick discussions of potential tweets at daily meetings, as well as e-mails between officials and digital media staff about potential content for tweets. http://news.bbc.co.uk/2/hi/uk_news/8171597.stm

- and -

NSO TO TRY BEETHOVEN’S TWEET SUITE (Washington Post, 30 July 2009) - The National Symphony Orchestra is trying an experiment. It’s tweeting Beethoven’s “Pastoral” Symphony, Thursday night at Wolf Trap. For a healthy portion of the classical music audience, Internet-related words such as “tweet” or “Twitter” cause parts of the brain to shut down. Deep breaths. Here’s what will happen: The orchestra will use the micro-blogging site Twitter to send text messages of 140 characters or fewer from conductor Emil de Cou during the performance. (Example: “In my score Beethoven has printed Nightingale = flute Quail = oboe Cuckoo = clarinet -- a mini concerto for woodwind/birds.”) The idea is that those interested will sit in a designated area on the Wolf Trap lawn with their BlackBerrys, iPhones or other mobile devices and, by following the Twitter user NSOatWolfTrap, gain a new perspective on the score. Of course, you can also follow along without actually being at Wolf Trap at all. http://www.washingtonpost.com/wp-dyn/content/article/2009/07/29/AR2009072903067.html?wprss=rss_technology

- and -

THE N.F.L. HAS IDENTIFIED THE ENEMY AND IT IS TWITTER (New York Times, 4 August 2009) - To the list of universal threats to football success — injury and indiscretion, a Tom Brady-led offense marching against your defense — the N.F.L. has added another: Twitter. As training camps opened last week, players were told that the same standard — read: paranoia — that applied to the flow of information to reporters also applied to Twitter. In Green Bay, players were told they would be fined if they texted or tweeted from team meetings or coaching sessions. When Coach Tony Sparano met with the Miami Dolphins before Sunday’s first practice, he effectively outlawed Twitter, nose tackle Jason Ferguson said. Football coaches are a password-protected lot, preferring to dispense so little information that most days, they would struggle to fill 140 characters. They worry that the casual nature of Twitter could inspire the budding bloggers in their locker rooms to inadvertently disclose more than they should about injuries, game plans and what is said behind closed doors. The N.F.L. does not have a policy about social media, although it warns players about the risks of someone impersonating them on one of the sites. Cellphones, computers and P.D.A.’s cannot be used by players, coaches or other club personnel on the sideline, in coaches’ booths or locker rooms from pregame warm-ups through the end of the game. But N.F.L. officials are working on a policy that would apply to the use of social media sites on the day of the game. http://www.nytimes.com/2009/08/04/sports/football/04twitter.html?_r=1

- and -

DOD RETHINKING SOCIAL-MEDIA ACCESS (FCW, 3 August 2009) - With concerns mounting over security and management, the Defense Department is reevaluating its policies on use of social media tools. Sites such as Facebook, MySpace and Twitter, once banned from DOD use, now play a major role for government and military public relations and recruiting. However, the threat of security breaches stemming from wide-open access could lessen Web 2.0’s appeal. U.S. Strategic Command, which oversees the use of the dot-mil network, has launched a review of the safety of the sites. The command acknowledged in media reports last week that it was doing so, but has otherwise remained mum on the topic. “There certainly are security concerns associated with social networking. But it would be a step back to ban social networks completely,” said information technology security expert Rohyt Belani, a consultant and instructor at Carnegie-Mellon University. “I think there is a middle ground that can be reached.” Security fears largely center on the familiar possibility of hackers infiltrating networks with sensitive information, particularly via phishing scams that dupe computer users into downloading viruses, clicking links to malware or entering secure information. But Web 2.0 brings an additional concern: People sharing too much information online, such as the case of incoming British intelligence chief John Sawers, whose wife posted personal information and photos on Facebook that have landed Sawers in serious hot water. http://fcw.com/articles/2009/08/03/dod-rethinking-social-media-access.aspx

DATA SECURITY BREACH NOTIFICATION LAW UPDATE (Hunton & Williams, 5 August 2009) - July saw a flurry of activity involving data security breach notification laws.
• On July 1, breach notification laws in Alaska and South Carolina went into effect.
• On July 9, Missouri became the 45th state to enact a data breach notification law. [Editor: But the Missouri law also includes health insurance and medical data in its definition of personal information.]
• On July 22, Senator Patrick Leahy reintroduced a comprehensive federal data security bill calling it one of his “highest legislative priorities.”
• On July 27, North Carolina amended its breach notification law to require notification of the state attorney general any time consumers are notified of a breach involving their personal information. The amendment also included content requirements for the attorney general’s notice. http://www.huntonprivacyblog.com/2009/08/articles/information-security/data-security-breach-notification-law-update/index.html#page=1

HEARTLAND SAYS BREACH HAS COST IT $32 MILLION THIS YEAR (StorefrontBacktalk, 6 August 2009) - Heartland Payment Systems on Aug. 4 said it spent $32 million this year paying for costs related to the major data breach it disclosed in January, including $22.1 million to cover fines from key payment card brands and a settlement offer. Heartland did not say how the $22.1 million was split between the fines and the settlement offer, but it did provide clues. http://www.storefrontbacktalk.com/securityfraud/heartland-says-breach-has-cost-it-32-million-this-year-including-22-1-million-in-card-brand-fines-settlement-offer/

CYBER ATTACKERS EMPTY BUSINESS ACCOUNTS IN MINUTE (Network World, 6 August 2009) - The criminals knew what they were doing when they hit the Western Beaver County School District. They waited until school administrators were away on holiday, and then during a four-day period between Dec. 29 and Jan. 2, siphoned US$704,610.35 out of two of the school district’s bank accounts. Western Beaver’s financial institution, ESB Bank, managed to reverse some of the transfers, but the Pennsylvania school district was out more than $441,000. On July 9, Western Beaver sued ESB to try and recover the money, but security experts say that it’s just one of many organizations that have been hit in recent months by a disturbing new type of financial fraud that can often leave the victim holding the bag. Fraudsters are taking advantage of the widely used but obscure Automated Clearing House (ACH) Network in order to pull off their attacks. This financial network is used by financial institutions to handle direct deposits, checks, bill payments and cash transfers between businesses and individuals. Criminals can make millions of dollars per day with ACH fraud, investigators say. And while consumers are protected from this type of fraud, the rules for corporations and organizations are not as clear-cut, so sometimes victims like Western Beaver find themselves having to pay. The fraud typically starts with a targeted phishing e-mail, aimed at whomever is in charge of the company’s checkbook. By tricking the victim into running software, opening a harmful attachment or visiting a malicious Web site, the criminals are able to install keylogging software and steal bank account passwords. http://www.networkworld.com/news/2009/080609-cyber-attackers-empty-business-accounts.html?source=NWWNLE_nlt_daily_am_2009-08-07

PUBLICIS GROUPE TO BUY MICROSOFT’S RAZORFISH (CNET, 9 August 2009) - French advertising group Publicis Groupe SA has agreed to acquire Internet ad agency Razorfish from Microsoft for $530 million in cash and stock. Razorfish will continue to operate under its own brand name and continue to serve as Microsoft’s “preferred provider” for Internet advertising, the companies announced Sunday in a joint statement. The deal includes a strategic alliance agreement in which Publicis Groupe will purchase display and search advertising from Microsoft over a five-year period. “The purchase of Razorfish is a new step in our strategic plan to be the unquestionable leader in digital communication,” Publicis Groupe Chief Executive Officer Maurice Levy said in the statement. “Once this acquisition is complete, about a quarter of our revenue will come from digital communication and our ability to grow and conquer will be reinforced.” Publicis Groupe is one of the world’s largest media companies, employing about 44,000 people at advertising networks Leo Burnett and Saatchi & Saatchi, as well as media buyers Starcom MediaVest Group and ZenithOptimedia. Microsoft had reportedly been shopping Razorfish around for the past few months, with top ad firms WPP, Omnicom Group, and Publicis Groupe all expressing interest in Razorfish. Talks were also held between Microsoft and agencies Interpublic Group and Dentsu. http://news.cnet.com/8301-1023_3-10306162-93.html?part=rss&subj=news&tag=2547-1_3-0-5

BANK WILL ALLOW CUSTOMERS TO DEPOSIT CHECKS BY IPHONE (New York Times, 10 August 2009) - The Internet has taken a lot of the paperwork out of banking, but there is no avoiding paper when someone gives you a check. Now one bank wants to let customers deposit checks immediately — through their phones. USAA, a privately held bank and insurance company, plans to update its iPhone application this week to introduce the check deposit feature, which requires a customer to photograph both sides of the check with the phone’s camera. “We’re essentially taking an image of the check, and once you hit the send button, that image is going into our deposit-taking system as any other check would,” said Wayne Peacock, a USAA executive vice president. Customers will not have to mail the check to the bank later; the deposit will be handled entirely electronically, and the bank suggests voiding the check and filing or discarding it. But to reduce the potential for fraud, only customers who are eligible for credit and have some type of insurance through USAA will be permitted to use the deposit feature. Mr. Peacock said that about 60 percent of the bank’s customers qualify. Three years ago, it introduced the option of depositing a check from home using a scanner. That laid the groundwork for the phone deposit feature, which USAA plans to offer on other phones this year. The deposit feature, which USAA previewed in an online video in June, puts the bank in the vanguard of the effort to turn cellphones into portable branches. http://www.nytimes.com/2009/08/10/technology/10check.html?_r=1&ref=business

CARE TO WRITE ARMY DOCTRINE? WITH ID, LOG ON (New York Times, 14 August 2009) - In July, in a sharp break from tradition, the Army began encouraging its personnel — from the privates to the generals — to go online and collaboratively rewrite seven of the field manuals that give instructions on all aspects of Army life. The program uses the same software behind the online encyclopedia Wikipedia and could potentially lead to hundreds of Army guides being “wikified.” The goal, say the officers behind the effort, is to tap more experience and advice from battle-tested soldiers rather than relying on the specialists within the Army’s array of colleges and research centers who have traditionally written the manuals. “For a couple hundred years, the Army has been writing doctrine in a particular way, and for a couple months, we have been doing it online in this wiki,” said Col. Charles J. Burnett, the director of the Army’s Battle Command Knowledge System. “The only ones who could write doctrine were the select few. Now, imagine the challenge in accepting that anybody can go on the wiki and make a change — that is a big challenge, culturally.” Under the three-month pilot program, the current version of each guide can be edited by anyone around the world who has been issued the ID card that allows access to the Army Internet system. About 200 other highly practical field manuals that will be renamed Army Tactics, Techniques and Procedures, or A.T.T.P., will be candidates for wikification. As is true with Wikipedia, those changes will appear immediately on the site, though there is a team assigned to each manual to review new edits. Unlike Wikipedia, however, there will be no anonymous contributors. http://www.nytimes.com/2009/08/14/business/14army.html?hp










**** NOTED PODCASTS ****
GOOGLE BOOK SEARCH SETTLEMENT (Google’s Alex Macgillivray at Berkman, 21 July 2009) - The proposed Google Book Search settlement creates the opportunity for unprecedented access by the public, scholars, libraries and others to a digital library containing millions of books assembled by major research libraries. But the settlement is controversial, in large part because this access is limited in major ways: instead of being truly open, this new digital library will be controlled by a single company, Google, and a newly created Book Rights Registry consisting of representatives of authors and publishers; it will include millions of so-called “orphan works” that cannot legally be included in any competing digitization and access effort, and it will be available to readers only in the United States. Alexander Macgillivray, Deputy General Counsel for Products and Intellectual Property at Google (and soon to be General Counsel of Twitter) chats about the Google Book Search Settlement, its intricacies, pros, and cons, and responds to provocative questions and comments. [Editor: ONE STAR] http://blogs.law.harvard.edu/mediaberkman/2009/07/21/alexander-macgillivray-of-google-on-the-google-book-search-settlement-audio/

**** DIFFERENT ****
WHAT’S IN A WORD? (Newsweek, 9 July 2009) - When the Viaduct de Millau opened in the south of France in 2004, this tallest bridge in the world won worldwide accolades. German newspapers described how it “floated above the clouds” with “elegance and lightness” and “breathtaking” beauty. In France, papers praised the “immense” “concrete giant.” Was it mere coincidence that the Germans saw beauty where the French saw heft and power? Lera Boroditsky thinks not. A psychologist at Stanford University, she has long been intrigued by an age-old question whose modern form dates to 1956, when linguist Benjamin Lee Whorf asked whether the language we speak shapes the way we think and see the world. If so, then language is not merely a means of expressing thought, but a constraint on it, too. Although philosophers, anthropologists, and others have weighed in, with most concluding that language does not shape thought in any significant way, the field has been notable for a distressing lack of empiricism—as in testable hypotheses and actual data. That’s where Boroditsky comes in. In a series of clever experiments guided by pointed questions, she is amassing evidence that, yes, language shapes thought. The effect is powerful enough, she says, that “the private mental lives of speakers of different languages may differ dramatically,” not only when they are thinking in order to speak, “but in all manner of cognitive tasks,” including basic sensory perception. “Even a small fluke of grammar”—the gender of nouns—”can have an effect on how people think about things in the world,” she says. http://www.newsweek.com/id/205985 [Editor: fascinating; I’ve often thought that language might channel thought.]

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
A PIECE OF SOFTWARE IS A JOY FOREVER: LINUX WINS ART PRIZE -- The top prize in the “.net” category of the prestigious international electronic-art competition Prix Ars Electronica has been awarded not to a beautiful Web page but to the Linux operating system created by Finnish programmer Linus Torvalds in 1991 and developed by scores of volunteer software developers contributing refinements to the code. Torvalds will receive the $8,260 prize. The judge says the selection of Linux was intended to send a message that “that the real material of the Web is the code” and to emphasize the Internet’s essential ability to establish online communities.” (New York Times 1 Jun 99)


************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.