Saturday, June 18, 2005

MIRLN -- Misc. IT Related Legal News [21 May – 18 June 2005; v8.07]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

E-MAIL RETENTION A MUST AFTER MORGAN STANLEY CASE (CNET, 21 May 2005) -- The $1.45 billion judgment against Morgan Stanley for deceiving billionaire Ronald Perelman over a business deal has a lesson all companies should learn--keeping e-mails is now a must, experts say. Banks and broker-dealers are obliged to retain e-mail and instant messaging documents for three years under U.S. Securities and Exchange Commission rules. But similar requirements will apply to all public companies from July 2006 under the Sarbanes-Oxley corporate reform measures. At the same time, U.S. courts are imposing increasingly harsh punishments on corporations that fail to comply with orders to produce e-mail documents, the experts said. Where judges once were more likely to accept that incompetence or computer problems might be to blame, they are now apt to rule that noncompliance is an indication a company has something to hide. “Morgan Stanley is going to be a harbinger,” said Bill Lyons, chief executive officer of AXS-One, a provider of records retention software systems. “I think general counsels around the world are going to look at this as a legal Chernobyl,” he said. Wednesday’s $1.45 billion verdict against Morgan Stanley in West Palm Beach, Fla., was the product of just such a negative ruling on e-mail retention, which is also expected to form the backbone of the Wall Street firm’s appeal. http://news.com.com/E-mail+retention+a+must+after+Morgan+Stanley+case/2100-1036_3-5715554.html?tag=nefd.top

-- and --

COMPANIES RAMPING UP E-MAIL MONITORING (CNET, 8 June 2005) -- A new study has found that 63 percent of corporations with 1,000 or more employees either employ or plan to employ staff to read or otherwise analyze outbound e-mail. The report, released Monday by e-mail security specialist Proofpoint, said 36.1 percent of companies employ staff to monitor e-mail today, with another 26.5 percent saying they intend to employ such staff in the future. In companies with more than 20,000 employees, this practice is even more common, according to the survey, which involved 332 technology decision-makers at large U.S. companies. Forty percent of those large companies employ staff to monitor e-mail today, and an additional 32 percent plan to employ such staff in the future. According to the study, companies are concerned about making sure e-mail isn’t used to leak company trade secrets or other intellectual property, and about complying with financial disclosure regulations. Another factor is preventing confidential internal memos from getting zapped outside the company, according to the report. The study comes amid a rise in workplace monitoring. The number of employers who monitor the amount of time employees spend on the phone and track the numbers called has jumped to 51 percent, up from 9 percent in 2001, according to a study released last month by the American Management Association and the ePolicy Institute. http://news.com.com/Companies+ramping+up+e-mail+monitoring/2100-1022_3-5738134.html?tag=html.alert

COURT RULES FOR GERMAN ISPS IN P2P IDENTITIES CASE (The Register, 17 May 2005) -- ISPs in the state of Hamburg can’t be forced to provide customer data to record companies, even when illegal copying is suspected, at least for now. The Higher Regional Court in Hamburg has ruled (http://www.heise.de/english/newsticker/news/59602) that there is no legal basis for demanding customer data. ISPs, the court argues, aren’t part of the criminal act. They merely provide access to the web. The Higher Regional Court overruled a earlier decision by the Hamburg District Court, which had granted record companies access to customer data after they discovered an FTP server where numbers by German band Rammstein could be downloaded for free. The District Court based its ruling on the German Copyright Act. http://www.theregister.co.uk/2005/05/17/hamburg_isp_ruling/print.html The full text of the decision is available (in German) at: http://www.jurpc.de/rechtspr/20050062.htm.

U.S. ARMY UPGRADES ARMY KNOWLEDGE ONLINE - AKO - PORTAL (Internet Ad Sales, 18 May 2005) -- Appian Corporation, the leading provider of business process management solutions to the government, today announced that the U.S. Army has purchased additional software licenses, as well as maintenance and professional services, for the Army Knowledge Online (AKO) portal. Additionally, AKO will be upgraded to Appian Enterprise v.3, the latest version of Appian’s award-winning portal solution for government. With more than 1.6 million registered users, AKO is widely regarded as one of the most successful enterprise portal implementations in the world. In April, 770,000 different people used AKO 12.5 million times. Overall, 72 percent of the active force uses AKO regularly. Considered the virtual nerve center of Army operations, AKO provides single sign-on access to as many as 300 of the Army’s mission-critical applications and services. “The global war on terror has created new demands for collaboration and information sharing,” said Gary Winkler, Director of Enterprise Integration, Chief Information Officer/G6. “The rapid and wide-spread acceptance of AKO as the Army operations portal and virtual workspace makes it the obvious and most appropriate vehicle for bringing groups of people with shared interests together.” http://www.internetadsales.com/modules/news/article.php?storyid=850

NEXT FOR BITTORRENT: SEARCH (Wired, 23 May 2005) -- Whiz kid inventor Bram Cohen and a small cadre of developers and entrepreneurs are in the final stage of launching an advertising-supported search engine dedicated to cataloging and indexing the thousands of movies, music tracks, software programs and other files for download over Cohen’s popular BitTorrent protocol. The free search tool will be the first large-scale commercial offering from BitTorrent, a five-person company headed by Cohen that so far has drawn most of its revenue from T-shirt sales and PayPal donations. The ranked search results will be accompanied by sponsored links provided through a partnership with Oakland, California, company Ask Jeeves, says Ashwin Navin, BitTorrent’s chief operating officer. BitTorrent will make money from each clickthrough. “Ask Jeeves syndicates our advertising products to many different sites, and BitTorrent will be one of them,” confirmed Ask Jeeves spokeswoman Darcy Cobb. Navin demonstrated the service for Wired News last week at BitTorrent’s temporary headquarters, a small, one-room San Francisco office shared with Navin’s last venture, an import/export firm called GSI Group. Surrounded by pallets of imported playing cards and poker chips, Navin fired up a browser on his laptop and typed “Mozilla” into the BitTorrent search field. The search quickly produced a site offering torrents for the free browser. The search engine is expected to go live within two weeks, according to Navin, who is moving to the Bay Area from Bellevue, Washington. It will live on BitTorrent, the website from which Cohen distributes the open-source software that has changed the way netizens distribute and connect with content online. BitTorrent speeds internet file transfers by shifting the bandwidth burden off the publisher, and distributing it among users downloading the file: Everyone downloading a file over BitTorrent is unobtrusively uploading it to other users at the same time so that large, popular files actually move at a faster rate than obscure ones. The new search engine takes that dynamic into account. It resembles Google in operation, with a simple interface and results ranked by an automated process. But unlike a general web search, the BitTorrent web crawler interacts with each torrent behind the scenes to determine the number of nodes downloading and uploading through it. That lets the search engine order its results by the throughput of each torrent. “Web search rates things by relevance,” says Navin, a former strategist for Yahoo. “Our search rates things by relevance and availability.” Although BitTorrent has become associated with online piracy thanks to its role in distributing copyright movies and television shows, the company is eager to highlight its utility as a completely lawful program for furthering free speech. That’s the vision that drives the company, says Navin -- now anyone can publish their own movies, music or software, because BitTorrent all but eliminates expensive bandwidth costs. http://www.wired.com/news/ebiz/0,1272,67596,00.html

-- but --

FEDS SHUT DOWN ILLEGAL ‘STAR WARS’ SITE (SciTechToday, 27 May 2005) -- Federal agents have shut down the Elite Torrents network, which distributed illegal copies of Star Wars: Revenge of the Sith before the movie appeared in theaters. Armed with 10 search warrants, agents from the FBI and the U.S. Immigration and Customs Enforcement seized the network’s main server, reporting that it contains nearly 18,000 movies and software programs. “Our goal is to shut down as much of this illegal operation as quickly as possible to stem the serious financial damage to the victims of this high-tech piracy -- the people who labor to produce these copyrighted products,” said Acting Assistant Attorney General Richter in a statement. The Elite Torrents network relied on BitTorrent Latest News about BitTorrent technology, which has been targeted by the Motion Picture Association of America Latest News about Motion Picture Association of America (MPAA) in several lawsuits. In December, the MPAA took actions against over 100 servers in the U.S. and Europe, going after site operators that used BitTorrent and eDonkey to swap movie files. One popular site that was closed, SuprNova.org, noted that it might return without hosting any more BitTorrent links, and other sites are expected to follow a similar tactic. The inclusion of federal authorities in the shutdown of Elite Torrents is indicative of the multipronged enforcement strategy being enacted at the MPAA, which helped with the recent shutdown. http://www.sci-tech-today.com/story.xhtml?story_id=13100EMJC2BR

-- and ---

NEW SWEDISH LAW TO BAN DOWNLOADING OF FILMS, MUSIC (Reuters, 25 May 2005) -- Sweden’s parliament approved a law on Wednesday that bans the downloading of copyrighted material such as films and music from the Internet after being singled out for criticism by Hollywood. Sweden had until now allowed downloading of files, while uploading, or putting material on the Web, was illegal. Actor Morgan Freeman, in a Reuters interview, recently cited Sweden as an example of a country where illegal peer-to-peer file-sharing was a growing problem. The Swedish parliament’s decision, which comes into effect July 1, aims to change that. “The decision means that a clear ban has been introduced against downloading music, pictures and other material on the Internet for private use without the copyright holder’s permission,” parliament said in a statement. http://www.reuters.com/newsArticle.jhtml?storyID=8606639

CONFIDENTIAL DATA, MANDATORY PROTECTION (National Law Journal, 23 May 2005; subscription required) -- As of Oct. 31, 2004, companies listed on the New York Stock Exchange (NYSE) are required to be in compliance with the NYSE’s corporate governance rules promulgated pursuant to the Sarbanes-Oxley Act. While § 406 of Sarbanes-Oxley only requires public companies to adopt codes of conduct governing “senior financial officers, applicable to its principal financial officer and comptroller or principal accounting officer,” the code of conduct required by the NYSE is not so narrowly limited. Codes of conduct promulgated by NYSE-listed companies must apply to “directors, officers and employees,” not just those involved in financial reporting, and must “address” conduct beyond financial reporting. NYSE’s Listed Company Manual, § 303A, ¶ 10. While recognizing that “[e]ach company may determine its own policies,” the NYSE now requires a listed company to address confidentiality as a goal of its compliance program and to adopt a policy that its “[e]mployees, officers and directors should maintain the confidentiality of information entrusted to them by the company or its customers.” This rule places the NYSE at the forefront of a trend that is drastically changing the traditional rules on protecting a company’s confidential information. It used to be that a company had the option of whether to protect its confidential information-an option that was driven solely by market incentives to keep the information away from the competition. Indeed, the courts will only protect company confidential information as a trade secret if the company itself takes reasonable steps to protect it. See, e.g., Teleflora LLC v. Florists’ Transworld Delivery Inc., No. C 03-05858, 2004 WL 1844847, at 6 (N.D. Calif. Oct. 5, 2004). The courts, of course, have never mandated that such reasonable steps be taken or that confidential company information be protected. For NYSE-listed companies, taking reasonable steps to protect confidential information-whether it is their own confidential business information or customers’ personal information-is no longer optional. Section 303A is part of a growing trend of laws and regulations requiring companies to protect confidential information. http://www.law.com/jsp/nlj/PubArticleNLJ.jsp?id=1116493510072

MINNESOTA COURT TAKES DIM VIEW OF ENCRYPTION (CNET, 24 May 2005) -- A Minnesota appeals court has ruled that the presence of encryption software on a computer may be viewed as evidence of criminal intent. Ari David Levie, who was convicted of taking illegal photographs of a nude 9-year-old girl, argued on appeal that the PGP encryption utility on his computer was irrelevant and should not have been admitted as evidence during his trial. PGP stands for Pretty Good Privacy and is sold by PGP Inc. of Palo Alto, Calif. But the Minnesota appeals court ruled 3-0 that the trial judge was correct to let that information be used when handing down a guilty verdict. “We find that evidence of appellant’s Internet use and the existence of an encryption program on his computer was at least somewhat relevant to the state’s case against him,” Judge R.A. Randall wrote in an opinion dated May 3. Randall favorably cited testimony given by retired police officer Brooke Schaub, who prepared a computer forensics report--called an EnCase Report--for the prosecution. Schaub testified that PGP “can basically encrypt any file” and “other than the National Security Agency,” nobody could break it. http://news.com.com/2100-1030_3-5718978.html Opinion at http://www.lawlibrary.state.mn.us/archive/ctappub/0505/opa040381-0503.htm

HOMELAND SECURITY FLUNKS CYBERSECURITY PREP TEST (CNET, 26 May 2005) -- The U.S. Department of Homeland Security has failed to live up to its cybersecurity responsibilities and may be “unprepared” for emergencies, federal auditors said in a scathing report released Thursday. More than two years after its creation, Homeland Security has never developed a contingency plan to restore Internet functions in an emergency and has yet to create a vulnerability assessment of what could happen in an worst-case scenario, the Government Accountability Office concluded. “DHS cannot effectively function as the cybersecurity focal point intended by law and national policy” at the moment, the report said. “There is increased risk that large portions of our national infrastructure are either unaware of key areas of cybersecurity risks or unprepared to effectively address cyber emergencies.” http://news.com.com/2100-7348_3-5722227.html Report at http://www.gao.gov/highlights/d05434high.pdf

-- and --

CIA OVERSEEING 3-DAY WAR GAME ON INTERNET (AP, 26 May 2005) -- The CIA is conducting a secretive war game, dubbed “Silent Horizon,” this week to practice defending against an electronic assault on the same scale as the Sept. 11 terrorism attacks. The three-day exercise, ending Thursday, was meant to test the ability of government and industry to respond to escalating Internet disruptions over many months, according to participants. They spoke on condition of anonymity because the CIA asked them not to disclose details of the sensitive exercise taking place in Charlottesville, Va., about two hours southwest of Washington. The simulated attacks were carried out five years in the future by a fictional alliance of anti-American organizations, including anti-globalization hackers. The most serious damage was expected to be inflicted in the war game’s closing hours. The national security simulation was significant because its premise — a devastating cyberattack that affects government and parts of the economy with the same magnitude as the Sept. 11, 2001, suicide hijackings — contravenes assurances by U.S. counterterrorism experts that such far-reaching effects from a cyberattack are highly unlikely. Previous government simulations have modeled damage from cyberattacks more narrowly. “You hear less and less about the digital Pearl Harbor,” said Dennis McGrath, who helped run three similar war games for the Institute for Security Technology Studies at Dartmouth College. “What people call cyberterrorism, it’s just not at the top of the list.” The CIA’s little-known Information Operations Center, which evaluates threats to U.S. computer systems from foreign governments, criminal organizations and hackers, was running the war game. About 75 people, mostly from the CIA, gathered in conference rooms and reacted to signs of mock computer attacks. http://story.news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050526/ap_on_hi_te/internet_terror

MAD AS HELL, SWITCHING TO MAC (MacCentral, 26 May 2005) -- This is my first column written on a Mac - ever. Maybe I should have done it a long time ago, but I never said I was smart, just obstinate. I was a PC bigot. But now, I’ve had it. I’m mad as hell and I’m not going to take it anymore. In the coming weeks I’m going to keep a diary of an experiment my company began at 6 p.m. April 29, 2005 - an experiment predicated on the hypothesis that the WinTel platform represents the greatest violation of the basic tenets of information security and has become a national economic security risk. I do not say this lightly, and I have never been a Microsoft basher, either. I never criticize a company without a fair bit of explanation, justification and supportive evidence. I have come to the belief that there is a much easier, more secure way to use computers. After having spent several years focusing my security work on Ma, Pa and the Corporate Clueless, I also have come to the conclusion that if I’m having such security problems, heaven help the 98 percent of humanity who merely want a computer for e-mail and multimedia. Even though I’m a security guy going on 22 years now, my day-to-day work is pretty much like everyone else’s. I live on laptops and use my desktops at home and the office for geeking and experimenting. My two day-to-day laptops (two, for 24/7 backup) are my business machines. I don’t need them to do a whole lot - except work reliably, which is why I am fed up with WinTel. My company has given up on WinTel. We have successfully moved to Mac in less than two days. Think about it: a security-friendly alternative that works and doesn’t require gobs of third-party utilities to safely perform the most mundane tasks. Please follow the details of our experiment at www.securityawareness.blogspot.com. It’s already way more interesting than I thought it would be. http://news.yahoo.com/news?tmpl=story&cid=77&e=1&u=/mc/20050526/tc_mc/madashellswitchingtomac [Editor: For similar reasons, I moved to Macintosh 17 months ago, even though my company remained a WinTel-required environment. Since then, I’ve never needed technical support.]

EU TO FUND GLOBAL RESEARCH ON OPEN SOURCE (CNET, 26 May 2005) -- The European Union is putting money toward research into open-source software and standards across the world. The newly approved funding--660,00 euros, or $825,594--is for the two-year FLOSSWorld project, Europe’s first initiative to support international research and policy development on “free/libre/open source software.” Previous FLOSS projects, starting as early as 2001, have concentrated on the use of open source in Europe alone. Rishab Aiyer Ghosh, FLOSSWorld coordinator at the Maastricht Economic Research Institute on Innovation and Technology at the University of Maastricht in the Netherlands, told Silicon.com that the EU doesn’t usually fund international projects. The grant will be shared by countries including Argentina, Brazil, Bulgaria, China, Croatia, India, Malaysia and South Africa. The research will focus on three areas: the impact of free and open-source software on skills development and its ability to affect economics and generate employment; regional differences in software development; and attitudes of governments and public sector organizations to using open source. http://news.com.com/2100-7344_3-5721867.html

FEDERAL REPORT WARNS OF RFID MISUSES (CNET, 27 May 2005) -- Radio frequency identification is becoming increasingly popular inside the U.S. government, but agencies have not seriously considered the privacy risks, federal auditors said. In a report published Friday, the Government Accountability Office said that 13 of the largest federal agencies are already using RFID or plan to use it. But only one of 23 agencies polled by the GAO had identified any legal or privacy issues--even though three admitted RFID would let them track employee movements. “Key security issues include protecting the confidentiality, integrity and availability of the data and information systems,” the GAO said. “The privacy issues include notifying consumers; tracking an individual’s movements; profiling an individual’s habits, tastes and predilections; and allowing for secondary uses of information.” http://news.com.com/2100-7342_3-5723535.html Report at http://www.gao.gov/new.items/d05551.pdf

FTC RULE REQUIRES DESTRUCTION OF CONSUMER DATA (Washington Post, 2 June 2005) -- A new federal rule that took effect yesterday requires all businesses and individuals to destroy private consumer information obtained from credit bureaus and other information providers in determining whether to grant credit, hire employees or rent an apartment. Issued under orders from Congress, which was trying to crack down on identity theft, the Federal Trade Commission’s new rule requires that personal information be burned, pulverized, shredded or destroyed in such a way that the information cannot be read or reconstructed. The rule also applies to electronic files, which must be erased or destroyed, and covers credit report data, credit scores, employment histories, insurance claims, check-writing histories, residential or tenant history and medical information. An FTC official said failure to properly dispose of the data could draw a $2,500 federal penalty per violation, as well as lawsuits from people who could seek damages if personal information was misused as a result of improper disposal. http://www.washingtonpost.com/wp-dyn/content/article/2005/06/01/AR2005060101940.html?nav=rss_technology

6TH CIRCUIT UPHOLDS DECISION ON COPYRIGHT EXCEPTION (BNA’s Internet Law News, 6 June 2005) -- The Sixth Circuit Court of Appeals has reaffirmed their decision that there is effectively no de minimus exception to copyright infringement for sound recordings. The court concluded that even copying of two notes from a sound recording constitutes infringement. Case name is Bridgeport Music v. Dimension Films. Decision at http://caselaw.lp.findlaw.com/data2/circs/6th/026521pv2.pdf

JUDGES TOSS OUT DUIs BECAUSE BREATHALYZERS’ SOURCE CODE IS SECRET (BoingBoing, 6 June 2005) -- Florida judges are tossing out DUI cases when defendants ask to see the source code for the breathalyzers that busted them -- the manufacturers won’t turn over the source, and since the machine’s correct operation is critical to establishing the case against the DUIers, the case is dismissed when it can’t be produced. All four of Seminole County’s criminal judges have been using a standard that if a DUI defendant asks for a key piece of information about how the machine works - its software source code, for instance - and the state cannot provide it, the breath test is rejected, the Orlando Sentinel reported Wednesday. Seminole judges have been following the lead of county Judge Donald Marblestone, who in January ruled that although the information may be a trade secret and controlled by a private contractor, defendants are entitled to it. http://www.boingboing.net/2005/06/06/judges_toss_out_duis.html

EBAY OFFERS GUARANTEES FOR SOME BUYS (CNET, 6 June 2005) -- eBay has launched a program offering purchase protection of up to $20,000 for certain capital goods bought through its Web site. Items covered include tractors from the auctioneer’s agriculture and forestry category; skid steers, backhoes, crawler dozers and other gear in the construction category; plus mills and lathes from the manufacturing and metalworking category, eBay said Monday. The offer, which is valid with purchases of $1,000 or more, is designed to give buyers protection against fraud and material misrepresentation. The program covers goods purchased in the United States, the auctioneer said. The offer covers items not received and those having damages or liens. There is no charge to buyers or sellers, the auctioneer said. The move is meant to appeal to small businesses and to boost confidence in online auctioning, eBay said. http://news.com.com/2100-1038_3-5733479.html

LEGAL ONLINE MUSIC STORES MAKE SOME GAINS (Reuters, 7 June 2005) -- Legal online music stores have gained a solid foothold against free file-sharing networks, according to new data released on Tuesday. The beleaguered music industry has been pursuing a carrot and stick strategy of supporting legal alternatives such as Apple’s iTunes, RealNetworks’s Rhapsody and Napster, while filing a barrage of lawsuits against people and services that share music illicitly online. According to data from market research firm NPD Group Inc, the efforts are bearing fruit: iTunes has surged to a tie for second place as the most popular online music source, with 1.7 million U.S. households downloading at least one song in March. That put it neck and neck with the peer-to-peer service LimeWire and slightly behind another P2P service, WinMX, which has 2.1 million households. “Legal services offer some obvious advantages: they’re spyware free, and it’s very quick and easy to get what you want,” said NPD’s Isaac Josephson. “The older, more affluent demographics are already a bit more inclined to go for convenience over free, and when you raise the legal issues that’s an important tipping point.” About 4 percent of Internet-enabled U.S. households used a legal online music store in March, according to NPD. http://www.reuters.com/newsArticle.jhtml?storyID=8721861

-- and --

COME ON MUSIC BIZ, EMBRACE P2P (Wired, 13 June 2005) -- File-swapping networks alone are not to blame for the recording industry’s woes and might plausibly be converted into legitimate channels for distributing music, one of Europe’s most influential economic bodies has concluded. In a report issued Monday, the Organisation for Economic Co-operation and Development -- a Paris-based alliance of developed nations -- also suggested that it’s difficult to establish a link between piracy and the music industry’s shrinking revenues. The report said a “re-evaluation” of music distribution needs to happen to achieve a balance between consumers’ desire to access digital music and the industry’s copyright protection concerns. “Online technologies could evolve in a manner in which unauthorized use of copyright works are finally transformed into legitimate businesses,” said Sacha Wunsch-Vincent, an OECD economist and one of the report’s authors. The report said it is difficult to establish a causal connection between the rise of file sharing and a drop in music sales. While the music industry’s revenues fell 20 percent from 1999 to 2003, other factors, such as illegal CD copying, might have played a role in the decline, the OECD said. http://www.wired.com/news/digiwood/0,1412,67820,00.html Report at http://cyber.law.harvard.edu/digitalmedia/music_dsti_iccp_ie_2004_12_final_eng.pdf

THE JOY OF STACKS (InsideHigherEd, 9 June 2005) -- To understand why professors need great libraries, says Andrew Abbott, “you need to think about an ape swinging through the trees.” Abbott is not an evolutionary biologist, but a sociologist at the University of Chicago. And to Abbott, a scholar in a library is just like a swinging primate. “You’ve got your current source, which is the branch you are on, and then you see the next source, on the next branch, so you swing over. And on that new hanging vine, you see the next source, which you didn’t see before, and you swing again.” When books aren’t browsable or instantly available, Abbott says, a scholar becomes the ape “with no branch to grab, and you are stopped, hanging on a branch with no place to go.” At far too many libraries, he says, that is becoming the norm. Many universities are boasting about how they are digitizing collections or building vast, off-site facilities to store millions of books. Even when those books are available within hours, Abbott says, that destroys the way scholars need to think — moving from source to source, not knowing which source they will stumble on. Abbott heads a faculty committee at Chicago in charge of guiding a mammoth expansion of the Joseph Regenstein Library there. Chicago recently embarked on a plan that will end up with Regenstein housing more volumes — 8 million — under a single roof than any other university library in the United States. http://insidehighered.com/news/2005/06/09/stacks

MICROSOFT JOINS YAHOO!, GOOGLE IN CENSORING CHINA’S WEB (AFP, 13 June 2005) -- Users of Microsoft’s new China-based Internet portal were blocked from using the words “democracy”, “freedom” and “human rights” in an apparent move by the US software giant to appease Beijing. Other words that could not be used on Microsoft’s free online blog service MSN Spaces include “Taiwan independence” and “demonstration”. Bloggers who enter such words or other politically charged or pornographic content are prompted with a message that reads: “This item should not contain forbidden speech such as profanity. Please enter a different word for this item”. Officials at Microsoft’s Beijing offices refused to comment Monday. Internet sites in China are strongly urged to abide by a code of conduct and self-censor any information that could be viewed by the government as politically sensitive, pornographic or illegal. For many Chinese websites, such content also includes news stories that the government considers unfavorable or does not want published. New regulations issued in March now require that all China-based websites be formally registered with the government by the end of June or be shut down by Internet police. Microsoft formed a joint venture with China’s state-funded Shanghai Alliance Investment Ltd (SAIL) last month to launch the MSN China web portal. Microsoft is not the only international tech company to comply with China’s stringent Internet rules. Yahoo! and Google -- the two most popular Internet search engines -- have already been criticized for cooperating with the Chinese government to censor the Internet. http://uk.news.yahoo.com/050613/323/fl019.html

LIBERTY ALLIANCE TAKES ON ID THEFT (CNET, 13 June 2005) -- In the wake of several high-profile data breaches, the Liberty Alliance is branching out to take on identity theft. The organization, formed to develop technology standards for online authentication, plans to launch its Identity Theft Protection Group on Tuesday. Headed by representatives from American Express and Fidelity Investments, the new effort plans to release an identity theft glossary next month and to subsequently come up with ways to prevent ID theft. “I am concerned that unless we do something as an industry, this problem is going to get worse and worse, to the point that it is no longer a question if your identity gets stolen, but when,” Michael Barrett, co-chairman of the Identity Theft Prevention Group and a security executive at American Express, said in an interview Monday. Identity-related crime such as phishing threatens the growth of the Internet, Barrett said. The Identity Theft Prevention Group hopes to become a hub for efforts to combat the issue. It plans to first define and dissect the problem and then develop solutions, which could be technical specifications, policy best practices or business guidelines, Barrett said. The launch comes in the wake of several high-profile data loss incidents that exposed American consumers to identity risk. Last week, CitiFinancial said tapes containing unencrypted information on 3.9 million customers were lost by the United Parcel Service while in transit to a credit bureau. CitiFinancial is the consumer finance subsidiary of Citigroup. In past months, data leaks have been reported by Bank of America and Wachovia, data brokers ChoicePoint and LexisNexis, and the University of California at Berkeley and Stanford University. http://news.com.com/2100-7348_3-5744641.html

COPYRIGHT-WORRIED PHOTO LABS SPURN JOBS (AP, 16 June 2005) -- Charlie Morgan says that if it weren't for digital photography, he wouldn't have a bustling business that specializes in publicity shots for musicians. That's because Morgan — perhaps being a bit modest — says he's not a very good photographer. He relies on Photoshop editing software to make his work look sharp. But digital sometimes presents a puzzling problem. When Morgan's mother and a client recently took CDs with some of his shots to a printing lab, the photo technicians spurned them. They said that since the shots seemed to have been taken by a professional, printing the pictures might be a copyright violation. The situation is not unusual, and it's getting trickier in our digital age. Copyright law requires photo labs to be on the lookout for portraits and other professional work that should not be duplicated without a photographer's permission. In the old days, questions about an image's provenance could be settled with a negative. If you had it, you probably had the right to reproduce it. Now, when images are submitted on CDs or memory cards or over the Web, photofinishers often have to guess whether a picture was truly taken by the customer — or whether it was scanned into a computer or pilfered off the Internet. That leads to some awkward moments at photo desks when customers' images get barred for essentially looking too good. Like others who have been told their work was unprintable, Morgan is frustrated that photo labs lack clear standards. "They really don't have anything etched in stone," said Morgan, who lives in Plant City, Fla. "The person that works in the photography section of Wal-Mart could take a break, someone from the underwear department could take their place, and they could decide to print the picture." Wal-Mart spokeswoman Jacquie Young said her company's photo departments are instructed to err on the side of protecting copyrights, even if that means a conflict with an insistent customer. She would not say what signs of professionalism the photofinishers are told to look for. http://news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050616/ap_on_hi_te/photo_printing_frustration

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Monday, May 23, 2005

MIRLN -- Misc. IT Related Legal News [23 April – 21 May 2005; v8.06]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

FRENCH DATA PROTECTION AUTHORITY ALLOWS SOFTWARE DEVELOPERS TO MONITOR P2P NETWORKS (DM Europe, 18 April 2005) -- The French data protection authority has announced that it is to allow the Syndicat des Editeurs de Logiciels de Loisi (SELL) - the French software developers’ trade association - to monitor data traffic over peer-to-peer file-sharing networks. The Commission nationale de l’informatique et des libertés (CNIL) has permitted SELL to send warning messages to users uploading illegally copied software and then locate and use the IP addresses of such individuals in legal proceedings. http://www.dmeurope.com/default.asp?ArticleID=7370

E-COMMERCE SITES FORCED TO ADOPT SECURITY STANDARDS (Ecommerce Times, 23 April 2005) -- Online retailers will be forced to tighten security and improve their handling of customer data under new rules being introduced by the credit card industry to stop identity theft. From June 30, all e-commerce sites with internal systems that process, store or transmit cardholder information will have to comply with the Payment Card Industry (PCI) Data Security Standard or face significant fines. In extreme cases, online merchants could be banned from processing transactions using payment cards. Backed by MasterCard, Visa, American Express (NYSE: AXP) Latest News about American Express, Diners Club and JCB Cards, the standard requires Internet retailers to carry out a 12-step security audit, which will be certified annually and checked every three months. http://www.ecommercetimes.com/story/ebiz/42479.html

-- and --

SOVEREIGN BLAMES RETAILER IN ID THEFT SCAM (Philadelphia Business Journal, 11 Feb 2005) -- Sovereign Bank is trying to blame BJ’s Wholesale Club Inc. in an identity theft scheme that victimized hundreds of the bank’s debit cardholders last year. The bank said last June that a computer hacker had stolen account information from at least 700 debit card customers and that it was forced to reissue 80,000 new debit cards. But it offered no other details at the time. But in January, Sovereign filed a civil lawsuit in Berks County Court of Common Pleas saying the account information was stolen from BJ’s after bank customers made purchases from the retailer, which has its headquarters in Natick, Mass. In its lawsuit, Sovereign said that under rules established by Visa, which issued the Sovereign cards, BJ’s was supposed to delete cardholder information from its computers after the transaction was complete. http://philadelphia.bizjournals.com/philadelphia/stories/2005/02/14/story4.html?t=printable%5BEditor’s

FEDS RETHINKING RFID PASSPORT (Wired, 26 April 2005) -- Following criticism from computer security professionals and civil libertarians about the privacy risks posed by new RFID passports the government plans to begin issuing, a State Department official said his office is reconsidering a privacy solution it rejected earlier that would help protect passport holders’ data. The solution would require an RFID reader to provide a key or password before it could read data embedded on an RFID passport’s chip. It would also encrypt data as it’s transmitted from the chip to a reader so that no one could read the data if they intercepted it in transit. Frank Moss, deputy assistant secretary for passport services, told Wired News on Monday that the government was “taking a very serious look” at the privacy solution in light of the 2,400-plus comments the department received about the e-passport rule and concerns expressed last week in Seattle by participants at the Computers, Freedom and Privacy conference. Moss said recent work on the passports conducted with the National Institute of Standards and Technology had also led him to rethink the issue. “Basically what changed my mind was a recognition that the (reading distance) may have actually been able to be more than 10 centimeters, and also recognition that we had to do everything possible to protect the security of people,” Moss said. http://www.wired.com/news/privacy/0,1848,67333,00.html

MICROSOFT TO ADD ‘BLACK BOX’ TO WINDOWS (CNET, 26 April 2005) -- In a move that could rankle privacy advocates, Microsoft said Monday that it is adding the PC equivalent of a flight data recorder to the next version of Windows, in an effort to better understand and prevent computer crashes. The tool will build on the existing Watson error-reporting tool in Windows but will provide Microsoft with much deeper information, including what programs were running at the time of the error and even the contents of documents that were being created. Businesses will also choose whether they want their own technology managers to receive such data when an employee’s machine crashes. “Think of it as a flight data recorder, so that any time there’s a problem, that ‘black box’ is there helping us work together and diagnose what’s going on,” Microsoft Chairman Bill Gates said during a speech at the Windows Hardware Engineering Conference here. For consumers, the choice of whether to send the data, and how much information to share, will be up to the individual. Though the details are being finalized, Windows lead product manager Greg Sullivan said users will be prompted with a message indicating the information to be sent and giving them an option to alter it, such as removing the contents of the e-mail they were writing when the machine crashed. Also, such reporting will also be anonymous. With businesses, however, IT managers typically set the policy. If they wanted total information, they could configure systems so that they’d know not only that a user was running Internet Explorer, for example, but also that he or she was watching a video from ESPN.com. Or, they might find out not only that a worker was running Instant Messenger but also that he or she was talking to a co-worker about getting a new job. And consumers could have a tough time knowing just what information they were sending. Though they’ll be able to see the contents of a document, they may not recognize the significance of the technical data--such as register settings--that’s being sent. http://news.com.com/2100-1016_3-5684051.html

GROUP WANTS ENCRYPTION BANS OVERTURNED (CNET, 27 April 2005) -- An international security consortium plans to push governments around the world to withdraw restrictions on the use of encryption. Countries including China, Israel, Russia and Saudi Arabia have strict rules governing the use of encryption tools, and in some cases they have banned these tools. The Jericho Forum, which is looking to move away from the perimeter model for cybersecurity toward an approach that would make data totally secure, hinted that such policies could cause problems for e-commerce. The Jericho Forum, whose membership includes many chief security officers from FTSE 100 companies, will push for the removal of encryption restrictions within the next three to five years. http://news.com.com/2100-7348_3-5687087.html

SPIDERS CAN ENTER CONTRACTS TOO! (Steptoe & Johnson’s E-Commerce Law Week, 28 April 2005) -- It wouldn’t be unheard-of for a web surfer to accept the terms of a Terms of Use or “click-through” agreement without actually reading it ... and then for a court to hold him to the terms of that agreement. So is there a difference if his automated software tool does the “clicking” -- also without actually reading the agreement? Not according to the US District Court for the Northern District of California. In Cairo, Inc. v. CrossMedia Services, Inc., the court held that automated software tools called “spiders” can legally consent to the terms of use or terms of service agreements on websites they visit -- thereby committing their operators to the terms of those agreements and subjecting them to liability for violations. (The case breaks new legal ground, but the court designates its opinion as “unpublished,” which usually means that the ruling has little or no precedential impact. In this case, it may mean that the court lacks confidence in its judgment -- or simply that no one has yet asked the court to publish the opinion.) http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9512&siteId=547

WIRETAPS IN U.S. JUMP 19 PERCENT IN 2004 (SFgate.com, 28 April 2005) -- The number of court-authorized wiretaps jumped 19 percent last year as investigators pursued drug and other cases against increasingly tech-savvy suspects. Every surveillance request made by authorities was granted. Federal and state judges approved 1,710 applications for wiretaps of wire, oral or electronic communications last year, and four states — New York, California, New Jersey and Florida — accounted for three of every four surveillance orders, according to the Administrative Office of the U.S. Courts. That agency is required to collect the figures and report them to Congress. The numbers, released Thursday, do not include court orders for terror-related investigations under the Foreign Intelligence Surveillance Act, known as FISA, which reached a record 1,754 warrants last year, according to the Justice Department. In non-terrorist criminal investigations, federally approved wiretaps increased 26 percent in a year, to 730 applications, while state judges approved 980 wiretaps, an increase of 13 percent. Department of Justice spokesman Kevin Madden said the numbers reflect “an increase in the resources geared toward targeting very serious federal and state offenses for which electronic surveillance is often the most, and sometimes the only, effective investigative method.” Timothy Edgar, legislative counsel for the American Civil Liberties Union, said traditional law enforcement work is catching up with increases in anti-terror wiretaps. “We’re still seeing a huge trend toward increased surveillance,” said Edgar. http://www.sfgate.com/cgi-bin/article.cgi?file=/news/archive/2005/04/28/national/a082547D09.DTL

U.S. CRITICIZES WORLD IN SPECIAL 301 IP REPORT (BNA’s Internet Law News, 3 May 2005) -- The U.S. Trade Representative has released its annual Special 301 report on the IP policies of countries from around the world. A long list of countries face criticism - for example, Canada is criticized for its proposed copyright reform, India and Israel on pharmaceuticals, and Taiwan for lack of enforcement. Special 301 report at http://www.ustr.gov/Document_Library/Reports_Publications/2005/2005_Special_301/Section_Index.html
Canadian report at http://www.michaelgeist.ca/home.php#396
Taiwan report at http://www.chinapost.com.tw/detail.asp?ID=61808&GRP=A
India report at http://www.hindustantimes.com/news/181_1343386,0002.htm
Israel report at http://www.globes.co.il/serveen/globes/docview.asp?did=909133&fid=942

YOUR IDENTITY, OPEN TO ALL (Wired, 6 May 2005) -- A search for personal data on ZabaSearch.com -- one of the most comprehensive personal-data search engines on the net -- tends to elicit one of two reactions from first-timers: terror or curiosity. Which reaction often depends on whether you are searching for someone else’s data, or your own. ZabaSearch queries return a wealth of info sometimes dating back more than 10 years: residential addresses, phone numbers both listed and unlisted, birth year, even satellite photos of people’s homes. ZabaSearch isn’t the first or only such service online. Yahoo’s free People Search, for example, returns names, telephone numbers and addresses. But the information is nothing more than what’s been available for years in the White Pages. Far more personal information is available from data brokers, including aliases, bankruptcy records and tax liens. That access typically requires a fee, however, which has always been a barrier to the casual snooper. But ZabaSearch makes it easier than ever to find comprehensive personal information on anyone. ZabaSearch may give away some data for free, but it charges for additional information -- like background checks and criminal history reports, which may or may not be accurate. The company also plans to sell ads and other services on the search site, much like Google or Yahoo. http://www.wired.com/news/privacy/0,1848,67407,00.html

EU CLARIFIES “FOURTH WAY” FOR FOREIGN DATA TRANSFERS (Steptoe & Johnson’s E-Commerce Law Week, 7 May 2005) -- Global companies trying to cope with Europe’s data protection laws have traditionally had three options if they wanted to move personal information out of Europe. They could get the consent of everyone whose data would be moved. They could execute a web of agreements among the receiving and sending companies, essentially guaranteeing that European protections would follow European data. Or they could move the data only to the handful of countries whose data protection laws had been approved by European authorities – Argentina, Canada, Guernsey, Isle of Man and Switzerland – and the US, at least for companies that have joined the US-EU Safe Harbor. Now there’s a fourth way. In a pair of documents issued in mid-April – a Model Checklist for Approval of Binding Corporate Rules (at http://www.steptoe.com/publications/352f.pdf) and a Co-Operation Procedure for Issuing Common Opinions on Adequate Safeguards Resulting From “Binding Corporate Rules” (at http://www.steptoe.com/publications/352g.pdf) – the EU Article 29 Data Protection Working Party set out procedures for approval of “binding corporate rules” (“BCRs”), adopted by a multinational company or other entity, that require compliance with the requirements of the Data Protection Directive and provide for redress by data subjects for violations of their data protection rights. The BCRs approach supplements the other three main options for transfer of personal data outside of the European Economic Area in accordance with Articles 25 and 26 of the Data Protection Directive. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9611&siteId=547

GUARDING INFORMATION (PublicCIO.com, May 2005) -- The United States loses billions of dollars every year to cyber-crimes, such as identify theft. Yet when it comes to developing a cadre of highly educated and trained cyber-security experts to combat this growing crime wave, we look the other way. Professor Eugene Spafford, executive director of the Center for Education and Research in Information Assurance and Security at Purdue University, points out that each year, fewer than 100 people graduate with a Ph.D. in cyber-security in the United States. Purdue, which has one of the largest graduate programs for information security in the country, issues only about 15 doctoral degrees in the field every year. Spafford, who also serves on the President’s Information Technology Advisory Committee (PITAC) and acts as security adviser to more than a dozen federal agencies and major corporations, believes strong cyber-security policies not only benefit information assurance and trust in cyber-space, but also can act as a bulwark against terrorist actions as well. But Spafford -- who chairs the U.S. Public Policy Committee of the Association for Computing Machinery, an agency that advises legislators and regulators about the impact of policy on computing technology and vice versa -- is worried about the ongoing lack of support for fighting this growing problem. He took time to speak with Government Technology’s Public CIO about his concerns, the nature of cyber-security, protecting information systems against intrusion and training security professionals.[interview then follows] http://www.public-cio.com/story.php?id=2005.04.28-93832

SUN MICROSYSTEMS TO DOUBLE INDIAN R&D STAFF (CNET, 6 May 2005) -- Sun Microsystems, which makes network computers and related software, said on Friday it would double the number of staff at its Indian engineering center to 2,000 over the next two to three years. Officials of U.S.-based Sun, which spends an annual $1.9 billion on research and development, said they would expand engineering centers in Russia, China, the Czech Republic and India, while holding back growth in the United States. Stephen Pelletier, senior vice-president of global engineering at Sun, told reporters at a news conference that India and China were important both for new software development and their high-growth economies that have yielded big customers. “You can say Sun software products are all made in India,” he said. “It is obviously cheaper to do business here. But we expect in the next five years the wages to converge more.” The U.S. engineering team is still the biggest for Sun, but the company’s current plans are to grow the R&D centers in Bangalore, Beijing, St. Petersburg and Prague, Pelletier said. The Beijing center is about half the size of the Indian one, which has grown five-fold from 200 staff about three years ago. Officials did not give staff sizes for the other centers. http://news.com.com/Sun+Microsystems+to+double+Indian+RD+staff/2100-1008_3-5698129.html?tag=nefd.top

MISSING BACKUP TAPES SPUR ENCRYPTION AT TIME WARNER (Computer World, 6 May 2005) -- Time Warner Inc. this week said it will “quickly” begin encrypting all data saved to backup tapes after 40 tapes with personal information on about 600,000 current and former employees were lost in transit to a storage facility. The incident is among the biggest in a string of recent data-security mishaps that have also affected companies such as ChoicePoint Inc., Bank of America Corp. and Reed Elsevier Group PLC’s LexisNexis Group unit. A shipping container that held the 40 data tapes was lost on March 22 during a routine shipment to an off-site facility by records management and storage firm Iron Mountain Inc., Time Warner spokeswoman Kathy McKiernan said. She wouldn’t provide more details. However, McKiernan did say Time Warner is trying to convince officials at Boston-based Iron Mountain to change some of their handling procedures. She declined to expand on the status of those discussions. The $42 billion New York-based media giant also said it has provided the affected employees with resources to monitor their credit reports. The lost tapes didn’t include data about Time Warner customers, the company said. http://www.computerworld.com/printthis/2005/0,4814,101589,00.html

-- and --

DATA-SECURITY LAWS SPROUT IN WAKE OF BREACHES (TechWeb, 13 May 2005) -- Laws at the federal and state levels are altering the landscape for sharing and protecting sensitive customer information, just as widely publicized breaches at companies like Bank of America, ChoicePoint, DSW Shoe Warehouse, and LexisNexis have focused attention on the problem of ID theft. Several states, including Arkansas, Georgia, Montana, and North Dakota, have implemented ID-theft laws patterned after a law in California, and many other states have legislation pending. Observers say a national ID-theft-protection bill also is likely to be enacted. In March several federal agencies--the Federal Reserve System, the Federal Deposit Insurance Corp., the Office of the Comptroller of the Currency, and the Office of Thrift Supervision--jointly issued the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. The guidelines state that financial institutions should implement a response program to address security breaches involving customer information, including procedures to notify customers about incidents of unauthorized access to customer information that could result in substantial harm or inconvenience to the customer. The guidelines also provide that when a financial institution becomes aware of an incident of unauthorized access to sensitive customer information, it should conduct a reasonable investigation to determine whether the information has been or will be misused. The interagency guidelines apply only to financial institutions or businesses that are regulated by the agencies that issued them. Morgan Stanley’s Discover Card division, for example, is covered, while its broker-dealer business isn’t, said Howard Lipper, executive director of the technology, intellectual property, and E-commerce group at Morgan Stanley. Lipper spoke at an information security session hosted by law firm Steptoe & Johnson in New York on Friday. The Securities and Exchange Commission, however, is likely to adopt the guidelines verbatim, Lipper said. Brokerage firms are likely to “face some very tough questions on information security practices during their next audit.” The Federal Trade Commission is likely to adopt many provisions of the interagency guidelines as it seeks to extend data-privacy protection across all industries. “The FTC wants to be the traffic cop on information security, but the problem is a traffic cop can’t be everywhere,” said Emily Hancock, an attorney in Steptoe & Johnson’s Washington office. She noted that California and Arkansas are the only states so far to have adopted provisions requiring both notification of breaches and “reasonable security” to prevent breaches. A patchwork of state and federal laws, each with different standards of notification, could raise the compliance costs without providing corresponding increases in data security, said Mark MacCarthy, senior VP of public policy at Visa U.S.A. “Simply passing a new bill isn’t going to make these things go away.” He suggested that market forces, such as the impact on a company’s reputation, would compel companies to adopt tighter security procedures. http://story.news.yahoo.com/news?tmpl=story&cid=74&e=2&u=/cmp/20050514/tc_cmp/163102113

PENTAGON CUT AND PASTE (Asia Times, 5 May 2005) -- Talk about rebel technology: the Pentagon this week was not overwhelmed by a dirty bomb or a jet converted into a missile, but by a simple cut and paste job. Like anyone else, the Pentagon uses Adobe Acrobat. At first, the 42 pages of the report which would supposedly shed some light on the March 4 killing of Italian secret agent Nicola Calipari and the wounding of kidnapped journalist Giuliana Sgrena in Baghdad showed up on the Centcom website as a PDF file heavily censored with large sections blacked out - including the significant omission, among others, of the names of all the soldiers involved in the shooting, as well as entire pages. But because the Pentagon failed to save the file properly, all it took was for someone to cut and paste the document into a word-processing application to give Italy and the rest of the world access to the full, uncensored version. http://atimes.com/atimes/Middle_East/GE05Ak04.html

USE OF TRADEMARKS IN INTERNET SEARCHES: GOOGLE CASES LEAD TO CONFLICTING RESULTS (Wilmer, Cutler analysis, 11 May 2005) -- Stemming from its AdWords program, Google Inc. has recently faced a spate of litigation in the United States and France. The AdWords program allows advertisers to bid on keywords, including trademarked terms, which result in the display of the advertisers’ sponsored links when users perform searches using the keywords. This controversial service has caused several companies to file lawsuits against Google. Examples of recent litigation, both foreign and domestic, as well as an overview of the company’s current trademark policies, are described ... (at http://www.wilmerhale.com/publications/whPubsDetail.aspx?id=b595a5af-cf02-4951-925b-234ca505623d)

ONLINE DATABASE WILL HOLD THE MIRROR UP TO ‘HAMLET,’ GATHERING EVERY COMMENTARY ON THE PLAY (Chronicle of Higher Education, 10 May 2005) -- More has been written about Hamlet than about any other Shakespeare play, and attitudes toward the work’s main character have shifted over time, says Eric C. Rasmussen, a professor of English at the University of Nevada at Reno. “Victorians saw Hamlet as a wilted wallflower, but in the 60s he was sort of the prototypical angry young man,” says Mr. Rasmussen, who is also the university’s director of graduate studies. “The way people think about Hamlet seems to be a mirror for the way we view our current cultural moment.” Mr. Rasmussen should know. He has spent the past 10 years working with a team of scholars to compile every piece of scholarship and criticism about the play, and then to link it, line by line, to the text in an online database. The mammoth project, supported by some $1-million in grants from the National Endowment for the Humanities, is nearing completion -- although editors plan to add to it as they find more material. “If you are interested in a particular line of the play, to be able to see 400 years’ worth of commentary on that line is pretty remarkable,” he says. About half of the group’s work is available on a free Web site. But readers won’t find commentary for most of the play’s most famous lines yet, because notes for the first half of the script have not yet been uploaded. The scholars hope to have notes for all 3,474 lines up in the next few months, at which point visitors can better discover the meaning of “To be, or not to be,” among other passages. http://chronicle.com/free/2005/05/2005051001t.htm

GILLETTE REPORTEDLY DELETED E-MAIL EVIDENCE (Messaging Pipeline, 12 May 2005) -- In what is apparently another incident of intentional e-mail destruction, Proofpoint reported today that Gillette has disclosed in a filing in Massachusetts Superior Court that senior executives may have deleted e-mails that are subject to a subpoena from Massachusetts Secretary of State William F. Galvin. It was reported in the Boston Globe and the Cincinnatti Business Courier that the company is currently under investigation regarding shareholder allegations that Gillette may have sold out to Procter & Gamble at an unacceptably low price. Galvin has called the incident an embarrassing “dog ate my homework” defense because e-mails at the company are saved on multiple machines. Normal backup mechanisms in large corporations generally make complete deletion very difficult. In a comment on the incident, Proofpoint notes that while 74.4 percent of surveyed large corporations have adopted formal e-mail retention policies, only 18.1 percent have deployed technology to enforce such policies. http://www.messagingpipeline.com/news/163101470;jsessionid=KL3XYTWANPZDWQSNDBGCKHSCJUMEKJVN

IBM BACKS FIREFOX IN-HOUSE (CNET, 13 May 2005) -- IBM is encouraging its employees to use Firefox, aiding the open-source Web browser’s quest to chip away at Microsoft’s Internet Explorer. Firefox is already used by about 10 percent of IBM’s staff, or about 30,000 people. Starting Friday, IBM workers can download the browser from internal servers and get support from the company’s help desk staff. IBM’s commitment to Firefox is among its most prominent votes of confidence from a large corporation. Based on development work by the nonprofit Mozilla Foundation, Firefox has been downloaded by more than 50 million people since it debuted in November. Internet Explorer still dominates the overall market by far, though, with Firefox’s share in the single digits. For IBM, the move is a significant step in lessening dependence on a product from rival Microsoft. By supporting Firefox internally, IBM is also furthering its commitment to open-source products based on industry standards, said Brian Truskowski, chief information officer at IBM. “This is a real good example of walking the talk when it comes it comes to open standards and open source,” Truskowski said. http://news.com.com/IBM+backs+Firefox+in-house/2100-7344_3-5704750.html?tag=nefd.top

LAWYER VS. LAWYER OVER WEB SITE (ABA Journal, 13 May 2005) -- One New York personal injury law firm is suing another personal injury firm in the state, alleging a Web site noting a state bar panel’s probe of the first firm violates the state’s civil rights act. According to the lawsuit, the firm Moran & Kufta of Rochester posted a headline with a hyperlink on its Web site that told readers that Cellino & Barnes, with offices in Buffalo and Rochester, was being investigated by the New York State Bar Association grievance committee. The headline in question was part of the “Hot Topics” portion of Moran & Kufta’s Web site. It referred readers to a March 11 story in The Buffalo News, “Cellino & Barnes Investigated,” and added: “State Court to Rule on Complaints by Former Clients.” That Web site has since been taken down. On April 18, Cellino & Barnes filed suit in the Supreme Court of New York in Erie County. The suit named James J. Moran and the law firm as defendants, and alleges Moran & Kufta violated section 50 of the New York Civil Rights Law. That law provides in part: “A person, firm or corporation that uses for advertising purposes, or for the purposes of trade, the name, portrait or picture of any living person without having first obtained the written consent of such person … is guilty of a misdemeanor.” http://www.abanet.org/journal/ereport/my13publish.html

TRADEMARKS BLINDSIDE GOOGLE (Steptoe & Johnson’s E-Commerce Law Week, 14 May 2005) -- Search engines make a remarkable amount of money selling ads that are triggered by the search terms you enter. Type in “American music” and Google serves you an ad for allcoolmusic.com. Type in “American clothes” and Google serves you an ad for unionwear.com. Type in “American blinds” and Google, well, Google gets served with a lawsuit. That’s because there’s a company called American Blind & Wallpaper Factory, which claims that its trademarked name allows it to prevent the use of “American blinds” as a trigger for ads for any other company. This is a controversial claim, to say the least, but it has proven surprisingly strong in the courts. The most recent court to buy into the cause of trademark maximalism, at least preliminarily, is the US District Court for the Northern District of California, which denied Google’s motion to dismiss American Blind’s trademark counterclaims. The court found that when search engines use a trademarked name to trigger ads for competing companies, the search engines have used the trademark in commerce, a use that supports a claim of trademark infringement. This is bad news for search engines and consumers but good news for companies with aggressive trademark programs. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9712&siteId=547

NEW YORK TIMES TO CHARGE FOR ARCHIVES, EDITORIALS (Reuters, 16 May 2005) -- The New York Times Co. on Monday said it plans to charge for some of its editorial columns and its archive of stories online to boost subscription sales, even as it invests in its free service. The New York-based publisher of the namesake newspaper and The Boston Globe said the new product, TimeSelect, will debut in September and cost $49.95 for an annual subscription. The company said most of its stories will still be available online for free. TimeSelect underscores the paper’s push to create more Web products, both free and for a fee, to offset an uncertain advertising market for its print newspapers. The New York Times purchased Web site About.com for about $410 million earlier this year to increase its online advertising inventory. The paper’s print subscribers will have free access to the paper’s columnists online, including those written by Times staffers and International Herald Tribune writers. TimeSelect will also give subscribers access to its archives dating back initially to 1980. The company plans to eventually extend its archives back to the 1850s, a spokesman said. http://story.news.yahoo.com/news?tmpl=story&cid=582&e=4&u=/nm/20050516/wr_nm/media_newyorktimes_dc

CARDS LET METRO COLLECT DATA ON RIDERS, TRACK TRIPS (Washington Times, 17 May 2005) -- Metro’s SmarTrip fare cards allow the transit agency to monitor passengers’ travel with little regard for privacy concerns, a group focused on privacy issues says. The SmarTrip fare card, which includes an embedded radio frequency identification (RFID) chip, tracks each rider’s travel and can be matched with the rider’s name, address and credit-card number, according to the District-based nonprofit Electronic Privacy Information Center (EPIC). “Our basic point is that there is a lot of detailed information being collected,” said Marc Rotenberg, executive director of EPIC, a public-interest group established in 1994 to focus attention on emerging threats to civil liberties. “The privacy protections, in our opinion, are inadequate.” http://washingtontimes.com/metro/20050517-120301-3752r.htm

IS YOUR BOSS MONITORING YOUR E-MAIL? (CNET, 18 May 2005) -- If you’re working for a U.S. company, there’s a good chance you’re being watched--and you may get fired for how you use your computer or office phone. That’s the gist of a study on electronic monitoring and surveillance released Wednesday by the American Management Association and the ePolicy Institute. The report found that companies increasingly are “putting teeth in technology policies.” About a quarter of employers have fired workers for misusing the Internet; another 25 percent have terminated employees for e-mail misuse; and 6 percent have fired employees for misusing office telephones, according to the report. “Concern over litigation and the role electronic evidence plays in lawsuits and regulatory investigations has spurred more employers to implement electronic technology policies,” Nancy Flynn, executive director of the ePolicy Institute, said in a statement. Although liability and regulatory issues may be convincing companies to peek in on their employees, such surveillance raises privacy concerns. Employers can monitor workers to a greater degree these days, thanks to newer technologies such as keystroke-logging software and satellite global positioning systems that can track a cell phone user’s whereabouts. The survey, which involved 526 U.S. companies, found that 5 percent use GPS technology to monitor cell phones and 8 percent use GPS to track company vehicles. About 75 percent of companies monitor workers’ Web site connections, and 65 percent use software to block connections to inappropriate Web sites. Computer monitoring takes various forms, according to the study, with 36 percent of employers tracking “content, keystrokes and time spent at the keyboard.” Another 50 percent of companies store and review employees’ computer files, according to the report. http://news.com.com/Is+your+boss+monitoring+your+e-mail/2100-1032_3-5712677.html?tag=nefd.top

PERSONAL DATA FOR THE TAKING (New York Times, 18 May 2005) – Senator Ted Stevens wanted to know just how much the Internet had turned private lives into open books. So the senator, a Republican from Alaska and the chairman of the Senate Commerce Committee, instructed his staff to steal his identity. “I regret to say they were successful,” the senator reported at a hearing he held last week on data theft. His staff, Mr. Stevens reported, had come back not just with digital breadcrumbs on the senator, but also with insights on his daughter’s rental property and some of the comings and goings of his son, a student in California. “For $65 they were told they could get my Social Security number,” he said. That would not surprise 41 graduate students in a computer security course at Johns Hopkins University. With less money than that, they became mini-data-brokers themselves over the last semester. They proved what privacy advocates have been saying for years and what Senator Stevens recently learned: all it takes to obtain reams of personal data is Internet access, a few dollars and some spare time. Working with a strict requirement to use only legal, public sources of information, groups of three to four students set out to vacuum up not just tidbits on citizens of Baltimore, but whole databases: death records, property tax information, campaign donations, occupational license registries. They then cleaned and linked the databases they had collected, making it possible to enter a single name and generate multiple layers of information on individuals. Each group could spend no more than $50. http://www.nytimes.com/2005/05/18/technology/18data.html?ex=1274068800&en=2e20e8def94eb234&ei=5090&partner=rssuserland&emc=rss

PLAN WOULD BROADEN F.B.I.’S TERROR ROLE (New York Times, 19 May 2005) -- The Bush administration and Senate Republican leaders are pushing a plan that would significantly expand the F.B.I.’s power to demand business records in terror investigations without obtaining approval from a judge, officials said on Wednesday. The proposal, which is likely to be considered next week in a closed session of the Senate intelligence committee, would allow federal investigators to subpoena records from businesses and other institutions without a judge’s sign-off if they declared that the material was needed as part of a foreign intelligence investigation. The proposal, part of a broader plan to extend antiterrorism powers under the law known as the USA Patriot Act, was concluded in recent days by Republican leaders on the Senate Select Committee on Intelligence in consultation with the Bush administration, Congressional officials said. Administration and Congressional officials who support the idea said the proposal would give the F.B.I. a much-needed tool to track leads in terrorism and espionage investigations that would be quicker and less cumbersome than existing methods. They pointed out that the administrative subpoena power being sought for the F.B.I. in terror cases was already in use in more than 300 other types of crimes, including health care fraud, child exploitation, racketeering and drug trafficking. http://www.nytimes.com/2005/05/19/politics/19terror.html?ex=1274155200&en=f6615ca026642d9a&ei=5090&partner=rssuserland&emc=rss

US TECH CO’S WANT CLICKWRAPS OUT OF HAGUE CONVENTION (BNA’s Internet Law News, 19 May 2005) -- BNA’s Electronic Commerce & Law Report reports that U.S. ISPs and other technology companies have urged State Department negotiators to exclude “clickwrap” agreements from the Draft Hague Convention on Exclusive Choice of Court Provisions in B2B Agreements. Negotiators are set to meet next month at the Hague Conference on Private International Law to discuss the convention. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b0w5h0d9

ISRAELI COURT RULES DIRECTORS HAVE COPYRIGHT IN THEIR MOVIES (BNA’s Internet Law News, 19 May 2005) -- After a protracted five-year legal battle, the Tel Aviv District Court recently ruled that directors have copyrights to movies they have directed, as they have contributed their creativity to the productions. This is viewed as a landmark decision because until now no court had ruled on the question of directors’ copyrights to their works. http://www.haaretzdaily.com/hasen/spages/577805.html


**** RESOURCES ****
A RARE NEWSBITES BOOK REVIEW: SILENCE ON THE WIRE (SANS NewsBytes, 27 April 2005) -- We rarely do book reviews, but this is an extraordinary collection of information on passive reconnaissance and the publisher is fairly unknown, so if we didn’t bring “Silence on the wire” to your attention it might get missed. If you are involved in information warfare, or in charge of security at an organization with high value assets you should be aware of this book: http://www.amazon.com/exec/obidos/tg/detail/-/1593270461/qid=1114558699/sr=8-1/ref=pd_csp_1/103-9311674-6721424?v=glance&s=books&n=507846


SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, April 23, 2005

MIRLN -- Misc. IT Related Legal News [27 March - 23 April 2005; v8.05]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

YAHOO ADDS SEARCH FOR ‘FLEXIBLE’ COPYRIGHT CONTENT (CNET, 24 March 2005) -- Yahoo has added a feature that lets people search content that’s been licensed through Creative Commons, a nonprofit group that specializes in copyrighting material so that it’s available for some reuse. Yahoo said the search tool links to millions of Web pages featuring Creative Commons’ unconventional content-licensing agreements. Most of the content available through the search feature can be licensed for free under noncommercial-usage or other guidelines, Yahoo said. Creative Commons says its mission is to carve out new ways to share creative works. For example, one alternative the group offers is “attribution only” distribution--the copyright holder lets others copy, distribute, display and perform his works, but only if users give the author credit. The organization lists the different licenses and details on its Web site. http://news.com.com/2100-1038_3-5633649.html

ICANN APPROVES .EU DOMAIN SPACE (Internet News, 25 March 2005) -- The European Union (EU) can now make a name for itself on the Internet, following this week’s approval to include .eu as a country code top-level domain (ccTLD). Directors at the Internet Corporation for Assigned Names and Numbers (ICANN) approved the new name space at a meeting Monday. Officials at EURid, who will take over registry management of the ccTLD, expect final approval from the U.S. Department of Commerce within the next week. http://www.internetnews.com/xSP/article.php/3492776

A CAPPS BY ANY OTHER NAME (Wired, 25 March 2005) -- The controversial Secure Flight passenger pre-screening system, or CAPPS III as some have dubbed it, is riddled with faults and should be shelved until it meets strict criteria laid out by Congress. That’s according to Rep. Loretta Sanchez (D-California), members of the American Civil Liberties Union and computer security expert Bruce Schneier, who held a press call Thursday to bring attention to an upcoming report by the Government Accountability Office, which they hope will fault Secure Flight for failing to meet several criteria for its implementation required by Congress. The GAO report, which was mandated by Congress last year in the Department of Homeland Security Appropriations Act of 2005, is likely to be released Monday. But Sanchez and others said they were concerned that the Transportation Security Administration, which will implement Secure Flight, is trying to ignore Congress by taking steps to roll out the system on two national airlines this August, before the program can be certified by the GAO or cleared by Congress. Sanchez also said they were speaking out now out of concern that the GAO could be pressured to certify Secure Flight before it’s ready to go forward. TSA spokeswoman Amy Von Walter would not comment on the GAO report’s contents before its release, but she said the TSA had been working closely with Congress and the GAO “to ensure we are meeting their requests and requirements as we move through the testing phase” and that they would continue to do so “to ensure they’re in agreement before implementing the program in August.” Although there has been some talk that the August rollout might be only a test, Von Walter confirmed that it is the first stage of officially implementing Secure Flight. The TSA had yet to determine which two airlines would participate in the rollout. http://www.wired.com/news/privacy/0,1848,67015,00.html

DEAR FEDS, SEND MONEY OR THE IT INFRASTRUCTURE COULD GET IT (Steptoe & Johnson’s E-Commerce Law Week, 26 March 2005) -- They say money makes the world go ‘round . . . And now a group of experts are warning that without a serious cash infusion, the nation’s information technology (IT) infrastructure world is at grave risk of being knocked off its axis by a terrorist or criminal attack. In a report entitled, “Cyber Security: A Crisis of Prioritization,” the President’s Information Technology Advisory Committee (PITAC) -- an advisory body of IT leaders in academia and industry -- argues that the IT infrastructure of the US is “highly vulnerable to terrorist and criminal attacks.” The report, made public on March 18, calls for a drastically increased federal role in supporting the development of new cybersecurity technologies. PITAC warns that short-term solutions to infrastructure vulnerability, like patching or retrofitting software, are inadequate and that only a massive deployment of money and manpower can successfully address the “large structural insecurities” of the nation’s IT infrastructure. We’ve heard such dire warnings before, however, to little discernable effect. But perhaps the current spotlight on identity theft and data security breaches will lend some heft to the argument that the security of the nation’s cyber infrastructure deserves at least as much attention as the data it carries. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9263&siteId=547

-- and --

BANK REGULATORS BEAT CONGRESS TO THE PUNCH ON SECURITY BREACH NOTIFICATIONS (Steptoe & Johnson’s E-Commerce Law Week, 26 March 2005) -- With all the Congressional activity on data security and identity theft these days, it’s easy to forget that threats of new legislation are only half the story. In some industries, federal regulators are already setting guidelines for when companies should disclose security breaches. For example, the four federal financial industry regulators have issued “Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice” to instruct financial institutions on when they will be expected to report security breaches of “sensitive customer information” -- whether that information is stored electronically or in paper form. The federal regulators will view a financial institution’s failure to comply with the guidance as an unsafe and unsound information security practice. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9263&siteId=547

TELECOM GIANTS JOIN FORCES AGAINST HACKERS (CNET, 28 March 2005) -- High-profile telecom and networking companies are banding together to crack down on hackers. The new Fingerprint Sharing Alliance hopes to help its members, which include British Telecommunications, Cisco Systems, EarthLink, MCI and NTT Communications, more effectively share information on individuals responsible for launching online attacks. Other organizations involved in the collaboration, which was announced Monday, include Asia Netcom, Broadwing Communications, Verizon Dominicana, XO Communications and the University of Pennsylvania. Members of the Fingerprint Sharing Alliance will automatically send one another data on computer hackers as they observe or experience new attacks. By immediately alerting other communications companies when they’re being threatened, members of the group hope they can more effectively guard against online attacks and infrastructure hacks that cross network boundaries. Arbor Networks is helping to spearhead the effort. The Lexington, Mass.-based company, which specializes in network threat detection and monitoring tools, will provide the technology used by the group’s members to share emerging attack data. By helping the communications giants rapidly distribute information on hackers, the security company said it can aid in blocking attacks closer to the source. Mark Sitko, vice president of MCI’s Security Services Product Management group, said the Fingerprint Sharing Alliance will quickly provide an “unparalleled view” into new security threats as they surface around the globe. Sitko also promised that MCI will bring significant antihacking firepower to the table. http://news.com.com/2100-7355_3-5642840.html

METLIFE PLANS FREE ID THEFT AID FOR CLIENTS (Washington Post, 28 March 2005) -- MetLife Inc., one of the nation’s largest insurers, is rolling out a new program this week to provide free help in resolving cases of identity theft for all of its homeowner insurance policyholders. Noel Edsall, director of MetLife Auto & Home product development, said the ID theft resolution service would be launched first in New York and Florida, then expand nationwide. While several insurance companies sell ID theft coverage, mainly to reimburse consumers for their costs in dealing with misuse of credit cards or other accounts, MetLife would be the first that works with consumers to resolve their problems at no cost. Matt Cullina, manager of the MetLife team that developed the new service, said that MetLife policyholders who are victimized by ID thieves will be urged to call the MetLife call center listed on their policies. From there they will be directed to specialists at Identity Theft 911 LLC of Scottsdale, Ariz., which provides ID theft resolution services. Sheryl Cox Christenson, the company’s chief executive, said Identity Theft 911 “serves as an advocate,” providing services that include preparing affidavits, contacting police and notifying credit bureaus on a consumer’s behalf. http://www.washingtonpost.com/wp-dyn/articles/A5805-2005Mar27.html

NIST OFFERS HIPAA SECURITY GUIDANCE (Government Computing News, 28 March 2005) -- The National Institute of Standards and Technology has issued a new guide on securing health information. The guide, Special Publication 800-66, recommends the type of systems that are needed to meet the Health Insurance Portability and Accountability Act security mandates that take effect April 20. The publication, An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act Security Rule, details the minimum requirements to secure health information and systems. NIST identifies resources relevant to the specific security standards included in the HIPAA security rule and provides implementation examples for each. Under the rule, doctors and hospitals must secure and protect patient information from unauthorized use, such as hackers, while also keeping it available for legitimate use. The rule also applies to agencies that transmit health information in electronic form. The guide also lays out similarities between the HIPAA security rule and the Federal Information Security Management Act of 2002, which all agencies must fulfill. http://www.gcn.com/cgi-bin/udt/im.display.printable?client.id=gcndaily2&story.id=35364; guide at http://csrc.nist.gov/publications/nistpubs/800-66/SP800-66.pdf

OUT-OF-STATE TELECOMMUTER RULED LIABLE FOR N.Y. TAXES (SiliconValley.com, 29 March 2005) -- A man who lives out of state while working by computer must pay New York tax on his full income, the state’s highest court ruled Tuesday in a case that could have wide implications for the growing practice of telecommuting. The Court of Appeals said computer programmer Thomas Huckaby, who lives in Nashville, Tenn., owed New York income tax for his full salary, not just the time he spent working at his employer’s New York offices. Huckaby, whose home state doesn’t have an income tax, paid New York state tax on about 25 percent of his income over two years for the time he spent working there for the National Organization of Industrial Trade Unions. The court upheld a state tax department ruling that all his income should be taxed. That amounts to $4,387 plus interest. However, the ruling could lead to much greater income for the state as it is applied to the growing field of telecommuting. The U.S. Census Bureau’s latest statistics show that nearly 4.2 million people worked at home in 2000, up from 3.4 million in 1990. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/11259955.htm

TEN QUESTIONS ABOUT SARBANES-OXLEY COMPLIANCE (Computerworld, 30 March 2005) -- Imagine this scenario: You are a CIO at a publicly traded company in turmoil, and your chief financial officer was forced to resign at the end of last quarter after material weakness concerns were raised by your external auditors. Three months ago, the Securities and Exchange Commission got involved and launched a formal investigation, and your company is now constantly scrutinized. It’s time for your CEO to report earnings, and it’s not good news. Now your general counsel adds more bad news. Under the Sarbanes-Oxley Act, your management must demonstrate that adequate internal controls have been established to safeguard confidential information from being compromised during the “blackout.” With the rumor mill running rampant, you know the likelihood of an internal disclosure concerning earnings information is high. However, you have no means to detect these communications if they are leaked in a Web mail or a post to an Internet bulletin board. Even if you could detect this, what information should you protect? Is there a blueprint compliance strategy that could be deployed in a way that could detect all electronic disclosures? There are solutions available, but first you must understand Sarbanes-Oxley, how it affects your business and what information -- by law -- needs to be protected. You and your CEO must know the answers to the following 10 questions in order to prepare and prove that you have deployed the right mix of internal controls: http://www.computerworld.com/printthis/2005/0,4814,100646,00.html [Editor: The ABA’s Cyberspace Law Committee soon will publish a “Directors Guide to Data Governance” addressing these issues. The book will be the subject of a committee panel presentation at the ABA annual meeting this August in Chicago. Registration information at http://www.abanet.org/annual/2005/]

CENTER CREATES ARCHIVING MODEL (Federal Computer Week, 30 March 2005) -- A New York-based technology research center has developed an approach and methodology designed to help state and territorial archivists and librarians preserve digital information. Through an $800,000 grant from the National Science Foundation, the University at Albany’s Center for Technology in Government has developed a national capability assessment and planning model -- containing information about the governance structure, business model, architecture, and data standards -- to assist governments in identifying, capturing and archiving digital content critical to government operations. As part of the National Digital Information Infrastructure and Preservation Program, the Library of Congress will distribute this toolkit during three workshops that will be held beginning in late April and through May for state and territorial government representatives. Library officials hope to collaborate with their state and territorial counterparts in devising long-term strategies, and receive feedback that can be used to help create a second version. While there are legal mandates in place for preserving paper records, safeguarding digital information is new territory for many governments. http://www.fcw.com/article88434-03-30-05-Web

HOLLYWOOD SEEKS ITUNES FOR FILM (CNET, 30 March 2005) -- Sony Pictures Digital Entertainment is trying to develop and own the next iTunes--but for films. “We want to set business models, pricing models, distribution models like (Apple Computer CEO Steve) Jobs did for music, but for the film industry,” Michael Arrieta, senior vice president of Sony Pictures, said at the Digital Hollywood conference here. “I’m trying to create the new ‘anti-Napster,’” he added. To that end, Arrieta said, his group plans to digitize Sony Pictures’ top 500 films and make them available for the first time in various digital environments within the next year. He said the distribution for films like “Spider-Man 2” will go beyond just Movielink, the video-on-demand joint venture of Sony Pictures and several other major studios, which to date has hosted a limited library of Sony’s movies. For example, Sony plans to sell and make films available in flash memory for mobile phones in the next year, Arrieta said. It also will further develop its digital stores for downloading and owning films on the PC, he said in an interview. Sony’s plans--and similar moves by other studios--are likely to avoid empowering any one technology company--such as Apple in the music equation--and allow studios to pocket more of the profits. The philosophy in Hollywood is “Define your own agenda or someone else will for you.” http://news.com.com/2100-1025_3-5647682.html

CHINESE ONLINE SIGNATURES GRANTED LEGAL EFFECT (China View, 31 March 2005) -- Online signatures will become valid in China as of April 1 to facilitate the country’s growing on-line trading, an official of the Ministry of Information Industry (MII) on Thursday. The law grants electronic signatures the same legal effect as handwritten signatures and seals for business transactions, acknowledged the official. It establishes a market access system for online certification providers to ensure the security of e-commerce. While giving due consideration to current electronic certification services that are still in a startup period, the law stipulates that governmental departments shall undertake “effective and appropriate” supervision and management over the electronic certification service organs in market access. The Administration Rules on Online Certification Service goes into effect on the same day to support the implementation of the law. The rules cover mainly the issuance and management of licenses for online certification service, standardization of service behavior, handling of suspension or alteration of the service, pattern and security measures of online signature certification, supervision and management and penalties for illegal activities in the field. http://news.xinhuanet.com/english/2005-03/31/content_2769741.htm

THE WELL CELEBRATES 20TH BIRTHDAY (CNET, 31 March 2005) -- One of the oldest and most celebrated online communities is celebrating its 20th birthday on Friday. Founded in 1985 as a humble computer conferencing system with six dial-up modems, The Well soon blossomed into a “literate watering hole,” luring tens of thousands of artists, technologists and writers. “It’s really something that you’re not going to see anywhere else,” said Gail Williams, director of communities. “It seems to have a tremendous momentum, no matter what happens.” The Well was the creation of Stewart Brand, publisher of the Whole Earth Catalog, who squirreled away the original VAX server in a corner of Whole Earth’s decrepit offices in Sausalito, Calif. Before long, The Well’s conferences became known for intelligent conversation and were attracting luminaries like Kevin Kelly (a Wired Magazine editor) and Mitchell Kapor (the founder of Lotus Development Corporation). Some of The Well’s discussions marked turning points in the history of the Internet. A post from John Perry Barlow, a former Grateful Dead lyricist, prompted Kapor to jet to Wyoming where the two created the Electronic Frontier Foundation. In another, Barlow famously invoked science fiction writer William Gibson’s term “cyberspace” to apply to the Internet of the present. Sometimes participants seemed to regret disclosures made in the chatty confines of the conferences. When James Rutt, a prominent Well member in the 1990s, became chief executive of Network Solutions, he raised eyebrows by deleting hundreds of his posts to avoid possible embarrassment. http://news.com.com/The+Well+celebrates+20th+birthday/2100-1025_3-5649445.html?tag=nefd.lede The Well is at http://www.well.com/

INTEL TO STOP USING OPEN-SOURCE LICENSE (CNET, 31 March 2005) -- Intel on Thursday said that it will discontinue an open-source license used to govern some of its software. The chipmaker said it has told the Open Source Initiative (OSI) to remove its open-source license from future use as an approved OSI license. The OSI is a nonprofit agency that promotes the use of open-source software and maintains a listing of open-source licenses on its Web site. McCoy Smith, an Intel attorney, raised the issue on an OSI mailing list earlier this week. He said that Intel would like to “remove from future use” the Intel Open Source License, to reduce license proliferation. Intel’s open-source license governs the use of security software that the company has defined. The issue of license proliferation has caused concern among some in the open-source community as it can increase the cost for companies wishing to adopt open-source software, as they need to review and manage each type of license. Intel decided to get rid of its license after finding that it had not been used within the company for several years and is not often used outside Intel, according to an Intel spokesman. Smith said that it does not want the “deapproval” of the license to be retroactive to past uses, as it does not want to force companies to relicense code. http://news.com.com/Intel+to+stop+using+open+source+license/2100-7344_3-5648518.html

POPE’S INFLUENCE INCLUDES TECHNOLOGY FIRSTS (CNET, 2 April 2005) -- While Pope John Paul II will largely be remembered for his influence on social issues ranging from euthanasia to AIDS, he also earned a place in history as the first pontiff to embrace computer technology. The Vatican brokered a deal with Verizon last year for a service to deliver a daily papal message to subscribers’ cell phones. A church representative said the Vatican had a history of embracing new communications media, and cell phones are a natural vehicle for reaching younger believers. “People are always trying to find ways to market His Holiness,” said Sister Mary Ann Walsh, a spokeswoman for the U.S. Conference of Catholic Bishops. Earlier, the Vatican set up a special page for the pope to deliver messages about faith and world peace. “While the Internet can never replace that profound experience of God which only the living, liturgical and sacramental life of the Church can offer, it can certainly provide a unique supplement and support in both preparing for the encounter with Christ in community, and sustaining the new believer in the journey of faith which then begins,” the pontiff proclaimed at the 36th annual World Communications Day in 2002. Under John Paul II’s leadership, the Vatican has also moved forward with plans to name St. Isidore of Seville, known for his scholarly work, as the patron saint of computer users, computer technicians and the Internet. The pope’s health crisis the past few weeks also prompted a flurry of Web activity. The main Vatican Web site was unreachable due to heavy traffic most of Friday. But American Catholics could still submit prayers for the pontiff through the Franciscan Friars’ online St. Anthony Shrine, while Your Catholic Voice encouraged the faithful to initiate e-mail prayer chains. http://news.com.com/Popes+influence+includes+technology+firsts/2100-1032_3-5650550.html?tag=nefd.top

-- related (somewhat) story on the security of the Papal election process, and how it might be “hacked” at http://www.schneier.com/crypto-gram-0504.html#8


B.C. COURT DISMISSES PRIVACY CLAIM OVER DATA OUTSOURCING (BNA’s Internet Law News, 4 April 2005) -- The British Columbia Supreme Court has dismissed a claim by a B.C. union challenging the outsourcing of the management of health information to a U.S. company. The court emphasized the importance of privacy protection, but concluded that “the contractual provisions, the corporate structure, and the legislative provisions provide more than reasonable security with respect to records in British Columbia.” It also noted that “all reasonable steps to ensure the confidentiality of the information which Maximus will receive in order to discharge its contractual obligations. Privacy is not absolute.” Case name is BC Govt Serv. Empl. Union v. British Columbia (Minister of Health Services). Decision at http://www.courts.gov.bc.ca/Jdb-txt/SC/05/04/2005BCSC0446.htm

THE NEXT CHAPTER IN THE PATRIOT ACT (CNET, 4 April 2005) -- Both the Senate and the House of Representatives are kicking off what promises to be a tumultuous series of hearings about whether to renew key sections of the controversial 2001 law. Roughly half of the law is set to expire on Dec. 31. It’s too early to know whether the hearings will be a sober analysis of surveillance and privacy or a Republican ploy to rubber-stamp a renewal. Early signs are positive; presiding over the Senate hearings will be Arlen Specter, R-Penn., who supported a partial repeal of the Patriot Act last year. His House counterpart, F. James Sensesnbrenner, R-Wis., has made similar comments in the past. The Patriot Act, of course, has been one of the most polarizing laws of the last few decades. The Bush administration drafted large portions of it, and the president himself sings its praises every chance he gets. But worries about the law’s effect on civil liberties led hundreds of communities to vote to condemn it. The law is long and convoluted. But five sections that are set to expire will have the most impact on the technology and telecommunications industries:
• Sec. 202: Computer hacking is a “predicate offense” permitting police to seek certain types of wiretaps.
• Sec. 203: Federal police can share information gleaned from a wiretap or Carnivore-like surveillance device with spy agencies. Previously, there was no explicit authorization for such data sharing.
• Sec. 212: Internet providers and other communications services can divulge information to police more readily. Specifically, customer records and other data may be legally handed over to police in an emergency.
• Sec. 215: Secret court orders can be used to obtain records or “tangible items” from any person or business if the FBI claims a link to terrorism. The unlucky recipient of the secret order is gagged; disclosing its existence is punishable by a prison term. Librarians are especially concerned about this (though the FBI claims it hasn’t invoked Sec. 215 so far).
• Sec. 217: Computer service providers may eavesdrop on electronic trespassers legally. Police can be authorized to “listen in” on what’s happening on the provider’s network. http://news.com.com/2010-1071_3-5650840.html

-- and --

FEDS UNCLOAK THE PATRIOT ACT (CNET, 5 April 2005) -- More information is dribbling out about the exercise of extraordinary powers granted to federal police nearly four years ago as part of the war on terror. As the Bush administration this week called on Congress to expand the USA Patriot Act, it disclosed how two of the most controversial sections of the law have been wielded by police. Police invoked the Patriot Act when surreptitiously entering and searching a home or office without notifying the owner 108 times during a 22-month period, according to a one-page summary released by the Justice Department late Monday. On Tuesday, U.S. Attorney General Alberto Gonzales told the Senate that police have employed secret court orders to obtain records 35 times so far. http://news.com.com/2100-1030_3-5655112.html

COURT RULES COMMON LAW PROTECTS RECORDINGS MADE BEFORE U.S. COPYRIGHT LAW (SiliconValley.com, 5 April 2005) -- New York’s highest court ruled that common law protects the rights of a record company for music recorded before the 1972 federal copyright law in a decision the judges expect to have “significant ramifications for the music recording industry.” The result is that artists, their estates and others involved in recordings made before 1972 should be able to collect royalties in the United States for their performances, said Philip Allen Lacovara, the attorney for Capitol Records that won the state decision released Tuesday. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/11316478.htm

GOOGLE FEATURE INCORPORATES SATELLITE MAPS (Washington Post, 5 April 2005) -- Online search engine leader Google has unveiled a new feature that will enable its users to zoom in on homes and businesses using satellite images, an advance that may raise privacy concerns as well as intensify the competitive pressures on its rivals. The satellite technology, which Google began offering late Monday at http://maps.google.com, is part of the package that the Mountain View-based company acquired when it bought digital map maker Keyhole Corp. for an undisclosed amount nearly six months ago. This marks the first time since the deal closed that Google has offered free access to Keyhole’s high-tech maps through its search engine. Users previously had to pay $29.95 to download a version of Keyhole’s basic software package. A more traditional map will continue to be the first choice served up by Google’s search engine. Users will have the option of retrieving a satellite picture by clicking on a button. The satellite maps could unnerve some people, even as the technology impresses others. That’s because the Keyhole technology is designed to provide close-up perspective of specific addresses. http://www.washingtonpost.com/wp-dyn/articles/A26445-2005Apr4.html [Editor: try it -- key in your home address and click on the “Satellite” URL at the upper-right of the window; zoom in]

IBM TO EXPENSE STOCK OPTIONS (News Factor, 6 April 2005) -- IBM says it will start expensing stock options in view of new Securities and Exchange Commission guidelines that go in effect on June 15th. The world’s largest computer firm joins other large firms that have decided to count the value of stock options against their earnings, but leaves the ranks of many technology firms that offer stock options as an incentive to attract the best talent. The company says it will restate earnings from last year based on the new policy. The total expense for distributed stock options in fiscal 2004 was 55 US cents a share. IBM says it will adopt the Financial Accounting Standards Board’s revised Shared-Based Payment policy -- known as “SFAS 123(R)” -- which was issued last December. FASB said the rule was needed to make company financial reporting more transparent and comparable for investors and regulators. The lack of expensing stock options is said to distort financial results. Some critics of stock-based compensation say the practice is merely a financial rearrangement of chairs to make earnings announcements appear better. The actual health of the company can be tested within its operational results. IBM is unlikely to be a leader among technology companies in the adoption of SFAS 123(R). “If technology companies don’t need to expense stock options, I don’t see many of them doing so just because IBM is doing it,” said Yankee Group analyst Michael Dominy. “They’ll do it if they’re forced to.” FASB said in December it would allow companies the option of continuing to apply previous guidelines regarding the expensing of stock options, “as long as the footnotes to financial statements disclosed what net income would have been had the preferable fair-value-based method been used.” http://story.news.yahoo.com/news?tmpl=story&cid=620&e=2&u=/nf/20050406/bs_nf/32375

HOMELAND SECURITY PANEL PICKS CONTROVERSIAL CHIEF (CNET, 6 April 2005) -- A federal privacy board on Wednesday appointed a prominent champion of government data-mining as its first chairman. The Department of Homeland Security’s privacy board chose as its chairman Paul Rosenzweig, a conservative lawyer best known in technology circles for his defense of the Pentagon’s Total Information Awareness project. Bowing to privacy concerns, Congress pulled the plug on the program two years ago. Nuala O’Connor Kelly, the department’s chief privacy officer, nominated Rosenzweig for the job during the group’s first meeting in a downtown hotel here. Rosenzweig is a senior fellow at the Heritage Foundation and a former Justice Department trial attorney. “Constructive criticism from the bully pulpit to which we’ve been advanced here can serve as a positive tool to the department,” Rosenzweig said during the meeting, which drew more than 100 audience members. Lisa Sotto, a partner at the New York law firm of Hunton and Williams, was appointed vice chairman. The privacy advisory board has already raised eyebrows when an executive from “adware” company Claria (formerly called Gator) was selected as a member in February. The group is charged with providing advice “programmatic, policy, operational and technological issues that affect privacy, data integrity and data interoperability.” “I don’t really regard Paul as a privacy advocate,” said Lee Tien, a lawyer with the Electronic Frontier Foundation in San Francisco. “I think he’s much more focused on whatever homeland security mission there is. He tends to view privacy as something to be circumvented.” http://news.com.com/Homeland+Security+panel+picks+controversial+chief/2100-7348_3-5657746.html?tag=nefd.top

FRENCH APPEALS COURT SAYS YAHOO NOT LIABLE FOR NAZI GEAR AUCTIONS (Silconvalley.com, 6 April 2005) -- A Paris appeals court on Wednesday upheld a decision that absolved Yahoo! Inc. of any legal responsibility for auctions of Nazi paraphernalia formerly held through its Web site. The attorney for Yahoo, Olivier Metzner, said the decision made clear that the company and its former chief executive, Tim Koogle, were not responsible for the Nazi collectibles sold. In 2003, a Paris court ruled that Yahoo and Koogle never sought to ``justify war crimes and crimes against humanity’‘ -- the accusation leveled by human rights activists, including Holocaust survivors and their families. The case was initiated in 2000, when France’s Union of Jewish Students and the International Anti-Racism and Anti-Semitism League sued Yahoo for allowing Nazi collectibles, including flags emblazoned with swastikas, to be sold on its auction pages. The case led to a landmark ruling in France, with a court ordering Yahoo to block Internet surfers in France from auctions selling Nazi memorabilia. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/11326488.htm

FORUM SELECTION CLAUSE UPHELD IN CONTENT SCRAPING CASE (InternetCases.com, 6 April 2005) -- In the case of Cairo, Inc. v. CrossMedia Services, Inc., decided on April 1, 2005, the U.S. District Court for the Northern District of California has held that although a company using scrapers to gather content from a competitor’s website did not expressly assent to the website’s terms of use, the scrapers’ “repeated and automated” access to the site created imputed assent to the terms of service and the forum selection clause appearing therein. http://www.internetcases.com/2005/04/forum-selection-clause-upheld-in.html

SPITZER PULLS CAMPAIGN AD OFF GOOGLE (CNET, 7 April 2005) -- New York Attorney General Eliot Spitzer on Wednesday pulled a political ad that ran on Google when Web searchers typed in the acronym for American International Group, a prosecutorial target of the crime-busting gubernatorial candidate. During Wednesday morning and early afternoon, Google searchers who typed in the keyword “AIG” were delivered a search ad at the top right of the results page that read “Spitzer for NY Governor.” People who clicked on that ad were sent to www.spitzer2006.com. “It wasn’t appropriate, and as soon as Mr. Spitzer found out about it, he had it removed it as soon as possible,” Darren Dopp, a spokesman for the New York attorney general, told Reuters. Dopp said it appeared that a relatively low-level campaign staffer responsible for promoting Spitzer’s campaign Web site made a mistake and put in the AIG keyword. http://news.com.com/2100-1024_3-5658463.html

UC ELECTRONIC RESERVES RANKLE PUBLISHERS (Chronicle of Higher Education, 7 April 2005) -- A system that handles electronic reserves at the University of California (UC) in San Diego has prompted complaints from publishers that the university has far exceeded the bounds of fair use. With the system, materials that faculty put on reserve are made available electronically, allowing students to access and even print them from outside the university library. The Association of American Publishers objected, saying that electronic access substantially changes the traditional terms of reserve materials and deprives publishers of sales. Publishers have previously won legal challenges to the production of coursepacks, which the courts said do not fall under the terms of fair use. The publishing group insisted the same applies to electronic resources. Representatives of UC disputed the claims, saying the reserve system does not infringe on sales of texts. Jonathan Franklin, associate law librarian at the University of Washington, noted that the fair use law is not clear and commented that if the disagreement is ultimately settled by the courts, such a resolution might provide needed clarification for all concerned. (sub. req’d) http://chronicle.com/prm/daily/2005/04/2005040701t.htm

AOL LAUNCHES INTERNET PHONE SERVICE (AP, 7 April 2005) -- America Online Inc. on Thursday launched its Internet telephone service, jumping into a market that’s already crowded with startups, cable operators and even traditional phone companies. The AOL Internet Phone Service, which is being offered to AOL members and others in 40 markets at first, includes the regular features of traditional telephony and combines them with advanced services that are accessed on a PC over the Internet. AOL’s subscribers must have a high-speed Internet connection and a router. An adapter connects to the router, and a conventional phone can be plugged into the adapter. Users will receive a number and can make or receive calls. AOL’s starting price for new users is $29.99 per month for the first six months — increasing to $39.99 after that. It includes unlimited local and long-distance calling within the U.S. and Canada as well as unlimited access to the regular AOL service over existing broadband. Plans for current AOL users start at $13.99 a month (increasing to $18.99 after three months) for unlimited local and regional calling to $29.99 (increasing to $34.99) for a global calling plan with low international rates. The price for new users is steeper than the current Internet telephony leader, Vonage, which charges $24.99 a month for unlimited U.S. and Canada dialing. Packet8, a similar service offered by 8x8 Inc., charges $19.95 for its “Freedom Unlimited” plan. AOL is apparently trying to differentiate itself by bundling its online service. It also claims to make it easier for consumers to manage their service from a Web-based “dashboard,” which New Jersey-based Vonage also uses to describe its Web-interface. From there, users can change call-forwarding settings, view call logs and access contact lists that will dial a number simply by clicking on it. http://story.news.yahoo.com/news?tmpl=story&cid=528&e=1&u=/ap/20050407/ap_on_hi_te/aol_internet_phone

-- and --

ENTERPRISE USERS ALREADY TALKING VOIP (AP, 13 April 2005) -- Because their phones speak the language of the Internet, Boeing Co. engineers can both hear and see each other as they remotely collaborate on projects. Boeing began experimenting with Internet telephony in 2001 and is now spreading it, videophones included, across the far-flung aerospace and defense company. The same technology lets brokers at Lehman Bros. pre-record voicemail messages and insert them into clients’ inboxes, while the town of Herndon, Va. distributes missing children alerts -- photos and text -- to its municipal employees over their Internet Protocol phones. At NFL Films, a Voice over Internet system makes setup easy as workers travel from stadium to stadium: Workers merely plug their phones into a network and everything from the phone number to user privileges are automatically set up. No trip to the wiring closet required. Home adoption of Internet telephones may not be mainstream, but many corporations, government agencies and other big institutions are cautiously embracing Internet calling for its advanced features and potential cost savings. A 2004 Yankee Group survey of 231 businesses found that 39 percent were using IP telephony in some form. Of those, 9 percent were testing, 25 percent were partially deployed and 5 percent were fully deployed. Of the 113 million U.S. business handsets in use today, only 10 percent use Internet Protocol tech. But growth is accelerating: In fact, the Yankee Group estimates 50 percent of new lines shipped this year will use IP. http://story.news.yahoo.com/news?tmpl=story&cid=74&e=3&u=/cmp/20050414/tc_cmp/160702562

ITALIAN DPA ISSUES RFID GUIDELINES (Hunton & William’s Privacy & E-Commerce Alert, 11 April 2005) -- On March 29, the Garante (Italian Data Protection Authority) published guidelines on the processing of personal data by RFID chips. The Guidelines set forth the following general principles for use of the chips: 1) individuals must be informed about their use; 2) explicit consent must be given for the processing of personal data; 3) there must be a way to deactivate the chips; 4) labor law rights of employees must be respected; 5) chips implanted under the skin may be used only in very exceptional cases; 6) the principles of proportionality and finality must be observed and the personal data may be retained only as long as necessary; 7) adequate security must be used; and 8) the processing must be notified to the Garante. The Guidelines are available (in Italian only) at: http://www.garanteprivacy.it/garante/doc.jsp?ID=1109670.

NEW GUIDE AIMS TO KEEP BLOGGERS SAFE FROM PINK SLIPS (CNET, 11 April 2005) -- As ex-Delta Air Lines and Google employees can testify, blogging about your workplace can often have unfortunate consequences, including receiving a pink slip. To help online scribes--and their bosses--stay on the right side of the law, the Electronic Frontier Foundation has launched a guide for blogging in the workplace. The EFF guide warns that not just random readers can find your blog; friends and colleagues can, too. But anonymity can help protect bloggers from the fallout. “Anyone can eventually find your blog if your real identity is tied to it in some way,” the guide says. “And there may be consequences. Family members may be shocked or upset when they read your uncensored thoughts. A potential boss may think twice about hiring you. But these concerns shouldn’t stop you from writing. Instead, they should inspire you to keep your blog private, or accessible only to certain trusted people.” Among the tips to preserving anonymity: Disguise your name and keep quiet on any details that might allow people to guess your identity--for instance, the location of your city, how many employees there are in your company, or the color of a boss’ cat. The guide also recommends not using work resources for blogging. “You could get in trouble for using company resources like an internet connection to maintain your blog, and it will be very hard for you to argue that the blog is a work-related activity. It will also be much more difficult for you to hide your blogging from officemates and IT operators who observe traffic over the office network,” the guide says. http://news.com.com/2100-1030_3-5662726.html; guide at http://www.eff.org/Privacy/Anonymity/blog-anonymously.php

AUSTRALIAN ACTORS’ UNION SHOUTS ‘CUT’ ON DIGITAL FILM (The Age, 12 April 2005) -- The Australian actors union is blocking a world-first remixable film project, and possibly forcing the production offshore, out of fear that footage of actors could be misused. The Media, Entertainment and Arts Alliance has stopped production on the “re-mixable” film experiment because of plans to release the film under a Creative Commons (CC) licence. The $100,000 short film Sanctuary has been seeking a dispensation from the MEAA since January to allow professional actors to participate in the production. The film’s cast supports the concept but the MEAA board has refused any dispensation, stalling production scheduled to start in late March. The CC licence will allow audiences to freely copy and edit the film’s digital assets for non-commercial purposes, this being the issue of central concern to the MEAA. “We don’t see any safe way a performer can appear in this,” says Simon Whipp, MEAA national director. “Footage could be taken and included in a pro-abortion advertisement or a pro-choice advertisement. http://www.theage.com.au/news/Outsourcing/Actors-union-shouts-cut/2005/04/11/1113071894581.html?oneclick=true

INFORMATION FROM GUANTANAMO DETAINEES (Department of Defense, April 2005) -- The US Government currently maintains custody of approximately 550 enemy combatants in the Global War on Terrorism at Guantanamo Bay, Cuba. Many of these enemy combatants are highly trained, dangerous members of al-Qaida, its related terrorist networks, and the former Taliban regime. More than 4,000 reports capture information provided by these detainees, much of it corroborated by other intelligence reporting. This unprecedented body of information has expanded our understanding of al-Qaida and other terrorist organizations and continues to prove valuable. Our intelligence and law enforcement communities develop leads, comprehensive assessments, and intelligence products based on information detainees provide. The information includes their leadership structures, recruiting practices, funding mechanisms, relationships, and the cooperation between terrorist groups, as well as training programs, and plans for attacking the United States and other countries. [Declassified report summary at http://www.defenselink.mil/news/Mar2005/d20050304info.pdf; at least one detainee reportedly is a lawyer]

COPYRIGHT REFORM TO FREE ORPHANS? (Wired, 12 April 2005) -- Veteran filmmaker Robert Goodman is working on a documentary about the first pop culture phenomenon of the 20th century: American picture postcards. But securing permission to use many of these works -- photos and illustrations that are around 100 years old -- is an impossible task, as many of the original owners are unknown or dead, or the publishing companies no longer exist. The uncertainty of copyright ownership means Goodman, an Emmy-nominated director with a long career in film, photography and writing, is facing substantial costs, a lot of tedious research and, if he’s really unlucky, lawsuits. “There’s no good copyright clearinghouse to go to and say, here’s all the people who copyrighted their materials and here’s how you find them,” said Goodman. “You’re left with trying to find their relatives, and we live in a society where people, on average, move every seven years. It’s an impossibility.” Stories like these about so-called “orphan works” -- items still locked up under copyright but where the owners are unknown or impossible to locate -- are leading the U.S. Copyright Office to try to fix the problem. The office is soliciting reply comments until May 9, and has already collected and posted more than 700 initial comments from artists, academics and copyright owners. Jule Sigall, associate register for policy and international affairs for the copyright office, said the office will hold public hearings this summer and report its findings to the Senate Judiciary Committee by the end of the year. It’s possible that Congress will address the orphan works issue with legislation. “We’re hoping to get a good factual record of what the problems are (and) what obstacles people are running into,” Sigall said. “We also asked people to propose solutions. There seem to be a lot of good suggestions as to the type of mechanisms that could be used to solve the problems.” The copyright office wants to find a solution to satisfy those who want to build on orphan works without jeopardizing copy protection for owners. http://www.wired.com/news/culture/0,1284,67139,00.html

SECURITY BREACH LAWS BECOME STATE’S RIGHTS ISSUE (CNET, 13 April 2005) -- In the wake of a series of high-profile security mishaps, key members of Congress have pledged to crack down on data brokers. But a Senate hearing on Wednesday showed that important federalism questions--namely, how much flexibility states will enjoy to craft their own rules--remain unresolved. “Why not pre-empt state laws so these companies know what they’re dealing with and don’t have to familiarize themselves with the differences” that 50 different state laws could pose, asked Arlen Specter, a Pennsylvania Republican who heads the Senate Judiciary Committee. On technology topics, Congress frequently sets national rules and prevents states from enacting stricter ones. That’s the approach taken by the 2003 Can-Spam Act, which overruled stricter state laws that, in some cases, set “opt-in” rules for bulk e-mail and granted junk e-mail recipients the right to sue spammers. Can-Spam doesn’t. William Sorrell, Vermont attorney general and president of the National Association of Attorneys General, asked senators to veer in a different direction this time. “Have your law be a floor rather than a ceiling,” Sorrell said Wednesday. “Be respectful of the ability of the states.” State legislators have wasted no time in responding to a series of security snafus involving Bank of America, payroll provider PayMaxx, and Reed Elsevier Group’s LexisNexis service. More than 20 states, including New York, Washington, Illinois and Texas, already have proposed responses such as requiring that consumers be alerted if their personal information is disclosed accidentally or improperly. The data mining companies that are likely targets of regulation aren’t exactly clamoring for a crackdown. But they said Wednesday that if new laws are going to be enacted, they’d strongly prefer a uniform federal rule over a state-by-state approach. http://news.com.com/Security+breach+laws+become+states+rights+issue/2100-7348_3-5669991.html?tag=nefd.top

PUTTING TEETH INTO U.S. CYBERCRIME POLICY (CNET, 14 April 2005) -- It wasn’t so long ago that interest in the topic of online crime was limited to a small circle of technologists. Nowadays, senior government officials talk about it as a potential national security threat. That’s where Paul Kurtz comes in. As the executive director of the Cyber Security Industry Alliance, a consortium of CEOs pressing for more-effective cybersecurity legislation, Kurtz is hoping to make sure any new regulations carry real weight. And since the 41-year-old Kurtz’s resume includes a stint on the White House’s National Security Council, as well as a period as senior director for national security at the Office of Cyberspace Security, it’s a good bet that he’ll find an audience willing to hear him out. Kurtz helped develop the international component of the National Strategy to Secure Cyberspace, as a member of the President’s Critical Infrastructure Protection Board. In his new post, Kurtz believes the CSIA, which was founded in 2003, can succeed where other security interest groups have not. Unlike industry efforts that have criticized the government for doing too little, or policy groups that have called for action and failed to consider the implications of technology-oriented legislation, Kurtz is looking for middle ground. The security expert believes that by helping the government see the big picture, tech-wise, and aiding politicians in writing laws that have real teeth against cybercriminals, true progress against the tide of online threats can be made. Earlier this month, CNET News.com caught up with Kurtz com to hear his ideas on where CSIA’s battle for better cybercrime legislation currently stands. [interview follows] http://news.com.com/Putting+teeth+into+U.S.+cybercrime+policy/2008-7348_3-5670019.html

THE SCO BOOMERANG AND THE STRENGTH OF LINUX (NewsFactor, 15 April 2005) -- Back in March of 2003, when SCO Group first brought its suit against IBM for, we thought, copyright infringement related to code IBM supposedly donated to Linux, the whole world thought it might be the death of Linux. Even those who didn’t think so certainly believed the litigation was at least about Linux. Two years later, and counting, there still is no indication from SCO what code it is precisely talking about, and any link to Linux seems to be getting weaker and weaker. The code SCO offered to the court so far as infringing materials was rejected as being not credible evidence of copyright infringement. So, where are we now in the SCO v. the World litigation? Most observers now seem to view the case as more about a contract dispute, and the latest SCO claim it wishes to add to its complaint seems to be about AIX code on the Power architecture, which absolutely has no relationship to Linux. So what happened to SCO’s Linux copyright infringement claims? While it’s unwise to predict outcomes in legal disputes beyond what ought to happen, the market already has reached its own conclusion, which is that in the enterprise, most folks just don’t care how it turns out. They want to switch to Linux and they are. http://story.news.yahoo.com/news?tmpl=story&cid=620&e=4&u=/nf/20050415/bs_nf/32974

-- and --

LINUX PROGRAMMER WINS LEGAL VICTORY (CNET, 15 April 2005) -- A Linux programmer has reported a legal victory in Germany in enforcing the General Public License, which governs countless projects in the free and open-source software realms. A Munich district court on Tuesday issued a preliminary injunction barring Fortinet, a maker of multipurpose security devices, from distributing products that include a Linux component called “initrd” that Harald Welte helped write. In addition to being a Linux programmer, Welte runs an operation called the GPL Violations project that attempts to encourage companies shipping products incorporating GPL software to abide by the license terms. The license lets anyone use GPL software in products without paying a fee, but it requires that they provide the underlying source code for the GPL components when they ship such a product. Fortinet, based in Sunnyvale, Calif., said in a statement it’s addressing the issue but is surprised that Welte resorted to legal action. “Fortinet recently became aware of Mr. Welte’s allegations and has, in good faith, been diligently working with him to resolve this matter outside of the German court system. Fortinet is actively taking steps to ensure that its products are compliant with GPL requirements. Therefore, Fortinet is surprised that Mr. Welte pursued a preliminary injunction against Fortinet in Germany and believes that this is an unnecessary action,” the company said. “Fortinet is continuing its efforts to expeditiously resolve this matter with Mr. Welte.” Welte has said he doesn’t object to corporate use of open-source software; he just wants it to be done properly. Welte first notifies companies of his accusations before beginning legal action, he said. In the case of Fortinet, the GPL Violations project informed the company of its concerns March 17, but “out-of-court negotiations on a settlement failed to conclude in a timely manner,” the project said in a statement. http://news.com.com/Linux+programmer+wins+legal+victory/2100-7344_3-5671209.html?tag=nefd.lede

CONTROVERSIAL TERROR DATABASE MATRIX SHUTS DOWN (AP, 18 April 2005) -- A three-year-old crime and terrorism database that came under fire for sharing and collecting personal information was closed down Friday because a federal grant ran out. Elements of the Multistate Anti-Terrorism Information Exchange - Matrix - may live on if individual states decide to fund it on their own, said Bob Cummings, executive vice president for the Institute for Intergovernmental Research in Tallahassee, which helped coordinate the Matrix network. “We’re winding up the project today. The system that the federal government has basically paid for, the application itself to the users and the states, will either be assumed by the states or will no longer exist,” he said. Matrix was down to four participants - Pennsylvania, Florida, Ohio and Connecticut - after several states opted out due to privacy concerns, legal issues or cost. It operated with grant money from the departments of Justice and Homeland Security, but that funding expired Friday. “They can put a good face on it, saying that the grant ran out, but frankly if there wasn’t growing opposition to this kind of intrusive, investigatory technique, the funding wouldn’t have run out,” said Howard Simon, executive director for the Florida American Civil Liberties Union. http://story.news.yahoo.com/news?tmpl=story&cid=74&e=5&u=/cmp/20050419/tc_cmp/160902250

FLEXIBLE COPYRIGHTS HOP THE POND (Wired, 18 April 2005) -- The British Broadcasting Corporation recently unveiled a license that will allow the public to access free television footage, films and sounds from some of the largest media archives in the United Kingdom. But don’t expect to mash up scenes of Monty Python with clips of The Simpsons. For the time being, those who want to create new media from the so-called Creative Archive will have to be content with works a bit more obscure. Still, the effort is seen by copyright-reform advocates as a great development for sharing and building upon old works. The Creative Archive License, originally scheduled to launch last fall, borrows from the U.S.-based Creative Commons, a nonprofit organization that develops and promotes flexible copyright licenses around the world. The license permits free use of materials as long as users credit the original author, use them in the United Kingdom for noncommercial purposes and agree to license what they make under the same terms. In addition, the work may not be used for political or derogatory purposes. The British Film Institute, Channel 4 and Open University have signed on to use the new Creative Archive License. Teachers’ TV and Arts Council England are also planning to use the licenses, Le Dieu said. So far, the British Film Institute is the only organization to make clips available. The group is releasing a handful of works from its archive that are in the public domain and do not include a soundtrack -- they are black-and-white clips from about 100 years ago. In the United Kingdom, the term of copyright is 70 years from the program’s first transmission or public showing. “We have an obligation to the public to make that material accessible to the extent that that is possible within the terms of copyright law,” said Richard Paterson, head of knowledge for the film institute, which holds 200,000 films and 400,000 television programs. Footage from industries owned by the state like railroads, buses, airlines, utilities and mining will be made available using the licenses. “It’s true of most archives in the world that most people don’t know what’s in them,” Paterson said. “This makes it accessible.” The BBC hasn’t released any of its content using the licenses yet because the company “wants to make sure that the rights owners are coming along with us on this journey,” Le Dieu said. She has no estimate of when the BBC will MAKE ANY OF ITS MATERIAL AVAILABLE. HTTP://WWW.WIRED.COM/NEWS/DIGIWOOD/0,1412,67239,00.HTML

**** RESOURCES ****
Two key documents relating to counsel’s obligations for control of electronic data and potential electronic evidence.

ELECTRONIC DISCOVERY SANCTIONS IN THE TWENTY FIRST CENTURY (Judge Shira Scheindlin, 14 Feb 2005) – Judge Scheindlin authored the Zubulake decisions that have set the ‘gold standard’ for defining counsel’s duty to issue, monitor and enforce litigation hold orders. http://www.mttlr.org/voleleven/scheindlin.pdf

-- and --

Decision of a court in Florida in the Morgan Stanley/Ron Perelman fraud litigation, in which the court severely criticizes conduct of Kirkland & Ellis and articulates additional standards for counsel’s obligations to preserve and disclose electronic records sought in pretrial discovery. http://commonscold.typepad.com/commonscold/files/adverse_inference.PDF

*** KNOWLEDGE MANAGEMENT IN CORPORATE LEGAL DEPARTMENTS ***
Learn whether your in-house legal department is making the most of what each of your lawyers knows, individually, how to break down “silos” and promote sharing, and how better to empower professional development. The Editor’s KnowConnect, Inc. provides advice and assistance in knowledge management process design. www.knowconnect.com. [My first and last plug in MIRLN.]

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.