Saturday, January 01, 2011

MIRLN --- 12-31 December 2010 (v13.18)


(supplemented by related Tweets: http://twitter.com/vpolley #mirln)

·      Website Privacy Policies - An Extensive Primer
·      Judges Can Have Facebook Friends, with ‘Constant Vigil,’ Says Ohio Supreme Court Board
·      Military Bans Disks, Threatens Courts-Martial to Stop New Leaks
o   Congressional Research Service Analysts Complaining About Blocked Access To Wikileaks
·      Protect Your Pre-1997 IP Address
·      EFF Victory: Appeals Court Holds that Email Privacy Protected by Fourth Amendment
·      A Mixed Ninth Circuit Ruling in MDY v. Blizzard: WoW Buyers Are Not Owners – But Glider Users Are Not Copyright Infringers
·      9th Circuit Rules Victims Needn’t Show ‘Misuse’ of Stolen Personal Data
·      UK’s Information Commissioner’s Office Issues First Data Breach Fines
·      A Magistrate Judge Correctly Ruled That A Youtube.Com User Waived The Attorney-Client Privilege By Recounting On Her Blog And In E-Mail Her Discussions With Her Attorneys
·      AMA Challenges E-Prescription Penalties
·      Vendors form ‘Legal Cloud Computing Association
·      Your Apps Are Watching You
·      The Report of Current Opinions
·      Updates to Twitter Allowed in British Courts
·      Social Media or Snake Oil: Does Social Media Measure Up to the Hype?
·      NIST Outlines An Organizational-Level Approach To Continuous Monitoring
·      Nebraska Rolls Out Free Docket App
·      Court Rejects Plaintiff’s Proposal of Class Notice via Twitter, SMS, and Email -- Jermyn v. Best Buy
o   Man Divorces Wife By SMS
·      VA Employees Using Unauthorized Cloud Services
·      Financial Industry Favors Security Through Obscurity; Demands Cambridge Censor Paper Detailing Weaknesses
·      Data Hacker Pageranks Members of the US Congress
·      First Amendment Rights To Blog A Case
·      E-Lawyering Expert: Stay Competitive With a Virtual Law Practice
·      NOAA Launches Website Housing Previously Released Public Information from the Deepwater Horizon Response
·      Email ‘Oops’ Ends With Gordon & Rees Being Booted From Case
·      MERS: How a Mortgage Clearinghouse Became a Villain in the Foreclosure Mess

PODCASTS | RESOURCES | LOOKING BACK | NOTES

Website Privacy Policies - An Extensive Primer..... (Foley Hoag, 1 Dec 2010) - If your start-up’s website will collect user information.... and chances are it will, you need to start thinking about your website privacy policy. I have often spoken with founders who think that the website privacy policy is a “one size fits all, grab an example from a well know e-retailer or established company web-site that appears to have a similar business model, snip here, paste there and you’re all set” deal. My wide eyed stare of horror in reaction to this is mostly dismissed as symptomatic of the overly cautious view of life that seemingly plagues my profession. I have discussed this with a colleague Patrick Connolly and he had the great idea to write a primer on the issue of Privacy Policies for websites. Now let me warn you, Patrick’s primer is not short and it isn’t meant to be because it highlights the issues that we step through and the risks and possible reprisals that we consider when we draft a privacy policy for a particular start-up. So without further ado, here’s Patrick’s well thought out “Primer on the Website Privacy Policies”, hopefully once your done reading you’ll agree that your privacy policy is not something to be taken lightly. http://www.securityprivacyandthelaw.com/2010/12/articles/retail-customer-information-sp/website-privacy-policies-an-extensive-primer/#page=1 [Editor: Provides a useful framework to begin to work thru the issues; this is one of my three practice areas, too.]

Judges Can Have Facebook Friends, with ‘Constant Vigil,’ Says Ohio Supreme Court Board (ABA Journal, 8 Dec 2010) - An Ohio judge is allowed to have Facebook friends, the Board of Commissioners on Grievances and Discipline of the state’s top court held today. But doing so requires “constant vigil,” the board says in its written opinion, because “a judge must maintain dignity in every comment, photograph and other information shared on the social network,” reports the Associated Press. They also have to be careful to avoid bias and can’t gather evidence for cases from social media sites. A state supreme court press release provides additional details and links to a copy of the Dec. 3 opinion. http://www.abajournal.com/news/article/ohio_judges_can_have_facebook_friends_with_constant_vigil_says_state_suprem?utm_source=maestro&utm_medium=email&utm_campaign=tech_monthly

Military Bans Disks, Threatens Courts-Martial to Stop New Leaks (Wired, 9 Dec 2010) - It’s too late to stop WikiLeaks from publishing thousands more classified documents, nabbed from the Pentagon’s secret network. But the U.S. military is telling its troops to stop using CDs, DVDs, thumb drives and every other form of removable media — or risk a court martial. Maj. Gen. Richard Webber, commander of Air Force Network Operations, issued the Dec. 3 “Cyber Control Order” — obtained by Danger Room — which directs airmen to “immediately cease use of removable media on all systems, servers, and stand alone machines residing on SIPRNET,” the Defense Department’s secret network. Similar directives have gone out to the military’s other branches. It’s one of a number of moves the Defense Department is making to prevent further disclosures of secret information in the wake of the WikiLeaks document dumps. Pfc. Bradley Manning says he downloaded hundreds of thousands of files from SIPRNET to a CD marked “Lady Gaga” before giving the files to WikiLeaks. To stop that from happening again, an August internal review suggested that the Pentagon disable all classified computers’ ability to write to removable media. About 60 percent of military machines are now connected to a Host Based Security System, which looks for anomalous behavior. And now there’s this disk-banning order. One military source who works on these networks says it will make the job harder; classified computers are often disconnected from the network, or are in low-bandwidth areas. A DVD or a thumb drive is often the easiest way to get information from one machine to the next. “They were asking us to build homes before,” the source says. “Now they’re taking away our hammers.” http://www.wired.com/dangerroom/2010/12/military-bans-disks-threatens-courts-martials-to-stop-new-leaks/

- and -

Congressional Research Service Analysts Complaining About Blocked Access To Wikileaks (Techdirt, 15 Dec 2010) - With the Library of Congress blocking access to Wikileaks over some misguided notion of what its legal responsibilities are, Copycense points us to a report about how librarians across the nation are now arguing over whether or not this was the right move, with many feeling that it was decidedly a bad move. However, perhaps more interesting is the claim, in the middle of the article, that analysts at the Congressional Research Service are negatively impacted by this as well: “Since the Congressional Research Service is a component of the Library, this means that CRS researchers will be unable to access or to cite the leaked materials in their research reports to Congress. Several current and former CRS analysts expressed perplexity and dismay about the move, and they said it could undermine the institution’s research activities. It’s a difficult situation,” one unidentified CRS analyst told Aftergood. “The information was released illegally, and it’s not right for government agencies to be aiding and abetting this illegal dissemination. But the information is out there. Presumably, any Library of Congress researcher who wants to access the information that WikiLeaks illegally released will simply use their home computers or cell phones to do so. Will they be able to refer directly to the information in their writings for the Library? Apparently not, unless a secondary source, like a newspaper, happens to have already cited it.” http://www.techdirt.com/articles/20101213/01240212254/congressional-research-service-analysts-complaining-about-blocked-access-to-wikileaks.shtml

Protect Your Pre-1997 IP Address (Computerworld, 10 Dec 2010) - If your company obtained its IP address space before 1997, you have probably received several letters from the American Registry for Internet Numbers Ltd. (ARIN) encouraging you to enter into a contractual agreement to protect the IP address. But should you sign it? ARIN’s contract is called the Legacy Registration Services Agreement (Legacy RSA). It proposes to give companies contractual guarantees, including grandfathering of certain protected rights; continued use -- at no extra charge, at least for now -- of IP address services like “in-addr” and “whois” listings; reduced annual fees compared with those of ARIN’s regular IP address holders; and future fee waivers, in exchange for returning unused IP address space. But be careful -- there are several issues you should consider before signing up for this. Registrants that obtained IP addresses directly from ARIN after 1997 entered into service agreements that fall under ARIN’s jurisdiction, and are therefore subject to ARIN’s resource utilization policies. But it is unclear whether IP address registrations of legacy IP address holders -- those that happened before 1997 -- were ever formally transferred to ARIN. ARIN has never claimed that it has control over these legacy IP addresses, but at the same time, it has never conceded that it lacks the authority either. http://www.computerworld.com/s/article/9200359/Protect_your_pre_1997_IP_address [This is a fairly arcane area, often overlooked in M&A transactions, which involves something like chain-of-title issues: how to prove your “ownership” of an IP address block, acquired thru a M&A transaction years ago? With the looming exhaustion of IP4 address space, such issues are coming to the fore.]

EFF Victory: Appeals Court Holds that Email Privacy Protected by Fourth Amendment (EFF, 14 Dec 2010) - In a landmark decision issued today in the criminal appeal of U.S. v. Warshak, the Sixth Circuit Court of Appeals has ruled that the government must have a search warrant before it can secretly seize and search emails stored by email service providers. Closely tracking arguments made by EFF in its amicus brief, the court found that email users have the same reasonable expectation of privacy in their stored email as they do in their phone calls and postal mail. EFF filed a similar amicus brief with the 6th Circuit in 2006 in a civil suit brought by criminal defendant Warshak against the government for its warrantless seizure of his emails. There, the 6th Circuit agreed with EFF that email users have a Fourth Amendment-protected expectation of privacy in the email they store with their email providers, though that decision was later vacated on procedural grounds. Warshak’s appeal of his criminal conviction has brought the issue back to the Sixth Circuit, and once again the court has agreed with EFF and held that email users have a Fourth Amendment-protected reasonable expectation of privacy in the contents of their email accounts. http://www.eff.org/deeplinks/2010/12/breaking-news-eff-victory-appeals-court-holds Opinion here: http://www.eff.org/files/warshak_opinion_121410.pdf

A Mixed Ninth Circuit Ruling in MDY v. Blizzard: WoW Buyers Are Not Owners – But Glider Users Are Not Copyright Infringers (EFF, 14 Dec 2010) - The Ninth Circuit today issued its decision in the second of a trio of cases that raise the critical legal question of whether “magic words” in a end-user license agreement (EULA) slapped onto a consumer product can turn buyers (or gift recipients) into mere licensees, rather than owners. Following its previous ruling in the first of these cases, Vernor v. Autodesk, the court today said yes — but there’s a twist. The case (which we’ve covered previously) pits Blizzard, the maker of World of Warcraft, against MDY, the maker of a program called Glider (what Blizzard calls a “bot”) that lets you play WoW on “auto-pilot” up to a certain level. Blizzard won in the district court, successfully arguing that WoW purchasers do not “own” their software, but merely “license” it. On this dystopian view, Blizzard owns every WoW DVD ever shipped for all eternity and may be able to use copyright law to punish WoW players who use the software in any manner not authorized by the “license” (like using Glider). The district court agreed, and MDY appealed. Ownership matters, because otherwise Blizzard and other software vendors can wipe away important consumer rights with legalese contained in license agreements. In September, the Ninth Circuit held that buyers of software (and possibly DVDs, CDs and other “licensed” content) are not owners as long as the vendor saddles the transfer with enough restrictions to transform what the buyer may think is sale into a mere license. Today, in yet another blow to user rights, the Ninth Circuit ruled that Blizzard’s license restrictions for WoW accomplish the same purpose. However, the court also held that using Glider in WoW play in violation of Blizzard’s terms did not amount to copyright infringement. Blizzard had argued that MDY was secondarily liable for copyright infringement because it provided software that allowed users to play in unauthorized ways. Not so, said the appellate court, because there was no direct liability to begin with. The license term that forbade WoW players from using Glider was a covenant — a promise not to do something — rather than a condition — limiting the scope of the copyright license. And while violating “antibot” covenants might breach a contract, it does not violate any copyright. (By contrast, creating a derivative work might.) This point may seem a bit arcane, but it’s crucial because it helps avoid a situation in which violating contracts and EULAs could result in a copyright infringement lawsuit (with the heavy club of statutory damages, attorney’s fees and low standards for injunctions) rather than just a simple breach of contract claim. http://www.eff.org/deeplinks/2010/12/mixed-ninth-circuit-ruling-mdy-v-blizzard-wow

9th Circuit Rules Victims Needn’t Show ‘Misuse’ of Stolen Personal Data (FPN, 15 Dec 2010) - Employees didn’t need to show misuse of their personal information in order to sue their employer over alleged negligence in allowing its theft, the 9th Circuit has ruled in affirming judgment. The plaintiffs are 97,000 current and former Starbucks employees whose names, addresses, and Social Security numbers were stored on a company laptop that was stolen. The plaintiffs filed a class action against Starbucks for the loss of their personal information, asserting negligence and breach of contract. Starbucks argued that, because none of the plaintiffs could show that their personal information was actually misused, they could not establish sufficient injury for purposes of standing under Article III of the Constitution. But the court concluded that an increased risk of identity theft satisfies Article III standing requirements. “If a plaintiff faces ‘a credible threat of harm,’ and that harm is ‘both real and immediate, not conjectural or hypothetical,’ the plaintiff has met the injury-in-fact requirement for standing under Article III. Here, [plaintiffs] have alleged a credible threat of real and immediate harm stemming from the theft of a laptop containing their unencrypted personal data,” the court said. U.S. Court of Appeals, 9th Circuit. Krottner v. Starbucks Corp., No. 09-35823. Dec. 14, 2010. Lawyers USA No. 993-2514. http://fpn.advisen.com/articles/article134418124682987552.html?elq_mid=12209&elq_cid=996107

UK’s Information Commissioner’s Office Issues First Data Breach Fines (Steptoe’s E-Commerce Law Week, 16 Dec 2010) - Until recently, the UK’s Information Commissioner’s Office (ICO) had more bark than bite when it came to data protection. The extent of its powers was issuing enforcement notices and bringing court cases against violators of the Data Protection Act 1998. But earlier this year, as we reported, the ICO was authorized to issue monetary penalties up to ₤500,000 for individual data security breaches. And now the ICO has exercised that new power, issuing two fines totaling ₤160,000 for data breaches. Both fines were for failures to properly safeguard private and sensitive information. The ICO noted that both violators failed to take even the most basic steps to protect the information; one of the cases turned largely on the fact that the employer had failed to put encryption on a laptop that an employee used to work from home. http://www.steptoe.com/publications-7299.html

A Magistrate Judge Correctly Ruled That A Youtube.Com User Waived The Attorney-Client Privilege By Recounting On Her Blog And In E-Mail Her Discussions With Her Attorneys (CCH’s Guide to Computer Law, 16 Dec 2010; subscription required) - The user argued that her comments regarding “her counsel’s motives for representing her pro bono” did not waive the attorney-client privilege with respect to her own motivations for filing suit. However, the two subjects were closely intertwined and could not easily be separated. The user also contended that she was mistaken when she stated that her case was “not a ‘fair use’ case at all,” based on conversations with her attorneys A party may not attempt to explain an apparent admission as a misinterpretation of a conversation with counsel, and then deny the opposing party on the basis of privilege access to the very conversations at issue. When a client reveals to a third party that something is “what my lawyer thinks,” she cannot avoid discovery on the basis that the communication was confidential. Lenz v. Universal Music Corp., NDCal

AMA Challenges E-Prescription Penalties (Information Week, 16 Dec 2010) - The American Medical Association and 103 state and specialty medical societies have sent a letter to Kathleen Sebelius, secretary for the Department of Health and Human Services, requesting that the Centers for Medicare & Medicaid Services (CMS) change its e-prescribing penalty requirements, which will create a financial burden on physicians, the letter said. The request was prompted by a change in the e-prescribing policy that CMS published in the 2011 Final Fee Schedule Rule, which introduced a provision requiring a physician to report at least ten instances of using e-prescriptions for Medicare office visits and services between January 1, 2011 through to June 30, 2011. If physicians don’t meet these requirements, they will face penalties in 2012 and 2013. http://www.informationweek.com/news/healthcare/policy/showArticle.jhtml?articleID=228800678&cid=RSSfeed_IWK_News

Vendors form ‘Legal Cloud Computing Association (Robert Ambrogi, 17 Dec 2010) - Four companies that offer legal-oriented products and services through the cloud have banded together to form the Legal Cloud Computing Association. LCCA’s purpose, according to its announcement, “is to promote standards for cloud computing that are responsive to the needs of the legal profession and to enable lawyers to become aware of the benefits of computing technology through the development and distribution of education and informational resources.” The four companies that make up LCCA’s founding membership are:
Clio (Themis Solutions Inc.)
DirectLaw, Inc.
Rocket Matter LLC
Total Attorneys, LLC
As its first official act as an organization, the LCCA published its comments on the ABA Commission on Ethics 20/20 paper concerning lawyers’ use of Internet-based client-development tools (PDF). With regard to cloud computing, the LCCA proposes that the ABA endorse a minimal set of standards for cloud-computing providers along with model terms of service for cloud providers. Those minimal standards, the LCCA says, should cover data-center security, network security, software security, data-transmission security, back-ups and redundancy, confidentiality and privacy, and data portability. http://www.lawsitesblog.com/2010/12/vendors-form-legal-cloud-computing-association.html

Your Apps Are Watching You (WSJ, 18 Dec 2010) - Few devices know more personal details about people than the smartphones in their pockets: phone numbers, current location, often the owner’s real name—even a unique ID number that can never be changed or turned off. These phones don’t keep secrets. They are sharing this personal data widely and regularly, a Wall Street Journal investigation has found. An examination of 101 popular smartphone “apps”—games and other software applications for iPhone and Android phones—showed that 56 transmitted the phone’s unique device ID to other companies without users’ awareness or consent. Forty-seven apps transmitted the phone’s location in some way. Five sent age, gender and other personal details to outsiders. The findings reveal the intrusive effort by online-tracking companies to gather personal data about people in order to flesh out detailed dossiers on them. Apps sharing the most information included TextPlus 4, a popular iPhone app for text messaging. It sent the phone’s unique ID number to eight ad companies and the phone’s zip code, along with the user’s age and gender, to two of them. Both the Android and iPhone versions of Pandora, a popular music app, sent age, gender, location and phone identifiers to various ad networks. Smartphone users are all but powerless to limit the tracking. With few exceptions, app users can’t “opt out” of phone tracking, as is possible, in limited form, on regular computers. On computers it is also possible to block or delete “cookies,” which are tiny tracking files. These techniques generally don’t work on cellphone apps. http://online.wsj.com/article/SB10001424052748704694004576020083703574602.html?mod=WSJ_Tech_RightMostPopular

The Report of Current Opinions (O’Reilly Radar, 19 Dec 2010) - Public.Resource.Org will begin providing in 2011 a weekly release of the Report of Current Opinions (RECOP). The Report will initially consist of HTML of all slip and final opinions of the appellate and supreme courts of the 50 states and the federal government. The feed will be available for reuse without restriction under the Creative Commons CC-Zero License and will include full star pagination. This data is being obtained through an agreement with Fastcase, one of the leading legal information publishers. Fastcase will be providing us all opinions in a given week by the end of the following week. We will work with our partners in Law.Gov to perform initial post-processing of the raw HTML data, including such tasks as privacy audits, conversion to XHTML, and tagging for style, content, and metadata. The RECOP feed will be treated as an open source project with revision control, multiple commiters [commentors?], open discussion lists, and perhaps even multiple branches. Law.Gov participants include both for-profit organizations such as Justia and Fastcase and academic institutions such as Princeton, Cornell, and Stanford. We welcome additional participants from both communities. More details will be made available in mid-January on the Law.Gov mailing list. n addition to weekly release of all current opinions, this feed will include periodic releases of important segments of the back file, including:
·      A release of 3 million pages of 9th Circuit briefs from 1892 to 1968 which was produced in cooperation with UC Hastings College of the Law and the Internet Archive and is scheduled for release in Q1 2011.
·      Double-keyed HTML for at least the first 10 volumes of the Federal Reporter, First Series and all 30 volumes of the Federal Cases will be completed by the end of Q2 2011. This data is being furnished as part of the YesWeScan Project. Now, you too can give the gift that you can cite forever.
·      William S. Hein & Co., which provided high-resolution scans of the Federal Cases, is providing a high-resolution scan of the Federal Reporter, First Series which will be released in Q1 2011.
We are actively pursuing several other important archives that are missing such as Supreme Court Briefs, multiple versions of the annotated statutes of the 50 states, and other key collections. We would welcome the contribution of any legal publishers wishing to furnish such data. http://radar.oreilly.com/2010/12/the-report-of-current-opinions.html

Updates to Twitter Allowed in British Courts (NYT, 20 Dec 2010) - The head of the judiciary in England and Wales ruled on Monday that reporters and other observers can send updates to Twitter and other short text messages from courtrooms while trials are in session so long as the messages do not impede the judicial process. The interim decision, meant to guide courts in his jurisdiction, came a week after an appeals court judge in London barred those present at a bail hearing for Julian Assange, the WikiLeaks founder, from posting messages to Twitter. “There is no statutory prohibition on the use of live text-based communications in open court,” the judicial head, Lord Chief Justice Igor Judge, found in the Monday ruling. (The full text of the ruling is embedded at the end of this post.) “But before such use is permitted, the court must be satisfied that its use does not pose a danger of interference to the proper administration of justice in the individual case.” While cameras and sound recording equipment remain prohibited, live text updates to social networks are “unobtrusive” and “virtually silent” and therefore “unlikely to interfere with the proper administration of justice,” he wrote. Because most courtrooms require that mobile phones and other devices be switched off during proceedings, reporters or others present for the trial must ask for an exception for the purpose of sending live messages via Twitter and other text-based services. Judges can decide, however, to limit such updates. Criminal cases may be particularly sensitive, the chief justice wrote, though reporters may also be prevented from using text devices during civil trials as well, especially in situations where the posting of information could pressure or distract a future witness. In the United States, state and federal courts have taken varied approaches to Twitter. In Georgia district court last year, a federal judge denied a journalist’s request to use his Blackberry mobile phone in court to post messages, citing a federal rule that prohibits the “broadcasting” of proceedings. But a court in Connecticut allowed Twitter updates during the heavily publicized murder trial of Steven J. Hayes. In that case, defense lawyers appeared to set the grounds for a possible appeal, arguing that tens of thousands of messages had been sent from the courtroom, creating a carnival atmosphere and denying Mr. Hayes a fair trial. http://thelede.blogs.nytimes.com/2010/12/20/updates-to-twitter-allowed-in-british-courts/?scp=1&sq=twitter%20judiciary%20assange%20london&st=cse Ruling here: http://www.scribd.com/doc/45696935/Ruling-on-Twitter-in-Courts

Social Media or Snake Oil: Does Social Media Measure Up to the Hype? (ABA Journal, 2010) - Is the social media phenomenon overhyped? A growing chorus of voices says yes. Critics argue there are no credible ways to measure return on investment in social media. They also contend there’s no definitive data showing that social media create business, or that the number of followers you have on Twitter or friends on Face book translates into dollars earned. The conundrum is that both the cynics and the cheerleaders may be right. Kevin O’Keefe, CEO and publisher of Seattle-based Lexblog, which provides social media consulting to law firms, says he does think there is too much hype about social media. “There are a lot of people who don’t know what they’re talking about creating a buzz about it. It’s terribly effective, but that doesn’t mean it’s not overhyped.” Perhaps the most overhyped metric of social media is the gross number of participants. Consultants waxing on about the value of social media start with Facebook’s 500 million active users and Twitter’s 190 million monthly visitors. Yet tallies of friends on Facebook and followers on Twitter mean little. If you’re hunting for hard numbers on social media value, you may be searching for fool’s gold. Social media isn’t about statistics. It’s about good, old-fashioned relationship building. “Numbers on your return on investment are meaningless,” says Daniel Harris of Harris & Moure in Seattle and author of the China Law Blog. “It’s like saying if you speak at a seminar, what’s the return? You never know in hard numbers, but you do know when someone calls six months later and says, ‘I heard you speak. We have this matter.’” http://www.abajournal.com/mobile/article/social_media_or_snake_oil?utm_source=maestro&utm_medium=email&utm_campaign=tech_monthly [Editor: you tell me; you’re reading this, after all.]

NIST Outlines An Organizational-Level Approach To Continuous Monitoring (GCN, 21 Dec 2010) - Effective IT security requires a top-down approach, with strategic planning at the organizational level rather than on a system-by-system basis, the National Institute of Standards and Technology says in newly released draft guidelines for continuous monitoring. Many, if not all, of an agency’s IT systems are mission-critical these days, and periodic snapshots of their status do not provide adequate assurance of security, according to the initial public draft of Special Publication 800-137, Information Security Continuous Monitoring for Federal Information Systems and Organizations.” Continuous monitoring to assess security status and enable incident response is now the standard for security assessment and maintenance. “Information security is a dynamic process that must be effectively managed to respond to new vulnerabilities, evolving threats and an organization’s constantly changing enterprise architecture and operational environment,” the publication states. The publication offers guidelines on the development of a continuous monitoring strategy and the implementation of a program based on that strategy. The program should provide visibility into assets and an awareness of threats and vulnerabilities to the system, and expose the effectiveness of security controls being used. It also should allow the organization to determine if the security controls are aligned properly with its risk tolerance and help the organization respond if it finds that security controls are not adequate. http://gcn.com/articles/2010/12/21/nist-continuous-monitoring.aspx

Nebraska Rolls Out Free Docket App (ABA Journal, 21 Dec 2010) - Attorneys and judges in Nebraska have been able to use a searchable online court calendar for several years. But since this past fall they’ve had something a lot more slick for finding court dates: an app. Last September the state of Nebraska authorized and created a free state court docket app for the iPhone and its progeny. Nebraska appears to be the only state, so far, to have created such an app. The app makes most district and all county court hearing schedules searchable by day, time and location in real time. During its first month, the app was downloaded over 150 times, says Jennifer Rasmussen, project manager at Nebraska.gov, the state portal site that handled the programming. There haven’t been any comments posted about it on iTunes, but Rasmussen figures the audience could widen considerably, with about 6,500 attorneys in the state—maybe half of them trial lawyers. http://www.abajournal.com/magazine/article/icourt_application_iphone?utm_source=maestro&utm_medium=email&utm_campaign=tech_monthly

Court Rejects Plaintiff’s Proposal of Class Notice via Twitter, SMS, and Email -- Jermyn v. Best Buy (Eric Goldman, 22 Dec 2010) - Plaintiffs brought a class action against Best Buy alleging that Best Buy failed to honor its price-match guarantee. The court certified the class with respect to New York residents who had bought certain items from Best Buy since 2002 and who were denied Best Buy’s price guarantee. The named plaintiff suggested several forms of notice to potential class members, including notification via: (1) Best Buy’s “Twelpforce“ Twitter account, (2) SMS, and (3) email. Noting that overinclusive individual notice is not required, and that Best Buy is only required to undertake “reasonable steps” to identify individual affected class members, the court rejects all three suggestions. The court conducted a random sample of Best Buy’s “Tweplforce” account and concluded that it was primarily a medium for providing technical support to customers. As with respect to the suggested notice via Twitter, the court accepts Best Buy’s argument that notice via SMS was overinclusive, based on Best Buy’s argument. The proposed email notice suffered the same fate, since Best Buy was “unable to restrict notice via email to only class members . . . [it] only collected customer emails when a customer makes a purchase on bestbuy.com; when a customer obtains a protection or service plan for an item purchased at bestbuy.com or at a Best Buy store; or when a customer voluntarily shares her email address when visiting bestbuy.com.” The court’s treatment of Twitter as an form of individual notice was interesting, and not entirely accurate. Tweets are not “individualized messages” in the sense that the list of recipients is not controlled by the sender (there’s not a finite list) - the list of recipients includes people who follow the general stream of Tweets as well as those who have opted in to receive messages. Additionally, tweets can be disseminated further by those who see initial tweets, increasing the odds that the word would get out to its intended audience. It’s also worth noting that the “Twelpforce” account is not Best Buy’s only Twitter account. For some reason, plaintiff didn’t suggest notice via Best Buy’s main account, which has approximately 123,000 followers. Given that the costs involved in disseminating notice via Twitter are de minimis, I’m surprised the court wasn’t more open to the suggestion. Also, I was surprised that neither party brought up Facebook as a possibility. Best Buy’s Facebook page is approaching 2 million followers, and offers a similarly inexpensive way to get the notice out to a broad group of interested people. I would think Best Buy’s resistance stems from not wanting to suffer any negative branding implications from including news of this class action in its overt marketing channels, but I would have thought the minimal cost would have swayed the court. http://blog.ericgoldman.org/archives/2010/12/court_rejects_p.htm

- but -

Man Divorces Wife By SMS (Emirates24, 25 Dec 2010) - A Saudi court decided to separate a national couple after the husband sent a SMS to his wife mobile phone telling her that she is divorced, a newspaper in the Gulf Kingdom reported on Saturday. The woman from the western town of Madina asked court to officially endorse her divorce and supported its complaint with the SMS from her husband, the online Arabic language daily Anakum said. “The husband told the judge he sent the message after an argument with his wife but that he did not mean to divorce her,” the paper said. “But the judge considered the SMS as a real divorce under Islam and decided to support the wife’s plea for divorce.” http://www.emirates247.com/news/region/man-divorces-wife-by-sms-2010-12-25-1.333715

VA Employees Using Unauthorized Cloud Services (Information Week, 23 Dec 2010) - The Obama administration might be pushing federal agencies to adopt cloud computing, but federal workers are already ahead of the curve, as the Department of Veterans Affairs recently discovered when it found out hospital employees were using Web-based tools from companies like Google and Yahoo on the job. The discovery isn’t shocking -- consumer adoption of cloud services has in many ways outstripped corporate and government adoption -- but it does raise security concerns, as the services being used haven’t necessarily gone through the rigorous certification process required to comply with federal cybersecurity guidelines. “The government can’t keep up with Google, Apple, Yahoo, and others who are creating grey apps for healthcare usage,” VA CIO Roger Baker said Thursday on a monthly cybersecurity conference call with reporters. “This is an issue we’re going to continue to deal with going forward. These are great tools for patient care, but at the same time we can’t use them. If we don’t figure out how to embrace them, our users will figure it out without us.” Baker applauded companies like Google for moving forward with government security certifications for “moderate” risk information, but said that the VA requires even higher security standards for personally identifiable information like the type its employees are beginning to store online. For now, the agency is treating the use of services like these as a security concern, and blocking access to sites as they became known. For example, last month the agency discovered that a few orthopedics department residents at the Jesse Brown VA Medical Center have been keeping a calendar of patient data on Yahoo Calendar for more than three years. The residents had stored full names, dates, types of surgery, and the last four digits of Social Security numbers for 878 patients on the site, sharing the same user account. When the VA discovered this, it blocked access to the site, deleted all the entries, changed the password (which hadn’t been changed once during the three years of use), and began mailing out letters of notification to all affected patients. Such a scenario has played out numerous times in recent months, Baker said. The most popular use of cloud services was by employees using Google Docs to store shift-change information and residents using it to document what type of role they played in various procedures. “While these are password-protected accounts, the issue is that they leave the VA,” Baker said. “We need to figure out how to meet this demand and still meet our requirements from the standpoint of security controls.” http://www.informationweek.com/news/government/cloud-saas/showArticle.jhtml?articleID=228900122&cid=RSSfeed_IWK_All

Financial Industry Favors Security Through Obscurity; Demands Cambridge Censor Paper Detailing Weaknesses (TechDirt, 27 Dec 2010) - The chip and PIN system that is used for financial transactions throughout large parts of Europe and Canada (still surprised that it hasn’t really come to the US...) has numerous vulnerabilities that have been detailed over the years. In the past year alone, there have been a number of problems and weaknesses highlighted with the system. Apparently, the financial industry isn’t happy about this, but rather than fixing the problems it’s reacting in the usual way: going after the messenger. Slashdot points us to the news that the UK Cards Association -- a trade group representing banks and credit card companies -- has asked Cambridge researchers to remove a thesis which highlights some of the vulnerabilities. You can see the demand letter embedded below, but it’s fairly amusing. The letter claims that the publication (which you can read about on the author’s (Omar Choudary) website, where he describes a device for intercepting, monitoring and modifying such data) “oversteps the boundaries of what constitutes responsible disclosure.” In other words, they’re not happy about it, so Cambridge should force the student to shut up. Of course, what’s amusing is that after chiding Cambridge University for such irresponsible publishing, the Association then tries to downplay the significance of the whole thing anyway: “Fortunately, the type of attack described in the research is difficult to undertake and is unlikely to carry a sufficient risk-reward ratio to interest genuine fraudsters. And, in the unlikely event that such an attack were to take place in the UK marketplace, the banking industry’s fraud prevention systems would be able to detect when such an attack had happened.” http://www.techdirt.com/articles/20101225/23212712406/financial-industry-favors-security-through-obscurity-demands-cambridge-censor-paper-detailing-weaknesses.shtml

Data Hacker Pageranks Members of the US Congress (ReadWriteWeb, 27 Dec 2010) - What’s the fastest way to evaluate the true behavior of a Senator or Representative in Congress? How about through a ready-made mathematical model and some charts? That’s what Josh Tauberer has created as the latest project at congress-tracking site GovTrack.us. “Bulk access to legislative information makes large-scale statistical analyses possible,” Tauberer writes. He’s performed analyses he says are like Google’s Pagerank, but for politicians: he’s tracked which politicians vote together in order to discover moderates and extremists, and he’s treated sponsorship and co-sponsorship of legislation like an endorsement of leadership, similar to the way Google treats links between web pages as an endorsement. The resulting chart, below, tracks Senate members on axis of leadership and ideology. It’s a fascinating way to see important qualitative matters quantified and to get a quick snapshot of politicians you might not follow very closely. Something like this could also be helpful in assessing claims and pushing for accountability of elected officials. http://www.readwriteweb.com/archives/data_hacker_pageranks_members_of_the_us_congress.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+readwriteweb+%28ReadWriteWeb%29&utm_content=Google+Reader

First Amendment Rights To Blog A Case (Cobalt Law Firm, 28 Dec 2010) – “Dear Mr. Olson -- We are in receipt of your letter (below) in which you demand that we cease or you will sue. We are a law firm; and we are reporting news in our blog. Clearly is that stated under the category on ‘News’ as you acknowledge in paragraph two of your letter. We acknowledge that your client has trademark rights. However, protection for trademark rights under the Lanham Act is limited to protection against another’s use of a designation to identify its business, or in marketing its goods or services in a way that causes a likelihood of confusion. Such trademark rights do not override First Amendment rights.” http://www.cobaltlaw.com/news/first-amendment-rights-to-blog-a-case Of course, this has now been picked up by TechDirt -- http://www.techdirt.com/articles/20101229/03133712447/when-sending-bogus-tm-cd-dont-send-it-to-lawyer-who-understand-tm-law.shtml

E-Lawyering Expert: Stay Competitive With a Virtual Law Practice (ABA Journal, 28 Dec 2010) - More clients than ever are seeking legal services online, and the market is growing every day with new competitors—online companies such as Legal Zoom, Inc. and “do it yourself” legal kits on the Internet, among them—that are challenging the dominance of the traditional law firm. Stephanie Kimbro, co-founder of Virtual Law Office software and a virtual law office owner, says in her book Virtual Law Practice that “mainstream legal professionals who have preferred to stick with more traditional law practice methods can no longer turn a blind eye to this change if they wish to remain competitive.” YourABA recently asked Kimbro to provide some guidance on establishing a virtual presence and best practices for effective e-lawyering. http://www.abanet.org/media/youraba/201012/article01.html

NOAA Launches Website Housing Previously Released Public Information from the Deepwater Horizon Response (NOAA, 29 Dec 2010) - NOAA today unveiled a web archive of the maps, wildlife reports, scientific reports and other previously released public information used by emergency responders, fishermen, mariners and local officials during the Deepwater Horizon oil spill. The NOAA Deepwater Horizon Library can be accessed via http://www.noaa.gov/deepwaterhorizon. “This website serves as a valuable learning tool and resource for scientists, students and historians of all backgrounds for many years to come,” said Jane Lubchenco, Ph.D., under secretary of commerce for oceans and atmosphere and NOAA administrator. “Good science underpins everything we do at NOAA, and our scientists worked tirelessly during the spill to monitor the oceans, coasts and skies. Much of that mission-critical information is now available in this library.” http://www.noaanews.noaa.gov/stories2010/20101229_dwh_library.html

Email ‘Oops’ Ends With Gordon & Rees Being Booted From Case (LegalPad, 29 Dec 2010) - It’s great the way email software autocompletes addresses for you. Except when it puts in the wrong one. That’s what happened to Braun Hagey partner J. Noah Hagey. But it wasn’t a total disaster, as it kicked off a chain of events that culminated last week with an eye-popping protective order (read it here) booting his opposing counsel and in-house lawyers off a case in federal court. Here’s what happened. Hagey represents a handful of engineers in Oakland who in September left engineering and design firm Arcadis to start their own shop. Apparently worried their former employer would try to interfere, they hired Braun Hagey and later conferred by email -- with autocomplete inserting an old Arcadis address for one of the former employees. So four message threads, including one attaching a draft declaration, were delivered to Arcadis, where an email monitoring system routed them to legal. In a declaration, Hagey said the plaintiffs didn’t realize their emails had been intercepted until lawyers at Gordon & Rees filed a counterclaim that references the day the former employees held a meeting -– a date, he said, Gordon & Rees could only have learned from the emails. Reached Wednesday, Hagey declined to comment publicly. In a declaration, Elizabeth Spangler, an inhouse lawyer at Arcadis, acknowledged receiving the threads and reviewing the draft complaint -- at which point she says she realized the material was probably privileged. She says, however, that there were no great revelations in the material, and she didn’t share it with anyone. She did say, though, that she must have inadvertently given Gordon & Rees the date on which the exiting employees met. She also said she later learned her boss, Arcadis’ General Counsel Steven Niparko, had also briefly reviewed the email. On Dec. 17, U.S. District Judge Jeffrey White ordered that Arcadis replace Gordon & Rees with new, untainted counsel. He also ordered Spangler off the case, and said the GC must be “removed from all aspects of the day-to-day management.” And he ordered Arcadis to pay fees and costs of $40,000. http://legalpad.typepad.com/my_weblog/2010/12/email-oops-ends-with-gordon-rees-being-booted-from-case.html [Editor: a possibly-unexpected outcome -- a risky way to contaminate opposing counsel.]

MERS: How a Mortgage Clearinghouse Became a Villain in the Foreclosure Mess (Washington Post, 31 Dec 2010) - In the early 1990s, the biggest names in the mortgage industry hatched a plan for a new electronic clearinghouse that would transform the home loan business - and unlock billions of dollars of new investments and profits. [A] central electronic clearinghouse would allow the companies to transfer thousands of mortgages instantaneously, greasing the wheels of a system in which loans could be repeatedly and quickly bought and sold. “Assignments are creatures of 17th-century real property law; they do not coexist easily with high-volume, late 20th-century secondary mortgage market transactions,” Phyllis K. Slesinger, then senior director of investor relations for the Mortgage Bankers Association of America, wrote in paper explaining the system. Sixteen years down the road, the mortgage business is a mess. The electronic clearinghouse has become a reality: The Virginia-based Mortgage Electronic Registrations Systems, a registry with 67 million mortgages on file, has become part of the industry’s standard operating procedure. But critics say promises of transparency and of ironing out wrinkles in record-keeping haven’t panned out. The firm, which tracks more than 60 percent of the country’s residential mortgages but whose parent company employs just 45 people in a Reston office building, is on the firing line now. * * * MERS became a stripped down version of the original idea. The first thing to go was the vault for keeping documents. MERS instead became a giant electronic card catalogue that tracked who was managing a particular loan as it was sold and resold, but it left the companies themselves responsible for guarding the mortgage (or deed of trust) and the promissory note (or IOU) - the two critical pieces of paper that prove who owns a loan. Next to go was transparency, critics say. When a home loan is securitized, at least a half-dozen parties are typically involved. The loan might be originated by a mortgage finance firm, sold to a company that aggregates them into a pool and then sells them to an investor such as a pension fund. A different “servicer” such as Bank of America is usually responsible for collecting payments. Most loans are bought and sold several times, and the servicer can change, too. The mortgage bankers decided that to simplify record-keeping, MERS would be listed as a “nominee” for the mortgage holder in local land records offices. When the loans changed hands, the new owner or servicer would register the transaction electronically in the MERS system without having to re-record the transaction across the country. But Mark Monacelli, a county recorder in Duluth, Minn., who was the lead negotiator for the association representing recorders from most of the nation’s 3,600 counties, said that practice makes it difficult for homeowners to be able to trace the chain of ownership of their loan. http://www.washingtonpost.com/wp-dyn/content/article/2010/12/30/AR2010123003056.html?hpid=topnews&sid=ST2010123003364 [Editor: Long article, interesting subject. Illustrates the tension between law and technology, and how things can go off the tracks when the tech/business side gets too far ahead of the law. This isn’t going to end prettily.]

**** NOTED PODCASTS ****
The Innovation Secrets of Steve Jobs (Carmine Gallo, 22 Nov 2010; 53 minutes) - Apple’s Steve Jobs has a reputation for innovation, particularly with Apple’s company slogan of “Think Different”. Carmine Gallo wrote a book that reviewed Jobs’ presentation secrets and now details his innovation secrets. Gallo discusses his book, including the seven points of innovation followed by Steve Jobs. Gallo also talks about the thought process that led to this follow-up to his previous successful book. [Editor: Gallo’s starts off a bit slick for my tastes, but he’s actually done a very useful job distilling and presenting here. These are extremely good points he makes, especially for younger people.] http://itc.conversationsnetwork.org/shows/detail4724.html

**** RESOURCES ****
Copyright for Internet Authors and Artists (Prof. Thomas Field, 16 Oct 2010) -- This small paper attempts to answer inquiries received during the span of at least a decade. It contains little information that is unavailable at the Copyright Office website, but it focuses on the needs of a much smaller, if sizable, audience. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1693203 [Editor: 6-page almost FAQ-like – useful for quick orientation of new clients.]

WIPO Launches On-line Tool to Assist in Filing International Trademark Applications (WIPO, 20 Dec 2010) - WIPO launched on December 20, 2010 an on-line tool - the Madrid System Goods & Services Manager (G&S Manager) - that will help trademark applicants in compiling the list of goods and services that must be submitted when filing an international application under the Madrid System for the International Registration of Marks. The G&S Manager, which can be accessed through the WIPO GOLD portal, gives access to thousands of standard terms classified in accordance with the 9th edition of the International Classification of Goods and Services for the Purposes of the Registration of Marks (Nice Classification). Applicants using the G&S Manager can select the terms that best describe the goods and services relating to the mark. Users of the Madrid system must ensure that they provide the correct description and classification of the goods and services for which the mark will be used. By selecting terms from the G&S Manager, applicants can be confident that no irregularity notice will be issued with respect to the classification or indication of those goods and services. The G&S Manager is available in the three working languages of the Madrid system, namely English, French and Spanish, and gives access to some 30,000 terms in English and their equivalents in French and Spanish. http://www.wipo.int/pressroom/en/articles/2010/article_0050.html

**** LOOKING BACK ****
JUDGE MAKES A CASE FOR THE DELETE KEY (New York Times 5 Oct 2000) - District Court Judge James Rosenbaum has published an article called “In Defense of the DELETE Key,” in which he bemoans the eternal nature of computer communications and reminisces fondly about pre-computer days when people casually spoke “off the record”: “At this earlier time, two people could easily say something -- even, perhaps, something politically incorrect -- simply between themselves. They might even have exchanged nasty notes between themselves. And when they had moved past this tacky, but probably innocent moment, it was truly gone.” Today, however, “an idle thought jotted onto a calendar, a tasteless joke passed to a once-trusted friend, a suggestive invitation directed at an uninterested recipient, if done electronically, will last forever. Years later, it can subject its author to liability.” Rosenbaum proposes a “cyber statute of limitations” -- perhaps six months for an isolated e-mail message -- after which “deleted” documents would be legally consigned to the electronic rubbish heap and become inadmissible as evidence of possible wrongdoing. He makes an exception for recovered “deleted” messages from someone who has exhibited a pattern of egregious behavior or communications. The article was published in the Summer issue of The Green Bag, a literary law journal. http://.nytimes.partners.com/2000/10/05/technology/06CYBERLAW.html [link broken]

**** NOTES ****
MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks. You can subscribe to the MIRLN distribution list by sending email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line. Unsubscribe by sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln. Get supplemental information through Twitter: http://twitter.com/vpolley)

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu
2. InsideHigherEd - http://www.insidehighered.com/
3. SANS Newsbites, sans@sans.org
4. NewsScan and Innovation, http://www.newsscan.com
5. BNA’s Internet Law News, http://ecommercecenter.bna.com
7. McGuire Wood’s Technology & Business Articles of Note
8. Steptoe & Johnson’s E-Commerce Law Week
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/
10. Law.com
11. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

Saturday, December 11, 2010

MIRLN --- 21 November – 11 December 2010 (v13.17)


(supplemented by related Tweets: http://twitter.com/vpolley #mirln)

·      Agencies To Look For a ‘Cloud Option’
o   GSA Chooses Google For Hosted E-Mail
·      Disney’s Earnings Leak Sprung From Goofy Mistake
·      Copyright Lawyers Sue Lawyer Who Helped Copyright Defendants
·      High Court Ruling Implies Headlines Are Copyright – We’re One Step Away From Links
·      10 Steps To Kickoff A Social Media Campaign
·      Supreme Court Won’t Hear RIAA File Sharing Case
·      Placing Files in Shared Folder Online Can Constitute Child Porn Distribution
·      Talking About Your Case On Your Blog? You May Have Just Waived Privilege
·      Facebook: State Bar Opinions Address Information Gathering
·      Google Changes Its Rank Algorithm In Response To NYT DecorMyEyes Story
·      Google Signs Deal With European Patent Office to Translate Patents
·      FTC Staff Issues Privacy Report Offers Framework for Consumers, Businesses, and Policymakers; Endorses “Do Not Track” to Facilitate Consumer Choice About Online Tracking
·      Race Is On to ‘Fingerprint’ Phones, PCs
·      Australian Government Gives Thumbs Down to PDF Format
·      New Oklahoma Law Puts Control of Deceased’s Social Media Accounts In Estate Executors
·      Companies Beware: The Next Big Leak Could Be Yours
·      FTC Offers Businesses Tips for Securing Data on Digital Copiers
·      Web Bugs the New Norm For Businesses?
·      DoD to Troops: Lawfare=Wikileaks
·      Risk of Cyber Attacks Should Be Board-Level Concern, Lloyd's Says
·      Government, Financial Industry Launch Cybersecurity Collaboration
·      Yahoo Finance Integrates Real-Time Stock Discussion From StockTwits
·      As Jurors Go Online, U.S. Trials Go Off Track
·      OFAC Expands Capacity of Designated Entities to Pay for Legal Services
·      Fail: NASA Sold Space Shuttle PCS Without Wiping Secret Data
·      UCLA Sued Over Streaming of Videos

NEWS | PODCASTS | RESOURCES | FUN | DIFFERENT | LOOKING BACK | NOTES

Agencies To Look For a ‘Cloud Option’ (Computerworld, 22 Nov 2010) - The federal government is adopting a “cloud-first” policy, marking the administration’s strongest statement yet in support of Web-based computing as it looks to overhaul the way it buys information technology. Jeffrey Zients, the federal government’s first chief performance officer, announced last week that the Office of Management and Budget will now require federal agencies to default to cloud-based solutions “whenever a secure, reliable, cost-effective cloud option exists.” The shift is part of a broader set of changes aimed at improving IT procurement. In recent months, the federal government has shut down or restructured a host of technology programs after they ran over budget and behind schedule. “Fixing IT is central to everything we’re trying to do across government,” Zients said. “IT is our top priority.” Zients outlined a series of initiatives the government plans to launch in the next six months, including pilot efforts to give agencies more flexibility in how they budget for programs. In addition, the administration wants to reconstitute oversight panels known as investment review boards and establish a career path for program managers. http://www.washingtonpost.com/wp-dyn/content/article/2010/11/19/AR2010111906449.html

- and -

GSA Chooses Google For Hosted E-Mail (Computerworld, 1 Dec 2010) - The U.S. General Services Administration will become the first federal agency to use a hosted e-mail service, choosing Google, Unisys and others to offer the service. The choice is a blow to Microsoft, which has tried to position itself as offering the most secure services for the government. It said it is the first federal agency to use a cloud-based system for e-mail across the entire agency. It expects a 50 percent cost savings over the next five years compared to costs associated with its current system. http://www.computerworld.com/s/article/9199079/US_agency_chooses_Google_for_hosted_e_mail See also “USDA Taps Microsoft Cloud For 120,000 Workers (Information Week, 8 Dec 2010)” here: http://www.informationweek.com/news/government/cloud-saas/showArticle.jhtml?articleID=228701932&cid=RSSfeed_IWK_News

Disney’s Earnings Leak Sprung From Goofy Mistake (Business Week, 24 Nov 2010) - There’s an explanation now for how Disney’s earnings report this month got released early: The company made the information accessible through an easy-to-guess Web address. The Walt Disney Co. didn’t plan on posting the link on its website until after the market closed Nov. 11. But a reporter at Bloomberg News found it with simple Internet sleuthing and reported results about a half-hour before the scheduled release. That’s according to a person familiar with Bloomberg’s practices. The person isn’t authorized to speak publicly and is speaking on condition of anonymity. Security experts characterize the companies’ failure to protect such valuable information as careless lapses. The Securities and Exchange Commission isn’t saying whether it’s investigating. Disney says its own probe is ongoing. http://www.businessweek.com/ap/financialnews/D9JML5LG0.htm

Copyright Lawyers Sue Lawyer Who Helped Copyright Defendants (The escapist, 26 Nov 2010) - Attorneys for the U.S. Copyright Group have filed a lawsuit against a lawyer who sold “self-help” documents to people who had been sued by the USCG, demanding that he pay the costs involved in dealing with the people who used the documents he sold. Try to stick with me here, because this one gets weird. Back in August, an attorney by the name of Graham Syfert began selling documents that would allow defendants in lawsuits filed by the U.S. Copyright Group to respond in court without having to fork over the huge piles of money needed to hire an attorney. The USCG sued “thousands” of BitTorrent users who had downloaded films like The Hurt Locker, Far Cry and Call of the Wild, demanding a settlement of $2500 to avoid the much more expensive proposition of going to court. “One of the major problems that people encounter when trying to hire me on these cases, is that a settlement is approximately what an attorney would need to even begin a defense,” Syfert said at the time. His package of paperwork, on the other hand, cost just ten bucks. 19 people have thus far taken advantage of Syfert’s offer and submitted responses to the court using his package, not a huge amount by any measure but 19 more than Dunlap, Grubb and Weaver, the law firm behind the USCG lawsuits, wants to put up with. The firm threatened Syfert with sanctions soon after he began selling his forms and also said it would double its settlement requests for anyone who used them; Syfert dismissed the threats with a “tongue in cheek” email and that was that, until earlier this week. On November 22, Syfert received another email from attorney Jeff Weaver informing him that he had made a formal request for sanctions against him on behalf of the production company behind The Hurt Locker, one of the driving forces behind the USCG lawsuits. Weaver is apparently claiming that the 19 cases filed using the self-help package have cost his firm $5000 and he wants Syfert to pay. http://www.escapistmagazine.com/news/view/105651-Copyright-Lawyers-Sue-Lawyer-Who-Helped-Copyright-Defendants

High Court Ruling Implies Headlines Are Copyright – We’re One Step Away From Links (TechCrunch, 27 Nov 2010) - The UK’s High Court has ruled that news monitoring agencies will have to pay publishing companies to use their web content, effectively re-classifying headlines as separate literary works subject to copyright. The moves follows a legal battle between the Newspaper Licensing Agency, owned by eight of the UK’s largest newspaper groups, and Meltwater, a news monitoring agency. Although cutting agencies like Meltwater pay the NLA a fee for reproducing full-length articles, this case was supposed to clarify the limits of the NLA’s licensing scheme. Meltwater didn’t like its clients needing to have a licence from the NLA for the use of mere headlines and short extracts from its service. Instead the case has ruled that similar aggregation sites that charge for a service will have to pay for those headlines. Meltwater plans to appeal against the decision, but if it’s upheld, you can expect a wave of more legal actions. And thus the fabric of the UK’s online publishing industry will start to break down. Well done High Court. Technically, that won’t affect blogs or search sites since they don’t charge. But it’s not far away from some publishers claiming that because those links are monetised in some other way, that they can charge for their use since the headlines and, therefore the links to those, are copyright. http://eu.techcrunch.com/2010/11/27/high-court-ruling-implies-headlines-are-copyright-were-one-step-away-from-links/

10 Steps To Kickoff A Social Media Campaign (Business Insider, 28 Nov 2010) - When it comes to using social media marketing to build your business, the worst action is no action, and your biggest problem is being invisible, not being talked about negatively. As long as you’re part of the conversation on the social Web, you can hear what’s being said about you and massage negative perceptions about your business. http://read.bi/i6ur44

Supreme Court Won’t Hear RIAA File Sharing Case (Wired, 29 Nov 2010) - The U.S. Supreme Court declined Monday to hear the first Recording Industry Association of America file sharing case to cross its desk, in a case that tested the so-called “innocent infringer” defense to copyright infringement. The case, which one justice voted to hear (.pdf), leaves undisturbed a federal appeals court’s decision in February ordering a university student to pay the Recording Industry Association of America $27,750 for file-sharing 37 songs when she was a high school cheerleader. The appeals court decision reversed a Texas federal judge who, after concluding the youngster was an innocent infringer, ordered defendant Whitney Harper to pay just $7,400, or $200 per song. That’s an amount well below the standard $750 fine required under the Copyright Act for each violation. Harper’s challenge weighed whether the innocent-infringer defense to the Copyright Act’s minimum $750-per-music-track fine may apply to online file sharing. Generally, an innocent infringer is someone who does not know she or he is committing copyright infringement. Attorneys for Harper told the justices (.pdf) that she should get the benefit of the $200 innocent-infringer fine, because the digital files in question contained no copyright notice. A Texas federal judge had granted Harper the innocent-infringer exemption to the Copyright Act’s minimum fine, because the teen claimed she did not know she was violating copyrights. She said she thought file sharing was akin to internet radio streaming. The 5th U.S. Circuit Court of Appeals, however, said she was not eligible for such a defense, even though she was between 14 and 16 years old when the infringing activity occurred on LimeWire. The reason, the appeals court concluded, is that the Copyright Act precludes such a defense if the legitimate CDs of the music in question carry copyright notices. http://www.wired.com/threatlevel/2010/11/innocent/

Placing Files in Shared Folder Online Can Constitute Child Porn Distribution (New Jersey Law Journal, 30 Nov 2010) - Internet file sharing is just that — sharing files with other users — and it can amount to illegal offering and distributing when the files are child pornography, a state appeals court ruled Tuesday. Though the defendant didn’t affirmatively offer the materials or seek out people to take them, a fact finder could see the act of placing the files in a shared folder online, where others might access them, as “offering” or “providing” under New Jersey’s child endangerment statute, the Appellate Division ruled in State v. Lyons , A-4893-09. Richard Lyons was indicted for possessing as well as offering and distributing child pornography via LimeWire, an online file-sharing network. On May 30, 2007, a state police investigator accessed LimeWire, entered search terms indicating child pornography, located a known child-pornography file on Lyons’ computer and downloaded it, along with other files he had stored that turned out to contain pornographic materials. During questioning, Lyons acknowledged that LimeWire’s default setting was to store downloaded files in a shared folder available to all network users, though the settings could be changed to store downloaded files in a private folder not accessible to other network users. Morris County Superior Court Judge Philip Maenza dismissed the offering and distributing counts, based on Lyons’ assertion that his failure to change the LimeWire settings was an omission and that he did not knowingly distribute the video files. Lyons claimed that passive conduct cannot satisfy the meaning stated in the statute. Appellate Division Judges Joseph Lisa, Susan Reisner and Jack Sabatino reversed, holding that Lyons acted affirmatively by installing the LimeWire program, downloading the pornography files and keeping the files in a shared folder knowing that others would find them and download them. http://www.law.com/jsp/nj/PubArticleNJ.jsp?id=1202475499826

Talking About Your Case On Your Blog? You May Have Just Waived Privilege (Stikeman, 30 Nov 2010) - On October 22, 2010, an American magistrate judge ruled that a plaintiff suing Universal Music Corp. for improperly sending a takedown notice under the Digital Millennium Copyright Act (DMCA) waived a number of heads of attorney-client privilege by discussing the details of her legal case by email and on a blog. In Lenz. v. Universal Music Corp, the plaintiff claimed damages and attorneys’ fees as a result of Universal Music Corp.’s filing of an allegedly fraudulent DMCA take-down notice seeking to have a home video of the plaintiff’s child dancing to a copyrighted song removed from YouTube. A magistrate judge ruled that plaintiff Stephanie Lenz waived attorney-client privilege by discussing her case in e-mail, on her blog, and in chat sessions. Through these online media, Lenz made representations about conversations she had had with her attorneys from Electronic Frontier Foundation (a non-profit digital rights advocacy and legal organization). These representations revealed information such as why she was suing Universal Music Corp. and legal strategies she was pursuing in her suit against the company. The magistrate judge ruled that these online communications amounted to a waiver of the attorney-client privilege. Accordingly, the magistrate ordered plaintiff to produce further documents and submit to further discovery regarding the plaintiff’s communications with her attorney as to (i) her motives for bringing the action; (ii) the specific legal strategies identified in her online discussions; and (iii) the specific factual allegations made in her online discussions. However, some have indicated that had this case been heard in Canada, the result may have been very different. Due to the high thresholds established by caselaw for determining when privilege has been waived, it is argued that a plaintiff’s mere musings or speculation about her lawyer’s legal strategy would likely not have lead to a waiver of solicitor-client privilege. http://www.canadiantechnologyiplaw.com/2010/11/articles/intellectual-property/talking-about-your-case-on-your-blog-you-may-have-just-waived-privilege/#page=1

Facebook: State Bar Opinions Address Information Gathering (ABA, 30 Nov 2010) – “You represent the mother in a child custody dispute that will most likely wind up in litigation. You recently interviewed a daycare provider who may be an adverse witness in the matter. You believe that there may be some very useful information on the daycare provider’s personal Facebook page that you may be able to use to impeach her testimony at trial, but you would need to “friend” her to gain access to them. You believe that she freely gives the friend status to almost anyone who requests it, but that she would most likely not grant it to you. Can you ask your paralegal, whose name the daycare provider would not recognize, to contact the provider in order to friend her without revealing his affiliation with you so that you can gain access to her personal Facebook page?” http://www.abanet.org/media/youraba/201011/article10.html

Google Changes Its Rank Algorithm In Response To NYT DecorMyEyes Story (TechCrunch, 1 Dec 2010) - Over Thanksgiving weekend a New York Times story, “A Bully Finds a Pulpit on the Web” clued a lot of people in to some of the drawbacks of Google PageRank. Negative attention online and complaint links from customer service sites like Get Satisfaction can actually be a benefit to business as in the problematic case of online retailer DecorMyEyes. The Times piece followed DecorMyEyes customer Clarabelle Rodriguez as she suffered online and offline harassment from DecorMyEyes founder Vitaly Borker, all in the name of improving his Google search rankings. While I saw that DecorMyEyes had dropped in the Google rankings for eyewear related searches like “La Font” directly after the piece went out, it was only a matter of time before Google did something official. From the Google blog: “We were horrified to read about Ms. Rodriguez’s dreadful experience. Even though our initial analysis pointed to this being an edge case and not a widespread problem in our search results, we immediately convened a team that looked carefully at the issue. That team developed an initial algorithmic solution, implemented it, and the solution is already live. I am here to tell you that being bad is, and hopefully will always be, bad for business in Google’s search results.” The Google post then goes on to outline the different ways the search engine could have solved the “Bad to customers = Good for PageRank” problem, by either blocking or using sentiment analysis to pull sites with a lot of negative comments down in the rankings. Using sentiment analysis in search rank is tricky however, because it would also pull down sites about unpopular politicians and controversial issues like abortion. Instead of using either of those two solutions to account for cases like the one described in the New York Times article, Google instead wrote an algorithm that can detect which hundreds of merchants (including DecorMyEyes) have provided “bad user experience” and algorithmically force them lower. http://techcrunch.com/2010/12/01/googl/

Google Signs Deal With European Patent Office to Translate Patents (Int’l Business Times, 1 Dec 2010) - Internet search company Google Inc on Tuesday said it has signed a deal with the European Patent Office (EPO) to use the company’s technology to translate patents into 29 European languages that will pave the way for a simplified European patent system. Google’s deal, which comes after years of infighting, is expected to make it easier for inventors and scientists from across the continent to access information on patents with the EPO that has 38 member countries. The European Commission has been pushing for a unified system for long but a European Union-wide standard patent had been halted for long due to a long standing dispute about which languages should take precedence on official documents. Italy and Spain had refused to accept a unified system and the contention that it was enough to have patent documents translated into English, French and German. Google’s agreement will help do away with the huge translation fees that had prevented growth and hit small businesses as it is presently 10 times more expensive to apply for a patent in Europe than in the US, European Commission said. Google transaction will also calm down fears of some countries that they will be at a language disadvantage. http://www.ibtimes.com/articles/87406/20101201/google-google-deal-with-european-patent-office-google-translation.htm

FTC Staff Issues Privacy Report Offers Framework for Consumers, Businesses, and Policymakers; Endorses “Do Not Track” to Facilitate Consumer Choice About Online Tracking (FTC, 1 Dec 2010) - The Federal Trade Commission, the nation’s chief privacy policy and enforcement agency for 40 years, issued a preliminary staff report today that proposes a framework to balance the privacy interests of consumers with innovation that relies on consumer information to develop beneficial new products and services. The proposed report also suggests implementation of a “Do Not Track” mechanism – likely a persistent setting on consumers’ browsers – so consumers can choose whether to allow the collection of data regarding their online searching and browsing activities. “Technological and business ingenuity have spawned a whole new online culture and vocabulary – email, IMs, apps and blogs – that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that’s what most Americans want as well,” said FTC Chairman Jon Leibowitz. The report states that industry efforts to address privacy through self-regulation “have been too slow, and up to now have failed to provide adequate and meaningful protection.” The framework outlined in the report is designed to reduce the burdens on consumers and businesses. To reduce the burden on consumers and ensure basic privacy protections, the report first recommends that “companies should adopt a ‘privacy by design’ approach by building privacy protections into their everyday business practices. http://ftc.gov/opa/2010/12/privacyreport.shtm Report here: http://ftc.gov/os/2010/12/101201privacyreport.pdf

Race Is On to ‘Fingerprint’ Phones, PCs (WSJ, 1 Dec 2010) - David Norris wants to collect the digital equivalent of fingerprints from every computer, cellphone and TV set-top box in the world. Companies are developing digital fingerprint technology to identify how we use our computers, mobile devices and TV set-top boxes. WSJ’s Simon Constable talks to Senior Technology Editor Julia Angwin about the next generation of tracking tools. He’s off to a good start. So far, Mr. Norris’s start-up company, BlueCava Inc., has identified 200 million devices. By the end of next year, BlueCava says it expects to have cataloged one billion of the world’s estimated 10 billion devices. Advertisers no longer want to just buy ads. They want to buy access to specific people. So, Mr. Norris is building a “credit bureau for devices” in which every computer or cellphone will have a “reputation” based on its user’s online behavior, shopping habits and demographics. He plans to sell this information to advertisers willing to pay top dollar for granular data about people’s interests and activities. It’s tough even for sophisticated Web surfers to tell if their gear is being fingerprinted. Even if people modify their machines—adding or deleting fonts, or updating software—fingerprinters often can still recognize them. There’s not yet a way for people to delete fingerprints that have been collected. In short, fingerprinting is largely invisible, tough to fend off and semi-permanent. http://online.wsj.com/article/SB10001424052748704679204575646704100959546.html?mod=WSJ_hp_LEFTTopStories

Australian Government Gives Thumbs Down to PDF Format (IT News, 1 Dec 2010) - The central IT office of Australia’s Federal Government has requested that agencies consider the use of alternative file formats to Adobe’s PDF. The advice follows a study which found that while accessibility of the Portable Document Format (PDF) has improved over time and remains a popular format for many organisations, it was less accessible to visually-impaired users. Published by the Australian Government Information Management Office (AGIMO), “The Australian Government’s study into the Accessibility of the Portable Document Format for people with a disability,” concluded that if PDF was used, accessible alternative file formats should be made available. http://www.itnews.com.au/News/240304,government-gives-thumbs-down-to-pdf-format.aspx

New Oklahoma Law Puts Control of Deceased’s Social Media Accounts In Estate Executors (IBT, 2 Dec 2010) - Estate executors or administrators in Oklahoma have the power to access, administer or terminate the online social media accounts of the deceased, according to a new state law. According to former state Rep. Ryan Kiesel (D-Seminole), who had co-authored House Bill 2800 before he left office, the law would remind the people of Oklahoma as they go about their estate planning that, in addition to their personal and real property, they should make plans for the vast amount of intellectual property we leave behind. “The number of people who use Facebook today is almost equal to the population of the United States. When a person dies, someone needs to have legal access to their accounts to wrap up any unfinished business, close out the account if necessary or carry out specific instructions the deceased left in their will,” Kiesel said. “Digital photo albums and e-mails are increasingly replacing their physical counterparts, and I encourage Oklahomans to think carefully about what they want to happen to these items when they pass away,” he said. The bill, which became a state law on Nov. 1, assumes a Facebook page or other social network account is the property of the person who creates and uses it. However, most websites claim the information as their own in service agreements when users sign up. Kiesel has acknowledged the law may conflict with service agreements, but said the law is intended to get people thinking seriously about what they leave behind on Facebook and other websites. “We’re not just leaving a couple of shoeboxes full of mementos behind,” Kiesel said. “We’re leaving behind potentially thousands of photographs and all kinds of aspects of our lives online.” The law is the first of its kind in the U.S. http://www.ibtimes.com/articles/88106/20101202/new-oklahama-law-puts-control-of-deceased-s-social-media-accounts-in-estate-executors.htm

Companies Beware: The Next Big Leak Could Be Yours (AP, 2 Dec 2010) - WikiLeaks’ release of secret government communications should serve as a warning to the nation’s biggest companies: You’re next. Computer experts have warned for years about the threat posed by disgruntled insiders and by poorly crafted security policies, which give too much access to confidential data. And there is nothing about WikiLeaks’ release of U.S. diplomatic documents to suggest that the group can’t — or won’t — use the same methods to reveal the secrets of powerful corporations. And as WikiLeaks claims it has incriminating documents from a major U.S. bank, possibly Bank of America, there’s new urgency to addressing information security inside corporations and a reminder of its limits when confronted with a determined insider. Despite the repeated warnings, many large companies lack clear policies on who should have access to certain data, said Christopher Glyer, a manager with the Mandiant Corp., an Alexandria, Va.-based security firm that investigates computer intrusions. WikiLeaks argues that revealing details of companies and governments behaving badly, no matter how the information is obtained, is good for democracy. Julian Assange, WikiLeaks’ founder, told Forbes magazine that the number of leaks his site gets has been increasing “exponentially” as the site has gotten more publicity. He said it sometimes numbers in the thousands per day. http://news.yahoo.com/s/ap/20101202/ap_on_hi_te/us_tec_wikileaks_security_lessons

FTC Offers Businesses Tips for Securing Data on Digital Copiers (FTC, 3 Dec 2010) - The Federal Trade Commission, the nation’s consumer protection agency, has tips for businesses on how to safeguard sensitive data stored on the hard drives of digital copiers. Here are the highlights of the FTC’s new publication, Copier Data Security: A Guide for Businesses: 
Before acquiring a copier, plan to have the information technology staff manage and maintain it just as they would a computer or a server.
When buying or leasing a copier, evaluate your options for securing the data on its hard drive – including the encryption or overwriting features that will be used. Encryption scrambles the data on the hard drive so it can only be read by particular software. This ensures that even if the hard drive is removed from the machine, the data cannot be retrieved. Overwriting – also known as file wiping or shredding – replaces the existing data with random characters, so that the file cannot be easily reconstructed.
Take advantage of all of the copier’s security features. Securely overwrite the entire hard drive at least once a month.
When returning or disposing of a copier, find out whether it is possible to have the hard drive removed and destroyed, or to overwrite the data on the hard drive. Generally, it is advisable for a skilled technician to remove the hard drive to avoid the risk of rendering the machine inoperable.
For more information about securing sensitive data, see Protecting Personal Information: A Guide for Business. http://ftc.gov/opa/2010/12/copierdata.shtm

Web Bugs the New Norm For Businesses? (SlashDot, 3 Dec 2010) –
An anonymous reader writes: “What ever happened to the good old days, when underhanded email practices were only used by shady email marketing companies and spammers? Today, it seems, the mainstream corporate world has begun to employ the same tactics as spammers to track their customers’ email. Jonathan Zdziarski noted in a blog entry that AT&T is using web bugs to track email sent to customers. Could this be used for nefarious purposes?” http://tech.slashdot.org/story/10/12/03/1845212/Web-Bugs-the-New-Norm-For-Businesses?from=rss

DoD to Troops: Lawfare=Wikileaks (Lawfare, 3 Dec 2010) - Those of you concerned about the Wikileaks disclosures will be reassured to know that the military IT folks are on the case and are aggressively cracking down on–drum-roll, please–us. That’s right, folks, Wikileaks, Lawfare. It’s all the same. They’re both on the Internet, after all. I awoke this morning to an email from alert reader Jeffrey A. Sherman, a reserve JAG Army Captain in the 2nd Stryker Brigade Combat Team, 25th Infantry Division, which is currently deployed in Iraq. He notified me that the following text now appears on his computer when he tries to access Lawfare:
USF-I ALERT NOTIFICATION
*** YOU HAVE SELECTED A SITE THAT MAY POTENTIALLY CONTAIN CLASSIFIED DOCUMENTS ***
Due to the recent disclosure of US Classified Information to public news and media sources, the site you are attempting to access may potentially be hosting US Classified Information (CONFIDENTIAL to SECRET//NOFORN) documents. Downloading, copying, typing text into another document or email, printing, saving to a workstation, server, or any drive connected to a NIPR or Unclassified system is considered a compromise of that system. Additionally, printing, sending, transmitting or forwarding this information is also considered a SPILL and established SPILL cleanup procedures must be followed. Users will lose network access until the incident can be fully resolved IAW USF-I and CENTCOM standards, including user training.
Viewing these documents is not considered a spill in of itself; however, once a user identifies the information as classified or potentially classified, the individual should immediately cease viewing the item and close their web browser.
IAW with DOD guidance and USF-I OPSEC Hash 10-2, all personnel are to refrain from viewing any of the articles pertaining to Wikileaks releases on their DOD NIPR system.
If you have questions regarding this message contact the JNCC-I IA Office, VoSIP: 708-243-6391.
*** YOU HAVE SELECTED A SITE THAT MAY POTENTIALLY CONTAIN CLASSIFIED
DOCUMENTS ***
Logged Information
Proxy Server: ARIF1-N-1-PROXY
Username:
IP Address: 143.73.144.27
UTC Timestamp: 2010-12-03 12:06:25
Category: Government/Legal;Blogs/Personal Pages
URL: http://www.lawfareblog.com/
I cannot tell you how much I resent this. It’s not just the stupidity of the failure to distinguish between leaks and commentary on national security law–which inevitably will occasionally touch on leaks. It’s also the ridiculous phrase “May Potentially Contain Classified Information,” which in this instance translates roughly to “Does Not Contain or Discuss Classified Information Not Already Disclosed by Entities With Orders of Magnitude More Readers.” We have not posted any State Department cables here on Lawfare. The most we have done is linked to a New York Times article that refers to some cables and re-quoted what the Times had already quoted. We have actually taken pains over the life of this blog–and before–to avoid compromising sensitive material in the course of work that necessarily brings us into contact with it. On a few occasions, we have gone so far as to decline to post on sensitive matters that have come our way as a result of accidental disclosures. We write off of the public record here at Lawfare. Some of my press friends may not admire that, but that’s what we do. Glad to know the military appreciates the effort. http://www.lawfareblog.com/2010/12/dod-to-troops-lawfarewikileaks/

Risk of Cyber Attacks Should Be Board-Level Concern, Lloyd's Says (Insurance Journal, 6 Dec 2010) - Digital risks must be a board-level concern for business as the range, frequency and scale of cyber attacks increases, according to a new report. Many companies are unwittingly vulnerable to the possibility of data leakage, phishing attacks, trojans or advance persistent threats, according to a new report from Lloyd's, the world's leading specialist insurance market, and HP, the world's largest technology company. The report, "Managing digital risks: trends, issues and implications for business," warns that, as businesses become more reliant on technology, they will face more complex and damaging digital attacks as sophisticated attackers quickly adapt their methods to steal from, disrupt and spy on businesses. http://www.insurancejournal.com/news/national/2010/12/06/115412.htm?elq_mid=11989&elq_cid=996107  Report here: http://www.lloyds.com/~/media/Lloyds/Reports/360%20Digital/Lloyds_360_Digital_Risk_Report%20(2).pdf 

Government, Financial Industry Launch Cybersecurity Collaboration (Information Week, 7 Dec 2010) - Federal agencies have teamed up with the financial services industry to promote a common way for the public and private sector to coordinate on cybersecurity. The effort is aimed at speeding the commercialization of technologies being developed to protect U.S. critical infrastructure so that both the federal government and private organizations can benefit from them, according to the White House. The National Institute of Standards and Technology (NIST) of the Department of Commerce, the Science and Technology Directorate of the Department of Homeland Security (DHS/S&T), and the Financial Services Sector Coordinating Council (FSSCC) released a memo Monday agreeing to pool their collective cybersecurity resources to facilitate innovation; identify and fight cybersecurity vulnerabilities; and develop more efficient and effective cybersecurity processes that can be used in the financial services sector as well as by other organizations. http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=228600170&cid=RSSfeed_IWK_News

Yahoo Finance Integrates Real-Time Stock Discussion From StockTwits (Mashable, 7 Dec 2010) - Yahoo Finance announced Tuesday that is has begun pulling data from StockTwits’s API, which curates stock-related conversation from Twitter tagged with $[stock symbol] (i.e. $AMZN) and messages sent through its own microblogging platform. StockTwits’s stream appears in a newly launched Market Pulse section, designed to help users keep track of real-time, user-generated finance news discussion on the web. We’ve pulled up the page for Google below. Unfortunately, the stream is not yet integrated into the main dashboard pages, which includes quotes, charts, news and other information for each stock. Instead, users have to navigate to a separate “Market Pulse” page on the left sidebar, which severely limits the stream’s exposure. http://mashable.com/2010/12/07/stocktwits-yahoo-finance/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Mashable+%28Mashable%29&utm_content=Google+Reader

As Jurors Go Online, U.S. Trials Go Off Track (Reuters, 8 Dec 2010) - The explosion of blogging, tweeting and other online diversions has reached into U.S. jury boxes, raising serious questions about juror impartiality and the ability of judges to control courtrooms. A Reuters Legal analysis found that jurors’ forays on the Internet have resulted in dozens of mistrials, appeals and overturned verdicts in the last two years. For decades, courts have instructed jurors not to seek information about cases outside of evidence introduced at trial, and jurors are routinely warned not to communicate about a case with anyone before a verdict is reached. But jurors these days can, with a few clicks, look up definitions of legal terms on Wikipedia, view crime scenes via Google Earth, or update their blogs and Facebook pages with snide remarks about the proceedings. The consequences can be significant. A Florida appellate court in September overturned the manslaughter conviction of a man charged with killing his neighbor, citing the jury foreman’s use of an iPhone to look up the definition of “prudent” in an online dictionary. In June, the West Virginia Supreme Court of Appeals granted a new trial to a sheriff’s deputy convicted of corruption, after finding that a juror had contacted the defendant through MySpace. Also in September, the Nevada Supreme Court granted a new trial to a defendant convicted of sexually assaulting a minor, because the jury foreman had searched online for information about the types of physical injuries suffered by young sexual assault victims. Reuters Legal, using data from the Westlaw online research service, a Thomson Reuters business, compiled a tally of reported decisions in which judges granted a new trial, denied a request for a new trial, or overturned a verdict, in whole or in part, because of juror actions related to the Internet. The data show that since 1999, at least 90 verdicts have been the subject of challenges because of alleged Internet-related juror misconduct. More than half of the cases occurred in the last two years. Judges granted new trials or overturned verdicts in 28 criminal and civil cases -- 21 since January 2009. In three-quarters of the cases in which judges declined to declare mistrials, they nevertheless found Internet-related misconduct on the part of jurors. These figures do not include the many incidents that escape judicial notice. http://www.reuters.com/article/idUSTRE6B74Z820101208

OFAC Expands Capacity of Designated Entities to Pay for Legal Services (Lawfare, 8 Dec 2010) - OFAC has issued a final rule amending the TSR and GTSR sanction regimes to expand the options for designated entities to pay for certain legal services. Presumably this is at least indirectly responsive to issues that arose over the past year when the ACLU and CCR sought to represent Anwar al-Aulaqi’s father in the targeted killing case, and when the Humanitarian Law Project litigation (which dealt with the 2339B material support regime, not an IEEPA regime) raised similar questions about the provision of legal services to designated terrorist organizations. Whatever the origin, the full details of the new rule are posted here, and the summary follows: ”SUMMARY: The Office of Foreign Assets Control (“OFAC”) of the U.S. Department of the Treasury is amending the Global Terrorism Sanctions Regulations (“GTSR”) and the Terrorism Sanctions Regulations (“TSR”) to expand the scope of authorizations in each of those programs for the provision of certain legal services. In addition, OFAC is adding new general licenses under the GTSR, the TSR, and the Foreign Terrorist Organizations Sanctions Regulations to authorize U.S. persons to receive specified types of payment for certain authorized legal services.” http://www.lawfareblog.com/2010/12/ofac-expands-capacity-of-designated-entities-to-pay-for-legal-services/?utm_source=twitterfeed&utm_medium=twitter

Fail: NASA Sold Space Shuttle PCS Without Wiping Secret Data (Computerworld, 8 Dec 2010) - For sale, used computer packed full of secret NASA Space Shuttle data. As part of a plan to securely end the Space Shuttle program, NASA is getting rid of old computers. However, NASA officials failed to delete sensitive data on PCs and hard drives before selling the equipment. The Office of Inspector General found “serious” security breaches at NASA centers in Florida, Virginia, Texas and California. NASA is full of very bright minds, so how did it manage to make such a noob mistake of selling PCs without wiping the hard drives? An audit [PDF] found 10 of 14 computers that failed tests to ascertain they’d been wiped properly. One computer that was to be sold still contained sensitive Space Shuttle data, which was subject to export control by the International Traffic in Arms Regulations. All electronic storage media is supposed to be wiped of data “to the degree that there is reasonable assurance that the data cannot be retrieved or reconstructed,” the audit stated. NASA approved software for sanitizing hard drives include DBAN (Darik’s Boot and Nuke), Secure Erase, and WipeDrive/WipeDrive Pro. Contractors in charge of deleting sensitive information used DBAN and Active@KillDisk - which is not NASA approved at Johnson’s disposition center. Ames used BCwipe, which is DOD compliant, but not NASA approved. USA used Symantec DateGone which is not approved by NASA, DOD or NSA. http://blogs.computerworld.com/17500/fail_nasa_sold_space_shuttle_pcs_without_wiping_secret_data

UCLA Sued Over Streaming of Videos (InsideHigherEd, 10 Dec 2010) - After a public copyright dispute in January, the Association for Information and Media Equipment says it has filed suit against the University of California at Los Angeles and the system’s Board of Regents. The association, a trade group that represents 16 educational media companies, objected to UCLA’s practice of allowing students to stream copyrighted videos on their course websites. Since course websites are not classrooms, the group said, the “fair use” exemptions for educational use do not apply. UCLA has said that since the course websites are password-protected, streaming videos on the site is the same as showing them in class, except far more convenient for students and professors. Allen Dohra, president of the trade group and vice president of Ambrose Video Publishing, which is named as a co-plaintiff in the suit, said in a press release that UCLA is undermining Ambrose’s own streaming service, which it offers at a price to subscribers. “UCLA’s behavior spells catastrophe for the entire educational video market, which increasingly will turn to streaming video,” the group said in the release. http://www.insidehighered.com/news/2010/12/10/qt#245547

**** NOTED PODCASTS ****
Kim Dulin and David Weinberger on the Meta-Library (Berkman Center, 9 Nov 2010) - s more and more content moves into the cloud libraries are decreasingly the single place to go to find the material you need for your research (except for rare books and special collections). But libraries know a huge amount about their contents. This metadata is becoming even more valuable as research moves online, since now it can be deployed to help scholars and researchers discover, understand, and share what they need to know. The co-directors of the Harvard Library Innovation Lab at Harvard Law School—Kim Dulin and David Weinberger—along with members of the Lab will demonstrate their lead project (ShelfLife) and talk about the Lab’s proposed multi-library metadata server (LibraryCloud). http://blogs.law.harvard.edu/mediaberkman/2010/11/09/kim-dulin-and-david-weinberger-on-the-meta-library-audio/

**** RESOURCES ****
OECD Privacy Guidelines: Thirty Years in the Public Sector (The Privacy Projects.org, edited by Richard Purcell) - At the 30th Anniversary of the OECD Privacy Guidelines, we present a comparative study of how those guidelines have influenced the development of laws, regulations and public policy in five representative OECD member states – Australia, Canada, Japan, Spain, and the United States. http://theprivacyprojects.org/wp-content/uploads/2009/08/Final-OECD-Privacy-Guidelines-in-the-Public-Sector.pdf

The Cyberthreat, Government Network Operations, and the Fourth Amendment (Jack Goldsmith paper, 9 Dec 2010) - Many corporations have intrusion-prevention systems on their computers’ connections to the Internet. These systems scan the contents and metadata of incoming communications for malicious code that might facilitate a cyber attack, and take steps to thwart it. The United States government will have a similar system in place soon. But public and private intrusion-prevention systems are uncoordinated, and most firms and individual users lack such systems. This is one reason why the national communications network is swarming with known malicious cyber agents that raise the likelihood of an attack on a critical infrastructure system that could cripple our economic or military security. To meet this threat, imagine that sometime in the near future the government mandates the use of a government-coordinated intrusion-prevention system throughout the domestic network to monitor all communications, including private ones. Imagine, more concretely, that this system requires the National Security Agency to work with private firms in the domestic communication network to collect, copy, share, and analyze the content and metadata of all communications for indicators of possible computer attacks, and to take real-time steps to prevent such attacks. This scenario, I argue in this essay, is one end point of government programs that are already up and running. It is where the nation might be headed, though perhaps not before we first suffer a catastrophic cyber attack that will spur the government to take these steps. Such a program would be controversial. It would require congressional approval and in particular would require mechanisms that credibly establish that the NSA is not using extraordinary access to the private network for pernicious ends. But with plausible assumptions, even such an aggressive program could be deemed consistent with the U.S. Constitution, including the Fourth Amendment. http://www.brookings.edu/papers/2010/1208_4th_amendment_goldsmith.aspx Paper here: http://www.brookings.edu/~/media/Files/rc/papers/2010/1208_4th_amendment_goldsmith/1208_4th_amendment_goldsmith.pdf

**** FUN ****
Law and the Multiverse; Superheroes, supervillains, and the law (blog) – If there’s one thing comic book nerds like doing it’s over thinking the smallest details. Here we turn our attention to the hypothetical legal ramifications of comic book tropes, characters, and powers. Just a few examples: Are mutants a protected class? Who foots the bill when a hero damages property while fighting a villain? What happens legally when a character comes back from the dead? [Creative, out of-the-box subject matter for lawyers: e.g., how does The Rule Against Perpetuities play if you’re immortal? or “Fee Simple and Alter-Egos” and “Is Batman a State Actor?”] http://lawandthemultiverse.com/

**** DIFFERENT ****
Lapsed Magazine Subscriptions (InsideHigherEd, 9 Dec 2010) - The most important shift brought about by the Web has been to move more of us from being consumers to producers. The fact that you are reading this blog now, and maybe will comment on the post - or tweet or blog yourself, is testament to this fact. Distressingly, the practice of higher ed has largely lagged this transition - too little of our student's time is spent producing for the world (writing, making videos, posting and sharing) - and too much time is still spent consuming words from the mouths of our professors. Today, in some of our courses and on some of our campuses, the transition to student as producer (student as research, student as writer, student as colleague), has already begun. In some courses, the lecture model has been inverted - so that the student time shifts lecture material at her convenience - and precious in-person class time is spent debating, discussing, creating, and sharing. In some courses and on some campuses, the Web has transformed learning into an active experience in the same way that the Web has transformed media. Which brings me to the subject of magazines in which I no longer subscribe. I'm somewhat saddened by my abandoned identity of a magazine subscriber. In days past, most of us defined ourselves by what we consumed. Magazines were a big part of my self-identity. Now, with more time spent writing - I have less time to consume - and many more options to consume via the Web in small chunks. The reams of paper that previously moved through my home have been replaced mostly by bits - but I'm nostalgic for those days of magazines strewn around the house. http://www.insidehighered.com/blogs/technology_and_learning/lapsed_magazine_subscriptions

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
MOVING ON TO M-COMMERCE -- In the rapidly growing market for “m-commerce” (e-commerce via mobile devices), Motorola is staking out new ground with a purchasing system for mobile phones that features voice-activated authentication of credit cards. Rather than typing numbers on a phone keypad to make a purchase, customer credit card numbers are stored on the cell-phone operator’s computer server. Once the customer approves a purchase, the information is sent from the server to the online merchant. In some cases, customers can choose items to buy and approve credit card purchases simply by speaking commands into the phone. The technology is based on software from Trintech Group. (Wall Street Journal 2 Feb 2000) http://wsj.com/

**** NOTES ****
MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks. You can subscribe to the MIRLN distribution list by sending email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line. Unsubscribe by sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln. Get supplemental information through Twitter: http://twitter.com/vpolley)

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu
2. InsideHigherEd - http://www.insidehighered.com/
3. SANS Newsbites, sans@sans.org
4. NewsScan and Innovation, http://www.newsscan.com
5. BNA’s Internet Law News, http://ecommercecenter.bna.com
7. McGuire Wood’s Technology & Business Articles of Note
8. Steptoe & Johnson’s E-Commerce Law Week
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/
10. Law.com
11. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.