Saturday, April 06, 2013

MIRLN --- 17 March – 6 April 2013 (v16.05)

MIRLN --- 17 March - 6 April 2013 (v16.05) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | RESOURCES | BOOK REVIEW | LOOKING BACK | NOTES

Investors Demand Cyber Security Transparency (Carlton Fields, 5 March 2013) - Almost daily we hear about a new cyber threat or information security breach. Just last week one of the world's largest cloud services providers, Evernote, fell victim to an attack that resulted in a security breach that potentially compromised more than 50 million user accounts. As corporate America becomes better informed about the cyber threats facing U.S. companies, investors will demand more information and transparency about a company's information security policies and practices. A recent survey conducted by Zogby Analytics raises serious concerns for C-suite managers who are simultaneously facing increased scrutiny from regulators, increased demands from investors, and a need to remain mindful of the damage negative press can have on stock prices. According to the Zogby survey, 70 percent of investors are interested in reviewing company cyber security practices and almost 80 percent would likely not consider investing in a company with a negative history of attacks. Notably, the survey also found that 66 percent of investors said corporate responses to attacks are more noteworthy than the attacks themselves. Additionally, the survey revealed investors are twice as concerned if a company had a breach of customer data (57 percent) as opposed to a theft of intellectual property (29 percent). While consumer-related data breaches grab headlines, the findings on intellectual property theft are particularly alarming. They demonstrate a fundamental misunderstanding of the damage that billions of dollars' worth of intellectual property theft can have on a company's bottom line.

top

Are Governments Ready to be Buyers of Cybersecurity Insurance? (Public CIO, 8 March 2013) - South Carolina is learning the hard way that the costs associated with a data breach can spiral upward in a hurry. Last year, hackers infiltrated a Department of Revenue computer system and swiped millions of unencrypted Social Security numbers and other personally identifiable information. The state reportedly has spent more than $20 million so far cleaning up the mess, including $12 million on credit monitoring services for affected citizens, and millions more on breach notification letters, security improvements, data forensics teams and IT consultants. And South Carolina isn't done opening its wallet - state agencies beyond the revenue department likely will request more funding to make IT security improvements of their own. Although South Carolina's woes are an extreme example - one security expert branded the hacking "the mother of all data breaches" - the incident shows how much an organization should expect to pay out to remediate a large-scale data breach. Other government agencies are dealing with the sticker shock. A separate high-profile breach last year of health-care data in Utah, for example, is costing millions; officials there spent hundreds of thousands of dollars alone on a crisis communications team. These figures aren't outliers: A study conducted last year by the Ponemon Institute found that cybercrime cost the average U.S. organization $8.9 million annually. Some public-sector officials and brokers in the insurance industry think the time has come to apply these same principles in the world of government IT. A small portion of local and state governments already have purchased what's known as "cybersecurity insurance," and at least a few officials think it's time to start talking about the idea more seriously. "The probabilities are such, because your networks and services are so complex and integrated now, that you can't cover up every manhole. Sooner or later someone is going to get through," said Dick Clark, the former CIO of Montana who retired last year, about the state's rationale for buying cyberinsurance. Montana recently joined the few states believed to carry some form of the insurance. Clark said if Montana suffered a South Carolina-style data breach, his state would have a tough time covering the $10 million or $20 million cost. Montana likely would have to raid its general fund to cover the expense, he said. States and cities, Clark said, need to be aware that a data breach can bring a swath of unplanned costs.

top

Which Encryption Apps Are Strong Enough to Help You Take Down a Government? (Gizmodo, 10 March 2013) - It seems like these days I can't eat breakfast without reading about some new encryption app that will (supposedly) revolutionize our communications - while making tyrannical regimes fall like cheap confetti. This is exciting stuff, and I want to believe. After all, I've spent a lot of my professional life working on crypto, and it's nice to imagine that people are actually going to start using it. At the same time, I worry that too much hype can be a bad thing - and could even get people killed. Given what's at stake, it seems worthwhile to sit down and look carefully at some of these new tools. How solid are they? What makes them different/better than what came before? And most importantly: should you trust them with your life? To take a crack at answering these questions, I'm going to look at four apps that seem to be getting a lot of press in this area. In no particular order, these are Cryptocat , Silent Circle [by Phil Zimmerman], RedPhone and Wickr * * *

top

Court Rules That Prosecutors Can Use E-mail Sent by Personal Attorney to Employee's Work Account (Suits By Suits, 18 March 2013) - Employees use their work e-mails for all kinds of communications, from the business-related to the personal and private. When a dispute arises, however, it's getting more difficult to keep those private e-mails from seeing the light of day. For example, last week's Inbox highlighted one recent decision in which a New York federal court ruled that an executive had "no reasonable expectation of confidentiality or privacy" in his work e-mail. United States v. Finazzo , No. 10-CR-457 (E.D.N.Y. Feb. 19, 2013). Finazzo is different from most of the cases we cover on this blog (with the exception of this post last week ) because it is a criminal case. The defendant is Christopher Finazzo, a former executive at Aeropostale , who was indicted on charges of mail fraud and false statements to the SEC. The government based the charges on Finazzo's undisclosed interest in one of Aeropostale's vendors, a company called South Bay. Aeropostale found out about Finazzo's role in South Bay when its investigator uncovered an e-mail that Finazzo's personal attorney sent to his work account, in which the attorney listed assets to be considered for the drafting of Finazzo's will. In the criminal case, Finazzo moved to keep the government from using the e-mail at trial, arguing that it was a privileged attorney-client communication. The court denied his motion, finding that the e-mail was not a confidential or private document. In assessing the privacy of the document, the court weighed a number of factors * * *

top

Who Owns a MOOC? (InsideHigherEd, 19 March 2013) - Faculty union officials in California worry professors who agree to teach free online classes could undermine faculty intellectual property rights and collective bargaining agreements. The union for faculty at the University of California at Santa Cruz said earlier this month it could seek a new round of collective bargaining after several professors agreed to teach classes on Coursera , the Silicon Valley-based provider of popular massive open online classes, or MOOCs. The union said the professors lobbied for a 12-year-old California law to guarantee that faculty -- not universities -- own the intellectual property rights to class lectures and course materials. But before professors can have their courses put on Coursera, they are expected to sign away those rights to the university so the university can give the professors' work to Coursera, the union said in a March 5 letter to a top labor relations official at Santa Cruz. In these waivers, professors "irrevocably grant the university the absolute right and permission to use" their course content, name, image and likeness. The university's own contract with Coursera remains neutral and said only that rights will "remain with the applicable instructor and university." [Polley: implicates the informal "Faculty Exception" to the work-for-hire doctrine (see, e.g., page 30 of this AAUP document ).]

top

Justice Dept. Drops Fight Against Tougher Rules to Access E-Mail (Washington Post, 19 March 2013) - The Justice Department has dropped its long-standing objection to proposed changes that would require law enforcement to get a warrant before obtaining e-mail from service providers, regardless of how old an e-mail is or whether it has been read. "There is no principled basis" to treat e-mail less than 180 days old differently than e-mail more than 180 days old, Elana Tyrangiel, acting assistant attorney general in the department's Office of Legal Policy, said Tuesday. Tyrangiel, testifying before a House Judiciary subcommittee, also said that opened e-mail should have no less protection than unopened e-mail. Current law requires law enforcement to obtain a warrant before gaining access to e-mail that is 180 days old or less if it has not been opened. But prosecutors may obtain e-mail older than 180 days, or any e-mail that has been opened, with a mere subpoena. The department's shift means that legislative efforts to amend the 1986 Electronic Communications Privacy Act stand a better chance at succeeding. Lawmakers have drafted legislation that would impose a warrant requirement for all e-mail held by commercial providers. In practice, since a 2010 ruling by the U.S. Court of Appeals for the 6th Circuit requiring a warrant for stored e-mail, most large commercial e-mail providers, such as Google and Yahoo, have adopted that standard.

top

Minnesota Modifies Liberal Open Records Law to Make Car Location Data Private (ArsTechnica, 19 March 2013) - A Minnesota state agency decreed on Monday that a vehicle's location data as captured by license plate readers , which under existing state law had been completely public, should now be kept private. This comes more than four months after a Minneapolis public committee lobbied to change the state's policy. The new temporary measure will expire in 2015. According to the Minneapolis Star-Tribune : "The Department of Administration ruled Monday that the following data generated by license plate readers would be private: plate numbers; times, dates, and locations of vehicle scans; and vehicle photos." As we reported earlier , Minnesota has a rather liberal open records state law known as the Data Practices Act , which makes all government data public by default. That means that anyone (up until now) could request the entire data set-including license plate data-from any law enforcement agency. In December 2012, Minneapolis mayor R.T. Rybak requested to a state committee that the data be immediately re-classified as "non-public." The new proposal resulted from increased scrutiny of the practice in Minneapolis after a local reporter managed to track the mayor's movements in August 2012 by filing a request with the police.

top

In Depth: The District Court's Remarkable Order Striking Down the NSL Statute (EFF, 19 March 2013) - On Friday, EFF received the long-awaiting ruling on its 2011 petition to set aside a National Security Letter (NSL) issued to a telecommunications company. The petition challenged the constitutionality of one of five national security letter statutes, 18 U.S.C. § 2709 . And what a ruling it was. In a detailed and careful 24-page opinion , Judge Susan Illston of the district court for the Northern District of California methodically addressed the government's attempted justifications for this controversial domestic surveillance tool and found that the statute failed to meet the standards of settled First Amendment law. First, a moment to underscore the importance of this ruling. Over the past decade, since the PATRIOT Act expanded its reach from foreign agents and spies to anyone whose information may be "relevant" to a national security investigation, the FBI has issued hundreds of thousands of NSLs seeking potentially intimate information about Americans. Supporters of NSLs have frequently attempted to discount privacy concerns and have characterized criticism as " hyperbole ," but the reality is very different. As Judge Victor Marrero of the Southern District of New York noted in his 2004 Doe v. Ashcroft NSL decision, the NSL statute grants enormous, unchecked power to pry into the private lives of people within the United States * * *. With Friday's opinion, entitled In Re National Security Letter, not only did the court set aside this particular letter, it barred any NSLs to telecommunications providers, finding that the statute was so inherently flawed that it could not stand. The decision will likely be appealed, and the order has been stayed in order to give the government the time to file an appeal, but the federal district court deserves enormous credit for not shying away from EFF's request and instead tackling most of the difficult issues head on. With this case, EFF follows in the strong footsteps of our friends at the ACLU. In 2008, on behalf of Nicholas Merrill , the ACLU succeeded in convincing both a district court and the Second Circuit Court of Appeals to recognize the acknowledge the serious structural problems with the NSL statute. Unfortunately, despite finding the statute unconstitutional, the Second Circuit in its Doe v. Mukasey opinion approved the continued use of NSLs if the FBI undertook certain voluntary measures aimed at curbing abuse. The district court here found similar constitutional flaws but took those problems to their rightful conclusion. The court flatly rejected the Second Circuit's attempts to rewrite the statute and rely on voluntary FBI actions to fix it, instead striking it down. While the decision rested primarily on failings with the gag provision, the court ruled that that provision was not severable from the rest of the statute and struck the statute in its entirety. As a result, if the decision is upheld, Congress must step in and repair the structural defects to better protect First Amendment rights if it intends to continue to grant similar power to the FBI. The court made five critical findings * * *

top

Supreme Court Sides with Bookseller in Major Copyright Ruling, Says Resale is OK (PaidContent, 19 March 2013) - In a court ruling that has major implications for used good merchants across the country, the Supreme Court overturned a lower court decision that forbid a textbook seller from reselling textbooks that he had purchased from overseas. In a 6-3 ruling , the court rejected publisher John Wiley's interpretation of a rule known as the " first sale doctrine " which prevents copyright owners from exerting rights over a product once it has been purchased legally. This rule is what allows used book and music stores to sell used items without the copyright owners permission. In recent years, copyright owners facing a wave of imported good have argued that the "first sale" only applies to goods manufactured in the United States. Lower courts have till now sided with the copyright owners which has produced considerable uncertainty about whether or not retailers good import and sells goods that they had legally bought from abroad. Writing for the majority, Justice Stephen Breyer rejected John Wiley's argument that the phrase "lawfully made under this act" implied a geographic limitation. He also referred to library associations, used-book dealers, technology companies, consumer-goods retailers, and museums - all of which had urged the court to reject the restricted notion of "first sale." The John Wiley ruling comes three years after the Supreme Court failed to resolve the same issue in a dispute between watch maker Omega and the retailer Costco. In that case, Omega had put little pictures on its watches and then argued that Costco infringed on its copyright when it imported them; that case produced a 4-4 tie which meant the lower ruling against Costco was upheld. The result was different this time with different judges on the bench. The ruling is likely to be a relief for used booksellers and others who feared that geographical limits on first sale would harm their business. In the case before the Supreme Court, the defendant was a college student who had arranged for his family in Asia to buy textbooks and mail them to him in America where he sold them at a profit. Justices Ginsburg, Kennedy and Scalia dissented from the ruling. To learn more about the first sale doctrine, read our background on the Wiley case here . [Polley: Dennis Crouch's Patently-O has an analysis of the case, suggesting that it also has implications for the patent exhaustion doctrine. EFF's take on the case is here .]

top

Courses, Facebook, and Secret Groups (InsideHigherEd, 21 March 2013) - Our students are leveraging the web and mobile apps to collaborate, share information, and study together.

They are sharing online resources such as videos and learning objects Khan Academy, digital textbook resources, YouTube, iTunesU, and other open online education resources.

Students are actively sharing information about study strategies and techniques designed to help each other learn the material and do well on quizzes, tests, and papers.

There is a world of social learning going on, and we (meaning us instructors, educational technologists - basically anyone employed on the instructional or administrative sides of the house), know nothing about what is going on. 

 The reason: Facebook Secret Groups. 

 To quote from the Facebook privacy option description page:

 Secret: Non-members can't find these groups in searches or see anything about the group, including its name and member list. The name of the group will not display on the timelines of members. To join a secret group, you need to be added by a member of the group. 

What is so appealing for students about Facebook Secret Groups is that instructors, or anyone else that works for the school, can't access the group. We can't even know that the group exists. An enormous amount of really high quality is learning going on on our networks and our campuses, but it is completely invisible to all of us. Facebook Secret Groups for classes means that our students are taking control of their learning. Freed from instructor and administrative surveillance and judgment they are able to learn in ways that fit their needs, not ours. They can be critical of our teaching, dismissive of our learning technologies, and disparaging of assignments - all without fear of retribution by grading.

top

Whole Internet Probed for Insecure Devices (BBC, 21 March 2013) - A surreptitious scan of the entire internet has revealed millions of printers, webcams and set-top boxes protected only by default passwords. An anonymous researcher used more than 420,000 of these insecure devices to test the security and responsiveness of other gadgets, in a nine-month survey. Using custom-written code, they sent out more than four trillion messages. The net's current addressing scheme accommodates about 4.2 billion devices. Only 1.3 billion addresses responded. The number of addresses responding was a surprise as the pool of addresses for that scheme has run dry. As a result, the net is currently going through a transition to a new scheme that has a vastly larger pool of addresses available. The scan found half a million printers, more than one million webcams and lots of other devices, including set-top boxes and modems, that still used the password installed in the factory, letting almost anyone take over that piece of hardware. Often the password was an easy to guess word such as "root" or "admin". "Whenever you think, 'That shouldn't be on the internet, but will probably be found a few times,' it's there a few hundred thousand times," wrote the un-named researcher in a paper documenting their work . HD Moore, who carried out a similar survey in 2012, told the Ars Technica news website the results looked "pretty accurate".

top

Michigan's Internet Privacy Protection Act (by MIRLN subscriber Michael Khoury , March 2013) - The tempest in the teapot for 2012 was generated when applicants at educational institutions and those searching for employment were compelled to turn over their user names and passwords for social media and other accounts. According to an April 2012 report by the Council of State Governments, "State Leaders Work to Protect the Privacy of Employees' and Students' Social Media Accounts,"1 the issue became significant in Michigan when a teacher's aide was fired for refusing to provide login credentials to her social media account. Late in the 2012 legislative session, Michigan became the sixth state in the United States to enact legislation addressing the privacy of individual accounts and prohibiting employers and educational institutions from taking actions related to these accounts * * *

top

AP Wins Big: Why a Court Said Clipping Content Is Not Fair Use (PaidContent, 22 March 2013) - A federal court has sided with the Associated Press and the New York Times in a closely-watched case involving a company that scraped news content from the internet without paying for it. The case has important implications for the news industry and for the ongoing debate about what counts as "fair use" under copyright law. Here's a plain English explanation of what the case is all about and what it means for content creators and free speech. The defendant in the case is Norway-based Meltwater, a service that monitors the internet for news about its clients. Its clients, which include companies and governments, pay thousands of dollars a year to receive news alerts and to search Meltwater's database. Meltwater sends its alerts to client in the form of newsletters that include stories from AP and other sources. Meltwater's reports include headlines, the first part of the story known as the "lede," and the sentence in the story in which a relevant keyword first appears. The Associated Press demanded Meltwater buy a license to distribute the story excerpts and, when the service refused, the AP sued it for copyright infringement. Meltwater responded by saying it can use the stories under copyright's "fair use" rules, which creates an exception for certain activities. Specifically, Meltwater said its activities are akin to a search engine - in the same way that it's fair use for Google to show headlines and snippets of text in its search results, Meltwater said it's fair use to clip and display news stories. The case has divided the tech and publishing communities. The influential Electronic Frontier Foundation filed in support of Meltwater, arguing that AP could inhibit innovation and free expression if it succeeds with the copyright claim. On the other side, the New York Times and other news outlets filed to support the AP ; they claim Meltwater was simply free-riding and that the company is undermining the ability to create the sort of journalism on which a free society depends. In a decision published Thursday in New York, U.S. District Judge Denise Cote shot down Meltwater in blunt language. While much of the 90-page ruling covers procedural issues and other defenses put forth by Meltwater, the heart of the decision is about fair use. Judge Cote rejected the fair use claim in large part because she didn't buy Meltwater's claim that it's a "search engine" that makes transformative use of the AP's content. Instead, Cote concluded that Meltwater is more like a business rival to AP: "Instead of driving subscribers to third-party websites, Meltwater News acts as a substitute for news sites operated or licensed by AP." Cote's rejection of Meltwater's search engine argument was based in part on the "click-through" rate of its stories. Whereas Google News users clicked through to 56 percent of excerpted stories, the equivalent rate for Meltwater was 0.08 percent, according to figures cited in the judgment. Cote's point was that Meltwater's service doesn't provide people with a means to discover the AP's stories (like a search engine) - but instead is a way to replace them. [Polley: implications for MIRLN? Fair use, or infringement? Would it be different if I charged for MIRLN? EFF's take on the case is here .]

top

A Libertarian Nightmare: Bitcoin Meets Big Government (Salon, 22 March 2013) - What's not to like about Bitcoin, every libertarian's favorite crypto-currency? For starters, Bitcoins are as cyberpunk as William Gibson's wildest dream: a form of monetary exchange invented in 2009 by a mysterious character who called himself "Satoshi Nakamoto" but then disappeared from view after unleashing his virtual currency upon the world. Bitcoins are undeniably cool: marvelously "mined" from the ore of computer processing power and electricity; more ready for prime time than any previous experiment in purely digital money. And Bitcoins, increasingly, are a success. At a Thursday afternoon all-time-high valuation of $72 per Bitcoin, there were around $700 million worth of Bitcoins in circulation. People are using Bitcoins to buy real goods and services, to hedge against European financial calamity, and to score drugs. That's money. Over the years, Bitcoin has experienced ups and downs; the currency has been targeted by hackers and thieves and botnets and been victim to more than one embarrassing software glitch. But it has persevered, and this week, one can fairly say that Bitcoin came of age. On Monday, the U.S. Treasury's Financial Crimes Enforcement Network (FinCEN) released its first " guidance " as to how "de-centralized virtual currencies" should fit into the larger regulatory regime under which currencies of all kinds are required to operate. The word "Bitcoin" is never mentioned in FinCEN's release, but that's just a technicality. Everyone in the Bitcoin community knew who the guidance was aimed at. Bitcoin is a big boy now. The State is paying attention. But while some observers have applauded FinCEN's guidance as acknowledgment that Bitcoin isn't illegal or considered a "threat" by the government, not everyone is cheering the news. Because there's a problem here. Bitcoin isn't just an elegant way to create money using peer-to-peer networks and cryptography. Bitcoin is a currency with an ideology. * * * [Polley: Spotted by MIRLN reader Corinne Cooper of Professional Presence ]

top

First Amendment Protects Online Republication of Court Records (Eric Goldman, 23 March 2013) - The court summarizes the facts: Nieman discovered in 2009 that certain legal-search websites (such as Lexis/Nexis.com, Justia.com, Leagle.com, and VersusLaw.com) were linking copies of documents from his prior lawsuit to his name. That litigation involved a former employer and was settled in 2011. When Nieman encountered difficulty obtaining another insurance job, he suspected that potential employers had learned of his prior lawsuit online and "blacklisted" him from employment opportunities. Nieman alleged that in late 2011 he wrote to each of the defendants and asked them to delink his court cases from their online search results. The defendants declined. The court's efficient disposition of the resulting lawsuits (citations omitted): The First Amendment privileges the publication of facts contained in lawfully obtained judicial records, even if reasonable people would want them concealed. We have explained that judicial "[o]pinions are not the litigants' property. They belong to the public, which underwrites the judicial system that produces them." Other legal documents included by the court as part of the public record of the judicial proceedings are also covered by the First Amendment privilege. The forprofit nature of the defendants' aggregation websites does not change the analysis; speech is protected even when "carried in a form that is 'sold' for profit." All of Nieman's claims are based on the defendants' republication of documents contained in the public record, so they fall within and are barred by the First Amendment privilege. The district court also relied on 47 USC 230; the Seventh Circuit doesn't address that issue. Nieman v. VersusLaw, Inc. , 2013 WL 1150277 (7th Cir. March 19, 2013)

top

The Dangers of Surveillance (Harvard Law Review, 25 March 2013) - Abstract: From the Fourth Amendment to George Orwell's Nineteen Eighty-Four, our law and literature are full of warnings about state scrutiny of our lives. These warnings are commonplace, but they are rarely very specific. Other than the vague threat of an Orwellian dystopia, as a society we don't really know why surveillance is bad, and why we should be wary of it. To the extent the answer has something to do with "privacy," we lack an understanding of what "privacy" means in this context, and why it matters. Developments in government and corporate practices, however, have made this problem more urgent. Although we have laws that protect us against government surveillance, secret government programs cannot be challenged until they are discovered. And even when they are, courts frequently dismiss challenges to such programs for lack of standing, under the theory that mere surveillance creates no tangible harms, as the Supreme Court did recently in the case of Clapper v. Amnesty International. We need a better account of the dangers of surveillance. This article offers such an account. Drawing on law, history, literature, and the work of scholars in the emerging interdisciplinary field of "surveillance studies," I explain what those harms are and why they matter. At the level of theory, I explain when surveillance is particularly dangerous, and when it is not. Surveillance is harmful because it can chill the exercise of our civil liberties, especially our intellectual privacy. It is also gives the watcher power over the watched, creating the risk of a variety of other harms, such as discrimination, coercion, and the threat of selective enforcement, where critics of the government can be prosecuted or blackmailed for wrongdoing unrelated to the purpose of the surveillance. At a practical level, I propose a set of four principles that should guide the future development of surveillance law, allowing for a more appropriate balance between the costs and benefits of government surveillance.

top

US Attorney Asserts Jurisdiction in International Cases Because of Computer Server Location (ABA Journal, 26 March 2013) - U.S. Attorney Neil MacBride of the Eastern District of Virginia is claiming jurisdiction to pursue cases against alleged international copyright pirates and out-of-state securities fraud defendants, citing the location of computer servers in his district. The Associated Press explains. MacBride says he has jurisdiction over most securities fraud cases because the servers for the EDGAR database of the Securities and Exchange Commission are located in Alexandria. He also claimed jurisdiction to bring charges against the Hong Kong file-sharing company Megaupload because many of the servers storing its content were leased from a northern Virginia company. A lawyer for Megaupload, Ira Rothken, has questioned prosecutors' theory that they have jurisdiction in the criminal copyright case because Internet traffic flows through their district. He is claiming a foreign corporation without U.S. offices cannot be prosecuted in this country. Megaupload officials are currently fighting extradition to the United States. [Polley: crazy, the idea of EDGAR-based jurisdiction; wrong, the idea that Megaupload is in HK - try New Zealand.]

top

Leading Library Journal's Editorial Board Resigns Over Publisher's Copyright Policy (MLPB, 26 March 2013) - The Chronicle of Higher Education reports that the editorial board of the Journal of Library Administration , a leading publication in the area of library management, has resigned en masse over the publisher's copyright policy. The now former editor, Damon Jaggers, notes that Taylor and Francis, the publisher of the journal, did negotiate with reluctant authors who objected to its previous policy, but the new policy requires potential authors to ante up $3,000 to publish with the journal.

Science Blogs reproduces the editorial board's resignation announcement here, along with some commentary. Below is the notification from the board: The Board believes that the licensing terms in the Taylor & Francis author agreement are too restrictive and out-of-step with the expectations of authors in the LIS community. A large and growing number of current and potential authors to JLA have pushed back on the licensing terms included in the Taylor & Francis author agreement. Several authors have refused to publish with the journal under the current licensing terms. Authors find the author agreement unclear and too restrictive and have repeatedly requested some form of Creative Commons license in its place. After much discussion, the only alternative presented by Taylor & Francis tied a less restrictive license to a $2995 per article fee to be paid by the
Author. As you know, this is not a viable licensing option for authors from the LIS community who are generally not conducting research under large grants. Thus, the Board came to the conclusion that it is not possible to produce a quality journal under the current licensing terms offered by Taylor & Francis and chose to collectively resign.

top

Public Cloud Service Agreements: What to Expect and What to Negotiate (Cloud Standards Customer Council, 30 March 2013) - For datacenters that have already leveraged outsourced infrastructure, the value of service level objectives and their formal contracts is understood. For datacenters that are using clouds as their first entrée into outsourced infrastructure, service agreements may be totally new. IT managers are not comfortable relying on infrastructure and infrastructure management that are outside their immediate control. Therefore, they are quickly realizing that they cannot guarantee a required level of service without understanding their objectives and formalizing such service level with organizations that are on the critical path of their business services delivery. This paper provides cloud consumers with a pragmatic approach to understand and evaluate public cloud service agreements. The recommendations in this paper are based on a thorough assessment of publicly available agreements from several leading public cloud providers. In addition to this paper, a great deal of research and analysis regarding the landscape of cloud service agreements is available in the CSCC companion paper, the "Practical Guide to Cloud Service Level Agreements". In general, we have found that the current terms proposed by public cloud providers fall short of the commitment that many businesses will require. Of course, these providers have reputations to establish or maintain, therefore they will likely employ all reasonable efforts to correct problems, restore performance, protect security, and so on. But neither the specifics of the measures they will take, nor the remedies they offer if they fall short, are currently expressed well enough in their formal agreements in most cases. Furthermore, the language about service levels is often distributed among several documents that do not follow a common industry-wide terminology. We hope that one impact of this paper will be to improve this state of affairs. [Polley: Spotted by MIRLN reader Claude Baudoin of Cebe IT & Knowledge Management ]

top

When Social Media at Work Don't Create Productivity-Killing Distractions (Bloomberg, 1 April 2013) - Workers who are encouraged to tweet, chat, like, and Skype on the job are among the most productive, new academic research says, shooting yet another hole in the managerial argument that social media in the workplace leads to goofing off and slacking on company time. Far from being a distraction, common social media tools such as Facebook, Twitter, and LinkedIn, plus Skype to chat, enable employees to answer more customer queries, and more quickly, says Joe Nandhakumar, professor of information systems at the Warwick Business School in the United Kingdom. He and his research team attribute this productivity boost to something Nandhakumar calls the "theory of virtual co-presence"-the ability to collaborate with others over long distances in relatively short, productive sessions to resolve problems or accomplish tasks. Plenty of surveys and studies have looked at the benefits of granting employees unfettered social media access in the workplace, often focusing on increased collaboration among co-workers and, at the very least, keeping companies digitally savvy enough to compete for young talent . The Warwick Business School study is unique: Over more than two years, it followed the way a company's policy to encourage social media usage among its employees led to increased customer interaction and, eventually, higher productivity.

top

Toward an International Law of the Internet (BeSpacific, 2 April 2013) - Toward an International Law of the Internet, Molly Land, New York Law School, November 19, 2012, Harvard International Law Journal, Vol. 54, 2013 (Forthcoming) via SSRN : "This Article presents the first and only analysis of Article 19 of the International Covenant on Civil and Political Rights as it applies to new technologies and uses this analysis to develop the foundation for an "international law of the Internet." Although Article 19 does not guarantee a right to the "Internet" per se, it explicitly protects the technologies of connection and access to information, and it limits states' ability to burden content originating abroad. The principles derived from Article 19 provide an important normative reorientation on individual rights for both domestic and international Internet governance debates. Article 19's guarantee of a right to the technologies of connection also fills a critical gap in human rights law. Protecting technology allows advocates to intervene in discussions about technological design that affect, but do not themselves violate, international human rights law. Failure to attend to these choices - to weigh in, ahead of time, on the human rights implications of software code, architecture design, and technological standards - can have significant consequences for human rights that may not be easily undone after the fact."

top

Law Firms Offer Cybersecurity Advice and Attorney-Client Privilege to Hacked Companies (ABA Journal, 2 April 2013) - Law firms are getting involved as companies investigate hacker incidents, providing attorney-client privilege to shield the findings in future lawsuits. The Wall Street Journal has a story on the trend. In one example, Nationwide Insurance hired Ropes & Gray after a hacker obtained personal details about 1 million people from the insurer. In another, Alston & Bird hired a former Justice Department lawyer in January to head its security-incident and management-response team. The lawyer, Kimberly Peretti, was a senior lawyer in the department's Computer Crime and Intellectual Property Section. Mike Dubose, who leads Kroll Advisory Solutions' cyberinvestigations practice, advises clients to hire a law firm before it hires Kroll. He explained that a client who hires Kroll directly probably won't be protected by attorney-client privilege. "What a company does not want is its investigation or due diligence, undertaken with the best of intentions, to be used against it in litigation," Dubose told the Wall Street Journal. [Polley: possibly great for protecting privilege; not-so-great for solving the problem unless the hired lawyer(s) are tech-fluent and already know your business inside-out. Further, almost all such internal investigations would/should have a non-privileged component, designed for ultimate disclosure to regulators or other non-control audiences. It's a real trick to manage a dual-track privileged/non-privileged internal investigation, and all the harder if counsel doesn't "grok" the technology.]

top

Social Media: SEC Issues Reg FD Guidance (In Form of Enforcement Report) (CorporateCounsel.net, 3 April 2013) - Last month, the SEC's Division of Investment Management issued this guidance in an effort to clarify when mutual funds must file social media messaging with the SEC. The guidance provides 5 categories of communications that IM doesn't believe needs to be filed - and examples of communications that do. At the time, I thought Corp Fin might weigh in with its own social media guidance soon - particularly due to widespread criticism in the wake of news that Netflix had received a Wells Notice from the Division of Enforcement (see my own blog on this topic - and Prof. Joe Grundfest's amicus curiae brief ). The answer is "yes, sort of." Yesterday, the SEC issued this Section 21(a) Report of Investigation stating that Enforcement has decided not to go after Netflix - mostly because its 2008 "corporate use of website" guidance may not have been sufficiently clear about how it applies to social media (given that social media exploded onto the scene more recently). More importantly, the Report clarifies that the SEC's '08 framework is sufficiently flexible to accommodate new "push" technologies like Facebook and Twitter - so that companies should continue to apply their own facts against whether they have created a "recognized channel of distribution" using that framework. Even though the SEC's press release touts the new report as a greenlight for companies - the press release's title is "SEC Says Social Media OK for Company Announcements If Investors Are Alerted" - I'm dubious that companies and their advisors will see it that way. For starters, the new guidance comes from an Enforcement report (here's an explanation of what a Section 21(a) report is) - perhaps not the best vehicle to encourage new practices. And it doesn't get into the nitty gritty like IM's new guidance does. Given the slow adoption rate of social media by IR, finance and governance professionals - compared to the rest of the world - I'm not convinced this will be enough to get folks moving (for example, see this blog by Blank Rome's Yelena Barychev and this Cooley news brief from Cydney Posner). [Polley: see also Bloomberg Adds Twitter Feeds to Financial Platform on Heels of New SEC Rules (PaidContent, 4 April 2013)]

top

If You Were 17, It Could Have Been Illegal To Read Seventeen.com Under the CFAA (EFF, 3 April 2013) - If you are 17 or under, a federal prosecutor could have charged you with computer hacking just for reading Seventeen magazine online-until today. It's not because the law got any better. Earlier today, we wrote about news sites that alarmingly prohibit their youth audiences from accessing the news and the potential criminal consequences under the Computer Fraud and Abuse Act . In response, the Hearst Corporation modified the terms of service across its family of publications, including the Hearst Teen Network, which notably includes titles like Seventeen, CosmoGirl, Teen and MisQuince. Seventeen highlights the absurdity of giving terms of service the force of law under the CFAA. It boasts a readership of almost 4.5 million teen readers with an average age of 16 and a half, and yet, until today, the average reader was legally banned from visiting Seventeen.com. That's right, for a magazine dedicated to teen fashion, the publisher's terms explicitly restricted online access to readers 18 and older. What's worse, the Justice Department could choose to bring the might of the government to enforce this contract against a Seventeen reader who may never have even seen the agreement. Federal prosecutors have argued in court that accessing a website in violation of terms of service is a crime. If the website's terms, like Seventeen magazine's previous version , explicitly state that you must be an adult to visit their sites or participate in their interactive features, then teenagers accessing the site "without authorization" under the CFAA and could be doing jail time, according to the DOJ. Hearst removed the following line from the terms for publications ranging from the Houston Chronicle to the San Francisco Chronicle, from Popular Mechanics to Seventeen: "YOU MAY NOT ACCESS OR USE THE COVERED SITES OR ACCEPT THE AGREEMENT IF YOU ARE NOT AT LEAST 18 YEARS OLD." The revisions are dated "April 23, 2013," but presumably they meant April 3. Thank you Hearst, we appreciate your prompt response. But the real problem is the CFAA, which allows prosecutors to use these silly terms to manufacture computer crimes. And prosecutors have plenty of opportunities, as ridiculous terms of service abound throughout the Internet.

top

Law Firm Fell Victim to Phishing Scam, Precipitating $336k Overseas Wire Transfer, Bank Suit Alleges (ABA Journal, 4 April 2013) - A North Carolina bank claims in a lawsuit that it isn't responsible for a $336,600 wire transfer to Russia from a law firm account. The suit by Charlotte-based Park Sterling Bank claims the law firm of Wallace & Pittman fell victim to a phishing scam that began with a click on a link in a fraudulent email, the Charlotte Observer reports. The email claimed to be from an industry group and warned that a banking transaction had failed to clear. Because of the clicked link, hackers were able to track a user's keystrokes and learn banking passwords used by Wallace & Pittman, the suit says. Hackers used the passwords to send $336,600 to a "Konstantin Pomogalove" in Moscow, according to legal documents cited by the newspaper. After receiving notice of the transaction, the law firm immediately sought to stop the transfer. Nevertheless, he call was too late, the story says. Park Sterling Bank initially refunded the money then told the law firm it wanted the funds returned. Before the bank could debit the amount, the law firm obtained a restraining order and closed its account. Park Sterling Bank says the law firm should have opted for a higher security level that requires two approvals for wire transfers, and says the law firm is responsible for the loss under its customer agreement. Wallace & Pittman, on the other hand, claims the international nature of the wire transfer should have raised the bank's suspicions, and the institution should have warned of phishing scams. [Polley: nearly on-point case decided against the bank's customer here .]

top

RESOURCES

Cloud Ethics Opinions (ABA's LTRC, March 2013) - There's a compelling business case for cloud computing, but can lawyers use it ethically? We've compiled these comparison charts to help you make the right decision for your practice. [Polley: clickable State map, with links to opinions and other resources.]

top

The Fair Use/Fair Dealing Handbook (InfoJustice.org, 27 March 2013) - More than 40 countries with over one-third of the world's population have fair use or fair dealing provisions in their copyright laws. These countries are in all regions of the world and at all levels of development. The broad diffusion of fair use and fair dealing indicates that there is no basis for preventing the more widespread adoption of these doctrines, with the benefits their flexibility brings to authors, publishers, consumers, technology companies, libraries, museums, educational institutions, and governments. Fair dealing was first developed by courts in England in the eighteenth century, and was codified in 1911. Fair dealing became incorporated into the copyright laws of the former British Imperial territories, now referred to as the Commonwealth countries. Over the past century, the fair dealing statutes have evolved in many of the Commonwealth countries, and increasingly resemble the fair use statute in the United States. Thus, although fair dealing is generally considered to be less flexible and open-ended than fair use, this is no longer the case in many Commonwealth countries. This handbook contains all the fair use and fair dealing statutes we were able to identify: The Fair Use/Fair Dealing Handbook

top

BOOKS

"Trademark and Deceptive Advertising Surveys" (review by Eric Goldman, 20 March 2013) - I read only a couple of books per year. As very long-form scholarship, books usually require big blocks of time to read (and I rarely have such blocks), and I typically find the payoff isn't worth the time investment. As a result, it's rare that I read a book, rarer when I like a book, and exceptionally rare when I think a book is worth recommending to you. Yet, I can hardly contain my enthusiasm for the 2012 book, "Trademark and Deceptive Advertising Surveys: Law, Science and Design," edited by Shari Seidman Diamond and Jerre B. Swann and published by the ABA's IP Section. It may be the best book I've read in years. Why do I like this book so much? It's the *perfect* legal resource guide. The chapters are written by the leading experts in the field--names you most likely recognize, including William Barber, Jerre Swann, Bruce Keller, Shari Seidman Diamond, Itamar Simonson, Jacob Jacoby and many more. In each chapter, an expert explains how he/she handles an aspect of the consumer survey process and why he/she makes certain professional judgments. It's like having am initial consultation with, or some private coaching from, the leaders in the consumer survey field, except that they aren't billing you by the hour and they give you citations for your deeper investigation if you want. I know I'm a hardcore geek, so my experience may not be representative, but I found this book a page-turner that I couldn't put down. Every page was packed with a golden nugget or two of insight, page after page, chapter after chapter. I'm not exaggerating at all when I say that I found the book gripping.

top

LOOKING BACK - MIRLN TEN YEARS AGO

(note: link-rot has affected about 50% of these original URLs)

FCC to Begin VOIP Inquiry (CNET, 6 Nov 2003) -- The Federal Communications Commission said Thursday that it plans to formally decide whether to regulate Internet telephone companies. The FCC will begin a yearlong inquiry into the "appropriate regulatory environment for these services" on Dec. 1, the commission said in an announcement. "The FCC has been studying VoIP issues for several years, but things have greatly accelerated over the past year, and, thus, so have the FCC's actions to address the complex issues that arise," FCC Chairman Michael Powell wrote in an accompanying letter to Oregon Sen. Ron Wyden, who is sponsoring an Internet tax ban that could affect voice over Internet Protocol services. VoIP is a technology for making phone calls using the Internet Protocol, the world's most popular method for sending data from one computer to another. It requires a network connection and a PC with a speaker and a microphone or a device to convert a telephone's analog signal into IP and vice versa. Pressure has been on the FCC to make its position known on VoIP ever since a U.S. District Court shot down an attempt by regulators in Minnesota to make VoIP provider Vonage follow state telephone rules. In that court case, Vonage argued that its service uses the Internet, which has historically fallen under federal control. Vonage, BellSouth, SBC Communications and Motorola have asked the FCC to draft a nationwide policy instead of a patchwork of possibly different state regulations. States are beginning to try to regulate VoIP services, which provide many of the same functions as the traditional phone system but with different technology and at a lower cost. At stake is a key distinction between voice services, which in the past have used the Public Switched Telephone Network, and data services such as the Internet.

top

Memories in the Corner of My Eye (Wired, 11 Nov 2003) -- Trying to remember a full day's schedule is no mean feat -- especially when it's full of business meetings, grocery shopping, kids' soccer practice and music lessons, and sundry other errands. Help may be on the way from a pair of specs dubbed the memory glasses. The specs have a tiny television screen embedded into one of the lenses and are hooked up to a PDA. The PDA can be programmed to send messages or images to the screen. Each prompt is geared to jog the wearer's memory -- whether it is an image of a soccer ball, the day's calendar or the name of the guy who just said hello. And all of these messages are flashed before the eye at 1/180 of a second, so the wearer isn't even conscious that they have been sent. "The thing that's unique about my work on the memory glasses is the use of subliminal messages," said Richard DeVaul, the glasses' inventor and a doctoral student at the Massachusetts Institute of Technology's Media Lab. DeVaul said subliminal messages aren't powerful enough to stimulate action; rather, they act as prompters -- they fill in the blanks that the wearer is already searching for. The fact that the wearer is unconscious of them is, according to DeVaul, the key to his system. "We can never precisely know what the wearer needs to know, or when he needs to know it, and this is why the fact the messages are subliminal is so important. If the information given is not helpful at that time, it's not important because it isn't noticed," DeVaul said. So rather than producing a barrage of distracting pop-up messages, the system provides a noninvasive wealth of information and memory cues about appointments, shopping-list items, meeting agendas, and the spouse's birthday. And for those awkward chance meetings when you are completely at a loss as to whom you are talking to, the system can flash a name or an image of the last meeting you had with the mystery person to help jog your memory. The system can find these matches by using voice- or face-recognition technologies. DeVaul has been using off-the-shelf PDAs in tests of the glasses. The mini TV screen itself is a few millimeters square and can be integrated into the wearer's own glasses, but for the trial the MIT team has been using a clip-on version.

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, sans@sans.org

4. NewsScan and Innovation, http://www.newsscan.com

5. Aon's Technology & Professional Risks Newsletter

6. Crypto-Gram, http://www.schneier.com/crypto-gram.html

7. McGuire Wood's Technology & Business Articles of Note

8. Steptoe & Johnson's E-Commerce Law Week

9. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/

10. The Benton Foundation's Communications Headlines

11. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top

Saturday, March 16, 2013

MIRLN --- 24 February – 16 March 2013 (v16.04)

MIRLN --- 24 February - 16 March 2013 (v16.04) --- by Vince Polley and KnowConnect PLLC (supplemented by related Tweets: @vpolley #mirln)

permalink

NEWS | RESOURCES | BOOKS | LOOKING BACK | NOTES

Secretly Taping Johns is not a Privacy Violation, State's Top Court Says (ABA Journal, 20 Feb 2013) - Maine's top court has upheld the dismissal of 46 charges against a businessman accused of taping a prostitute's sexual encounters, holding that the johns have no reasonable expectation of privacy under a state law banning recording in private places. The Maine Supreme Judicial Court dismissed the invasion of privacy charges against Mark Strong in a decision (PDF) on Friday. He was accused of videotaping people who paid to have sex with dance instructor Alexis Wright, who his was his business partner in a Zumba dance studio in Kennebunk. He still faces accusations that he promoted prostitution. "Places of prostitution and people who knowingly frequent them to engage a prostitute are not sanctioned by society," the court said. "Accordingly, it is objectively unreasonable for a person who knowingly enters a place of prostitution for the purpose of engaging a prostitute to expect that society recognizes a right to be safe from surveillance while inside."

top

HTC Settles Privacy Case Over Flaws in Phones (NYT, 22 Feb 2013) - More than 18 million smartphones and other mobile devices made by HTC, a Taiwanese company that is one of the largest sellers of smartphones in the United States, had security flaws that could allow location tracking of users against their will and the theft of personal information stored on their phones, federal officials said Friday. The Federal Trade Commission charged HTC with customizing the software on its Android- and Windows-based phones in ways that let third-party applications install software that could steal personal information, surreptitiously send text messages or enable the device's microphone to record the user's phone calls. The action is the first attempt by the commission to police a manufacturer of mobile devices. As smartphones and tablets become a common way for consumers to shop, bank and chat online, personal information and privacy will need to be guarded. HTC America, based in Bellevue, Wash., agreed to settle the civil suit with the commission by issuing software patches that close the security holes, and by creating a security program that will be monitored by an independent party for the next 20 years. The F.T.C. does not have the authority to assess fines in consumer protection cases. "The company didn't design its products with security in mind," Lesley Fair, a senior lawyer in the commission's Bureau of Consumer Protection, wrote in a blog post . "HTC didn't test the software on its mobile devices for potential security vulnerabilities, didn't follow commonly accepted secure coding practices and didn't even respond when warned about the flaws in its devices."

top

Michigan Right of Publicity Law (Harvard's DMLP, 25 Feb 2013) - This page covers legal information specific to the State of Michigan. For more general information, see the Legal Guide page on Using the Name or Likeness of Another ; for other states, see State Law: Right of Publicity . Although no state appellate court in Michigan has yet explicitly recognized a common law right of publicity, the U.S. Court of Appeals for the Sixth Circuit has opined that such a right would be recognized under Michigan law. In addition, Michigan's state appellate courts have recognized comparable protection in the nature of a property right under its "appropriation" tort. The state has no corresponding statute. Publications and political organizations concerned about infringing on a plaintiff's right of publicity should note that state appellate courts have interpreted the First Amendment to protect a broad range of speech from appropriation claims. For more detail, consult the First Amendment section below. The Sixth Circuit has suggested that Michigan would recognize a right of publicity to protect a person's 'identity' in addition to their name and likeness. It would therefore be possible to violate Michigan's common law right of publicity without employing a person's photo or name. In Carson v. Here's Johnny Portable Toilets, Inc. , 698 F.2d 831 (6th Cir. 1983), the U.S. Court of Appeals for the Sixth Circuit held that the use of an identifying catchphrase ("Here's Johnny") by a portable toilet company was enough to constitute an appropriation of Johnny Carson's identity under Michigan law. In fact, the court in Carson noted that the use of Johnny Carson's full name, John William Carson, would not have infringed on his right of publicity as it is distinct from his identity as celebrity.

top

Idaho Taxes Software in the Cloud (Westlaw Insider, 25 Feb 2013) - In a surprising and troubling move for the providers and users of "cloud" computing services, state tax authorities in Idaho ruled that software provided through cloud computing networks is subject to the state's six percent sales tax. The Idaho ruling characterized all computer software as tangible property subject to tax no mater how it is made accessible to users. Use of cloud computing networks to make software accessible to consumers is increasingly popular. The process of providing software through computer networks is commonly referred to as, "software as a service." Several states, including Virginia, Nebraska, Tennessee, Kansas, Rhode Island, and Wisconsin determined that software as a service is not subject to sales tax. They concluded that sales tax should only apply when a copy of software is downloaded to the possession of the end user. Most cloud computing systems provide access to shared software and do not involve downloading of copies. Other states are developing some form of sales tax specifically for application to software as a service. Those states include Washington, Texas, Indiana, New York, and Arizona. The Idaho ruling is reportedly based on the interpretation that software made accessible through cloud networks is within the "constructive" control of the end user. Idaho authorities contend that this constructive control is sufficient to make software as a service tangible property under Idaho law. Idaho is the only state, to date, that treats software in all forms as tangible property. Providers of cloud computing services fear that the Idaho action will adversely affect the popularity of cloud services by raising the costs of use. In addition to affecting the cost of software as a service, the Idaho ruling has potentially broader impact, as well. By characterizing all computer software as tangible property, Idaho has set the foundation for broad and possibly intrusive assertion of its state law against cloud service providers operating out of other jurisdictions.

top

Iowa Retains Media/Non-Media Distinction, Leaving Bloggers Vulnerable (Berkman's DMLP, 26 Feb 2013) - I've already written several posts about the overblown predictions that a ruling involving an Oregon blogger ( now on appeal ) would have dire consequences for bloggers in that state. But a recent decision by Iowa's Supreme Court on who can be considered "news media" under Iowa law may truly endanger bloggers and other online contributors in the Hawkeye State. The issue is that the Iowa Supreme Court decided to maintain the distinction in Iowa state law between "media" and "non-media" defendants, with the latter being easier to sue for some types of libel. Bierman v. Weier , No. 10-1503, 2013 WL 203611 (Iowa Jan. 18, 2013) is a libel suit based on Scott Weier's memoir, Mind, Body and Soul , which focuses on Weier's personal transformation after his divorce from plaintiff Beth Weier. In the book Scott Weier alleged that Beth suffered from mental illness because her father, plaintiff Gail Bierman, had molested her as a child. * * *

top

ABA Issues New Opinion: Judicial Ethics and Social Media (Ride The Lightning, 28 Feb 2013) - On February 21st, the American Bar Association released Formal Opinion 462 , Judge's Use of Electronic Social Networking Media. It offers a new acronym, ESM, meaning electronic social media. Judges are allowed to participate in ESM so long as they "comply with the relevant provisions of the Code of Judicial Conduct and avoid any conduct that would undermine the judge's independence, integrity or impartiality, or create an appearance of impropriety." Nothing new there but I did note this paragraph: A judge should disclose on the record information the judge believes the parties or their lawyers might reasonably consider relevant to a possible motion for disqualification even if the judge believes there is no basis for the disqualification. For example, a judge may decide to disclose that the judge and a party, a party's lawyer or a witness have an ESM connection, but that the judge believes the connection has not resulted in a relationship requiring disqualification. However, nothing requires a judge to search all of the judge's ESM connections if a judge does not have specific knowledge of an ESM connection that rises to the level of an actual or perceived problematic relationship with any individual. That is indeed new. I like the practicality of that advice. In the same way, we have had judges note on the record, "I know Mr. Simek of Sensei Enterprises and have had some social interactions with him - does (the other side) have any objection to proceeding in this case with Mr. Simek as an expert?" Invariably, the answer is "No, your Honor" but I love the transparency. Judges who are active on social media will certainly want to read this opinion carefully. [Polley: the ABA Journal's piece on the Opinion is here .]

top

What Does Your Lawyer Want You to Know About Social Media? (Gov't Technology, 28 Feb 2013) - The benefits of social media have been well documented in the public sector. From soliciting new ideas and opinions on Facebook to sending out key announcements through Twitter, social networks have become vital communication mediums for government agencies. But while online tools have made interacting with the public more convenient, the legal pitfalls associated with social media have also been exposed. Chief among those concerns are the free speech rights of users, particularly if a government entity deletes comments off its social pages. Municipal attorneys recommend that agencies refrain from deleting user commentary on official government Facebook walls or Twitter if those pages are open to public posting, which could be construed as a public forum in the eyes of the law. A public forum is a venue open to all types of expression allowed under the First Amendment like parks and streets. However, there is an exception if the speech incites violence or is threatening. In those cases, removing the comments won't subject an agency to liability on the basis of a First Amendment challenge, according to Christina Checel, senior deputy city attorney of Long Beach, Calif. But if someone posts a statement damning city services or making a political statement that's critical of elected officials, it must remain up. That advice may seem cut and dry, but it can get murky when the commentator is an employee of or affiliated with the government agency. * * *

top

CRS - Cybersecurity: Authoritative Reports and Resources (Congressional Research Service, 28 Feb 2013) - Cybersecurity vulnerabilities challenge governments, businesses, and individuals worldwide. Attacks have been initiated by individuals, as well as countries. Targets have included government networks, military defenses, companies, or political organizations, depending upon whether the attacker was seeking military intelligence, conducting diplomatic or industrial espionage, or intimidating political activists. In addition, national borders mean little or nothing to cyberattackers, and attributing an attack to a specific location can be difficult, which also makes a response problematic. Congress has been actively involved in cybersecurity issues, holding hearings every year since 2001. There is no shortage of data on this topic: government agencies, academic institutions, think tanks, security consultants, and trade associations have issued hundreds of reports, studies, analyses, and statistics. This report provides links to selected authoritative resources related to cybersecurity issues.

top

Federal Judge Alex Kozinski Talks About Using TOR to Surf Silk Road & The Armory for Drugs, Weapons and Hitmen (TechDirt, 1 March 2013) - While I don't always agree with him (who do I always agree with?), like many folks who follow legal issues, Judge Alex Kozinski, the chief judge of the court of appeals for the 9th circuit, is one of my favorite judges. Known almost as much for his ability to entertain as for his clear, well-written (and frequently funny) judicial rulings, one thing that's always been clear is that, unlike some judges, Kozinski is both down to earth and really inquisitive when it comes to understanding how things really work, rather than just accepting common wisdom. Last night, Judge Kozinski gave a lecture at Santa Clara University on "The Two Faces of Anonymity." As I expected, it was entertaining and insightful, with a few Kozinski-esque surprises thrown in. By far the most entertaining part of the evening was Kozinski sharing (with screenshots) his experience exploring the "hidden web." He claims that when he told his children about the topic of the talk, they told him he needed to explore the hidden web. So, "with some trepidation," he downloaded Tor and dove in, starting out at Silk Road, which still remains the most well known hidden website out there. As we've noted in the past, for all the excitement and press attention Silk Road has received for being a totally anonymous online marketplace used mainly for buying and selling drugs and other illicit goods, it still is a fairly small business . Still, Judge Kozinski detailed his exploration of the market, including checking out various drugs (including many he'd never heard of before). He also looked into the ability to buy forged documents and lots of counterfeit software.

top

More Companies Reporting Cybersecurity Incidents (Washington Post, 1 March 2013) - At least 19 financial institutions have disclosed to investors in recent weeks that their computers were targets of malicious cyber­assaults last year, a sign of growing openness among corporations about the breadth of cybersecurity incidents plaguing the private sector. In their annual financial reports to the Securities and Exchange Commission, major banks such as Bank of America, Citi, Wells Fargo and JPMorgan Chase, along with smaller institutions, have reported that their systems were hit with computer disruptions or intrusions. The disclosures are significant in that for years, companies, including banks, have been loath even to acknowledge that they have been victims of such incidents. But it appears that SEC guidance issued in October 2011 making clear that companies need to report significant computerized theft or disruption, combined with greater public attention to the issue, is forcing more disclosure. Also, the fact that the banks hit by the DDOS attacks have been named in media accounts has made ignoring them more difficult. Such corporations as eBay, LinkedIn, Level 3 Communications, Chesapeake Energy and AT&T have admitted they suffered intrusions or disruptions last year. "It's almost naive for most large companies in the critical infrastructure sector to say that they aren't subject to attack," said Paul Smocer, president of BITS, a financial services trade organization.

top

Newspapers Go All-In for Copyright Fight Against Clipping Service (Ars Technica, 3 March 2013) - A copyright battle between The Associated Press and an online news-clipping service is reaching a climax, and the case could have significant implications for fair use. AP sued Meltwater Group last year, arguing the "reputation management" company had a "parasitic business model" that violated copyright. Meltwater is defending the case, arguing that it is merely a search engine. Meltwater News is a media-monitoring service that helps corporations track what's being said about them in press outlets online. The company boasts that it can "track keywords, phrases, and topics in over 192,000 sources from over 190 countries and 100 languages" throughout the day. It doesn't send its subscribers full articles, but does copy snippets and headlines then provide links to full stories-like Google News. Last week, the nation's largest newspapers lined up to tell the New York federal judge considering the case that they support the AP. An amicus brief [ PDF ] was filed by The New York Times , The McClatchy Company, Advance Publications, and the Newspaper Association of America, which represents 200 newspapers around the country. In the brief, they argue that Meltwater isn't a search engine-it's a competitor. Briefs have also been filed in this case by the Electronic Frontier Foundation and the Computer & Communications Industry Association [ PDF ], a tech industry trade group that includes Google as a member. Both groups are supporting Meltwater.

top

Google Offers Searchable Map of All White Space Spectrum in the US (ArsTechnica, 4 March 2013) - If and when White Spaces networks become a major success story, it will be a very well-organized one . Internet-capable devices will get online by accessing the empty airwaves in unused TV channels, and they'll avoid interference with actual broadcasts by connecting to databases that keep track of all available spectrum. Google today began a public test of a White Spaces database to help make this a reality. Google isn't the first to operate one of these databases, but it's done so with a very Google-like approach. In addition to letting white space devices identify available spectrum, Google unveiled a browser-based tool that lets anybody find out what spectrum is available nearby.

top

CRS - Public Access to Data from Federally Funded Research (BeSpacific, 5 March 2013) - Public Access to Data from Federally Funded Research: Provisions in OMB Circular A-110 . Eric A. Fischer, Senior Specialist in Science and Technology. March 1, 2013 : "The results of scientific studies are often used in making government policy decisions. While the studies are often published, traditional federal research funding policies did not require the data on which they are based to be made available publicly. Such policies did, however, generally require researchers to share data and physical samples with other scientists after publication of the research. A rider, often called the Shelby Amendment or Data Access Act, that was attached to the Omnibus Appropriations Act for FY1999, P.L. 105-277, mandated the Office of Management and Budget (OMB) to amend Circular A-110 to require federal agencies to ensure that "all data produced under a [federally funded] award will be made available to the public through the procedures established under the Freedom of Information Act [FOIA]." The amendment
authorizes user fees. OMB was required to make changes and release a revised circular; subsequently, agencies that chose to do so issued their own conforming rules. The final revision was published in the Federal Register on October 8, 1999, and has not been changed in subsequent updates to the circular."

top

Google Releases First Data on National Security Letters (Mashable, 5 March 2013) - Google received somewhere between zero and 999 National Security Letters requesting information about its users in each of the last four years, according to newly revealed data released by the company today. This is the first time that Google, or any other company, has published data regarding the secretive information requests. National Security Letters (NSLs), which are different from subpoenas, are used by U.S. government agencies - particularly the FBI - when investigating national security matters. Their main peculiarity is that they contain a gag order preventing the recipient from disclosing the existence of the letter itself. This means that if the FBI requests data from Google about a certain user, Google can't notify the user of such a request. That is why we know so little about the extent of their use. According to the Electronic Communications Privacy Act, the FBI can use NSLs to seek non-content data like "the name, address, length of service, and local and long distance toll billing records." For Google, this means that the FBI can't ask for "Gmail content, search queries, YouTube videos or user IP addresses," with an NSL, the company wrote in its updated FAQ .

top

FTC Staff Report Examines Growing Use of Mobile Payments Report Includes Recommendations for Industry (BeSpacific, 8 March 2013) - "As part of its efforts to ensure that consumers are protected in the growing mobile marketplace, the Federal Trade Commission issued a staff report today highlighting key issues facing consumers and companies as they adopt mobile payment services. The report, titled Paper, Plastic… or Mobile? An FTC Workshop on Mobile Payments , is based on a workshop held by the Commission in 2012 to examine these issues."

top

Why We Miss the First Sale Doctrine in Digital Libraries (John Palfrey in TheDigitalShift, 8 March 2013) - Publishers, ebook vendors, and libraries are engaged in a "tug of war" over the lending of electronic books, according to Library Journal 's recent ebook survey . This clash inhibits most libraries from fulfilling their important institutional missions to provide access to knowledge and preserve our cultural heritage. In the best case, this tug of war will be a temporary struggle. The best outcome is not a winner who holds all the rope and another lying on the ground with rope-burned hands. If there must be a winner of any kind, it ought to be the reading public. In this article, the fourth installment in a series on the initiative to build a Digital Public Library of America , I examine the underlying role of law in the ebook lending debate, explore potential solutions to the problems, and consider how the DPLA can contribute to solutions for those we serve. At the core of this issue is the way the copyright law works-or doesn't-when it comes to books, libraries, and readers in the United States today and into the future. A bit of background on the relevant law helps to set the scene for the tug-of-war. In the United States, copyright law grants to the creators of original works of authorship a bundle of exclusive rights -namely, the ability to legally exclude others from copying, adapting, distributing, displaying, and performing their creations. Should an individual (or a library, for that matter) make use of a copyrighted work in a manner that implicates one of these rights, an exception to the law must apply; otherwise, the copyright owner may be able to make a successful claim for infringement. * * *

top

En Banc Ninth Circuit Holds That Computer Forensic Searches Are Like "Virtual Strip Searches" And Require Reasonable Suspicion At the Border (Volokh Conspiracy, 8 March 2013) - Today the Ninth Circuit handed down its long-awaited en banc decision in United States v. Cotterman , a case on the lawfulness of searching a computer at the border. (My prior posts are here , here , here , and here .) Today the Ninth Circuit announced a special rule for computer searches: Although a "review of computer files" can occur without reasonable suspicion, the "forensic examination" of a computer at the border requires reasonable suspicion because it is "akin to reading a diary line by line looking for mention of criminal activity-plus looking at everything the writer may have erased."

top

When it Comes to Getting News on Twitter, You Are Who You Follow? (GigaOM, 10 March 2013) - As Nate Silver discussed earlier today at SXSW in Austin on Sunday, the polarization of cable news and politics means that if you're a serious Rachel Maddow fan, there's only a tiny chance that you also vote Republican, and the same is true of Sean Hannity listeners and chances they'll go for Democrats. But as we change where we get our news and turn to places like Twitter for information and verification of facts, it's important to ask how that polarization will translate to social media - if it will at all. Several journalists discussing the future of news dissemination (something we'll also be discussing at paidContent Live in April) tied these issues to those of crowdsourced news, particularly in the Middle East, when the tensions between accuracy and access are most apparent. NBC correspondent Ayman Mohyeldin made an interesting argument about verification, arguing that people should be free to select the accounts they want to follow and personally decide whether to trust that information or not, just as they tune into particular cable shows in the United States and apply their own sense of skepticism to Maddow and Hannity.

top

Small Businesses Have Big Data Breach Problems (Ride The Lightning, 11 March 2013) - A recently released report issued by the Ponemon Institute reveals that 55 percent of U.S. small businesses have experienced at least one data breach, but only a third notified individuals that their personal information had been exposed. The companies which participated had annual revenues of less than $10 million. The survey indicated that 53 percent had multiple breaches. That last statistic should raise eyebrows. And since 46 states have data breach notification laws, it is disturbing that a third of the respondents did not notify the people affected by the breach. 70 percent of the respondents believed that sensitive data is more likely to be breached when the data is outsourced - but 62 percent do not have contracts in place requiring third parties to cover the costs associated with a breach. It is troubling that 85% share customer and employee records with third parties such as those which provide billing, payroll, employee benefits, web hosting and information technology services but obviously are not taking adequate data security precautions.

top

"Regulation of Social Media and Mobile Media" Talk Slides (Eric Goldman, 12 March 2013) - Last month, I spoke at the ABA Antitrust Section's always-well-done Consumer Protection Conference . This time I was recruited as the provocateur to discuss the challenges of regulating social media and mobile media. Regular readers know where I stand on that question .

top

How to Make Effective Disclosures in Digital Advertising (FTC, March 2013) - In the online marketplace, consumers can transact business without the constraints of time or distance. One can log on to the Internet day or night and purchase almost anything one desires, and advances in mobile technology allow advertisers to reach consumers nearly anywhere they go. But cyberspace is not without boundaries, and deception is unlawful no matter what the medium. The FTC has enforced and will continue enforcing its consumer protection laws to ensure that products and services are described truthfully online, and that consumers understand what they are paying for. These activities benefit consumers as well as sellers, who expect and deserve the opportunity to compete in a marketplace free of deception and unfair practices. The general principles of advertising law apply online, but new issues arise almost as fast as technology develops - most recently, new issues have arisen concerning space- constrained screens and social media platforms. This FTC staff guidance document describes the information businesses should consider as they develop ads for online media to ensure that they comply with the law.

top

FTC Can Serve Foreign Defendants Via Facebook, Federal Judge Rules (ABA Journal, 13 March 2013) - The Hague Service Convention doesn't expressly authorize service on foreign defendants by email or social media accounts. But, saying that a U.S. court has the power under the treaty and the Federal Rules of Civil Procedure to approve supplemental means of service, a federal judge in Manhattan has OK'd a plan for the Federal Trade Commission to serve to serve defendants in India with duplicate sets of documents both by email and via Facebook, according to Reuters . The federal courts need to keep an open mind about new technology, wrote U.S. District Judge Paul Engelmayer in his opinion (PDF) last week, to which the S.D.N.Y. Blog provides a link. The judge determined that Facebook service was authorized by Fed. Rule Civ. Pro. 4(f)(3), which provides that "a Court may fashion means of service on an individual in a foreign country, so long as the ordered means of service (1) is not prohibited by international agreement; and (2) comports with constitutional notions of due process." He cited a 1980 decision in which a federal court in New York authorized service by Telex, as well as a recent opinion by the San Francisco-based 9th U.S. Circuit Court of Appeals approving service by email. "The court acknowledges that service by Facebook is a relatively novel concept, and that it is conceivable that defendants will not in fact receive notice by this means," wrote Engelmayer. "But, as noted, the proposed service by Facebook is intended not as the sole method of service, but instead to backstop the service upon each defendant at his, or its, known email address. And history teaches that, as technology advances and modes of communication progress, courts must be open to considering requests to authorize service via technological means of then-recent vintage, rather than dismissing them out of hand as novel." The unusual ruling apparently is one of the first of its kind in the United States. A 2009 article in the Federal Courts Law Review says courts in Australia and New Zealand have also OK'd service by Facebook, Reuters notes, and in 2009 the British High Court allowed service to be made via Twitter . This year, the High Court also authorized service by Facebook .

top

Massachusetts Supreme Judicial Court Expands Consumer Zip Code Privacy Protection (Edwards Wildman, 12 March 2013) - In a closely watched case with a somewhat unexpected result, the highest Massachusetts court decided in Tyler v. Michaels Stores that zip codes are "personal identifying information" that may not be collected and recorded as part of a credit card transaction. A consumer could establish a violation of the state's unfair business practices statute based on retailers' collection and entry of zip codes at the point of sale, if some distinct injury or harm was met, said the Mass. Supreme Judicial Court ("SJC"). Plaintiff's privacy claim, which was also brought as a class action, was permitted to move forward even though the collection of zip codes did not cause the plaintiff to become a victim of identity fraud. The Court found that the plaintiff could establish a claim merely by showing that she received unwanted marketing materials from the merchant as a result of disclosing her zip code, or that the merchant sold the zip code information for a profit to a third party. With the Court's ruling, even zip code information that does not directly identify the consumer is nevertheless "personal identifying information" because, the court noted, it can be combined with other information enabling merchants to identify the consumer's address and telephone number through publicly available databases.

top

RESOURCES

International Compendium of Data Privacy Laws (Baker Hostetler, March 2013) - Privacy and data protection issues confront all organizations-whether you handle employee information, credit card data, sensitive financial information, or trade secrets. Securing data is a daunting task that is further complicated by cross-border transfer issues and the differences in privacy laws around the world. These laws are complex and can pose myriad and sometimes conflicting obligations to a multinational enterprise. Our practitioners are experienced at guiding our clients through this maze of global privacy norms. The BakerHostetler Privacy and Data Protection Team has developed a prompt and practical approach. We have a comprehensive international network of expert service providers who are responsive when our clients require support and guidance through a data security event. This compendium represents our global experience in this field. While it is not a substitute for legal advice, it is a reference guide that outlines the basic requirements in place when dealing with international data breach so that you can know what immediate steps to take, and what questions you need to ask to minimize your company's exposure.

top

BOOKS

A Practical Guide to Software Licensing for Licensees and Licensors (5th Edition, by Ward Classen, available thru the ABA Webstore) - [Polley: I reviewed the 4th edition in MIRLN 15.07. This new edition still contains a CD with contract language (perfect for cut-and-paste) and new chapters on FOSS, Maintenance & Support, and ancillary clauses). With a discount for ABA Business Law Section members, it's a worthwhile addition to your library.]

top

LOOKING BACK

Furtive Phone Photography Spurs Ban (BBC, 4 April 2003) -- As camera phones become more popular, national, governments, local authorities and some businesses are starting to restrict the places they can be used. Italy's data protection commissioner has issued stringent rules governing how the phones can be used and some other organisations, including strip clubs and gyms, have banned the phones from their premises. Picture phones are already banned in Saudi Arabia and their use is frowned upon in other Middle Eastern nations. Some people have already been prosecuted for misusing their mobile phone camera. In mid-March the Italian information commissioner, which oversees the ways that companies and individuals use data they collect about other people, issued regulations setting out what people can do with camera phones. The rules only allow images of people to be snapped for personal use, demand that the images be kept safe and require users to tell people if the image they have taken of them will appear online. The Italian data watchdog is worried that people will abuse the ease with which snaps can be taken with phones such as the Nokia 3650, SonyEricsson T68, Panasonic GD87 and Sharp GX-10. Some Middle Eastern nations are banning picture phones To head off such abuse Saudi Arabia's Commission for Promoting Virtue and Preventing Vice has banned the phones. In the United Arab Emirates and Japan some men have already been prosecuted for using their camera phone to surreptitiously take voyeuristic pictures of women.

top

Use a Honeypot, Go to Prison? (SecurityFocus, 16 April 2003) -- Using a honeypot to detect and surveil computer intruders might put you on the working end of federal wiretapping beef, or even get you sued by the next hacker that sticks his nose in the trap, a Justice Department attorney warned Wednesday. "There are some legal issues here, and they are not necessarily trivial, and they're not necessarily easy," said Richard Salgado, senior counsel for the Department of Justice's computer crime unit, speaking at the RSA Conference here Wednesday. An increasingly popular technique for detecting would-be intruders, a honeypot is a type of hacker flypaper: a system that sits on an organization's network for no other purpose than to be hacked, in theory diverting attackers away from genuinely valuable targets and putting them in an closely monitored environment where every keystroke can be analyzed. But that monitoring is what federal criminal law calls "interception of communications," said Salgado, a felony that carries up to five years in prison. Fortunately for honeypot operators, there are exemptions to the Federal Wiretap Act that could be applied to some honeypot configurations, but they still leave many hacker traps in a legal danger zone. One exemption permits interception of a communication if one of the parties consents to it the monitoring. To that end, Salgado suggested that honeypots display a banner message warning that use of the computer is monitored. "You can banner your honeypot... and you've got the argument that they saw the banner, continued using the system, and consented to monitoring," he said. But most hackers don't penetrate a system through the front door -- telneting in or surfing to a web page -- and if they never see the banner, they haven't consented to monitoring. "It's not the silver bullet."

top

NOTES

MIRLN (Misc. IT Related Legal News) is a free e-newsletter published every three weeks by Vince Polley at KnowConnect PLLC. You can subscribe to the MIRLN distribution list by sending email to Vince Polley ( mailto:vpolley@knowconnect.com?subject=MIRLN ) with the word "MIRLN" in the subject line. Unsubscribe by sending email to Vince with the words "MIRLN REMOVAL" in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln . Get supplemental information through Twitter: http://twitter.com/vpolley #mirln.

SOURCES (inter alia):

1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu

2. InsideHigherEd - http://www.insidehighered.com/

3. SANS Newsbites, sans@sans.org

4. NewsScan and Innovation, http://www.newsscan.com

5. Aon's Technology & Professional Risks Newsletter

6. Crypto-Gram, http://www.schneier.com/crypto-gram.html

7. McGuire Wood's Technology & Business Articles of Note

8. Steptoe & Johnson's E-Commerce Law Week

9. Eric Goldman's Technology and Marketing Law Blog, http://blog.ericgoldman.org/ 10. The Benton Foundation's Communications Headlines

11. Readers' submissions, and the editor's discoveries

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: Addresses and other personal information provided during the subscription process will be kept confidential, and will not be used for any other purpose. top