**************Introductory Note**********************
MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.
Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.
Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.
**************End of Introductory Note***************
TROJAN E-MAILS SUGGEST TREND TOWARD TARGETED ATTACKS (Computerworld, 17 June 2005) -- A report on Trojan e-mail attacks against critical-infrastructure systems in the U.K. highlights an emerging trend away from mass-mailing worms and viruses to far more targeted ones, analysts said. The U.K.’s National Infrastructure Security Co-Ordination Center yesterday released a report (PDF format) disclosing that more than 300 government departments and businesses were targeted by a continuing series of e-mail attacks designed to covertly gather sensitive and economically valuable information (see story). Unlike with phishing and mass-mailing worms, the attackers appear to be going after specific individuals who have access to commercially or economically privileged information, the report said. The attacks involved the use of e-mails containing so-called Trojan programs or links to Web sites containing Trojan files. Once installed on a user’s system, Trojans covertly run in the background and perform a variety of functions, including collecting usernames, passwords and system information; scanning of drives; and uploading of documents and data to remote computers. “The e-mails use social engineering to appear credible, with subject lines often referring to news articles that would be of interest to the recipient,” the report said. “In fact, they are ‘spoofed,’ making them appear to originate from trusted contacts, news agencies or government departments.”The report highlights how hackers are starting to tailor their attacks and go after specific high-value targets instead of simply launching mass-mailing worms and viruses, said Mark Sunner, chief technology officer at MessageLabs Ltd., a New York-based provider of e-mail security services. http://www.computerworld.com/printthis/2005/0,4814,102595,00.html and http://www.securityfocus.com/news/11222 Report at http://www.niscc.gov.uk/niscc/docs/ttea.pdf
FIVE FINNS GET SUSPENDED SENTENCES IN SONERA TELEPHONE RECORD CASE (Helsingin Salomat, 17 June 2005) – The Helsinki District Court handed down suspended sentences to five defendants in the case involving unauthorised use of mobile telephone records by executives of the telecommunications service provider Sonera. All five were found guilty of violating telecommunications privacy. Although the sentences were less severe than the prosecution had called for, the court generally agreed with the prosecutors’ assertion that there had been extensive misuse of telecommunications information at Sonera from 1998 to 2001. The harshest sentence was handed down to former Information Security Manager Juha E. Miettinen, who got a ten-month suspended jail term. Two other defendants, an investigator for the National Bureau of Investigation, as well as Ari Uutinen, a former security chief at the Council of State (government), were fined for incitement to the main crime in the case, and for violating their official duties. The court found a number of both aggravating and mitigating circumstances in the case. One aggravating factor was the large number of targets of the illegal investigations. Another factor was the high position of the defendants in the company, their roles as initiators in the case, and their attempts to break the confidentiality between journalists and their sources. http://www.helsinginsanomat.fi/english/article/1101979719153
MIX BRIX, CLIX? FACE TAX TO MAX, SAYS CAL. COURT (Steptoe & Johnson’s E-Commerce Law Week, 18 June 2005) -- Hatfields and McCoys have nothing on the feud between distance sellers and state revenue authorities. States have long sought to collect sales tax on mail order sales. After bitter litigation the Supreme Court has held and reheld that distance sellers can’t be forced to collect the tax unless those sellers have sufficient contacts with the state to become subject to state law. Then bricks-and-mortar companies got into the act, creating “clicks and mortar” companies to sell their products over the Internet -- without collecting taxes. As long as the Internet company was formally separate from the “bricks and mortar” company, the Internet company could not be forced to collect taxes because it didn’t have any assets in the taxing jurisdiction. That was the theory, anyway. But now a California court has thrown a brick of its own right through that notion. In Borders Online, LLC v. State Board of Equalization, a California Court of Appeal has upheld a trial court’s ruling that although “Borders” and “Borders Online” were two separate companies, Borders’ activities in the state “on behalf” of Borders Online were sufficient for the online retailer to be subject to California’s tax code. Further, the appeals court held that the online retailer had a “sufficient physical presence” in California -- by virtue of the presence of brick-and-mortar Borders stores -- to satisfy the commerce clause of the US Constitution. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9917&siteId=547 Decision at http://www.steptoe.com/publications/358a.pdf
-- and --
STATES MOVE FORWARD ON INTERNET SALES TAX (Washington Post, 1 July 2005) -- Tax officials, state lawmakers and industry representatives agreed Thursday to establish an 18-state network for collecting taxes on Internet sales, a compact they hope will encourage online retailers and Congress to endorse a mandatory national program. Meeting in Chicago under the auspices of the Streamlined Sales Tax Project, the officials agreed that 11 states will oversee the project and outlined incentives to encourage retailers to participate. Forty states have been negotiating since 2000 to create a framework for collecting sales taxes on all remote transactions, whether through regular mail or online. “The vote is a culmination of over five years of hard work by states, local governments and businesses interested in seeing the complexity in sales tax [reduced],” said Stephen Kranz, tax counsel for the Council on State Taxation, an industry trade association. Starting Oct. 1, software vendors contracted by the Streamlined Sales Tax Project will begin providing free tax collection and remittance software and services to online merchants who voluntarily agree to collect taxes on all online sales on behalf of the 18 participating states. Under the states’ plan, Internet retailers that agree to collect and remit taxes will do so for online sales originating in any of 11 states that have amended their state laws to fully comply with standards developed by the sales tax project. In the other seven states, the Internet sales tax collection would be optional until their tax codes are brought into full compliance. In both cases, any taxes the retailer collected would be based on the rates in effect where the buyer lives, and the retailers would be compensated for the cost of collecting and remitting that revenue to the states. As an incentive, the states will offer a one-year amnesty for e-commerce companies that may owe taxes on past online sales to any of the participating states. The amnesty offer could prove attractive for several major retailers that are currently involved in legal disputes over whether they owe taxes on Internet sales. http://www.washingtonpost.com/wp-dyn/content/article/2005/07/01/AR2005070101475.html
APPEALS COURT LIMITS CALIFORNIA’S FINANCIAL PRIVACY LAW (Timesleader.com, 20 June 2005) -- A federal appeals court blocked a portion of California’s landmark financial privacy law Monday, ruling that banks have a right to sell their customers’ private information to affiliated companies. The 9th U.S. Circuit Court of Appeals ruled that federal law pre-empts a portion of California’s 2003 privacy law, the toughest in the nation, but leaves most of it intact. The part of the California law at issue is a section that gives consumers the right to block banks from selling their personal information to affiliates that are not in the same line of business. That could include a bank sharing data with an insurance company owned by the same corporation. Three trade associations challenged that aspect of the law, but it was upheld in July by a federal judge in Sacramento. That judge ruled that a 1999 federal financial-privacy law allows states to enact stricter rules. The American Bankers Association, the Financial Services Roundtable and the Consumer Bankers Association appealed. They said the federal 2003 Fair and Accurate Credit Transactions Act pre-empts California’s restrictions on how affiliated companies can share customer data. The 9th Circuit agreed, reversing the lower court ruling and sending the case back to the district judge. The lower court judge, U.S. District Judge Morrison C. England Jr., will be asked to determine whether any aspects of the California law dealing with this kind of information swapping might still be legal in light of the 2003 federal law. Specifically, England will determine whether any consumer information can be shielded from affiliated companies under the state law. Given that the appeals court sent the case back for further review, Monday’s ruling is not the “smashing pre-emption victory” that bankers had sought, said Tom Dresslar, spokesman for state Attorney General Bill Lockyer, who defended the state law. http://www.timesleader.com/mld/timesleader/business/11942397.htm Decision at http://caselaw.findlaw.com/data2/circs/9th/0416334p.pdf
L.A. TIMES SUSPENDS ‘WIKITORIALS’ (AP, 21 June 2005) -- A bold Los Angeles Times experiment in letting readers rewrite the paper’s editorials lasted all of three days. The newspaper suspended its “Wikitorial” Web feature after some users flooded the site over the weekend with foul language and pornographic photos. The paper had posted on its Web site Friday an editorial urging a better-defined plan to withdraw troops from Iraq. Readers were invited to add their thoughts. Dozens did, with some adding hyperlinks and others adding opposing views. One reader split the long editorial in two, something that pleased Michael Kinsley, the Times’ editorial and opinion editor. But the number of “inappropriate” posts soon began to overwhelm the editors’ ability to monitor the site. On Sunday, editors decided to remove the feature. The newspaper’s Web page was to show the original editorial and interim versions along with the readers’ final product. “The result is a constantly evolving collaboration among readers in a communal search for truth,” the paper said in its Friday edition. “Or that’s the theory.” The Times said it might be creating a new form of opinion journalism — or an embarrassing failure. In a statement Monday, the Times said the feature would stay offline indefinitely while it looked at what happened and how to fix it. “We thank the thousands of people who logged onto the Wikitorial in the right spirit,” the paper said. http://news.yahoo.com/news?tmpl=story&cid=528&e=5&u=/ap/20050621/ap_on_bi_ge/la_times_wikitorials
EMPLOYEE WHISTLEBLOWER HOTLINES FOUND ILLEGAL IN FRANCE AND GERMANY (Hunton & William’s Privacy & E-Commerce Alert, 22 June 2005) -- In its session of May 26, 2005, the plenary of the French DPA (CNIL) refused to authorize the use of anonymous whistleblower hotlines operated by McDonalds France and CEAC (an affiliate of Exide Technologies) that would enable employees to alert their headquarters or managers (by phone, fax e-mail of mail) of their colleagues’ possible misconduct. These hotlines were set up by the companies in order to comply with the requirements of the US Sarbanes-Oxley law, which requires such anonymous complaint mechanisms. In two separate decisions, the CNIL expressed particular concern over: (1) anonymous reporting that could lead to slanderous denunciation; (2) disproportionality between the purpose and the risk of malicious reporting; (3) the fact that suspected staff would not be informed of a complaint or investigation in the early stage of the process; and (4) the period of data retention. Both decisions are available (in French) on the CNIL web site: Decision 2005/110 at http://www.cnil.fr/index.php?id=1833 (McDonalds); and Decision 2005/111 at http://www.cnil.fr/index.php?id=1834 (CEAC).
FTC OPPOSES MANDATORY “ADV” LABELING OF EMAIL (BNA’s Internet Law News, 233 June 2005) -- BNA’s Electronic Commerce & Law Report reports that the FTC has believes that federal legislation mandating the inclusion of “ADV” in the subject line of unsolicited commercial e-mail messages would be ineffective in combatting spam. The FTC’s views were informed by the belief that so-called “outlaw spammers” would not obey the law, that “ADV” labelling proved ineffective at the state level, and that anti-spam filters and other emerging e-mail technologies hold more promise as anti-spam tools than an “ADV” label. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b0z2n5c7
SHOULD CITIES BE ISPS? (CNET, 23 June 2005) -- When Philadelphia’s city government decided to sell wireless access to downtown residents last year, a furious political fight in the state capital erupted. Verizon stridently opposed the plan, liberal advocacy groups just as emphatically endorsed it, and politicians in Harrisburg ended up approving a compromise bill that effectively let the city of brotherly love do what it wanted. Now this politechnical dispute is bubbling up from states to Washington, D.C., where lobbyists are pressuring Congress to resolve the question of whether governments or private companies do a better job as Internet service providers. “Our focus is that 75 to 85 percent of our population in our low-income and minority areas that don’t have access,” said Dianah Neff, Philadelphia’s chief information officer. “When we talked to them and we did surveys with them, they said 76 percent of the time that cost was the No. 1 reason why they didn’t have access to the Internet.” But if reaching low-income people is the primary goal, said Jim Speta, an associate professor at the Northwestern University School of Law, then cities could keep costs down by relying on “consumer demand pull”--that is, handing vouchers to poorer consumers, who could use them to pay for private sector broadband. http://news.com.com/2100-1034_3-5758262.html
PEER-TO-PEER FILE SHARING COMES WITH RISKS, SAYS FTC (Information Week, 23 June 2005) -- Peer-to-peer file-sharing technology offers both benefits and risks, according to a report issued today by the Federal Trade Commission. The report, based on comments from the FTC’s P2P workshop last December, cites benefits such as fast file transfers, bandwidth conservation, and reduced storage needs. It also warns of risks related to data security, spyware and adware, viruses, copyright infringement, and pornography. How significant are those risks compared with general Internet use? The FTC doesn’t know. “Workshop participants submitted little empirical evidence concerning whether the risks arising from P2P file sharing are greater than, equal to, or less than these risks from other Internet-related activities,” the report finds. The report comes at an odd time. The Supreme Court is expected to soon decide the future of peer-to-peer technology when it rules in the case of Metro-Goldwyn Mayer Studios v. Grokster Ltd. As the FTC says, “Because [this case] likely will clarify the legal framework applicable to P2P file sharing and may have a profound effect on the future structure and impact of P2P file-sharing programs, FTC staff does not believe that it would be prudent at this time to make specific recommendations regarding the intellectual-property issues raised by P2P file sharing.” http://informationweek.com/story/showArticle.jhtml?articleID=164902381 Report at http://www.ftc.gov/reports/p2p05/050623p2prpt.pdf
DATABASE TARGETS TEENS AS RECRUITS FOR MILITARY (Houston Chronicle, 23 June 2005) -- The Defense Department began working Wednesday with a private marketing company to create a database of all U.S. college students and high school students between 16 and 18 years old, to help the military identify potential recruits in a time of dwindling enlistment in some branches. The new database will include an array of personal information including birth dates, Social Security numbers, e-mail addresses, grade-point averages, ethnicity and what subjects the students are studying. The data will be managed by BeNOW Inc. of Wakefield, Mass., one of many marketing companies that use computers to analyze large amounts of data to target potential customers based on their personal profiles and habits. “The purpose of the system ... is to provide a single central facility within the Department of Defense to compile, process and distribute files of individuals who meet age and minimum school requirements for military service,” according to the official notice of the program. Privacy advocates said the plan appeared to be an effort to circumvent laws that restrict the government’s right to collect or hold citizen information by turning to private firms to do the work. Some data on high school students already is given to military recruiters in a separate program under provisions of the 2002 No Child Left Behind Act. Under the new system, additional data will be collected from commercial data brokers, state driver’s license records and other sources, including information already held by the military. The Pentagon’s statements added that anyone can “opt out” of the system by providing detailed personal information that will be kept in a separate “suppression file.” That file will be matched with the full database regularly to ensure that those who do not wish to be contacted are not, according to the Pentagon. But privacy advocates said using database marketers for military recruitment is inappropriate. Chris Hoofnagle, West Coast director of the Electronic Privacy Information Center, called the system “an audacious plan to target-market kids, as young as 16, for military solicitation.” He added that collecting Social Security numbers was not only unnecessary but posed a needless risk of identity fraud. Theft of Social Security numbers and other personal information from data brokers, government agencies, financial institutions and other companies is rampant. BeNOW’s Web site does not have a published privacy policy, nor does it list either a chief privacy officer on its executive team. http://www.chron.com/cs/CDA/ssistory.mpl/nation/3237413
ALMOST ALL LIBRARIES IN U.S. OFFER FREE ACCESS TO INTERNET (New York Times, 24 June 2005) -- Nearly all libraries around the country have free public Internet access and an increasing number are offering wireless connections, according to a study released Thursday by the American Library Association here. The study, which was conducted by researchers at Florida State University, found that 98.9 percent of libraries offer free public Internet access, up from 21 percent in 1994 and 95 percent in 2002. It also found that 18 percent of libraries have wireless Internet access and 21 percent plan to get it within the next year. The study found that rural areas were more likely to have slower connections and fewer workstations and training opportunities. Arkansas, California, Idaho, New Hampshire, Virginia and West Virginia had the lowest levels of access. Urban areas, which also had some of the highest poverty rates, tended to have high levels of connectivity, bandwidth and wireless access. Hazel Williams, 50, of Chicago said she started going to the library for Internet research two years ago while she was earning her high school equivalency diploma. People like Ms. Williams who go to the library for Internet access might be one reason that the number of annual library visits has increased from 500 million in the early 1990’s to 1.2 billion today, said Carol Brey-Casiano, president of the American Library Association. The study also reported that almost 40 percent of public libraries filter public Internet access to prevent minors from gaining access to sexually related materials. State library systems in Georgia and West Virginia put filters on all public libraries, the study reported. http://www.nytimes.com/2005/06/24/national/24library.html?ex=1277265600&en=844132cc8d3c7fe3&ei=5090&partner=rssuserland&emc=rss
AT PARTYGAMING, EVERYTHING’S WILD (New York Times, 26 June 2005) -- As a rule, companies don’t often draw attention to business practices that could land their executives in jail. But for PartyGaming PLC, potential illegalities aren’t just a secret hidden in its business plan - they are the centerpiece of its business plan. A giant in the online gambling business, PartyGaming is an often-overlooked megasurvivor from the dot-com crash of the late 1990’s. As hundreds of profitless commercial sites disappeared into the digital ether, PartyGaming’s popular gambling sites - like PartyPoker.com - soared, with revenues and profits growing exponentially year after year. This week, the company will go public in what is expected to be the largest offering in years on the London Stock Exchange, one that will make billionaires out of its ragtag assortment of founders and major stockholders - including a California lawyer who earned her first fortune in online pornography and phone-sex lines. All told, as much as $9 billion is expected to be raised, with all of the cash going to private shareholders selling portions of their stakes. PartyGaming, based in Gibraltar, has no assets in the United States, and its officers or directors could risk being served with a civil suit - or an arrest warrant - if they came to the United States on business. The reason? The Justice Department and numerous state attorneys general maintain that providing the opportunity for online gambling is against the law in the United States - and PartyGaming does it anyway. Indeed, of its $600 million in revenue and $350 million in profit in 2004, almost 90 percent came from the wallets and bank accounts of American gamblers. To justify this, PartyGaming walks a very thin line. Providing online gambling is not illegal per se in the United States, the company argues - federal prosecutors just say it is. The company’s prospectus - a British document that is not available in the United States - at times reads something like a legal brief, citing American case law to support the company’s position that no prosecution would ever take place. Still, in its offering documents, PartyGaming makes no secret of the fact that even if the company’s view of the law proves wrong, it is banking on its executives’ belief that there is little that law enforcement can do - or will do - to prosecute. “In many countries, including the United States, the group’s activities are considered to be illegal by the relevant authorities,” PartyGaming says in its offering document. “PartyGaming and its directors rely on the apparent unwillingness or inability of regulators generally to bring actions against businesses with no physical presence in the country concerned.” [Editor: Lengthy, interesting piece (with a too-long digression into 1990s internet pornography). Particularly interesting: the “offshore” move to avoid U.S. jurisdiction.] http://www.nytimes.com/2005/06/26/business/yourmoney/26poker.html?ex=1277438400&en=a47371cd660556db&ei=5090&partner=rssuserland&emc=rss
THE VOICEMAIL MESSAGE THAT HAS GCs TALKING (Law.com, 27 June 2005) -- There are dumb mistakes, and then there are really dumb mistakes. Four years ago Matthew Gloss, the general counsel of Marvell Semiconductor Inc., and two of his colleagues phoned the legal chief of a rival company, Jasmine Networks Inc. The call went straight to voicemail, so Gloss left a message and hung up. At least, he thought he did. Though the Marvell officials didn’t know it, the Jasmine lawyer’s voicemail was still taping them as they continued to talk on speakerphone -- allegedly about how they were stealing their rival’s trade secrets. Gloss’ little boo-boo has turned into a major headache, not just for Marvell but potentially for in-house lawyers everywhere. That’s because when Jasmine filed its inevitable lawsuit against Marvell, it tried to enter the voicemail as evidence. Marvell moved to exclude the tape, arguing that it was protected by attorney-client privilege, since two company lawyers took part in the conversation. The trial judge sided with Marvell, but a California appellate court backed Jasmine. By failing to disconnect his phone, Gloss had waived privilege, the appellate court ruled last year. Moreover, since he is also a company officer -- he holds the title of vice president for business affairs -- Gloss had the authority to waive privilege on Marvell’s behalf. The appellate decision so worried the Association of Corporate Counsel that it asked the California Supreme Court to review the case. The justices agreed, and Marvell and Jasmine are currently preparing their briefs. ACC is also backing a proposed state law that says privilege can only be waived intentionally and not inadvertently. http://www.law.com/jsp/article.jsp?id=1119603919501
US SUPREME COURT REVERSES GROKSTER DECISION (BNA’s Internet Law News, 28 June 2005) -- The US Supreme Court has ruled against file-swapping companies Grokster and StreamCast Networks in their high profile battle with the content indusries. The court sought to leave the 1984 Sony Betamax decision untouched, but added the notion of active inducement. Although the 9-0 decision was a loss for Grokster, the court provided a potential roadmap for future P2P services by ruling that there is no liability for knowledge of potential or actual infringement; no liability for product support or technical updates, and (absent other evidence of intent) no liability for failure to take affirmative steps to prevent infringement. Decision at http://laws.findlaw.com/us/000/04-480.html Media coverage at http://news.com.com/2100-1030_3-5764998.html http://news.com.com/2100-1028_3-5764787.html http://www.wired.com/news/digiwood/0,1412,68018,00.html
-- and --
THE COURT HAS RULED SO ENTER THE GEEKS (New York Times, 29 June 2005) -- The Supreme Court’s unanimous decision Tuesday in the Grokster case means trouble and potentially ruinous judgments against commercial file-sharing services, but it has also established a new standard for software innovation: don’t ask, don’t sell. That is, don’t ask for or gather information on what users are doing with the software you write, and don’t sell ads that profit from access to copyrighted material. The court found that the file-sharing companies Grokster and Streamcast could be sued for copyright infringement because they offered marketing and technical advice that clearly induced their customers to share files illegally, so the companies could attract larger numbers of users and thus more advertising. But the court did not give the movie and recording businesses much ammunition to attack the Robin Hoods of the Internet: those software geeks and culture fans who really just want to share. They are online right now building Web sites that don’t make a dime and spending hours writing and editing “mp3 blogs” - Web page collections of downloadable songs. They hook people up, basically because they can and because people want access to art. The court’s decision may torpedo the parasitical, ad-pumping services like Grokster, Kazaa and Morpheus, but no one’s going to miss them much. There are plenty of geek alternatives that were devised not as business startups, but for the programmers’ satisfaction and the users’ sense of connection. It’s a completely alien mentality for profit-focused companies that still dream of being paid every time someone hears a song. Reality has never exactly worked that way, from radio to the Internet. In the United States, songwriters are paid for radio air play, but performers and recording companies are not, on the theory that having a song broadcast sells recordings and concert tickets. [Editor: The entire story is worthwhile.] http://www.nytimes.com/2005/06/29/arts/music/29pare.html?ex=1277697600&en=a4e8e6f3cc33bd23&ei=5090&partner=rssuserland&emc=rss
-- and --
REFLECTING ON THE GROKSTER DECISION (BNA’s Internet Law News, 29 June 2005) -- Several articles focus on the fallout from the Grokster decision. The Toronto Star features a special edition of my Law Bytes column which comments on Monday’s Grokster decision. The column argues that the case is a mirror image of the recent Canadian file sharing case as despite the unanimous verdict, it provides a roadmap for file sharing services to avoid future liability. Larry Lessig warns of chilled innovation in a Business Week interview, while other articles include reaction from industry players on both sides of the issue. Geist Toronto Star column at http://geistgrokster.notlong.com/ http://www.michaelgeist.ca/resc/html_bkup/june292005.html Reaction articles at http://news.com.com/2100-1027_3-5767277.html http://www.nytimes.com/2005/06/29/arts/music/29pare.html Lessig interview at http://www.businessweek.com/technology/content/jun2005/tc20050629_2928_tc057.htm
BLOGGERS FIGHTING GOVERNMENT REGULATIONS (AP, 28 June 2005) -- Bloggers who built their Internet followings with anti-establishment prose are now lobbying the establishment to protect their livelihoods from federal regulations. Some are even working with lawyers, public-relations consultants and a political action committee to do it. “I like to think of myself as just a guy with a blog, but it’s clear that ‘just a guy with a blog’ is different today than it was when I started three years ago,” said Markos Moulitsas Zuniga, founder of the Web log www.DailyKos.com. “One sign of having arrived is when government regulators start wanting to poke their fingers into what you do.” Moulitsas was to testify Tuesday at a hearing on a Federal Election Commission proposal that would extend some campaign finance rules to the Internet, including bloggers. Moulitsas also is working with a lawyer who volunteered to help bloggers fight new government regulations and whose efforts were promoted in a PR firm press release Monday. He is prepared to lobby Congress himself if necessary, and he is the treasurer of BlogPac, a political action committee formed last year by bloggers. Duncan Black — who founded the www.atrios.blogspot.com blog — featured a headline Monday on his Web site, “Bite me, Congressman,” that linked to a diatribe against a Republican House committee chairman over global warming. Asked whether the use of hearing testimony and PACs is a sign that bloggers are succumbing to mainstream political techniques, Black said he and his colleagues have no choice. “I think once you do achieve a certain degree of traffic, influence, notoriety — however you want to call it — eventually the outsider label is not perfectly applicable anymore,” said Black, who describes himself as a “recovering economist.” He too planned to testify before the FEC. http://news.yahoo.com/news?tmpl=story&cid=528&e=1&u=/ap/20050628/ap_on_hi_te/bloggers_lobby
CONGRESS MODIFIES FCC RULING ON UNSOLICITED FAXES (SiliconValley.com 28 June 2005) -- Congress approved junk fax legislation Tuesday that allows businesses to send out unsolicited faxes in certain circumstances while protecting the rights of consumers to stop receiving them. The legislation, passed by the House on a voice vote and now headed for President Bush’s signature, reinstates a 1992 Federal Communications Commission ruling that permits businesses and associations to send unsolicited faxes to those with whom they have an ``established business relationship.” It would eliminate a new FCC ruling, first drawn up in 2003, that required businesses and organizations to obtain prior written approval before sending a commercial fax. That rule was supposed to go into effect on Friday, but the FCC on Tuesday announced it would further delay its new junk fax rule until Jan. 9, 2006, ``in light of the ongoing developments in Congress.” The agency said the delay would also give more time to respond to petitions to reconsider the rule. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/12005819.htm
PUBLISHING MAKES SHIFT TO DIGITAL (BBC, 29 June 2005) -- The vast majority of UK research material will be available in electronic form by 2020. According to a study commissioned by the British Library, 90% of newly published work will be available digitally by this time. Only half of this will also be available in print form, with just 10% of new titles available only in print. It represents a “seismic shift” in the world of publishing said British Library chief executive Lynne Brindley. For its part, the British Library aims to spend the next three years developing the infrastructure necessary to store, manage, preserve and provide access to digital material. “In many ways digital material is more fragile than physical material and if we don’t manage it effectively it won’t survive for future generations,” said Ms Brindley. http://news.bbc.co.uk/2/hi/technology/4633423.stm
THEFT FEARS RULE OUT NATIONAL AUSTRALIAN CARD (AustralianIT, 29 June 2005) -- Australia will not introduce a national identification card because of the fear of identity theft by criminals, Attorney-General Philip Ruddock said. Mr Ruddock today rejected media reports that the federal Government was considering introducing a national ID card. His comments come as the British government legislates to introduce the country’s first national ID card since World War II. The UK cards, which Prime Minister Tony Blair says are necessary to fight terrorism, fraud and illegal immigration, will include biometric details such as iris scans and fingerprints. But Mr Ruddock told a security technology conference in Sydney today a national ID card could actually compromise Australians’ security. “We haven’t supported an approach where all personal information is centralised on one database and a single form of identification is used,” Mr Ruddock told the gathering of government, security and business leaders. “Such an approach could actually increase the risk of identity fraud because only one document would need to be counterfeited to establish an identity.” Outside the forum, Mr Ruddock said the government wanted to step up security of existing personal identification documents such as passports, birth certificates and drivers’ licences. “We are not about developing a national ID card, we are about improving identity security arrangements - that’s the approach we’re taking,” he told reporters. http://australianit.news.com.au/articles/0,7204,15767261%5E15319%5E%5Enbv%5E15306,00.html
ONE FIFTH OF JAPANESE BUSINESSES USING OPEN SOURCE OS (Info World, 5 July 2005) -- The use of open-source operating systems in enterprise servers is growing in Japan, with companies citing low introduction costs as the main factor for adoption, according to a recent report by the Japanese government. So far, 21 percent of Japanese companies have already introduced open-source operating systems including Linux, FreeBSD, and OpenBSD systems, while 22 percent either have plans to deploy, or are considering plans to deploy, an open-source operating system, according to an annual white paper released by Japan’s Ministry of Internal Affairs and Communications (MIC). By contrast, 33 percent of U.S. companies have adopted open-source operating systems in at least some of their servers, MIC said. Among the companies polled by the MIC, 66 percent said open-source operating systems have low initial costs, while 47.8 percent said the software has low operating costs. Of those companies that have so far adopted open-source operating systems, major uses for these servers include Web, mail, and file servers. Open-source operating systems are used with much less frequency in applications for financial, payment, distribution and customer service applications, the report said. http://www.infoworld.com/article/05/07/05/HNjapaneseopensource_1.html
MAN CHARGED WITH STEALING WI-FI SIGNAL (Forbes, 6 July 2005) -- Police have arrested a man for using someone else’s wireless Internet network in one of the first criminal cases involving this fairly common practice. Benjamin Smith III, 41, faces a pretrial hearing this month following his April arrest on charges of unauthorized access to a computer network, a third-degree felony. Police say Smith admitted using the Wi-Fi signal from the home of Richard Dinon, who had noticed Smith sitting in an SUV outside Dinon’s house using a laptop computer. The practice is so new that the Florida Department of Law Enforcement doesn’t even keep statistics, according to the St. Petersburg Times, which reported Smith’s arrest this week. Innocuous use of other people’s unsecured Wi-Fi networks is common, though experts say that plenty of illegal use also goes undetected: such as people sneaking on others’ networks to traffic in child pornography, steal credit card information and send death threats. http://www.forbes.com/business/feeds/ap/2005/07/06/ap2126874.html [Editor: There must be more to this story. Smith has been charged with unauthorized access to a computer network, a third-degree felony.]
E-VOTE GUIDELINES NEED WORK (Wired, 7 July 2005) -- In an effort to keep pace with changing technology and address widespread security concerns about electronic voting machines, the federal government has released new guidelines for voting systems. The guidelines, published in late June, call for vendors to follow better programming practices and make some suggestions for addressing problems with vote integrity. Computer security experts say the guidelines are a step in the right direction, but fall short of making voting systems secure. They also don’t require systems to produce a voter-verified paper audit trail, which would allow voters to confirm their vote. The government is accepting public comment on the guidelines for 90 days, after which it will revise them, if needed, and release them for states to adopt. But there has been some confusion on whether these should be considered final guidelines, or simply a first step toward more permanent guidelines. Avi Rubin, a Johns Hopkins University computer science professor and technical director of the university’s Information Security Institute, said the new guidelines are an improvement but contain some serious security red flags. He also said they have some requirements that, had they been included in previous versions of voting system guidelines, would have prevented voting systems made by Diebold Election Systems from being certified. http://www.wired.com/news/evote/0,2645,68116,00.html?tw=wn_4polihead
GOOGLE WINS COPYCAT WEB DOMAIN DISPUTE (Reuters, 8 July 2005) -- The National Arbitration Forum said on Friday that Google Inc. has rights to the Internet domain names googkle.com, ghoogle.com, gfoogle.com and gooigle.com, which are similar to its own google.com domain. The Web search leader filed a complaint with the NAF on May 11, claiming legal rights to Web addresses bearing a close resemblance to google.com, which it registered in late 1999. Sergey Gridasov, of St. Petersburg, Russia, registered googkle.com, ghoogle.com, gfoogle.com and gooigle.com between December 2000 and January 2001 through Computer Services Langenbach GmbH, which did business as Joker.com. He did not respond to charges levied against him. Because Gridasov failed to answer, the arbitrator was entitled to accept all reasonable allegations and inferences in the complaint from Google as true, unless the evidence was clearly contradictory. The NAF arbitrator, Paul Dorf, found that Gridasov did not have legitimate rights to the Web addresses, and the Web addresses were confusingly similar to Google’s trademark rights to its own name. Further, the arbitrator found that Gridasov was using them in bad faith by presumably profiting from the use of domains. http://today.reuters.com/business/newsArticle.aspx?storyID=nN78398318
DOWNLOADING TROUBLE AT THE BBC (BBC, 10 July 2005) -- The BBC has been lambasted by classical music labels for making all nine of Beethoven’s symphonies available for free download over the Internet. This week the BBC will announce there have been more than a million downloads of the symphonies during the month-long scheme. But the initiative has infuriated the bosses of leading classical record companies who argue the offer undermines the value of music and that any further offers would be unfair competition. http://news.independent.co.uk/media/article298067.ece
WILL THE U.N. RUN THE INTERNET? (CNET, 11 July 2005) -- An international political spat is brewing over whether the United Nations will seize control of the heart of the Internet. U.N. bureaucrats and telecommunications ministers from many less-developed nations claim the U.S. government has undue influence over how things run online. Now they want to be the ones in charge. While the formal proposal from a U.N. working group will be released July 18, it’s already clear what it will contain. A preliminary summary of governmental views claims there’s a “convergence of views” supporting a new organization to oversee crucial Internet functions, most likely under the aegis of the United Nations or the International Telecommunications Union. Beyond the usual levers of diplomatic pressure and public kvetching, Brazil and China could choose what amounts to the nuclear option: a fragmented root. At issue is who decides key questions like adding new top-level domains, assigning chunks of numeric Internet addresses, and operating the root servers that keep the Net humming. Other suggested responsibilities for this new organization include Internet surveillance, “consumer protection,” and perhaps even the power to tax domain names to pay for “universal access.” This development represents a grave political challenge to the Internet Corporation for Assigned Names and Numbers (ICANN), which was birthed by the U.S. government to handle some of those topics. A recent closed-door meeting in Geneva convened by the U.N.’s Working Group on Internet Governance offers clues about the plot to dethrone ICANN. As these excerpts from a transcript show, dissatisfaction and general-purpose griping is rampant * * * http://news.com.com/2010-1071_3-5780157.html
UK LOBBIES FOR DATA RENTENTION (ZDnet, 11 July 2005) -- Charles Clarke wants email and phone records kept for up to three years to aid police investigations, but critics have claimed the scheme is expensive and unwieldy. Britain will renew its efforts this week to get fellow European Union members to agree to the introduction of new controls for the retention of telecommunications data, following last week’s bombings in London. Under the proposals, telecoms operators and Internet service providers would have to keep records of emails, telephone calls and text messages for between 12 months and three years. Law enforcement agencies would be able to see who had sent and received these communications, although the content of these communications would not be stored. Home secretary Charles Clarke claims that the powers would help to establish links between individuals. “Telecommunications records, whether of telephones or of emails, which record what calls were made from what number to another number at what time are of important use for intelligence,” said Clarke, according to reports. The UK is one of several countries advocating the introduction of such measures over recent months. Other EU members have opposed them, fearing they would erode civil liberties. Back in June the European Parliament rejected draft legislation introduced by France, Ireland, Sweden and the UK, amid fears that the proposals were illegal. http://uk.news.yahoo.com/050711/152/fn318.html
NEW BATTLE BREWS OVER UCITA, SOFTWARE LICENSING TERMS (Computer World, 11 July 2005) -- A new legislative battle is looming over the controversial UCITA software licensing law. But this time, it’s software users, not vendors, who are poised to attack. The push for state-by-state adoption of the Uniform Computer Information Transactions Act was abandoned nearly two years ago because of widespread opposition. But the group of software users that led that opposition has since been quietly drafting its own model software-licensing law. Its concern is that courts may use UCITA as a reference point in legal disputes, giving vendors a victory through the legal system that they couldn’t gain in state legislatures. “That battle against UCITA is still going on; it’s just taken another form,” said Riva Kinstlick, vice president of government relations at Prudential Financial in Newark, N.J. “People are starting to be concerned about it,” said Kinstlick, who maintained that stopping UCITA wasn’t enough. “If there is a void and UCITA is the only thing to take the place of the void, this could end up being the model almost by default rather than choice,” she said. UCITA is a software licensing law that specifies terms and conditions for licensing contracts. Under the act, unless the parties agree otherwise, the default terms apply. Its supporters argued that UCITA would provide a legal framework for online commerce. Opponents said the default rules favored vendors and created potential perils for corporate users, such as allowing vendors to knowingly ship defective products. Virginia approved the law in 2000, and Maryland quickly followed. But opponents—especially those in the financial services industry—joined the state-by-state battle to block further adoptions. In August 2003, the law’s legislative sponsor, the Chicago-based National Conference of Commissioners on Uniform State Laws (NCCUSL), suspended efforts to win state adoption. But UCITA can still be used as a contract model, said Jean Braucher, a University of Arizona law professor who is working with Americans for Fair Electronic Commerce Transactions (AFFECT) to develop a model bill. “Eventually, we need an alternative,” she said. http://www.computerworld.com/softwaretopics/software/story/0,10801,103065,00.html
GIVING NEW MEANING TO ‘SPYWARE’ (Wired, 12 July 2005) -- Supreme Court Justice Potter Stewart famously said that he couldn’t define obscenity, but that he knew it when he saw it. The same has long been the case with spyware. It’s not easy to define, but most people know it when parasitic programs suck up resources on their computer and clog their browsers with pop-up ads. Recognizing that one person’s search toolbar is another’s spyware, a coalition of consumer groups, ISPs and software companies announced on Tuesday that it has finally come up with a mutually agreeable definition for the internet plague. Spyware impairs “users’ control over material changes that affect their user experience, privacy or system security; use of their system resources, including what programs are installed on their computers; or collection, use and distribution of their personal or otherwise sensitive information,” according to the Anti-Spyware Coalition, which includes Microsoft, EarthLink, McAfee and Hewlett-Packard. The group hopes the definitions will clear the way for anti-spyware legislation and help create a formal, centralized method for companies to dispute or change their software’s classification. http://www.wired.com/news/privacy/0,1848,68167,00.html
BUSH PICKS TECH LAWYER FOR SECURITY POST (CNET, 13 July 2005) -- President Bush has chosen Stewart Baker, one of Washington’s most influential technology lawyers, to be assistant secretary for policy in the Homeland Security Department. Baker’s new job, which requires Senate confirmation, would place him in the prominent position of shaping policy on topics from data mining to the department’s planning for “what if” scenarios far off in the future. It also could include evaluating existing department functions for efficiency and creating a national strategy to prevent terrorists from entering the United States. The nomination, announced Wednesday, is part of a sweeping reorganization of the department that Secretary Michael Chertoff announced Wednesday. “Creation of a DHS policy shop has been suggested by members of Congress, (former Secretary Tom Ridge), and numerous outside experts,” Chertoff said. “Now is the time to make this a reality.” Baker is currently a partner at the Steptoe and Johnson law firm--which counts many technology companies as clients--and has been an important but polarizing fixture in many privacy debates during the last 15 years. Baker served as the general counsel of the National Security Agency--the bane of many civil libertarians--during the early 1990s. “For the civil liberties community, this could be a troubling appointment,” said Marc Rotenberg, director of the Electronic Privacy Information Center. “Stu Baker often stood on the other side of important national debates on protecting privacy and preserving open government.” [Editor: I don’t share Marc’s concerns. I find Stewart to be a careful, thoughtful, and well-informed lawyer who also possesses rarer attributes: he’s open-minded and an excellent listener. For me, he’s the ideal person for this new position. I *AM* sad that he’ll no longer be able to concoct the snappy headlines I’ve come to love in Steptoe & Johnson’s E-Commerce Law Week report!] http://news.com.com/2100-7348_3-5787520.html
**** RESOURCES ****
EFF: LEGAL GUIDE FOR BLOGGERS (8 June 2005) -- Like all journalists and publishers, bloggers sometimes publish information that other people don’t want published. You might, for example, publish something that someone considers defamatory, republish an AP news story that’s under copyright, or write a lengthy piece detailing the alleged crimes of a candidate for public office. The difference between you and the reporter at your local newspaper is that in many cases, you may not have the benefit of training or resources to help you determine whether what you’re doing is legal. And on top of that, sometimes knowing the law doesn’t help - in many cases it was written for traditional journalists, and the courts haven’t yet decided how it applies to bloggers. But here’s the important part: None of this should stop you from blogging. Freedom of speech is the foundation of a functioning democracy, and Internet bullies shouldn’t use the law to stifle legitimate free expression. That’s why EFF created this guide, compiling a number of FAQs designed to help you understand your rights and, if necessary, defend your freedom. To be clear, this guide isn’t a substitute for, nor does it constitute, legal advice. Only an attorney who knows the details of your particular situation can provide the kind of advice you need if you’re being threatened with a lawsuit. The goal here is to give you a basic roadmap to the legal issues you may confront as a blogger, to let you know you have rights, and to encourage you to blog freely with the knowledge that your legitimate speech is protected. http://www.eff.org/bloggers/lg/
A MODEL REGIME OF PRIVACY PROTECTION (by Daniel Solove, GW Law School, and Chris Hoofnagle, EPIC) -- Privacy protection in the United States has often been criticized, but critics have too infrequently suggested specific proposals for reform. Recently, there has been significant legislative interest at both the federal and state levels in addressing the privacy of personal information. This was sparked when ChoicePoint, one of the largest data brokers in the United States with records on almost every adult American citizen, sold data on about 145,000 people to fraudulent businesses set up by identity thieves. Other companies announced security breaches, including LexisNexis, from which personal information about 32,000 people was improperly accessed. Senator Schumer criticized Westlaw for making available to certain subscribers personal information including Social Security Numbers (SSNs). In the aftermath of the ChoicePoint debacle and other major information security breaches, both of us have been asked by Congressional legislative staffers, state legislative policymakers, journalists, academics, and others about what specifically should be done to better regulate information privacy. In response to these questions, we believe that it is imperative to have a discussion of concrete legislative solutions to privacy problems. http://papers.ssrn.com/sol3/papers.cfm?abstract_id=699701
SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.
PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.
MIRLN stands for Miscellaneous IT Related Legal News, since 1997 a free monthly e-newsletter edited by Vince Polley (www.knowconnect.com). Earlier editions, and email delivery subscription information, are at http://www.knowconnect.com/mirln/
Friday, July 15, 2005
Saturday, June 18, 2005
MIRLN -- Misc. IT Related Legal News [21 May – 18 June 2005; v8.07]
**************Introductory Note**********************
MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.
Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.
Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.
**************End of Introductory Note***************
E-MAIL RETENTION A MUST AFTER MORGAN STANLEY CASE (CNET, 21 May 2005) -- The $1.45 billion judgment against Morgan Stanley for deceiving billionaire Ronald Perelman over a business deal has a lesson all companies should learn--keeping e-mails is now a must, experts say. Banks and broker-dealers are obliged to retain e-mail and instant messaging documents for three years under U.S. Securities and Exchange Commission rules. But similar requirements will apply to all public companies from July 2006 under the Sarbanes-Oxley corporate reform measures. At the same time, U.S. courts are imposing increasingly harsh punishments on corporations that fail to comply with orders to produce e-mail documents, the experts said. Where judges once were more likely to accept that incompetence or computer problems might be to blame, they are now apt to rule that noncompliance is an indication a company has something to hide. “Morgan Stanley is going to be a harbinger,” said Bill Lyons, chief executive officer of AXS-One, a provider of records retention software systems. “I think general counsels around the world are going to look at this as a legal Chernobyl,” he said. Wednesday’s $1.45 billion verdict against Morgan Stanley in West Palm Beach, Fla., was the product of just such a negative ruling on e-mail retention, which is also expected to form the backbone of the Wall Street firm’s appeal. http://news.com.com/E-mail+retention+a+must+after+Morgan+Stanley+case/2100-1036_3-5715554.html?tag=nefd.top
-- and --
COMPANIES RAMPING UP E-MAIL MONITORING (CNET, 8 June 2005) -- A new study has found that 63 percent of corporations with 1,000 or more employees either employ or plan to employ staff to read or otherwise analyze outbound e-mail. The report, released Monday by e-mail security specialist Proofpoint, said 36.1 percent of companies employ staff to monitor e-mail today, with another 26.5 percent saying they intend to employ such staff in the future. In companies with more than 20,000 employees, this practice is even more common, according to the survey, which involved 332 technology decision-makers at large U.S. companies. Forty percent of those large companies employ staff to monitor e-mail today, and an additional 32 percent plan to employ such staff in the future. According to the study, companies are concerned about making sure e-mail isn’t used to leak company trade secrets or other intellectual property, and about complying with financial disclosure regulations. Another factor is preventing confidential internal memos from getting zapped outside the company, according to the report. The study comes amid a rise in workplace monitoring. The number of employers who monitor the amount of time employees spend on the phone and track the numbers called has jumped to 51 percent, up from 9 percent in 2001, according to a study released last month by the American Management Association and the ePolicy Institute. http://news.com.com/Companies+ramping+up+e-mail+monitoring/2100-1022_3-5738134.html?tag=html.alert
COURT RULES FOR GERMAN ISPS IN P2P IDENTITIES CASE (The Register, 17 May 2005) -- ISPs in the state of Hamburg can’t be forced to provide customer data to record companies, even when illegal copying is suspected, at least for now. The Higher Regional Court in Hamburg has ruled (http://www.heise.de/english/newsticker/news/59602) that there is no legal basis for demanding customer data. ISPs, the court argues, aren’t part of the criminal act. They merely provide access to the web. The Higher Regional Court overruled a earlier decision by the Hamburg District Court, which had granted record companies access to customer data after they discovered an FTP server where numbers by German band Rammstein could be downloaded for free. The District Court based its ruling on the German Copyright Act. http://www.theregister.co.uk/2005/05/17/hamburg_isp_ruling/print.html The full text of the decision is available (in German) at: http://www.jurpc.de/rechtspr/20050062.htm.
U.S. ARMY UPGRADES ARMY KNOWLEDGE ONLINE - AKO - PORTAL (Internet Ad Sales, 18 May 2005) -- Appian Corporation, the leading provider of business process management solutions to the government, today announced that the U.S. Army has purchased additional software licenses, as well as maintenance and professional services, for the Army Knowledge Online (AKO) portal. Additionally, AKO will be upgraded to Appian Enterprise v.3, the latest version of Appian’s award-winning portal solution for government. With more than 1.6 million registered users, AKO is widely regarded as one of the most successful enterprise portal implementations in the world. In April, 770,000 different people used AKO 12.5 million times. Overall, 72 percent of the active force uses AKO regularly. Considered the virtual nerve center of Army operations, AKO provides single sign-on access to as many as 300 of the Army’s mission-critical applications and services. “The global war on terror has created new demands for collaboration and information sharing,” said Gary Winkler, Director of Enterprise Integration, Chief Information Officer/G6. “The rapid and wide-spread acceptance of AKO as the Army operations portal and virtual workspace makes it the obvious and most appropriate vehicle for bringing groups of people with shared interests together.” http://www.internetadsales.com/modules/news/article.php?storyid=850
NEXT FOR BITTORRENT: SEARCH (Wired, 23 May 2005) -- Whiz kid inventor Bram Cohen and a small cadre of developers and entrepreneurs are in the final stage of launching an advertising-supported search engine dedicated to cataloging and indexing the thousands of movies, music tracks, software programs and other files for download over Cohen’s popular BitTorrent protocol. The free search tool will be the first large-scale commercial offering from BitTorrent, a five-person company headed by Cohen that so far has drawn most of its revenue from T-shirt sales and PayPal donations. The ranked search results will be accompanied by sponsored links provided through a partnership with Oakland, California, company Ask Jeeves, says Ashwin Navin, BitTorrent’s chief operating officer. BitTorrent will make money from each clickthrough. “Ask Jeeves syndicates our advertising products to many different sites, and BitTorrent will be one of them,” confirmed Ask Jeeves spokeswoman Darcy Cobb. Navin demonstrated the service for Wired News last week at BitTorrent’s temporary headquarters, a small, one-room San Francisco office shared with Navin’s last venture, an import/export firm called GSI Group. Surrounded by pallets of imported playing cards and poker chips, Navin fired up a browser on his laptop and typed “Mozilla” into the BitTorrent search field. The search quickly produced a site offering torrents for the free browser. The search engine is expected to go live within two weeks, according to Navin, who is moving to the Bay Area from Bellevue, Washington. It will live on BitTorrent, the website from which Cohen distributes the open-source software that has changed the way netizens distribute and connect with content online. BitTorrent speeds internet file transfers by shifting the bandwidth burden off the publisher, and distributing it among users downloading the file: Everyone downloading a file over BitTorrent is unobtrusively uploading it to other users at the same time so that large, popular files actually move at a faster rate than obscure ones. The new search engine takes that dynamic into account. It resembles Google in operation, with a simple interface and results ranked by an automated process. But unlike a general web search, the BitTorrent web crawler interacts with each torrent behind the scenes to determine the number of nodes downloading and uploading through it. That lets the search engine order its results by the throughput of each torrent. “Web search rates things by relevance,” says Navin, a former strategist for Yahoo. “Our search rates things by relevance and availability.” Although BitTorrent has become associated with online piracy thanks to its role in distributing copyright movies and television shows, the company is eager to highlight its utility as a completely lawful program for furthering free speech. That’s the vision that drives the company, says Navin -- now anyone can publish their own movies, music or software, because BitTorrent all but eliminates expensive bandwidth costs. http://www.wired.com/news/ebiz/0,1272,67596,00.html
-- but --
FEDS SHUT DOWN ILLEGAL ‘STAR WARS’ SITE (SciTechToday, 27 May 2005) -- Federal agents have shut down the Elite Torrents network, which distributed illegal copies of Star Wars: Revenge of the Sith before the movie appeared in theaters. Armed with 10 search warrants, agents from the FBI and the U.S. Immigration and Customs Enforcement seized the network’s main server, reporting that it contains nearly 18,000 movies and software programs. “Our goal is to shut down as much of this illegal operation as quickly as possible to stem the serious financial damage to the victims of this high-tech piracy -- the people who labor to produce these copyrighted products,” said Acting Assistant Attorney General Richter in a statement. The Elite Torrents network relied on BitTorrent Latest News about BitTorrent technology, which has been targeted by the Motion Picture Association of America Latest News about Motion Picture Association of America (MPAA) in several lawsuits. In December, the MPAA took actions against over 100 servers in the U.S. and Europe, going after site operators that used BitTorrent and eDonkey to swap movie files. One popular site that was closed, SuprNova.org, noted that it might return without hosting any more BitTorrent links, and other sites are expected to follow a similar tactic. The inclusion of federal authorities in the shutdown of Elite Torrents is indicative of the multipronged enforcement strategy being enacted at the MPAA, which helped with the recent shutdown. http://www.sci-tech-today.com/story.xhtml?story_id=13100EMJC2BR
-- and ---
NEW SWEDISH LAW TO BAN DOWNLOADING OF FILMS, MUSIC (Reuters, 25 May 2005) -- Sweden’s parliament approved a law on Wednesday that bans the downloading of copyrighted material such as films and music from the Internet after being singled out for criticism by Hollywood. Sweden had until now allowed downloading of files, while uploading, or putting material on the Web, was illegal. Actor Morgan Freeman, in a Reuters interview, recently cited Sweden as an example of a country where illegal peer-to-peer file-sharing was a growing problem. The Swedish parliament’s decision, which comes into effect July 1, aims to change that. “The decision means that a clear ban has been introduced against downloading music, pictures and other material on the Internet for private use without the copyright holder’s permission,” parliament said in a statement. http://www.reuters.com/newsArticle.jhtml?storyID=8606639
CONFIDENTIAL DATA, MANDATORY PROTECTION (National Law Journal, 23 May 2005; subscription required) -- As of Oct. 31, 2004, companies listed on the New York Stock Exchange (NYSE) are required to be in compliance with the NYSE’s corporate governance rules promulgated pursuant to the Sarbanes-Oxley Act. While § 406 of Sarbanes-Oxley only requires public companies to adopt codes of conduct governing “senior financial officers, applicable to its principal financial officer and comptroller or principal accounting officer,” the code of conduct required by the NYSE is not so narrowly limited. Codes of conduct promulgated by NYSE-listed companies must apply to “directors, officers and employees,” not just those involved in financial reporting, and must “address” conduct beyond financial reporting. NYSE’s Listed Company Manual, § 303A, ¶ 10. While recognizing that “[e]ach company may determine its own policies,” the NYSE now requires a listed company to address confidentiality as a goal of its compliance program and to adopt a policy that its “[e]mployees, officers and directors should maintain the confidentiality of information entrusted to them by the company or its customers.” This rule places the NYSE at the forefront of a trend that is drastically changing the traditional rules on protecting a company’s confidential information. It used to be that a company had the option of whether to protect its confidential information-an option that was driven solely by market incentives to keep the information away from the competition. Indeed, the courts will only protect company confidential information as a trade secret if the company itself takes reasonable steps to protect it. See, e.g., Teleflora LLC v. Florists’ Transworld Delivery Inc., No. C 03-05858, 2004 WL 1844847, at 6 (N.D. Calif. Oct. 5, 2004). The courts, of course, have never mandated that such reasonable steps be taken or that confidential company information be protected. For NYSE-listed companies, taking reasonable steps to protect confidential information-whether it is their own confidential business information or customers’ personal information-is no longer optional. Section 303A is part of a growing trend of laws and regulations requiring companies to protect confidential information. http://www.law.com/jsp/nlj/PubArticleNLJ.jsp?id=1116493510072
MINNESOTA COURT TAKES DIM VIEW OF ENCRYPTION (CNET, 24 May 2005) -- A Minnesota appeals court has ruled that the presence of encryption software on a computer may be viewed as evidence of criminal intent. Ari David Levie, who was convicted of taking illegal photographs of a nude 9-year-old girl, argued on appeal that the PGP encryption utility on his computer was irrelevant and should not have been admitted as evidence during his trial. PGP stands for Pretty Good Privacy and is sold by PGP Inc. of Palo Alto, Calif. But the Minnesota appeals court ruled 3-0 that the trial judge was correct to let that information be used when handing down a guilty verdict. “We find that evidence of appellant’s Internet use and the existence of an encryption program on his computer was at least somewhat relevant to the state’s case against him,” Judge R.A. Randall wrote in an opinion dated May 3. Randall favorably cited testimony given by retired police officer Brooke Schaub, who prepared a computer forensics report--called an EnCase Report--for the prosecution. Schaub testified that PGP “can basically encrypt any file” and “other than the National Security Agency,” nobody could break it. http://news.com.com/2100-1030_3-5718978.html Opinion at http://www.lawlibrary.state.mn.us/archive/ctappub/0505/opa040381-0503.htm
HOMELAND SECURITY FLUNKS CYBERSECURITY PREP TEST (CNET, 26 May 2005) -- The U.S. Department of Homeland Security has failed to live up to its cybersecurity responsibilities and may be “unprepared” for emergencies, federal auditors said in a scathing report released Thursday. More than two years after its creation, Homeland Security has never developed a contingency plan to restore Internet functions in an emergency and has yet to create a vulnerability assessment of what could happen in an worst-case scenario, the Government Accountability Office concluded. “DHS cannot effectively function as the cybersecurity focal point intended by law and national policy” at the moment, the report said. “There is increased risk that large portions of our national infrastructure are either unaware of key areas of cybersecurity risks or unprepared to effectively address cyber emergencies.” http://news.com.com/2100-7348_3-5722227.html Report at http://www.gao.gov/highlights/d05434high.pdf
-- and --
CIA OVERSEEING 3-DAY WAR GAME ON INTERNET (AP, 26 May 2005) -- The CIA is conducting a secretive war game, dubbed “Silent Horizon,” this week to practice defending against an electronic assault on the same scale as the Sept. 11 terrorism attacks. The three-day exercise, ending Thursday, was meant to test the ability of government and industry to respond to escalating Internet disruptions over many months, according to participants. They spoke on condition of anonymity because the CIA asked them not to disclose details of the sensitive exercise taking place in Charlottesville, Va., about two hours southwest of Washington. The simulated attacks were carried out five years in the future by a fictional alliance of anti-American organizations, including anti-globalization hackers. The most serious damage was expected to be inflicted in the war game’s closing hours. The national security simulation was significant because its premise — a devastating cyberattack that affects government and parts of the economy with the same magnitude as the Sept. 11, 2001, suicide hijackings — contravenes assurances by U.S. counterterrorism experts that such far-reaching effects from a cyberattack are highly unlikely. Previous government simulations have modeled damage from cyberattacks more narrowly. “You hear less and less about the digital Pearl Harbor,” said Dennis McGrath, who helped run three similar war games for the Institute for Security Technology Studies at Dartmouth College. “What people call cyberterrorism, it’s just not at the top of the list.” The CIA’s little-known Information Operations Center, which evaluates threats to U.S. computer systems from foreign governments, criminal organizations and hackers, was running the war game. About 75 people, mostly from the CIA, gathered in conference rooms and reacted to signs of mock computer attacks. http://story.news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050526/ap_on_hi_te/internet_terror
MAD AS HELL, SWITCHING TO MAC (MacCentral, 26 May 2005) -- This is my first column written on a Mac - ever. Maybe I should have done it a long time ago, but I never said I was smart, just obstinate. I was a PC bigot. But now, I’ve had it. I’m mad as hell and I’m not going to take it anymore. In the coming weeks I’m going to keep a diary of an experiment my company began at 6 p.m. April 29, 2005 - an experiment predicated on the hypothesis that the WinTel platform represents the greatest violation of the basic tenets of information security and has become a national economic security risk. I do not say this lightly, and I have never been a Microsoft basher, either. I never criticize a company without a fair bit of explanation, justification and supportive evidence. I have come to the belief that there is a much easier, more secure way to use computers. After having spent several years focusing my security work on Ma, Pa and the Corporate Clueless, I also have come to the conclusion that if I’m having such security problems, heaven help the 98 percent of humanity who merely want a computer for e-mail and multimedia. Even though I’m a security guy going on 22 years now, my day-to-day work is pretty much like everyone else’s. I live on laptops and use my desktops at home and the office for geeking and experimenting. My two day-to-day laptops (two, for 24/7 backup) are my business machines. I don’t need them to do a whole lot - except work reliably, which is why I am fed up with WinTel. My company has given up on WinTel. We have successfully moved to Mac in less than two days. Think about it: a security-friendly alternative that works and doesn’t require gobs of third-party utilities to safely perform the most mundane tasks. Please follow the details of our experiment at www.securityawareness.blogspot.com. It’s already way more interesting than I thought it would be. http://news.yahoo.com/news?tmpl=story&cid=77&e=1&u=/mc/20050526/tc_mc/madashellswitchingtomac [Editor: For similar reasons, I moved to Macintosh 17 months ago, even though my company remained a WinTel-required environment. Since then, I’ve never needed technical support.]
EU TO FUND GLOBAL RESEARCH ON OPEN SOURCE (CNET, 26 May 2005) -- The European Union is putting money toward research into open-source software and standards across the world. The newly approved funding--660,00 euros, or $825,594--is for the two-year FLOSSWorld project, Europe’s first initiative to support international research and policy development on “free/libre/open source software.” Previous FLOSS projects, starting as early as 2001, have concentrated on the use of open source in Europe alone. Rishab Aiyer Ghosh, FLOSSWorld coordinator at the Maastricht Economic Research Institute on Innovation and Technology at the University of Maastricht in the Netherlands, told Silicon.com that the EU doesn’t usually fund international projects. The grant will be shared by countries including Argentina, Brazil, Bulgaria, China, Croatia, India, Malaysia and South Africa. The research will focus on three areas: the impact of free and open-source software on skills development and its ability to affect economics and generate employment; regional differences in software development; and attitudes of governments and public sector organizations to using open source. http://news.com.com/2100-7344_3-5721867.html
FEDERAL REPORT WARNS OF RFID MISUSES (CNET, 27 May 2005) -- Radio frequency identification is becoming increasingly popular inside the U.S. government, but agencies have not seriously considered the privacy risks, federal auditors said. In a report published Friday, the Government Accountability Office said that 13 of the largest federal agencies are already using RFID or plan to use it. But only one of 23 agencies polled by the GAO had identified any legal or privacy issues--even though three admitted RFID would let them track employee movements. “Key security issues include protecting the confidentiality, integrity and availability of the data and information systems,” the GAO said. “The privacy issues include notifying consumers; tracking an individual’s movements; profiling an individual’s habits, tastes and predilections; and allowing for secondary uses of information.” http://news.com.com/2100-7342_3-5723535.html Report at http://www.gao.gov/new.items/d05551.pdf
FTC RULE REQUIRES DESTRUCTION OF CONSUMER DATA (Washington Post, 2 June 2005) -- A new federal rule that took effect yesterday requires all businesses and individuals to destroy private consumer information obtained from credit bureaus and other information providers in determining whether to grant credit, hire employees or rent an apartment. Issued under orders from Congress, which was trying to crack down on identity theft, the Federal Trade Commission’s new rule requires that personal information be burned, pulverized, shredded or destroyed in such a way that the information cannot be read or reconstructed. The rule also applies to electronic files, which must be erased or destroyed, and covers credit report data, credit scores, employment histories, insurance claims, check-writing histories, residential or tenant history and medical information. An FTC official said failure to properly dispose of the data could draw a $2,500 federal penalty per violation, as well as lawsuits from people who could seek damages if personal information was misused as a result of improper disposal. http://www.washingtonpost.com/wp-dyn/content/article/2005/06/01/AR2005060101940.html?nav=rss_technology
6TH CIRCUIT UPHOLDS DECISION ON COPYRIGHT EXCEPTION (BNA’s Internet Law News, 6 June 2005) -- The Sixth Circuit Court of Appeals has reaffirmed their decision that there is effectively no de minimus exception to copyright infringement for sound recordings. The court concluded that even copying of two notes from a sound recording constitutes infringement. Case name is Bridgeport Music v. Dimension Films. Decision at http://caselaw.lp.findlaw.com/data2/circs/6th/026521pv2.pdf
JUDGES TOSS OUT DUIs BECAUSE BREATHALYZERS’ SOURCE CODE IS SECRET (BoingBoing, 6 June 2005) -- Florida judges are tossing out DUI cases when defendants ask to see the source code for the breathalyzers that busted them -- the manufacturers won’t turn over the source, and since the machine’s correct operation is critical to establishing the case against the DUIers, the case is dismissed when it can’t be produced. All four of Seminole County’s criminal judges have been using a standard that if a DUI defendant asks for a key piece of information about how the machine works - its software source code, for instance - and the state cannot provide it, the breath test is rejected, the Orlando Sentinel reported Wednesday. Seminole judges have been following the lead of county Judge Donald Marblestone, who in January ruled that although the information may be a trade secret and controlled by a private contractor, defendants are entitled to it. http://www.boingboing.net/2005/06/06/judges_toss_out_duis.html
EBAY OFFERS GUARANTEES FOR SOME BUYS (CNET, 6 June 2005) -- eBay has launched a program offering purchase protection of up to $20,000 for certain capital goods bought through its Web site. Items covered include tractors from the auctioneer’s agriculture and forestry category; skid steers, backhoes, crawler dozers and other gear in the construction category; plus mills and lathes from the manufacturing and metalworking category, eBay said Monday. The offer, which is valid with purchases of $1,000 or more, is designed to give buyers protection against fraud and material misrepresentation. The program covers goods purchased in the United States, the auctioneer said. The offer covers items not received and those having damages or liens. There is no charge to buyers or sellers, the auctioneer said. The move is meant to appeal to small businesses and to boost confidence in online auctioning, eBay said. http://news.com.com/2100-1038_3-5733479.html
LEGAL ONLINE MUSIC STORES MAKE SOME GAINS (Reuters, 7 June 2005) -- Legal online music stores have gained a solid foothold against free file-sharing networks, according to new data released on Tuesday. The beleaguered music industry has been pursuing a carrot and stick strategy of supporting legal alternatives such as Apple’s iTunes, RealNetworks’s Rhapsody and Napster, while filing a barrage of lawsuits against people and services that share music illicitly online. According to data from market research firm NPD Group Inc, the efforts are bearing fruit: iTunes has surged to a tie for second place as the most popular online music source, with 1.7 million U.S. households downloading at least one song in March. That put it neck and neck with the peer-to-peer service LimeWire and slightly behind another P2P service, WinMX, which has 2.1 million households. “Legal services offer some obvious advantages: they’re spyware free, and it’s very quick and easy to get what you want,” said NPD’s Isaac Josephson. “The older, more affluent demographics are already a bit more inclined to go for convenience over free, and when you raise the legal issues that’s an important tipping point.” About 4 percent of Internet-enabled U.S. households used a legal online music store in March, according to NPD. http://www.reuters.com/newsArticle.jhtml?storyID=8721861
-- and --
COME ON MUSIC BIZ, EMBRACE P2P (Wired, 13 June 2005) -- File-swapping networks alone are not to blame for the recording industry’s woes and might plausibly be converted into legitimate channels for distributing music, one of Europe’s most influential economic bodies has concluded. In a report issued Monday, the Organisation for Economic Co-operation and Development -- a Paris-based alliance of developed nations -- also suggested that it’s difficult to establish a link between piracy and the music industry’s shrinking revenues. The report said a “re-evaluation” of music distribution needs to happen to achieve a balance between consumers’ desire to access digital music and the industry’s copyright protection concerns. “Online technologies could evolve in a manner in which unauthorized use of copyright works are finally transformed into legitimate businesses,” said Sacha Wunsch-Vincent, an OECD economist and one of the report’s authors. The report said it is difficult to establish a causal connection between the rise of file sharing and a drop in music sales. While the music industry’s revenues fell 20 percent from 1999 to 2003, other factors, such as illegal CD copying, might have played a role in the decline, the OECD said. http://www.wired.com/news/digiwood/0,1412,67820,00.html Report at http://cyber.law.harvard.edu/digitalmedia/music_dsti_iccp_ie_2004_12_final_eng.pdf
THE JOY OF STACKS (InsideHigherEd, 9 June 2005) -- To understand why professors need great libraries, says Andrew Abbott, “you need to think about an ape swinging through the trees.” Abbott is not an evolutionary biologist, but a sociologist at the University of Chicago. And to Abbott, a scholar in a library is just like a swinging primate. “You’ve got your current source, which is the branch you are on, and then you see the next source, on the next branch, so you swing over. And on that new hanging vine, you see the next source, which you didn’t see before, and you swing again.” When books aren’t browsable or instantly available, Abbott says, a scholar becomes the ape “with no branch to grab, and you are stopped, hanging on a branch with no place to go.” At far too many libraries, he says, that is becoming the norm. Many universities are boasting about how they are digitizing collections or building vast, off-site facilities to store millions of books. Even when those books are available within hours, Abbott says, that destroys the way scholars need to think — moving from source to source, not knowing which source they will stumble on. Abbott heads a faculty committee at Chicago in charge of guiding a mammoth expansion of the Joseph Regenstein Library there. Chicago recently embarked on a plan that will end up with Regenstein housing more volumes — 8 million — under a single roof than any other university library in the United States. http://insidehighered.com/news/2005/06/09/stacks
MICROSOFT JOINS YAHOO!, GOOGLE IN CENSORING CHINA’S WEB (AFP, 13 June 2005) -- Users of Microsoft’s new China-based Internet portal were blocked from using the words “democracy”, “freedom” and “human rights” in an apparent move by the US software giant to appease Beijing. Other words that could not be used on Microsoft’s free online blog service MSN Spaces include “Taiwan independence” and “demonstration”. Bloggers who enter such words or other politically charged or pornographic content are prompted with a message that reads: “This item should not contain forbidden speech such as profanity. Please enter a different word for this item”. Officials at Microsoft’s Beijing offices refused to comment Monday. Internet sites in China are strongly urged to abide by a code of conduct and self-censor any information that could be viewed by the government as politically sensitive, pornographic or illegal. For many Chinese websites, such content also includes news stories that the government considers unfavorable or does not want published. New regulations issued in March now require that all China-based websites be formally registered with the government by the end of June or be shut down by Internet police. Microsoft formed a joint venture with China’s state-funded Shanghai Alliance Investment Ltd (SAIL) last month to launch the MSN China web portal. Microsoft is not the only international tech company to comply with China’s stringent Internet rules. Yahoo! and Google -- the two most popular Internet search engines -- have already been criticized for cooperating with the Chinese government to censor the Internet. http://uk.news.yahoo.com/050613/323/fl019.html
LIBERTY ALLIANCE TAKES ON ID THEFT (CNET, 13 June 2005) -- In the wake of several high-profile data breaches, the Liberty Alliance is branching out to take on identity theft. The organization, formed to develop technology standards for online authentication, plans to launch its Identity Theft Protection Group on Tuesday. Headed by representatives from American Express and Fidelity Investments, the new effort plans to release an identity theft glossary next month and to subsequently come up with ways to prevent ID theft. “I am concerned that unless we do something as an industry, this problem is going to get worse and worse, to the point that it is no longer a question if your identity gets stolen, but when,” Michael Barrett, co-chairman of the Identity Theft Prevention Group and a security executive at American Express, said in an interview Monday. Identity-related crime such as phishing threatens the growth of the Internet, Barrett said. The Identity Theft Prevention Group hopes to become a hub for efforts to combat the issue. It plans to first define and dissect the problem and then develop solutions, which could be technical specifications, policy best practices or business guidelines, Barrett said. The launch comes in the wake of several high-profile data loss incidents that exposed American consumers to identity risk. Last week, CitiFinancial said tapes containing unencrypted information on 3.9 million customers were lost by the United Parcel Service while in transit to a credit bureau. CitiFinancial is the consumer finance subsidiary of Citigroup. In past months, data leaks have been reported by Bank of America and Wachovia, data brokers ChoicePoint and LexisNexis, and the University of California at Berkeley and Stanford University. http://news.com.com/2100-7348_3-5744641.html
COPYRIGHT-WORRIED PHOTO LABS SPURN JOBS (AP, 16 June 2005) -- Charlie Morgan says that if it weren't for digital photography, he wouldn't have a bustling business that specializes in publicity shots for musicians. That's because Morgan — perhaps being a bit modest — says he's not a very good photographer. He relies on Photoshop editing software to make his work look sharp. But digital sometimes presents a puzzling problem. When Morgan's mother and a client recently took CDs with some of his shots to a printing lab, the photo technicians spurned them. They said that since the shots seemed to have been taken by a professional, printing the pictures might be a copyright violation. The situation is not unusual, and it's getting trickier in our digital age. Copyright law requires photo labs to be on the lookout for portraits and other professional work that should not be duplicated without a photographer's permission. In the old days, questions about an image's provenance could be settled with a negative. If you had it, you probably had the right to reproduce it. Now, when images are submitted on CDs or memory cards or over the Web, photofinishers often have to guess whether a picture was truly taken by the customer — or whether it was scanned into a computer or pilfered off the Internet. That leads to some awkward moments at photo desks when customers' images get barred for essentially looking too good. Like others who have been told their work was unprintable, Morgan is frustrated that photo labs lack clear standards. "They really don't have anything etched in stone," said Morgan, who lives in Plant City, Fla. "The person that works in the photography section of Wal-Mart could take a break, someone from the underwear department could take their place, and they could decide to print the picture." Wal-Mart spokeswoman Jacquie Young said her company's photo departments are instructed to err on the side of protecting copyrights, even if that means a conflict with an insistent customer. She would not say what signs of professionalism the photofinishers are told to look for. http://news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050616/ap_on_hi_te/photo_printing_frustration
SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.
PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.
MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.
Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.
Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.
**************End of Introductory Note***************
E-MAIL RETENTION A MUST AFTER MORGAN STANLEY CASE (CNET, 21 May 2005) -- The $1.45 billion judgment against Morgan Stanley for deceiving billionaire Ronald Perelman over a business deal has a lesson all companies should learn--keeping e-mails is now a must, experts say. Banks and broker-dealers are obliged to retain e-mail and instant messaging documents for three years under U.S. Securities and Exchange Commission rules. But similar requirements will apply to all public companies from July 2006 under the Sarbanes-Oxley corporate reform measures. At the same time, U.S. courts are imposing increasingly harsh punishments on corporations that fail to comply with orders to produce e-mail documents, the experts said. Where judges once were more likely to accept that incompetence or computer problems might be to blame, they are now apt to rule that noncompliance is an indication a company has something to hide. “Morgan Stanley is going to be a harbinger,” said Bill Lyons, chief executive officer of AXS-One, a provider of records retention software systems. “I think general counsels around the world are going to look at this as a legal Chernobyl,” he said. Wednesday’s $1.45 billion verdict against Morgan Stanley in West Palm Beach, Fla., was the product of just such a negative ruling on e-mail retention, which is also expected to form the backbone of the Wall Street firm’s appeal. http://news.com.com/E-mail+retention+a+must+after+Morgan+Stanley+case/2100-1036_3-5715554.html?tag=nefd.top
-- and --
COMPANIES RAMPING UP E-MAIL MONITORING (CNET, 8 June 2005) -- A new study has found that 63 percent of corporations with 1,000 or more employees either employ or plan to employ staff to read or otherwise analyze outbound e-mail. The report, released Monday by e-mail security specialist Proofpoint, said 36.1 percent of companies employ staff to monitor e-mail today, with another 26.5 percent saying they intend to employ such staff in the future. In companies with more than 20,000 employees, this practice is even more common, according to the survey, which involved 332 technology decision-makers at large U.S. companies. Forty percent of those large companies employ staff to monitor e-mail today, and an additional 32 percent plan to employ such staff in the future. According to the study, companies are concerned about making sure e-mail isn’t used to leak company trade secrets or other intellectual property, and about complying with financial disclosure regulations. Another factor is preventing confidential internal memos from getting zapped outside the company, according to the report. The study comes amid a rise in workplace monitoring. The number of employers who monitor the amount of time employees spend on the phone and track the numbers called has jumped to 51 percent, up from 9 percent in 2001, according to a study released last month by the American Management Association and the ePolicy Institute. http://news.com.com/Companies+ramping+up+e-mail+monitoring/2100-1022_3-5738134.html?tag=html.alert
COURT RULES FOR GERMAN ISPS IN P2P IDENTITIES CASE (The Register, 17 May 2005) -- ISPs in the state of Hamburg can’t be forced to provide customer data to record companies, even when illegal copying is suspected, at least for now. The Higher Regional Court in Hamburg has ruled (http://www.heise.de/english/newsticker/news/59602) that there is no legal basis for demanding customer data. ISPs, the court argues, aren’t part of the criminal act. They merely provide access to the web. The Higher Regional Court overruled a earlier decision by the Hamburg District Court, which had granted record companies access to customer data after they discovered an FTP server where numbers by German band Rammstein could be downloaded for free. The District Court based its ruling on the German Copyright Act. http://www.theregister.co.uk/2005/05/17/hamburg_isp_ruling/print.html The full text of the decision is available (in German) at: http://www.jurpc.de/rechtspr/20050062.htm.
U.S. ARMY UPGRADES ARMY KNOWLEDGE ONLINE - AKO - PORTAL (Internet Ad Sales, 18 May 2005) -- Appian Corporation, the leading provider of business process management solutions to the government, today announced that the U.S. Army has purchased additional software licenses, as well as maintenance and professional services, for the Army Knowledge Online (AKO) portal. Additionally, AKO will be upgraded to Appian Enterprise v.3, the latest version of Appian’s award-winning portal solution for government. With more than 1.6 million registered users, AKO is widely regarded as one of the most successful enterprise portal implementations in the world. In April, 770,000 different people used AKO 12.5 million times. Overall, 72 percent of the active force uses AKO regularly. Considered the virtual nerve center of Army operations, AKO provides single sign-on access to as many as 300 of the Army’s mission-critical applications and services. “The global war on terror has created new demands for collaboration and information sharing,” said Gary Winkler, Director of Enterprise Integration, Chief Information Officer/G6. “The rapid and wide-spread acceptance of AKO as the Army operations portal and virtual workspace makes it the obvious and most appropriate vehicle for bringing groups of people with shared interests together.” http://www.internetadsales.com/modules/news/article.php?storyid=850
NEXT FOR BITTORRENT: SEARCH (Wired, 23 May 2005) -- Whiz kid inventor Bram Cohen and a small cadre of developers and entrepreneurs are in the final stage of launching an advertising-supported search engine dedicated to cataloging and indexing the thousands of movies, music tracks, software programs and other files for download over Cohen’s popular BitTorrent protocol. The free search tool will be the first large-scale commercial offering from BitTorrent, a five-person company headed by Cohen that so far has drawn most of its revenue from T-shirt sales and PayPal donations. The ranked search results will be accompanied by sponsored links provided through a partnership with Oakland, California, company Ask Jeeves, says Ashwin Navin, BitTorrent’s chief operating officer. BitTorrent will make money from each clickthrough. “Ask Jeeves syndicates our advertising products to many different sites, and BitTorrent will be one of them,” confirmed Ask Jeeves spokeswoman Darcy Cobb. Navin demonstrated the service for Wired News last week at BitTorrent’s temporary headquarters, a small, one-room San Francisco office shared with Navin’s last venture, an import/export firm called GSI Group. Surrounded by pallets of imported playing cards and poker chips, Navin fired up a browser on his laptop and typed “Mozilla” into the BitTorrent search field. The search quickly produced a site offering torrents for the free browser. The search engine is expected to go live within two weeks, according to Navin, who is moving to the Bay Area from Bellevue, Washington. It will live on BitTorrent, the website from which Cohen distributes the open-source software that has changed the way netizens distribute and connect with content online. BitTorrent speeds internet file transfers by shifting the bandwidth burden off the publisher, and distributing it among users downloading the file: Everyone downloading a file over BitTorrent is unobtrusively uploading it to other users at the same time so that large, popular files actually move at a faster rate than obscure ones. The new search engine takes that dynamic into account. It resembles Google in operation, with a simple interface and results ranked by an automated process. But unlike a general web search, the BitTorrent web crawler interacts with each torrent behind the scenes to determine the number of nodes downloading and uploading through it. That lets the search engine order its results by the throughput of each torrent. “Web search rates things by relevance,” says Navin, a former strategist for Yahoo. “Our search rates things by relevance and availability.” Although BitTorrent has become associated with online piracy thanks to its role in distributing copyright movies and television shows, the company is eager to highlight its utility as a completely lawful program for furthering free speech. That’s the vision that drives the company, says Navin -- now anyone can publish their own movies, music or software, because BitTorrent all but eliminates expensive bandwidth costs. http://www.wired.com/news/ebiz/0,1272,67596,00.html
-- but --
FEDS SHUT DOWN ILLEGAL ‘STAR WARS’ SITE (SciTechToday, 27 May 2005) -- Federal agents have shut down the Elite Torrents network, which distributed illegal copies of Star Wars: Revenge of the Sith before the movie appeared in theaters. Armed with 10 search warrants, agents from the FBI and the U.S. Immigration and Customs Enforcement seized the network’s main server, reporting that it contains nearly 18,000 movies and software programs. “Our goal is to shut down as much of this illegal operation as quickly as possible to stem the serious financial damage to the victims of this high-tech piracy -- the people who labor to produce these copyrighted products,” said Acting Assistant Attorney General Richter in a statement. The Elite Torrents network relied on BitTorrent Latest News about BitTorrent technology, which has been targeted by the Motion Picture Association of America Latest News about Motion Picture Association of America (MPAA) in several lawsuits. In December, the MPAA took actions against over 100 servers in the U.S. and Europe, going after site operators that used BitTorrent and eDonkey to swap movie files. One popular site that was closed, SuprNova.org, noted that it might return without hosting any more BitTorrent links, and other sites are expected to follow a similar tactic. The inclusion of federal authorities in the shutdown of Elite Torrents is indicative of the multipronged enforcement strategy being enacted at the MPAA, which helped with the recent shutdown. http://www.sci-tech-today.com/story.xhtml?story_id=13100EMJC2BR
-- and ---
NEW SWEDISH LAW TO BAN DOWNLOADING OF FILMS, MUSIC (Reuters, 25 May 2005) -- Sweden’s parliament approved a law on Wednesday that bans the downloading of copyrighted material such as films and music from the Internet after being singled out for criticism by Hollywood. Sweden had until now allowed downloading of files, while uploading, or putting material on the Web, was illegal. Actor Morgan Freeman, in a Reuters interview, recently cited Sweden as an example of a country where illegal peer-to-peer file-sharing was a growing problem. The Swedish parliament’s decision, which comes into effect July 1, aims to change that. “The decision means that a clear ban has been introduced against downloading music, pictures and other material on the Internet for private use without the copyright holder’s permission,” parliament said in a statement. http://www.reuters.com/newsArticle.jhtml?storyID=8606639
CONFIDENTIAL DATA, MANDATORY PROTECTION (National Law Journal, 23 May 2005; subscription required) -- As of Oct. 31, 2004, companies listed on the New York Stock Exchange (NYSE) are required to be in compliance with the NYSE’s corporate governance rules promulgated pursuant to the Sarbanes-Oxley Act. While § 406 of Sarbanes-Oxley only requires public companies to adopt codes of conduct governing “senior financial officers, applicable to its principal financial officer and comptroller or principal accounting officer,” the code of conduct required by the NYSE is not so narrowly limited. Codes of conduct promulgated by NYSE-listed companies must apply to “directors, officers and employees,” not just those involved in financial reporting, and must “address” conduct beyond financial reporting. NYSE’s Listed Company Manual, § 303A, ¶ 10. While recognizing that “[e]ach company may determine its own policies,” the NYSE now requires a listed company to address confidentiality as a goal of its compliance program and to adopt a policy that its “[e]mployees, officers and directors should maintain the confidentiality of information entrusted to them by the company or its customers.” This rule places the NYSE at the forefront of a trend that is drastically changing the traditional rules on protecting a company’s confidential information. It used to be that a company had the option of whether to protect its confidential information-an option that was driven solely by market incentives to keep the information away from the competition. Indeed, the courts will only protect company confidential information as a trade secret if the company itself takes reasonable steps to protect it. See, e.g., Teleflora LLC v. Florists’ Transworld Delivery Inc., No. C 03-05858, 2004 WL 1844847, at 6 (N.D. Calif. Oct. 5, 2004). The courts, of course, have never mandated that such reasonable steps be taken or that confidential company information be protected. For NYSE-listed companies, taking reasonable steps to protect confidential information-whether it is their own confidential business information or customers’ personal information-is no longer optional. Section 303A is part of a growing trend of laws and regulations requiring companies to protect confidential information. http://www.law.com/jsp/nlj/PubArticleNLJ.jsp?id=1116493510072
MINNESOTA COURT TAKES DIM VIEW OF ENCRYPTION (CNET, 24 May 2005) -- A Minnesota appeals court has ruled that the presence of encryption software on a computer may be viewed as evidence of criminal intent. Ari David Levie, who was convicted of taking illegal photographs of a nude 9-year-old girl, argued on appeal that the PGP encryption utility on his computer was irrelevant and should not have been admitted as evidence during his trial. PGP stands for Pretty Good Privacy and is sold by PGP Inc. of Palo Alto, Calif. But the Minnesota appeals court ruled 3-0 that the trial judge was correct to let that information be used when handing down a guilty verdict. “We find that evidence of appellant’s Internet use and the existence of an encryption program on his computer was at least somewhat relevant to the state’s case against him,” Judge R.A. Randall wrote in an opinion dated May 3. Randall favorably cited testimony given by retired police officer Brooke Schaub, who prepared a computer forensics report--called an EnCase Report--for the prosecution. Schaub testified that PGP “can basically encrypt any file” and “other than the National Security Agency,” nobody could break it. http://news.com.com/2100-1030_3-5718978.html Opinion at http://www.lawlibrary.state.mn.us/archive/ctappub/0505/opa040381-0503.htm
HOMELAND SECURITY FLUNKS CYBERSECURITY PREP TEST (CNET, 26 May 2005) -- The U.S. Department of Homeland Security has failed to live up to its cybersecurity responsibilities and may be “unprepared” for emergencies, federal auditors said in a scathing report released Thursday. More than two years after its creation, Homeland Security has never developed a contingency plan to restore Internet functions in an emergency and has yet to create a vulnerability assessment of what could happen in an worst-case scenario, the Government Accountability Office concluded. “DHS cannot effectively function as the cybersecurity focal point intended by law and national policy” at the moment, the report said. “There is increased risk that large portions of our national infrastructure are either unaware of key areas of cybersecurity risks or unprepared to effectively address cyber emergencies.” http://news.com.com/2100-7348_3-5722227.html Report at http://www.gao.gov/highlights/d05434high.pdf
-- and --
CIA OVERSEEING 3-DAY WAR GAME ON INTERNET (AP, 26 May 2005) -- The CIA is conducting a secretive war game, dubbed “Silent Horizon,” this week to practice defending against an electronic assault on the same scale as the Sept. 11 terrorism attacks. The three-day exercise, ending Thursday, was meant to test the ability of government and industry to respond to escalating Internet disruptions over many months, according to participants. They spoke on condition of anonymity because the CIA asked them not to disclose details of the sensitive exercise taking place in Charlottesville, Va., about two hours southwest of Washington. The simulated attacks were carried out five years in the future by a fictional alliance of anti-American organizations, including anti-globalization hackers. The most serious damage was expected to be inflicted in the war game’s closing hours. The national security simulation was significant because its premise — a devastating cyberattack that affects government and parts of the economy with the same magnitude as the Sept. 11, 2001, suicide hijackings — contravenes assurances by U.S. counterterrorism experts that such far-reaching effects from a cyberattack are highly unlikely. Previous government simulations have modeled damage from cyberattacks more narrowly. “You hear less and less about the digital Pearl Harbor,” said Dennis McGrath, who helped run three similar war games for the Institute for Security Technology Studies at Dartmouth College. “What people call cyberterrorism, it’s just not at the top of the list.” The CIA’s little-known Information Operations Center, which evaluates threats to U.S. computer systems from foreign governments, criminal organizations and hackers, was running the war game. About 75 people, mostly from the CIA, gathered in conference rooms and reacted to signs of mock computer attacks. http://story.news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050526/ap_on_hi_te/internet_terror
MAD AS HELL, SWITCHING TO MAC (MacCentral, 26 May 2005) -- This is my first column written on a Mac - ever. Maybe I should have done it a long time ago, but I never said I was smart, just obstinate. I was a PC bigot. But now, I’ve had it. I’m mad as hell and I’m not going to take it anymore. In the coming weeks I’m going to keep a diary of an experiment my company began at 6 p.m. April 29, 2005 - an experiment predicated on the hypothesis that the WinTel platform represents the greatest violation of the basic tenets of information security and has become a national economic security risk. I do not say this lightly, and I have never been a Microsoft basher, either. I never criticize a company without a fair bit of explanation, justification and supportive evidence. I have come to the belief that there is a much easier, more secure way to use computers. After having spent several years focusing my security work on Ma, Pa and the Corporate Clueless, I also have come to the conclusion that if I’m having such security problems, heaven help the 98 percent of humanity who merely want a computer for e-mail and multimedia. Even though I’m a security guy going on 22 years now, my day-to-day work is pretty much like everyone else’s. I live on laptops and use my desktops at home and the office for geeking and experimenting. My two day-to-day laptops (two, for 24/7 backup) are my business machines. I don’t need them to do a whole lot - except work reliably, which is why I am fed up with WinTel. My company has given up on WinTel. We have successfully moved to Mac in less than two days. Think about it: a security-friendly alternative that works and doesn’t require gobs of third-party utilities to safely perform the most mundane tasks. Please follow the details of our experiment at www.securityawareness.blogspot.com. It’s already way more interesting than I thought it would be. http://news.yahoo.com/news?tmpl=story&cid=77&e=1&u=/mc/20050526/tc_mc/madashellswitchingtomac [Editor: For similar reasons, I moved to Macintosh 17 months ago, even though my company remained a WinTel-required environment. Since then, I’ve never needed technical support.]
EU TO FUND GLOBAL RESEARCH ON OPEN SOURCE (CNET, 26 May 2005) -- The European Union is putting money toward research into open-source software and standards across the world. The newly approved funding--660,00 euros, or $825,594--is for the two-year FLOSSWorld project, Europe’s first initiative to support international research and policy development on “free/libre/open source software.” Previous FLOSS projects, starting as early as 2001, have concentrated on the use of open source in Europe alone. Rishab Aiyer Ghosh, FLOSSWorld coordinator at the Maastricht Economic Research Institute on Innovation and Technology at the University of Maastricht in the Netherlands, told Silicon.com that the EU doesn’t usually fund international projects. The grant will be shared by countries including Argentina, Brazil, Bulgaria, China, Croatia, India, Malaysia and South Africa. The research will focus on three areas: the impact of free and open-source software on skills development and its ability to affect economics and generate employment; regional differences in software development; and attitudes of governments and public sector organizations to using open source. http://news.com.com/2100-7344_3-5721867.html
FEDERAL REPORT WARNS OF RFID MISUSES (CNET, 27 May 2005) -- Radio frequency identification is becoming increasingly popular inside the U.S. government, but agencies have not seriously considered the privacy risks, federal auditors said. In a report published Friday, the Government Accountability Office said that 13 of the largest federal agencies are already using RFID or plan to use it. But only one of 23 agencies polled by the GAO had identified any legal or privacy issues--even though three admitted RFID would let them track employee movements. “Key security issues include protecting the confidentiality, integrity and availability of the data and information systems,” the GAO said. “The privacy issues include notifying consumers; tracking an individual’s movements; profiling an individual’s habits, tastes and predilections; and allowing for secondary uses of information.” http://news.com.com/2100-7342_3-5723535.html Report at http://www.gao.gov/new.items/d05551.pdf
FTC RULE REQUIRES DESTRUCTION OF CONSUMER DATA (Washington Post, 2 June 2005) -- A new federal rule that took effect yesterday requires all businesses and individuals to destroy private consumer information obtained from credit bureaus and other information providers in determining whether to grant credit, hire employees or rent an apartment. Issued under orders from Congress, which was trying to crack down on identity theft, the Federal Trade Commission’s new rule requires that personal information be burned, pulverized, shredded or destroyed in such a way that the information cannot be read or reconstructed. The rule also applies to electronic files, which must be erased or destroyed, and covers credit report data, credit scores, employment histories, insurance claims, check-writing histories, residential or tenant history and medical information. An FTC official said failure to properly dispose of the data could draw a $2,500 federal penalty per violation, as well as lawsuits from people who could seek damages if personal information was misused as a result of improper disposal. http://www.washingtonpost.com/wp-dyn/content/article/2005/06/01/AR2005060101940.html?nav=rss_technology
6TH CIRCUIT UPHOLDS DECISION ON COPYRIGHT EXCEPTION (BNA’s Internet Law News, 6 June 2005) -- The Sixth Circuit Court of Appeals has reaffirmed their decision that there is effectively no de minimus exception to copyright infringement for sound recordings. The court concluded that even copying of two notes from a sound recording constitutes infringement. Case name is Bridgeport Music v. Dimension Films. Decision at http://caselaw.lp.findlaw.com/data2/circs/6th/026521pv2.pdf
JUDGES TOSS OUT DUIs BECAUSE BREATHALYZERS’ SOURCE CODE IS SECRET (BoingBoing, 6 June 2005) -- Florida judges are tossing out DUI cases when defendants ask to see the source code for the breathalyzers that busted them -- the manufacturers won’t turn over the source, and since the machine’s correct operation is critical to establishing the case against the DUIers, the case is dismissed when it can’t be produced. All four of Seminole County’s criminal judges have been using a standard that if a DUI defendant asks for a key piece of information about how the machine works - its software source code, for instance - and the state cannot provide it, the breath test is rejected, the Orlando Sentinel reported Wednesday. Seminole judges have been following the lead of county Judge Donald Marblestone, who in January ruled that although the information may be a trade secret and controlled by a private contractor, defendants are entitled to it. http://www.boingboing.net/2005/06/06/judges_toss_out_duis.html
EBAY OFFERS GUARANTEES FOR SOME BUYS (CNET, 6 June 2005) -- eBay has launched a program offering purchase protection of up to $20,000 for certain capital goods bought through its Web site. Items covered include tractors from the auctioneer’s agriculture and forestry category; skid steers, backhoes, crawler dozers and other gear in the construction category; plus mills and lathes from the manufacturing and metalworking category, eBay said Monday. The offer, which is valid with purchases of $1,000 or more, is designed to give buyers protection against fraud and material misrepresentation. The program covers goods purchased in the United States, the auctioneer said. The offer covers items not received and those having damages or liens. There is no charge to buyers or sellers, the auctioneer said. The move is meant to appeal to small businesses and to boost confidence in online auctioning, eBay said. http://news.com.com/2100-1038_3-5733479.html
LEGAL ONLINE MUSIC STORES MAKE SOME GAINS (Reuters, 7 June 2005) -- Legal online music stores have gained a solid foothold against free file-sharing networks, according to new data released on Tuesday. The beleaguered music industry has been pursuing a carrot and stick strategy of supporting legal alternatives such as Apple’s iTunes, RealNetworks’s Rhapsody and Napster, while filing a barrage of lawsuits against people and services that share music illicitly online. According to data from market research firm NPD Group Inc, the efforts are bearing fruit: iTunes has surged to a tie for second place as the most popular online music source, with 1.7 million U.S. households downloading at least one song in March. That put it neck and neck with the peer-to-peer service LimeWire and slightly behind another P2P service, WinMX, which has 2.1 million households. “Legal services offer some obvious advantages: they’re spyware free, and it’s very quick and easy to get what you want,” said NPD’s Isaac Josephson. “The older, more affluent demographics are already a bit more inclined to go for convenience over free, and when you raise the legal issues that’s an important tipping point.” About 4 percent of Internet-enabled U.S. households used a legal online music store in March, according to NPD. http://www.reuters.com/newsArticle.jhtml?storyID=8721861
-- and --
COME ON MUSIC BIZ, EMBRACE P2P (Wired, 13 June 2005) -- File-swapping networks alone are not to blame for the recording industry’s woes and might plausibly be converted into legitimate channels for distributing music, one of Europe’s most influential economic bodies has concluded. In a report issued Monday, the Organisation for Economic Co-operation and Development -- a Paris-based alliance of developed nations -- also suggested that it’s difficult to establish a link between piracy and the music industry’s shrinking revenues. The report said a “re-evaluation” of music distribution needs to happen to achieve a balance between consumers’ desire to access digital music and the industry’s copyright protection concerns. “Online technologies could evolve in a manner in which unauthorized use of copyright works are finally transformed into legitimate businesses,” said Sacha Wunsch-Vincent, an OECD economist and one of the report’s authors. The report said it is difficult to establish a causal connection between the rise of file sharing and a drop in music sales. While the music industry’s revenues fell 20 percent from 1999 to 2003, other factors, such as illegal CD copying, might have played a role in the decline, the OECD said. http://www.wired.com/news/digiwood/0,1412,67820,00.html Report at http://cyber.law.harvard.edu/digitalmedia/music_dsti_iccp_ie_2004_12_final_eng.pdf
THE JOY OF STACKS (InsideHigherEd, 9 June 2005) -- To understand why professors need great libraries, says Andrew Abbott, “you need to think about an ape swinging through the trees.” Abbott is not an evolutionary biologist, but a sociologist at the University of Chicago. And to Abbott, a scholar in a library is just like a swinging primate. “You’ve got your current source, which is the branch you are on, and then you see the next source, on the next branch, so you swing over. And on that new hanging vine, you see the next source, which you didn’t see before, and you swing again.” When books aren’t browsable or instantly available, Abbott says, a scholar becomes the ape “with no branch to grab, and you are stopped, hanging on a branch with no place to go.” At far too many libraries, he says, that is becoming the norm. Many universities are boasting about how they are digitizing collections or building vast, off-site facilities to store millions of books. Even when those books are available within hours, Abbott says, that destroys the way scholars need to think — moving from source to source, not knowing which source they will stumble on. Abbott heads a faculty committee at Chicago in charge of guiding a mammoth expansion of the Joseph Regenstein Library there. Chicago recently embarked on a plan that will end up with Regenstein housing more volumes — 8 million — under a single roof than any other university library in the United States. http://insidehighered.com/news/2005/06/09/stacks
MICROSOFT JOINS YAHOO!, GOOGLE IN CENSORING CHINA’S WEB (AFP, 13 June 2005) -- Users of Microsoft’s new China-based Internet portal were blocked from using the words “democracy”, “freedom” and “human rights” in an apparent move by the US software giant to appease Beijing. Other words that could not be used on Microsoft’s free online blog service MSN Spaces include “Taiwan independence” and “demonstration”. Bloggers who enter such words or other politically charged or pornographic content are prompted with a message that reads: “This item should not contain forbidden speech such as profanity. Please enter a different word for this item”. Officials at Microsoft’s Beijing offices refused to comment Monday. Internet sites in China are strongly urged to abide by a code of conduct and self-censor any information that could be viewed by the government as politically sensitive, pornographic or illegal. For many Chinese websites, such content also includes news stories that the government considers unfavorable or does not want published. New regulations issued in March now require that all China-based websites be formally registered with the government by the end of June or be shut down by Internet police. Microsoft formed a joint venture with China’s state-funded Shanghai Alliance Investment Ltd (SAIL) last month to launch the MSN China web portal. Microsoft is not the only international tech company to comply with China’s stringent Internet rules. Yahoo! and Google -- the two most popular Internet search engines -- have already been criticized for cooperating with the Chinese government to censor the Internet. http://uk.news.yahoo.com/050613/323/fl019.html
LIBERTY ALLIANCE TAKES ON ID THEFT (CNET, 13 June 2005) -- In the wake of several high-profile data breaches, the Liberty Alliance is branching out to take on identity theft. The organization, formed to develop technology standards for online authentication, plans to launch its Identity Theft Protection Group on Tuesday. Headed by representatives from American Express and Fidelity Investments, the new effort plans to release an identity theft glossary next month and to subsequently come up with ways to prevent ID theft. “I am concerned that unless we do something as an industry, this problem is going to get worse and worse, to the point that it is no longer a question if your identity gets stolen, but when,” Michael Barrett, co-chairman of the Identity Theft Prevention Group and a security executive at American Express, said in an interview Monday. Identity-related crime such as phishing threatens the growth of the Internet, Barrett said. The Identity Theft Prevention Group hopes to become a hub for efforts to combat the issue. It plans to first define and dissect the problem and then develop solutions, which could be technical specifications, policy best practices or business guidelines, Barrett said. The launch comes in the wake of several high-profile data loss incidents that exposed American consumers to identity risk. Last week, CitiFinancial said tapes containing unencrypted information on 3.9 million customers were lost by the United Parcel Service while in transit to a credit bureau. CitiFinancial is the consumer finance subsidiary of Citigroup. In past months, data leaks have been reported by Bank of America and Wachovia, data brokers ChoicePoint and LexisNexis, and the University of California at Berkeley and Stanford University. http://news.com.com/2100-7348_3-5744641.html
COPYRIGHT-WORRIED PHOTO LABS SPURN JOBS (AP, 16 June 2005) -- Charlie Morgan says that if it weren't for digital photography, he wouldn't have a bustling business that specializes in publicity shots for musicians. That's because Morgan — perhaps being a bit modest — says he's not a very good photographer. He relies on Photoshop editing software to make his work look sharp. But digital sometimes presents a puzzling problem. When Morgan's mother and a client recently took CDs with some of his shots to a printing lab, the photo technicians spurned them. They said that since the shots seemed to have been taken by a professional, printing the pictures might be a copyright violation. The situation is not unusual, and it's getting trickier in our digital age. Copyright law requires photo labs to be on the lookout for portraits and other professional work that should not be duplicated without a photographer's permission. In the old days, questions about an image's provenance could be settled with a negative. If you had it, you probably had the right to reproduce it. Now, when images are submitted on CDs or memory cards or over the Web, photofinishers often have to guess whether a picture was truly taken by the customer — or whether it was scanned into a computer or pilfered off the Internet. That leads to some awkward moments at photo desks when customers' images get barred for essentially looking too good. Like others who have been told their work was unprintable, Morgan is frustrated that photo labs lack clear standards. "They really don't have anything etched in stone," said Morgan, who lives in Plant City, Fla. "The person that works in the photography section of Wal-Mart could take a break, someone from the underwear department could take their place, and they could decide to print the picture." Wal-Mart spokeswoman Jacquie Young said her company's photo departments are instructed to err on the side of protecting copyrights, even if that means a conflict with an insistent customer. She would not say what signs of professionalism the photofinishers are told to look for. http://news.yahoo.com/news?tmpl=story&cid=528&e=2&u=/ap/20050616/ap_on_hi_te/photo_printing_frustration
SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.
PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.
Monday, May 23, 2005
MIRLN -- Misc. IT Related Legal News [23 April – 21 May 2005; v8.06]
**************Introductory Note**********************
MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.
Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.
Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.
**************End of Introductory Note***************
FRENCH DATA PROTECTION AUTHORITY ALLOWS SOFTWARE DEVELOPERS TO MONITOR P2P NETWORKS (DM Europe, 18 April 2005) -- The French data protection authority has announced that it is to allow the Syndicat des Editeurs de Logiciels de Loisi (SELL) - the French software developers’ trade association - to monitor data traffic over peer-to-peer file-sharing networks. The Commission nationale de l’informatique et des libertés (CNIL) has permitted SELL to send warning messages to users uploading illegally copied software and then locate and use the IP addresses of such individuals in legal proceedings. http://www.dmeurope.com/default.asp?ArticleID=7370
E-COMMERCE SITES FORCED TO ADOPT SECURITY STANDARDS (Ecommerce Times, 23 April 2005) -- Online retailers will be forced to tighten security and improve their handling of customer data under new rules being introduced by the credit card industry to stop identity theft. From June 30, all e-commerce sites with internal systems that process, store or transmit cardholder information will have to comply with the Payment Card Industry (PCI) Data Security Standard or face significant fines. In extreme cases, online merchants could be banned from processing transactions using payment cards. Backed by MasterCard, Visa, American Express (NYSE: AXP) Latest News about American Express, Diners Club and JCB Cards, the standard requires Internet retailers to carry out a 12-step security audit, which will be certified annually and checked every three months. http://www.ecommercetimes.com/story/ebiz/42479.html
-- and --
SOVEREIGN BLAMES RETAILER IN ID THEFT SCAM (Philadelphia Business Journal, 11 Feb 2005) -- Sovereign Bank is trying to blame BJ’s Wholesale Club Inc. in an identity theft scheme that victimized hundreds of the bank’s debit cardholders last year. The bank said last June that a computer hacker had stolen account information from at least 700 debit card customers and that it was forced to reissue 80,000 new debit cards. But it offered no other details at the time. But in January, Sovereign filed a civil lawsuit in Berks County Court of Common Pleas saying the account information was stolen from BJ’s after bank customers made purchases from the retailer, which has its headquarters in Natick, Mass. In its lawsuit, Sovereign said that under rules established by Visa, which issued the Sovereign cards, BJ’s was supposed to delete cardholder information from its computers after the transaction was complete. http://philadelphia.bizjournals.com/philadelphia/stories/2005/02/14/story4.html?t=printable%5BEditor’s
FEDS RETHINKING RFID PASSPORT (Wired, 26 April 2005) -- Following criticism from computer security professionals and civil libertarians about the privacy risks posed by new RFID passports the government plans to begin issuing, a State Department official said his office is reconsidering a privacy solution it rejected earlier that would help protect passport holders’ data. The solution would require an RFID reader to provide a key or password before it could read data embedded on an RFID passport’s chip. It would also encrypt data as it’s transmitted from the chip to a reader so that no one could read the data if they intercepted it in transit. Frank Moss, deputy assistant secretary for passport services, told Wired News on Monday that the government was “taking a very serious look” at the privacy solution in light of the 2,400-plus comments the department received about the e-passport rule and concerns expressed last week in Seattle by participants at the Computers, Freedom and Privacy conference. Moss said recent work on the passports conducted with the National Institute of Standards and Technology had also led him to rethink the issue. “Basically what changed my mind was a recognition that the (reading distance) may have actually been able to be more than 10 centimeters, and also recognition that we had to do everything possible to protect the security of people,” Moss said. http://www.wired.com/news/privacy/0,1848,67333,00.html
MICROSOFT TO ADD ‘BLACK BOX’ TO WINDOWS (CNET, 26 April 2005) -- In a move that could rankle privacy advocates, Microsoft said Monday that it is adding the PC equivalent of a flight data recorder to the next version of Windows, in an effort to better understand and prevent computer crashes. The tool will build on the existing Watson error-reporting tool in Windows but will provide Microsoft with much deeper information, including what programs were running at the time of the error and even the contents of documents that were being created. Businesses will also choose whether they want their own technology managers to receive such data when an employee’s machine crashes. “Think of it as a flight data recorder, so that any time there’s a problem, that ‘black box’ is there helping us work together and diagnose what’s going on,” Microsoft Chairman Bill Gates said during a speech at the Windows Hardware Engineering Conference here. For consumers, the choice of whether to send the data, and how much information to share, will be up to the individual. Though the details are being finalized, Windows lead product manager Greg Sullivan said users will be prompted with a message indicating the information to be sent and giving them an option to alter it, such as removing the contents of the e-mail they were writing when the machine crashed. Also, such reporting will also be anonymous. With businesses, however, IT managers typically set the policy. If they wanted total information, they could configure systems so that they’d know not only that a user was running Internet Explorer, for example, but also that he or she was watching a video from ESPN.com. Or, they might find out not only that a worker was running Instant Messenger but also that he or she was talking to a co-worker about getting a new job. And consumers could have a tough time knowing just what information they were sending. Though they’ll be able to see the contents of a document, they may not recognize the significance of the technical data--such as register settings--that’s being sent. http://news.com.com/2100-1016_3-5684051.html
GROUP WANTS ENCRYPTION BANS OVERTURNED (CNET, 27 April 2005) -- An international security consortium plans to push governments around the world to withdraw restrictions on the use of encryption. Countries including China, Israel, Russia and Saudi Arabia have strict rules governing the use of encryption tools, and in some cases they have banned these tools. The Jericho Forum, which is looking to move away from the perimeter model for cybersecurity toward an approach that would make data totally secure, hinted that such policies could cause problems for e-commerce. The Jericho Forum, whose membership includes many chief security officers from FTSE 100 companies, will push for the removal of encryption restrictions within the next three to five years. http://news.com.com/2100-7348_3-5687087.html
SPIDERS CAN ENTER CONTRACTS TOO! (Steptoe & Johnson’s E-Commerce Law Week, 28 April 2005) -- It wouldn’t be unheard-of for a web surfer to accept the terms of a Terms of Use or “click-through” agreement without actually reading it ... and then for a court to hold him to the terms of that agreement. So is there a difference if his automated software tool does the “clicking” -- also without actually reading the agreement? Not according to the US District Court for the Northern District of California. In Cairo, Inc. v. CrossMedia Services, Inc., the court held that automated software tools called “spiders” can legally consent to the terms of use or terms of service agreements on websites they visit -- thereby committing their operators to the terms of those agreements and subjecting them to liability for violations. (The case breaks new legal ground, but the court designates its opinion as “unpublished,” which usually means that the ruling has little or no precedential impact. In this case, it may mean that the court lacks confidence in its judgment -- or simply that no one has yet asked the court to publish the opinion.) http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9512&siteId=547
WIRETAPS IN U.S. JUMP 19 PERCENT IN 2004 (SFgate.com, 28 April 2005) -- The number of court-authorized wiretaps jumped 19 percent last year as investigators pursued drug and other cases against increasingly tech-savvy suspects. Every surveillance request made by authorities was granted. Federal and state judges approved 1,710 applications for wiretaps of wire, oral or electronic communications last year, and four states — New York, California, New Jersey and Florida — accounted for three of every four surveillance orders, according to the Administrative Office of the U.S. Courts. That agency is required to collect the figures and report them to Congress. The numbers, released Thursday, do not include court orders for terror-related investigations under the Foreign Intelligence Surveillance Act, known as FISA, which reached a record 1,754 warrants last year, according to the Justice Department. In non-terrorist criminal investigations, federally approved wiretaps increased 26 percent in a year, to 730 applications, while state judges approved 980 wiretaps, an increase of 13 percent. Department of Justice spokesman Kevin Madden said the numbers reflect “an increase in the resources geared toward targeting very serious federal and state offenses for which electronic surveillance is often the most, and sometimes the only, effective investigative method.” Timothy Edgar, legislative counsel for the American Civil Liberties Union, said traditional law enforcement work is catching up with increases in anti-terror wiretaps. “We’re still seeing a huge trend toward increased surveillance,” said Edgar. http://www.sfgate.com/cgi-bin/article.cgi?file=/news/archive/2005/04/28/national/a082547D09.DTL
U.S. CRITICIZES WORLD IN SPECIAL 301 IP REPORT (BNA’s Internet Law News, 3 May 2005) -- The U.S. Trade Representative has released its annual Special 301 report on the IP policies of countries from around the world. A long list of countries face criticism - for example, Canada is criticized for its proposed copyright reform, India and Israel on pharmaceuticals, and Taiwan for lack of enforcement. Special 301 report at http://www.ustr.gov/Document_Library/Reports_Publications/2005/2005_Special_301/Section_Index.html
Canadian report at http://www.michaelgeist.ca/home.php#396
Taiwan report at http://www.chinapost.com.tw/detail.asp?ID=61808&GRP=A
India report at http://www.hindustantimes.com/news/181_1343386,0002.htm
Israel report at http://www.globes.co.il/serveen/globes/docview.asp?did=909133&fid=942
YOUR IDENTITY, OPEN TO ALL (Wired, 6 May 2005) -- A search for personal data on ZabaSearch.com -- one of the most comprehensive personal-data search engines on the net -- tends to elicit one of two reactions from first-timers: terror or curiosity. Which reaction often depends on whether you are searching for someone else’s data, or your own. ZabaSearch queries return a wealth of info sometimes dating back more than 10 years: residential addresses, phone numbers both listed and unlisted, birth year, even satellite photos of people’s homes. ZabaSearch isn’t the first or only such service online. Yahoo’s free People Search, for example, returns names, telephone numbers and addresses. But the information is nothing more than what’s been available for years in the White Pages. Far more personal information is available from data brokers, including aliases, bankruptcy records and tax liens. That access typically requires a fee, however, which has always been a barrier to the casual snooper. But ZabaSearch makes it easier than ever to find comprehensive personal information on anyone. ZabaSearch may give away some data for free, but it charges for additional information -- like background checks and criminal history reports, which may or may not be accurate. The company also plans to sell ads and other services on the search site, much like Google or Yahoo. http://www.wired.com/news/privacy/0,1848,67407,00.html
EU CLARIFIES “FOURTH WAY” FOR FOREIGN DATA TRANSFERS (Steptoe & Johnson’s E-Commerce Law Week, 7 May 2005) -- Global companies trying to cope with Europe’s data protection laws have traditionally had three options if they wanted to move personal information out of Europe. They could get the consent of everyone whose data would be moved. They could execute a web of agreements among the receiving and sending companies, essentially guaranteeing that European protections would follow European data. Or they could move the data only to the handful of countries whose data protection laws had been approved by European authorities – Argentina, Canada, Guernsey, Isle of Man and Switzerland – and the US, at least for companies that have joined the US-EU Safe Harbor. Now there’s a fourth way. In a pair of documents issued in mid-April – a Model Checklist for Approval of Binding Corporate Rules (at http://www.steptoe.com/publications/352f.pdf) and a Co-Operation Procedure for Issuing Common Opinions on Adequate Safeguards Resulting From “Binding Corporate Rules” (at http://www.steptoe.com/publications/352g.pdf) – the EU Article 29 Data Protection Working Party set out procedures for approval of “binding corporate rules” (“BCRs”), adopted by a multinational company or other entity, that require compliance with the requirements of the Data Protection Directive and provide for redress by data subjects for violations of their data protection rights. The BCRs approach supplements the other three main options for transfer of personal data outside of the European Economic Area in accordance with Articles 25 and 26 of the Data Protection Directive. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9611&siteId=547
GUARDING INFORMATION (PublicCIO.com, May 2005) -- The United States loses billions of dollars every year to cyber-crimes, such as identify theft. Yet when it comes to developing a cadre of highly educated and trained cyber-security experts to combat this growing crime wave, we look the other way. Professor Eugene Spafford, executive director of the Center for Education and Research in Information Assurance and Security at Purdue University, points out that each year, fewer than 100 people graduate with a Ph.D. in cyber-security in the United States. Purdue, which has one of the largest graduate programs for information security in the country, issues only about 15 doctoral degrees in the field every year. Spafford, who also serves on the President’s Information Technology Advisory Committee (PITAC) and acts as security adviser to more than a dozen federal agencies and major corporations, believes strong cyber-security policies not only benefit information assurance and trust in cyber-space, but also can act as a bulwark against terrorist actions as well. But Spafford -- who chairs the U.S. Public Policy Committee of the Association for Computing Machinery, an agency that advises legislators and regulators about the impact of policy on computing technology and vice versa -- is worried about the ongoing lack of support for fighting this growing problem. He took time to speak with Government Technology’s Public CIO about his concerns, the nature of cyber-security, protecting information systems against intrusion and training security professionals.[interview then follows] http://www.public-cio.com/story.php?id=2005.04.28-93832
SUN MICROSYSTEMS TO DOUBLE INDIAN R&D STAFF (CNET, 6 May 2005) -- Sun Microsystems, which makes network computers and related software, said on Friday it would double the number of staff at its Indian engineering center to 2,000 over the next two to three years. Officials of U.S.-based Sun, which spends an annual $1.9 billion on research and development, said they would expand engineering centers in Russia, China, the Czech Republic and India, while holding back growth in the United States. Stephen Pelletier, senior vice-president of global engineering at Sun, told reporters at a news conference that India and China were important both for new software development and their high-growth economies that have yielded big customers. “You can say Sun software products are all made in India,” he said. “It is obviously cheaper to do business here. But we expect in the next five years the wages to converge more.” The U.S. engineering team is still the biggest for Sun, but the company’s current plans are to grow the R&D centers in Bangalore, Beijing, St. Petersburg and Prague, Pelletier said. The Beijing center is about half the size of the Indian one, which has grown five-fold from 200 staff about three years ago. Officials did not give staff sizes for the other centers. http://news.com.com/Sun+Microsystems+to+double+Indian+RD+staff/2100-1008_3-5698129.html?tag=nefd.top
MISSING BACKUP TAPES SPUR ENCRYPTION AT TIME WARNER (Computer World, 6 May 2005) -- Time Warner Inc. this week said it will “quickly” begin encrypting all data saved to backup tapes after 40 tapes with personal information on about 600,000 current and former employees were lost in transit to a storage facility. The incident is among the biggest in a string of recent data-security mishaps that have also affected companies such as ChoicePoint Inc., Bank of America Corp. and Reed Elsevier Group PLC’s LexisNexis Group unit. A shipping container that held the 40 data tapes was lost on March 22 during a routine shipment to an off-site facility by records management and storage firm Iron Mountain Inc., Time Warner spokeswoman Kathy McKiernan said. She wouldn’t provide more details. However, McKiernan did say Time Warner is trying to convince officials at Boston-based Iron Mountain to change some of their handling procedures. She declined to expand on the status of those discussions. The $42 billion New York-based media giant also said it has provided the affected employees with resources to monitor their credit reports. The lost tapes didn’t include data about Time Warner customers, the company said. http://www.computerworld.com/printthis/2005/0,4814,101589,00.html
-- and --
DATA-SECURITY LAWS SPROUT IN WAKE OF BREACHES (TechWeb, 13 May 2005) -- Laws at the federal and state levels are altering the landscape for sharing and protecting sensitive customer information, just as widely publicized breaches at companies like Bank of America, ChoicePoint, DSW Shoe Warehouse, and LexisNexis have focused attention on the problem of ID theft. Several states, including Arkansas, Georgia, Montana, and North Dakota, have implemented ID-theft laws patterned after a law in California, and many other states have legislation pending. Observers say a national ID-theft-protection bill also is likely to be enacted. In March several federal agencies--the Federal Reserve System, the Federal Deposit Insurance Corp., the Office of the Comptroller of the Currency, and the Office of Thrift Supervision--jointly issued the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. The guidelines state that financial institutions should implement a response program to address security breaches involving customer information, including procedures to notify customers about incidents of unauthorized access to customer information that could result in substantial harm or inconvenience to the customer. The guidelines also provide that when a financial institution becomes aware of an incident of unauthorized access to sensitive customer information, it should conduct a reasonable investigation to determine whether the information has been or will be misused. The interagency guidelines apply only to financial institutions or businesses that are regulated by the agencies that issued them. Morgan Stanley’s Discover Card division, for example, is covered, while its broker-dealer business isn’t, said Howard Lipper, executive director of the technology, intellectual property, and E-commerce group at Morgan Stanley. Lipper spoke at an information security session hosted by law firm Steptoe & Johnson in New York on Friday. The Securities and Exchange Commission, however, is likely to adopt the guidelines verbatim, Lipper said. Brokerage firms are likely to “face some very tough questions on information security practices during their next audit.” The Federal Trade Commission is likely to adopt many provisions of the interagency guidelines as it seeks to extend data-privacy protection across all industries. “The FTC wants to be the traffic cop on information security, but the problem is a traffic cop can’t be everywhere,” said Emily Hancock, an attorney in Steptoe & Johnson’s Washington office. She noted that California and Arkansas are the only states so far to have adopted provisions requiring both notification of breaches and “reasonable security” to prevent breaches. A patchwork of state and federal laws, each with different standards of notification, could raise the compliance costs without providing corresponding increases in data security, said Mark MacCarthy, senior VP of public policy at Visa U.S.A. “Simply passing a new bill isn’t going to make these things go away.” He suggested that market forces, such as the impact on a company’s reputation, would compel companies to adopt tighter security procedures. http://story.news.yahoo.com/news?tmpl=story&cid=74&e=2&u=/cmp/20050514/tc_cmp/163102113
PENTAGON CUT AND PASTE (Asia Times, 5 May 2005) -- Talk about rebel technology: the Pentagon this week was not overwhelmed by a dirty bomb or a jet converted into a missile, but by a simple cut and paste job. Like anyone else, the Pentagon uses Adobe Acrobat. At first, the 42 pages of the report which would supposedly shed some light on the March 4 killing of Italian secret agent Nicola Calipari and the wounding of kidnapped journalist Giuliana Sgrena in Baghdad showed up on the Centcom website as a PDF file heavily censored with large sections blacked out - including the significant omission, among others, of the names of all the soldiers involved in the shooting, as well as entire pages. But because the Pentagon failed to save the file properly, all it took was for someone to cut and paste the document into a word-processing application to give Italy and the rest of the world access to the full, uncensored version. http://atimes.com/atimes/Middle_East/GE05Ak04.html
USE OF TRADEMARKS IN INTERNET SEARCHES: GOOGLE CASES LEAD TO CONFLICTING RESULTS (Wilmer, Cutler analysis, 11 May 2005) -- Stemming from its AdWords program, Google Inc. has recently faced a spate of litigation in the United States and France. The AdWords program allows advertisers to bid on keywords, including trademarked terms, which result in the display of the advertisers’ sponsored links when users perform searches using the keywords. This controversial service has caused several companies to file lawsuits against Google. Examples of recent litigation, both foreign and domestic, as well as an overview of the company’s current trademark policies, are described ... (at http://www.wilmerhale.com/publications/whPubsDetail.aspx?id=b595a5af-cf02-4951-925b-234ca505623d)
ONLINE DATABASE WILL HOLD THE MIRROR UP TO ‘HAMLET,’ GATHERING EVERY COMMENTARY ON THE PLAY (Chronicle of Higher Education, 10 May 2005) -- More has been written about Hamlet than about any other Shakespeare play, and attitudes toward the work’s main character have shifted over time, says Eric C. Rasmussen, a professor of English at the University of Nevada at Reno. “Victorians saw Hamlet as a wilted wallflower, but in the 60s he was sort of the prototypical angry young man,” says Mr. Rasmussen, who is also the university’s director of graduate studies. “The way people think about Hamlet seems to be a mirror for the way we view our current cultural moment.” Mr. Rasmussen should know. He has spent the past 10 years working with a team of scholars to compile every piece of scholarship and criticism about the play, and then to link it, line by line, to the text in an online database. The mammoth project, supported by some $1-million in grants from the National Endowment for the Humanities, is nearing completion -- although editors plan to add to it as they find more material. “If you are interested in a particular line of the play, to be able to see 400 years’ worth of commentary on that line is pretty remarkable,” he says. About half of the group’s work is available on a free Web site. But readers won’t find commentary for most of the play’s most famous lines yet, because notes for the first half of the script have not yet been uploaded. The scholars hope to have notes for all 3,474 lines up in the next few months, at which point visitors can better discover the meaning of “To be, or not to be,” among other passages. http://chronicle.com/free/2005/05/2005051001t.htm
GILLETTE REPORTEDLY DELETED E-MAIL EVIDENCE (Messaging Pipeline, 12 May 2005) -- In what is apparently another incident of intentional e-mail destruction, Proofpoint reported today that Gillette has disclosed in a filing in Massachusetts Superior Court that senior executives may have deleted e-mails that are subject to a subpoena from Massachusetts Secretary of State William F. Galvin. It was reported in the Boston Globe and the Cincinnatti Business Courier that the company is currently under investigation regarding shareholder allegations that Gillette may have sold out to Procter & Gamble at an unacceptably low price. Galvin has called the incident an embarrassing “dog ate my homework” defense because e-mails at the company are saved on multiple machines. Normal backup mechanisms in large corporations generally make complete deletion very difficult. In a comment on the incident, Proofpoint notes that while 74.4 percent of surveyed large corporations have adopted formal e-mail retention policies, only 18.1 percent have deployed technology to enforce such policies. http://www.messagingpipeline.com/news/163101470;jsessionid=KL3XYTWANPZDWQSNDBGCKHSCJUMEKJVN
IBM BACKS FIREFOX IN-HOUSE (CNET, 13 May 2005) -- IBM is encouraging its employees to use Firefox, aiding the open-source Web browser’s quest to chip away at Microsoft’s Internet Explorer. Firefox is already used by about 10 percent of IBM’s staff, or about 30,000 people. Starting Friday, IBM workers can download the browser from internal servers and get support from the company’s help desk staff. IBM’s commitment to Firefox is among its most prominent votes of confidence from a large corporation. Based on development work by the nonprofit Mozilla Foundation, Firefox has been downloaded by more than 50 million people since it debuted in November. Internet Explorer still dominates the overall market by far, though, with Firefox’s share in the single digits. For IBM, the move is a significant step in lessening dependence on a product from rival Microsoft. By supporting Firefox internally, IBM is also furthering its commitment to open-source products based on industry standards, said Brian Truskowski, chief information officer at IBM. “This is a real good example of walking the talk when it comes it comes to open standards and open source,” Truskowski said. http://news.com.com/IBM+backs+Firefox+in-house/2100-7344_3-5704750.html?tag=nefd.top
LAWYER VS. LAWYER OVER WEB SITE (ABA Journal, 13 May 2005) -- One New York personal injury law firm is suing another personal injury firm in the state, alleging a Web site noting a state bar panel’s probe of the first firm violates the state’s civil rights act. According to the lawsuit, the firm Moran & Kufta of Rochester posted a headline with a hyperlink on its Web site that told readers that Cellino & Barnes, with offices in Buffalo and Rochester, was being investigated by the New York State Bar Association grievance committee. The headline in question was part of the “Hot Topics” portion of Moran & Kufta’s Web site. It referred readers to a March 11 story in The Buffalo News, “Cellino & Barnes Investigated,” and added: “State Court to Rule on Complaints by Former Clients.” That Web site has since been taken down. On April 18, Cellino & Barnes filed suit in the Supreme Court of New York in Erie County. The suit named James J. Moran and the law firm as defendants, and alleges Moran & Kufta violated section 50 of the New York Civil Rights Law. That law provides in part: “A person, firm or corporation that uses for advertising purposes, or for the purposes of trade, the name, portrait or picture of any living person without having first obtained the written consent of such person … is guilty of a misdemeanor.” http://www.abanet.org/journal/ereport/my13publish.html
TRADEMARKS BLINDSIDE GOOGLE (Steptoe & Johnson’s E-Commerce Law Week, 14 May 2005) -- Search engines make a remarkable amount of money selling ads that are triggered by the search terms you enter. Type in “American music” and Google serves you an ad for allcoolmusic.com. Type in “American clothes” and Google serves you an ad for unionwear.com. Type in “American blinds” and Google, well, Google gets served with a lawsuit. That’s because there’s a company called American Blind & Wallpaper Factory, which claims that its trademarked name allows it to prevent the use of “American blinds” as a trigger for ads for any other company. This is a controversial claim, to say the least, but it has proven surprisingly strong in the courts. The most recent court to buy into the cause of trademark maximalism, at least preliminarily, is the US District Court for the Northern District of California, which denied Google’s motion to dismiss American Blind’s trademark counterclaims. The court found that when search engines use a trademarked name to trigger ads for competing companies, the search engines have used the trademark in commerce, a use that supports a claim of trademark infringement. This is bad news for search engines and consumers but good news for companies with aggressive trademark programs. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9712&siteId=547
NEW YORK TIMES TO CHARGE FOR ARCHIVES, EDITORIALS (Reuters, 16 May 2005) -- The New York Times Co. on Monday said it plans to charge for some of its editorial columns and its archive of stories online to boost subscription sales, even as it invests in its free service. The New York-based publisher of the namesake newspaper and The Boston Globe said the new product, TimeSelect, will debut in September and cost $49.95 for an annual subscription. The company said most of its stories will still be available online for free. TimeSelect underscores the paper’s push to create more Web products, both free and for a fee, to offset an uncertain advertising market for its print newspapers. The New York Times purchased Web site About.com for about $410 million earlier this year to increase its online advertising inventory. The paper’s print subscribers will have free access to the paper’s columnists online, including those written by Times staffers and International Herald Tribune writers. TimeSelect will also give subscribers access to its archives dating back initially to 1980. The company plans to eventually extend its archives back to the 1850s, a spokesman said. http://story.news.yahoo.com/news?tmpl=story&cid=582&e=4&u=/nm/20050516/wr_nm/media_newyorktimes_dc
CARDS LET METRO COLLECT DATA ON RIDERS, TRACK TRIPS (Washington Times, 17 May 2005) -- Metro’s SmarTrip fare cards allow the transit agency to monitor passengers’ travel with little regard for privacy concerns, a group focused on privacy issues says. The SmarTrip fare card, which includes an embedded radio frequency identification (RFID) chip, tracks each rider’s travel and can be matched with the rider’s name, address and credit-card number, according to the District-based nonprofit Electronic Privacy Information Center (EPIC). “Our basic point is that there is a lot of detailed information being collected,” said Marc Rotenberg, executive director of EPIC, a public-interest group established in 1994 to focus attention on emerging threats to civil liberties. “The privacy protections, in our opinion, are inadequate.” http://washingtontimes.com/metro/20050517-120301-3752r.htm
IS YOUR BOSS MONITORING YOUR E-MAIL? (CNET, 18 May 2005) -- If you’re working for a U.S. company, there’s a good chance you’re being watched--and you may get fired for how you use your computer or office phone. That’s the gist of a study on electronic monitoring and surveillance released Wednesday by the American Management Association and the ePolicy Institute. The report found that companies increasingly are “putting teeth in technology policies.” About a quarter of employers have fired workers for misusing the Internet; another 25 percent have terminated employees for e-mail misuse; and 6 percent have fired employees for misusing office telephones, according to the report. “Concern over litigation and the role electronic evidence plays in lawsuits and regulatory investigations has spurred more employers to implement electronic technology policies,” Nancy Flynn, executive director of the ePolicy Institute, said in a statement. Although liability and regulatory issues may be convincing companies to peek in on their employees, such surveillance raises privacy concerns. Employers can monitor workers to a greater degree these days, thanks to newer technologies such as keystroke-logging software and satellite global positioning systems that can track a cell phone user’s whereabouts. The survey, which involved 526 U.S. companies, found that 5 percent use GPS technology to monitor cell phones and 8 percent use GPS to track company vehicles. About 75 percent of companies monitor workers’ Web site connections, and 65 percent use software to block connections to inappropriate Web sites. Computer monitoring takes various forms, according to the study, with 36 percent of employers tracking “content, keystrokes and time spent at the keyboard.” Another 50 percent of companies store and review employees’ computer files, according to the report. http://news.com.com/Is+your+boss+monitoring+your+e-mail/2100-1032_3-5712677.html?tag=nefd.top
PERSONAL DATA FOR THE TAKING (New York Times, 18 May 2005) – Senator Ted Stevens wanted to know just how much the Internet had turned private lives into open books. So the senator, a Republican from Alaska and the chairman of the Senate Commerce Committee, instructed his staff to steal his identity. “I regret to say they were successful,” the senator reported at a hearing he held last week on data theft. His staff, Mr. Stevens reported, had come back not just with digital breadcrumbs on the senator, but also with insights on his daughter’s rental property and some of the comings and goings of his son, a student in California. “For $65 they were told they could get my Social Security number,” he said. That would not surprise 41 graduate students in a computer security course at Johns Hopkins University. With less money than that, they became mini-data-brokers themselves over the last semester. They proved what privacy advocates have been saying for years and what Senator Stevens recently learned: all it takes to obtain reams of personal data is Internet access, a few dollars and some spare time. Working with a strict requirement to use only legal, public sources of information, groups of three to four students set out to vacuum up not just tidbits on citizens of Baltimore, but whole databases: death records, property tax information, campaign donations, occupational license registries. They then cleaned and linked the databases they had collected, making it possible to enter a single name and generate multiple layers of information on individuals. Each group could spend no more than $50. http://www.nytimes.com/2005/05/18/technology/18data.html?ex=1274068800&en=2e20e8def94eb234&ei=5090&partner=rssuserland&emc=rss
PLAN WOULD BROADEN F.B.I.’S TERROR ROLE (New York Times, 19 May 2005) -- The Bush administration and Senate Republican leaders are pushing a plan that would significantly expand the F.B.I.’s power to demand business records in terror investigations without obtaining approval from a judge, officials said on Wednesday. The proposal, which is likely to be considered next week in a closed session of the Senate intelligence committee, would allow federal investigators to subpoena records from businesses and other institutions without a judge’s sign-off if they declared that the material was needed as part of a foreign intelligence investigation. The proposal, part of a broader plan to extend antiterrorism powers under the law known as the USA Patriot Act, was concluded in recent days by Republican leaders on the Senate Select Committee on Intelligence in consultation with the Bush administration, Congressional officials said. Administration and Congressional officials who support the idea said the proposal would give the F.B.I. a much-needed tool to track leads in terrorism and espionage investigations that would be quicker and less cumbersome than existing methods. They pointed out that the administrative subpoena power being sought for the F.B.I. in terror cases was already in use in more than 300 other types of crimes, including health care fraud, child exploitation, racketeering and drug trafficking. http://www.nytimes.com/2005/05/19/politics/19terror.html?ex=1274155200&en=f6615ca026642d9a&ei=5090&partner=rssuserland&emc=rss
US TECH CO’S WANT CLICKWRAPS OUT OF HAGUE CONVENTION (BNA’s Internet Law News, 19 May 2005) -- BNA’s Electronic Commerce & Law Report reports that U.S. ISPs and other technology companies have urged State Department negotiators to exclude “clickwrap” agreements from the Draft Hague Convention on Exclusive Choice of Court Provisions in B2B Agreements. Negotiators are set to meet next month at the Hague Conference on Private International Law to discuss the convention. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b0w5h0d9
ISRAELI COURT RULES DIRECTORS HAVE COPYRIGHT IN THEIR MOVIES (BNA’s Internet Law News, 19 May 2005) -- After a protracted five-year legal battle, the Tel Aviv District Court recently ruled that directors have copyrights to movies they have directed, as they have contributed their creativity to the productions. This is viewed as a landmark decision because until now no court had ruled on the question of directors’ copyrights to their works. http://www.haaretzdaily.com/hasen/spages/577805.html
**** RESOURCES ****
A RARE NEWSBITES BOOK REVIEW: SILENCE ON THE WIRE (SANS NewsBytes, 27 April 2005) -- We rarely do book reviews, but this is an extraordinary collection of information on passive reconnaissance and the publisher is fairly unknown, so if we didn’t bring “Silence on the wire” to your attention it might get missed. If you are involved in information warfare, or in charge of security at an organization with high value assets you should be aware of this book: http://www.amazon.com/exec/obidos/tg/detail/-/1593270461/qid=1114558699/sr=8-1/ref=pd_csp_1/103-9311674-6721424?v=glance&s=books&n=507846
SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.
PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.
MIRLN (Misc. IT Related Legal News) is a free product of the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.
Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.
Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.
**************End of Introductory Note***************
FRENCH DATA PROTECTION AUTHORITY ALLOWS SOFTWARE DEVELOPERS TO MONITOR P2P NETWORKS (DM Europe, 18 April 2005) -- The French data protection authority has announced that it is to allow the Syndicat des Editeurs de Logiciels de Loisi (SELL) - the French software developers’ trade association - to monitor data traffic over peer-to-peer file-sharing networks. The Commission nationale de l’informatique et des libertés (CNIL) has permitted SELL to send warning messages to users uploading illegally copied software and then locate and use the IP addresses of such individuals in legal proceedings. http://www.dmeurope.com/default.asp?ArticleID=7370
E-COMMERCE SITES FORCED TO ADOPT SECURITY STANDARDS (Ecommerce Times, 23 April 2005) -- Online retailers will be forced to tighten security and improve their handling of customer data under new rules being introduced by the credit card industry to stop identity theft. From June 30, all e-commerce sites with internal systems that process, store or transmit cardholder information will have to comply with the Payment Card Industry (PCI) Data Security Standard or face significant fines. In extreme cases, online merchants could be banned from processing transactions using payment cards. Backed by MasterCard, Visa, American Express (NYSE: AXP) Latest News about American Express, Diners Club and JCB Cards, the standard requires Internet retailers to carry out a 12-step security audit, which will be certified annually and checked every three months. http://www.ecommercetimes.com/story/ebiz/42479.html
-- and --
SOVEREIGN BLAMES RETAILER IN ID THEFT SCAM (Philadelphia Business Journal, 11 Feb 2005) -- Sovereign Bank is trying to blame BJ’s Wholesale Club Inc. in an identity theft scheme that victimized hundreds of the bank’s debit cardholders last year. The bank said last June that a computer hacker had stolen account information from at least 700 debit card customers and that it was forced to reissue 80,000 new debit cards. But it offered no other details at the time. But in January, Sovereign filed a civil lawsuit in Berks County Court of Common Pleas saying the account information was stolen from BJ’s after bank customers made purchases from the retailer, which has its headquarters in Natick, Mass. In its lawsuit, Sovereign said that under rules established by Visa, which issued the Sovereign cards, BJ’s was supposed to delete cardholder information from its computers after the transaction was complete. http://philadelphia.bizjournals.com/philadelphia/stories/2005/02/14/story4.html?t=printable%5BEditor’s
FEDS RETHINKING RFID PASSPORT (Wired, 26 April 2005) -- Following criticism from computer security professionals and civil libertarians about the privacy risks posed by new RFID passports the government plans to begin issuing, a State Department official said his office is reconsidering a privacy solution it rejected earlier that would help protect passport holders’ data. The solution would require an RFID reader to provide a key or password before it could read data embedded on an RFID passport’s chip. It would also encrypt data as it’s transmitted from the chip to a reader so that no one could read the data if they intercepted it in transit. Frank Moss, deputy assistant secretary for passport services, told Wired News on Monday that the government was “taking a very serious look” at the privacy solution in light of the 2,400-plus comments the department received about the e-passport rule and concerns expressed last week in Seattle by participants at the Computers, Freedom and Privacy conference. Moss said recent work on the passports conducted with the National Institute of Standards and Technology had also led him to rethink the issue. “Basically what changed my mind was a recognition that the (reading distance) may have actually been able to be more than 10 centimeters, and also recognition that we had to do everything possible to protect the security of people,” Moss said. http://www.wired.com/news/privacy/0,1848,67333,00.html
MICROSOFT TO ADD ‘BLACK BOX’ TO WINDOWS (CNET, 26 April 2005) -- In a move that could rankle privacy advocates, Microsoft said Monday that it is adding the PC equivalent of a flight data recorder to the next version of Windows, in an effort to better understand and prevent computer crashes. The tool will build on the existing Watson error-reporting tool in Windows but will provide Microsoft with much deeper information, including what programs were running at the time of the error and even the contents of documents that were being created. Businesses will also choose whether they want their own technology managers to receive such data when an employee’s machine crashes. “Think of it as a flight data recorder, so that any time there’s a problem, that ‘black box’ is there helping us work together and diagnose what’s going on,” Microsoft Chairman Bill Gates said during a speech at the Windows Hardware Engineering Conference here. For consumers, the choice of whether to send the data, and how much information to share, will be up to the individual. Though the details are being finalized, Windows lead product manager Greg Sullivan said users will be prompted with a message indicating the information to be sent and giving them an option to alter it, such as removing the contents of the e-mail they were writing when the machine crashed. Also, such reporting will also be anonymous. With businesses, however, IT managers typically set the policy. If they wanted total information, they could configure systems so that they’d know not only that a user was running Internet Explorer, for example, but also that he or she was watching a video from ESPN.com. Or, they might find out not only that a worker was running Instant Messenger but also that he or she was talking to a co-worker about getting a new job. And consumers could have a tough time knowing just what information they were sending. Though they’ll be able to see the contents of a document, they may not recognize the significance of the technical data--such as register settings--that’s being sent. http://news.com.com/2100-1016_3-5684051.html
GROUP WANTS ENCRYPTION BANS OVERTURNED (CNET, 27 April 2005) -- An international security consortium plans to push governments around the world to withdraw restrictions on the use of encryption. Countries including China, Israel, Russia and Saudi Arabia have strict rules governing the use of encryption tools, and in some cases they have banned these tools. The Jericho Forum, which is looking to move away from the perimeter model for cybersecurity toward an approach that would make data totally secure, hinted that such policies could cause problems for e-commerce. The Jericho Forum, whose membership includes many chief security officers from FTSE 100 companies, will push for the removal of encryption restrictions within the next three to five years. http://news.com.com/2100-7348_3-5687087.html
SPIDERS CAN ENTER CONTRACTS TOO! (Steptoe & Johnson’s E-Commerce Law Week, 28 April 2005) -- It wouldn’t be unheard-of for a web surfer to accept the terms of a Terms of Use or “click-through” agreement without actually reading it ... and then for a court to hold him to the terms of that agreement. So is there a difference if his automated software tool does the “clicking” -- also without actually reading the agreement? Not according to the US District Court for the Northern District of California. In Cairo, Inc. v. CrossMedia Services, Inc., the court held that automated software tools called “spiders” can legally consent to the terms of use or terms of service agreements on websites they visit -- thereby committing their operators to the terms of those agreements and subjecting them to liability for violations. (The case breaks new legal ground, but the court designates its opinion as “unpublished,” which usually means that the ruling has little or no precedential impact. In this case, it may mean that the court lacks confidence in its judgment -- or simply that no one has yet asked the court to publish the opinion.) http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9512&siteId=547
WIRETAPS IN U.S. JUMP 19 PERCENT IN 2004 (SFgate.com, 28 April 2005) -- The number of court-authorized wiretaps jumped 19 percent last year as investigators pursued drug and other cases against increasingly tech-savvy suspects. Every surveillance request made by authorities was granted. Federal and state judges approved 1,710 applications for wiretaps of wire, oral or electronic communications last year, and four states — New York, California, New Jersey and Florida — accounted for three of every four surveillance orders, according to the Administrative Office of the U.S. Courts. That agency is required to collect the figures and report them to Congress. The numbers, released Thursday, do not include court orders for terror-related investigations under the Foreign Intelligence Surveillance Act, known as FISA, which reached a record 1,754 warrants last year, according to the Justice Department. In non-terrorist criminal investigations, federally approved wiretaps increased 26 percent in a year, to 730 applications, while state judges approved 980 wiretaps, an increase of 13 percent. Department of Justice spokesman Kevin Madden said the numbers reflect “an increase in the resources geared toward targeting very serious federal and state offenses for which electronic surveillance is often the most, and sometimes the only, effective investigative method.” Timothy Edgar, legislative counsel for the American Civil Liberties Union, said traditional law enforcement work is catching up with increases in anti-terror wiretaps. “We’re still seeing a huge trend toward increased surveillance,” said Edgar. http://www.sfgate.com/cgi-bin/article.cgi?file=/news/archive/2005/04/28/national/a082547D09.DTL
U.S. CRITICIZES WORLD IN SPECIAL 301 IP REPORT (BNA’s Internet Law News, 3 May 2005) -- The U.S. Trade Representative has released its annual Special 301 report on the IP policies of countries from around the world. A long list of countries face criticism - for example, Canada is criticized for its proposed copyright reform, India and Israel on pharmaceuticals, and Taiwan for lack of enforcement. Special 301 report at http://www.ustr.gov/Document_Library/Reports_Publications/2005/2005_Special_301/Section_Index.html
Canadian report at http://www.michaelgeist.ca/home.php#396
Taiwan report at http://www.chinapost.com.tw/detail.asp?ID=61808&GRP=A
India report at http://www.hindustantimes.com/news/181_1343386,0002.htm
Israel report at http://www.globes.co.il/serveen/globes/docview.asp?did=909133&fid=942
YOUR IDENTITY, OPEN TO ALL (Wired, 6 May 2005) -- A search for personal data on ZabaSearch.com -- one of the most comprehensive personal-data search engines on the net -- tends to elicit one of two reactions from first-timers: terror or curiosity. Which reaction often depends on whether you are searching for someone else’s data, or your own. ZabaSearch queries return a wealth of info sometimes dating back more than 10 years: residential addresses, phone numbers both listed and unlisted, birth year, even satellite photos of people’s homes. ZabaSearch isn’t the first or only such service online. Yahoo’s free People Search, for example, returns names, telephone numbers and addresses. But the information is nothing more than what’s been available for years in the White Pages. Far more personal information is available from data brokers, including aliases, bankruptcy records and tax liens. That access typically requires a fee, however, which has always been a barrier to the casual snooper. But ZabaSearch makes it easier than ever to find comprehensive personal information on anyone. ZabaSearch may give away some data for free, but it charges for additional information -- like background checks and criminal history reports, which may or may not be accurate. The company also plans to sell ads and other services on the search site, much like Google or Yahoo. http://www.wired.com/news/privacy/0,1848,67407,00.html
EU CLARIFIES “FOURTH WAY” FOR FOREIGN DATA TRANSFERS (Steptoe & Johnson’s E-Commerce Law Week, 7 May 2005) -- Global companies trying to cope with Europe’s data protection laws have traditionally had three options if they wanted to move personal information out of Europe. They could get the consent of everyone whose data would be moved. They could execute a web of agreements among the receiving and sending companies, essentially guaranteeing that European protections would follow European data. Or they could move the data only to the handful of countries whose data protection laws had been approved by European authorities – Argentina, Canada, Guernsey, Isle of Man and Switzerland – and the US, at least for companies that have joined the US-EU Safe Harbor. Now there’s a fourth way. In a pair of documents issued in mid-April – a Model Checklist for Approval of Binding Corporate Rules (at http://www.steptoe.com/publications/352f.pdf) and a Co-Operation Procedure for Issuing Common Opinions on Adequate Safeguards Resulting From “Binding Corporate Rules” (at http://www.steptoe.com/publications/352g.pdf) – the EU Article 29 Data Protection Working Party set out procedures for approval of “binding corporate rules” (“BCRs”), adopted by a multinational company or other entity, that require compliance with the requirements of the Data Protection Directive and provide for redress by data subjects for violations of their data protection rights. The BCRs approach supplements the other three main options for transfer of personal data outside of the European Economic Area in accordance with Articles 25 and 26 of the Data Protection Directive. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9611&siteId=547
GUARDING INFORMATION (PublicCIO.com, May 2005) -- The United States loses billions of dollars every year to cyber-crimes, such as identify theft. Yet when it comes to developing a cadre of highly educated and trained cyber-security experts to combat this growing crime wave, we look the other way. Professor Eugene Spafford, executive director of the Center for Education and Research in Information Assurance and Security at Purdue University, points out that each year, fewer than 100 people graduate with a Ph.D. in cyber-security in the United States. Purdue, which has one of the largest graduate programs for information security in the country, issues only about 15 doctoral degrees in the field every year. Spafford, who also serves on the President’s Information Technology Advisory Committee (PITAC) and acts as security adviser to more than a dozen federal agencies and major corporations, believes strong cyber-security policies not only benefit information assurance and trust in cyber-space, but also can act as a bulwark against terrorist actions as well. But Spafford -- who chairs the U.S. Public Policy Committee of the Association for Computing Machinery, an agency that advises legislators and regulators about the impact of policy on computing technology and vice versa -- is worried about the ongoing lack of support for fighting this growing problem. He took time to speak with Government Technology’s Public CIO about his concerns, the nature of cyber-security, protecting information systems against intrusion and training security professionals.[interview then follows] http://www.public-cio.com/story.php?id=2005.04.28-93832
SUN MICROSYSTEMS TO DOUBLE INDIAN R&D STAFF (CNET, 6 May 2005) -- Sun Microsystems, which makes network computers and related software, said on Friday it would double the number of staff at its Indian engineering center to 2,000 over the next two to three years. Officials of U.S.-based Sun, which spends an annual $1.9 billion on research and development, said they would expand engineering centers in Russia, China, the Czech Republic and India, while holding back growth in the United States. Stephen Pelletier, senior vice-president of global engineering at Sun, told reporters at a news conference that India and China were important both for new software development and their high-growth economies that have yielded big customers. “You can say Sun software products are all made in India,” he said. “It is obviously cheaper to do business here. But we expect in the next five years the wages to converge more.” The U.S. engineering team is still the biggest for Sun, but the company’s current plans are to grow the R&D centers in Bangalore, Beijing, St. Petersburg and Prague, Pelletier said. The Beijing center is about half the size of the Indian one, which has grown five-fold from 200 staff about three years ago. Officials did not give staff sizes for the other centers. http://news.com.com/Sun+Microsystems+to+double+Indian+RD+staff/2100-1008_3-5698129.html?tag=nefd.top
MISSING BACKUP TAPES SPUR ENCRYPTION AT TIME WARNER (Computer World, 6 May 2005) -- Time Warner Inc. this week said it will “quickly” begin encrypting all data saved to backup tapes after 40 tapes with personal information on about 600,000 current and former employees were lost in transit to a storage facility. The incident is among the biggest in a string of recent data-security mishaps that have also affected companies such as ChoicePoint Inc., Bank of America Corp. and Reed Elsevier Group PLC’s LexisNexis Group unit. A shipping container that held the 40 data tapes was lost on March 22 during a routine shipment to an off-site facility by records management and storage firm Iron Mountain Inc., Time Warner spokeswoman Kathy McKiernan said. She wouldn’t provide more details. However, McKiernan did say Time Warner is trying to convince officials at Boston-based Iron Mountain to change some of their handling procedures. She declined to expand on the status of those discussions. The $42 billion New York-based media giant also said it has provided the affected employees with resources to monitor their credit reports. The lost tapes didn’t include data about Time Warner customers, the company said. http://www.computerworld.com/printthis/2005/0,4814,101589,00.html
-- and --
DATA-SECURITY LAWS SPROUT IN WAKE OF BREACHES (TechWeb, 13 May 2005) -- Laws at the federal and state levels are altering the landscape for sharing and protecting sensitive customer information, just as widely publicized breaches at companies like Bank of America, ChoicePoint, DSW Shoe Warehouse, and LexisNexis have focused attention on the problem of ID theft. Several states, including Arkansas, Georgia, Montana, and North Dakota, have implemented ID-theft laws patterned after a law in California, and many other states have legislation pending. Observers say a national ID-theft-protection bill also is likely to be enacted. In March several federal agencies--the Federal Reserve System, the Federal Deposit Insurance Corp., the Office of the Comptroller of the Currency, and the Office of Thrift Supervision--jointly issued the Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice. The guidelines state that financial institutions should implement a response program to address security breaches involving customer information, including procedures to notify customers about incidents of unauthorized access to customer information that could result in substantial harm or inconvenience to the customer. The guidelines also provide that when a financial institution becomes aware of an incident of unauthorized access to sensitive customer information, it should conduct a reasonable investigation to determine whether the information has been or will be misused. The interagency guidelines apply only to financial institutions or businesses that are regulated by the agencies that issued them. Morgan Stanley’s Discover Card division, for example, is covered, while its broker-dealer business isn’t, said Howard Lipper, executive director of the technology, intellectual property, and E-commerce group at Morgan Stanley. Lipper spoke at an information security session hosted by law firm Steptoe & Johnson in New York on Friday. The Securities and Exchange Commission, however, is likely to adopt the guidelines verbatim, Lipper said. Brokerage firms are likely to “face some very tough questions on information security practices during their next audit.” The Federal Trade Commission is likely to adopt many provisions of the interagency guidelines as it seeks to extend data-privacy protection across all industries. “The FTC wants to be the traffic cop on information security, but the problem is a traffic cop can’t be everywhere,” said Emily Hancock, an attorney in Steptoe & Johnson’s Washington office. She noted that California and Arkansas are the only states so far to have adopted provisions requiring both notification of breaches and “reasonable security” to prevent breaches. A patchwork of state and federal laws, each with different standards of notification, could raise the compliance costs without providing corresponding increases in data security, said Mark MacCarthy, senior VP of public policy at Visa U.S.A. “Simply passing a new bill isn’t going to make these things go away.” He suggested that market forces, such as the impact on a company’s reputation, would compel companies to adopt tighter security procedures. http://story.news.yahoo.com/news?tmpl=story&cid=74&e=2&u=/cmp/20050514/tc_cmp/163102113
PENTAGON CUT AND PASTE (Asia Times, 5 May 2005) -- Talk about rebel technology: the Pentagon this week was not overwhelmed by a dirty bomb or a jet converted into a missile, but by a simple cut and paste job. Like anyone else, the Pentagon uses Adobe Acrobat. At first, the 42 pages of the report which would supposedly shed some light on the March 4 killing of Italian secret agent Nicola Calipari and the wounding of kidnapped journalist Giuliana Sgrena in Baghdad showed up on the Centcom website as a PDF file heavily censored with large sections blacked out - including the significant omission, among others, of the names of all the soldiers involved in the shooting, as well as entire pages. But because the Pentagon failed to save the file properly, all it took was for someone to cut and paste the document into a word-processing application to give Italy and the rest of the world access to the full, uncensored version. http://atimes.com/atimes/Middle_East/GE05Ak04.html
USE OF TRADEMARKS IN INTERNET SEARCHES: GOOGLE CASES LEAD TO CONFLICTING RESULTS (Wilmer, Cutler analysis, 11 May 2005) -- Stemming from its AdWords program, Google Inc. has recently faced a spate of litigation in the United States and France. The AdWords program allows advertisers to bid on keywords, including trademarked terms, which result in the display of the advertisers’ sponsored links when users perform searches using the keywords. This controversial service has caused several companies to file lawsuits against Google. Examples of recent litigation, both foreign and domestic, as well as an overview of the company’s current trademark policies, are described ... (at http://www.wilmerhale.com/publications/whPubsDetail.aspx?id=b595a5af-cf02-4951-925b-234ca505623d)
ONLINE DATABASE WILL HOLD THE MIRROR UP TO ‘HAMLET,’ GATHERING EVERY COMMENTARY ON THE PLAY (Chronicle of Higher Education, 10 May 2005) -- More has been written about Hamlet than about any other Shakespeare play, and attitudes toward the work’s main character have shifted over time, says Eric C. Rasmussen, a professor of English at the University of Nevada at Reno. “Victorians saw Hamlet as a wilted wallflower, but in the 60s he was sort of the prototypical angry young man,” says Mr. Rasmussen, who is also the university’s director of graduate studies. “The way people think about Hamlet seems to be a mirror for the way we view our current cultural moment.” Mr. Rasmussen should know. He has spent the past 10 years working with a team of scholars to compile every piece of scholarship and criticism about the play, and then to link it, line by line, to the text in an online database. The mammoth project, supported by some $1-million in grants from the National Endowment for the Humanities, is nearing completion -- although editors plan to add to it as they find more material. “If you are interested in a particular line of the play, to be able to see 400 years’ worth of commentary on that line is pretty remarkable,” he says. About half of the group’s work is available on a free Web site. But readers won’t find commentary for most of the play’s most famous lines yet, because notes for the first half of the script have not yet been uploaded. The scholars hope to have notes for all 3,474 lines up in the next few months, at which point visitors can better discover the meaning of “To be, or not to be,” among other passages. http://chronicle.com/free/2005/05/2005051001t.htm
GILLETTE REPORTEDLY DELETED E-MAIL EVIDENCE (Messaging Pipeline, 12 May 2005) -- In what is apparently another incident of intentional e-mail destruction, Proofpoint reported today that Gillette has disclosed in a filing in Massachusetts Superior Court that senior executives may have deleted e-mails that are subject to a subpoena from Massachusetts Secretary of State William F. Galvin. It was reported in the Boston Globe and the Cincinnatti Business Courier that the company is currently under investigation regarding shareholder allegations that Gillette may have sold out to Procter & Gamble at an unacceptably low price. Galvin has called the incident an embarrassing “dog ate my homework” defense because e-mails at the company are saved on multiple machines. Normal backup mechanisms in large corporations generally make complete deletion very difficult. In a comment on the incident, Proofpoint notes that while 74.4 percent of surveyed large corporations have adopted formal e-mail retention policies, only 18.1 percent have deployed technology to enforce such policies. http://www.messagingpipeline.com/news/163101470;jsessionid=KL3XYTWANPZDWQSNDBGCKHSCJUMEKJVN
IBM BACKS FIREFOX IN-HOUSE (CNET, 13 May 2005) -- IBM is encouraging its employees to use Firefox, aiding the open-source Web browser’s quest to chip away at Microsoft’s Internet Explorer. Firefox is already used by about 10 percent of IBM’s staff, or about 30,000 people. Starting Friday, IBM workers can download the browser from internal servers and get support from the company’s help desk staff. IBM’s commitment to Firefox is among its most prominent votes of confidence from a large corporation. Based on development work by the nonprofit Mozilla Foundation, Firefox has been downloaded by more than 50 million people since it debuted in November. Internet Explorer still dominates the overall market by far, though, with Firefox’s share in the single digits. For IBM, the move is a significant step in lessening dependence on a product from rival Microsoft. By supporting Firefox internally, IBM is also furthering its commitment to open-source products based on industry standards, said Brian Truskowski, chief information officer at IBM. “This is a real good example of walking the talk when it comes it comes to open standards and open source,” Truskowski said. http://news.com.com/IBM+backs+Firefox+in-house/2100-7344_3-5704750.html?tag=nefd.top
LAWYER VS. LAWYER OVER WEB SITE (ABA Journal, 13 May 2005) -- One New York personal injury law firm is suing another personal injury firm in the state, alleging a Web site noting a state bar panel’s probe of the first firm violates the state’s civil rights act. According to the lawsuit, the firm Moran & Kufta of Rochester posted a headline with a hyperlink on its Web site that told readers that Cellino & Barnes, with offices in Buffalo and Rochester, was being investigated by the New York State Bar Association grievance committee. The headline in question was part of the “Hot Topics” portion of Moran & Kufta’s Web site. It referred readers to a March 11 story in The Buffalo News, “Cellino & Barnes Investigated,” and added: “State Court to Rule on Complaints by Former Clients.” That Web site has since been taken down. On April 18, Cellino & Barnes filed suit in the Supreme Court of New York in Erie County. The suit named James J. Moran and the law firm as defendants, and alleges Moran & Kufta violated section 50 of the New York Civil Rights Law. That law provides in part: “A person, firm or corporation that uses for advertising purposes, or for the purposes of trade, the name, portrait or picture of any living person without having first obtained the written consent of such person … is guilty of a misdemeanor.” http://www.abanet.org/journal/ereport/my13publish.html
TRADEMARKS BLINDSIDE GOOGLE (Steptoe & Johnson’s E-Commerce Law Week, 14 May 2005) -- Search engines make a remarkable amount of money selling ads that are triggered by the search terms you enter. Type in “American music” and Google serves you an ad for allcoolmusic.com. Type in “American clothes” and Google serves you an ad for unionwear.com. Type in “American blinds” and Google, well, Google gets served with a lawsuit. That’s because there’s a company called American Blind & Wallpaper Factory, which claims that its trademarked name allows it to prevent the use of “American blinds” as a trigger for ads for any other company. This is a controversial claim, to say the least, but it has proven surprisingly strong in the courts. The most recent court to buy into the cause of trademark maximalism, at least preliminarily, is the US District Court for the Northern District of California, which denied Google’s motion to dismiss American Blind’s trademark counterclaims. The court found that when search engines use a trademarked name to trigger ads for competing companies, the search engines have used the trademark in commerce, a use that supports a claim of trademark infringement. This is bad news for search engines and consumers but good news for companies with aggressive trademark programs. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=9712&siteId=547
NEW YORK TIMES TO CHARGE FOR ARCHIVES, EDITORIALS (Reuters, 16 May 2005) -- The New York Times Co. on Monday said it plans to charge for some of its editorial columns and its archive of stories online to boost subscription sales, even as it invests in its free service. The New York-based publisher of the namesake newspaper and The Boston Globe said the new product, TimeSelect, will debut in September and cost $49.95 for an annual subscription. The company said most of its stories will still be available online for free. TimeSelect underscores the paper’s push to create more Web products, both free and for a fee, to offset an uncertain advertising market for its print newspapers. The New York Times purchased Web site About.com for about $410 million earlier this year to increase its online advertising inventory. The paper’s print subscribers will have free access to the paper’s columnists online, including those written by Times staffers and International Herald Tribune writers. TimeSelect will also give subscribers access to its archives dating back initially to 1980. The company plans to eventually extend its archives back to the 1850s, a spokesman said. http://story.news.yahoo.com/news?tmpl=story&cid=582&e=4&u=/nm/20050516/wr_nm/media_newyorktimes_dc
CARDS LET METRO COLLECT DATA ON RIDERS, TRACK TRIPS (Washington Times, 17 May 2005) -- Metro’s SmarTrip fare cards allow the transit agency to monitor passengers’ travel with little regard for privacy concerns, a group focused on privacy issues says. The SmarTrip fare card, which includes an embedded radio frequency identification (RFID) chip, tracks each rider’s travel and can be matched with the rider’s name, address and credit-card number, according to the District-based nonprofit Electronic Privacy Information Center (EPIC). “Our basic point is that there is a lot of detailed information being collected,” said Marc Rotenberg, executive director of EPIC, a public-interest group established in 1994 to focus attention on emerging threats to civil liberties. “The privacy protections, in our opinion, are inadequate.” http://washingtontimes.com/metro/20050517-120301-3752r.htm
IS YOUR BOSS MONITORING YOUR E-MAIL? (CNET, 18 May 2005) -- If you’re working for a U.S. company, there’s a good chance you’re being watched--and you may get fired for how you use your computer or office phone. That’s the gist of a study on electronic monitoring and surveillance released Wednesday by the American Management Association and the ePolicy Institute. The report found that companies increasingly are “putting teeth in technology policies.” About a quarter of employers have fired workers for misusing the Internet; another 25 percent have terminated employees for e-mail misuse; and 6 percent have fired employees for misusing office telephones, according to the report. “Concern over litigation and the role electronic evidence plays in lawsuits and regulatory investigations has spurred more employers to implement electronic technology policies,” Nancy Flynn, executive director of the ePolicy Institute, said in a statement. Although liability and regulatory issues may be convincing companies to peek in on their employees, such surveillance raises privacy concerns. Employers can monitor workers to a greater degree these days, thanks to newer technologies such as keystroke-logging software and satellite global positioning systems that can track a cell phone user’s whereabouts. The survey, which involved 526 U.S. companies, found that 5 percent use GPS technology to monitor cell phones and 8 percent use GPS to track company vehicles. About 75 percent of companies monitor workers’ Web site connections, and 65 percent use software to block connections to inappropriate Web sites. Computer monitoring takes various forms, according to the study, with 36 percent of employers tracking “content, keystrokes and time spent at the keyboard.” Another 50 percent of companies store and review employees’ computer files, according to the report. http://news.com.com/Is+your+boss+monitoring+your+e-mail/2100-1032_3-5712677.html?tag=nefd.top
PERSONAL DATA FOR THE TAKING (New York Times, 18 May 2005) – Senator Ted Stevens wanted to know just how much the Internet had turned private lives into open books. So the senator, a Republican from Alaska and the chairman of the Senate Commerce Committee, instructed his staff to steal his identity. “I regret to say they were successful,” the senator reported at a hearing he held last week on data theft. His staff, Mr. Stevens reported, had come back not just with digital breadcrumbs on the senator, but also with insights on his daughter’s rental property and some of the comings and goings of his son, a student in California. “For $65 they were told they could get my Social Security number,” he said. That would not surprise 41 graduate students in a computer security course at Johns Hopkins University. With less money than that, they became mini-data-brokers themselves over the last semester. They proved what privacy advocates have been saying for years and what Senator Stevens recently learned: all it takes to obtain reams of personal data is Internet access, a few dollars and some spare time. Working with a strict requirement to use only legal, public sources of information, groups of three to four students set out to vacuum up not just tidbits on citizens of Baltimore, but whole databases: death records, property tax information, campaign donations, occupational license registries. They then cleaned and linked the databases they had collected, making it possible to enter a single name and generate multiple layers of information on individuals. Each group could spend no more than $50. http://www.nytimes.com/2005/05/18/technology/18data.html?ex=1274068800&en=2e20e8def94eb234&ei=5090&partner=rssuserland&emc=rss
PLAN WOULD BROADEN F.B.I.’S TERROR ROLE (New York Times, 19 May 2005) -- The Bush administration and Senate Republican leaders are pushing a plan that would significantly expand the F.B.I.’s power to demand business records in terror investigations without obtaining approval from a judge, officials said on Wednesday. The proposal, which is likely to be considered next week in a closed session of the Senate intelligence committee, would allow federal investigators to subpoena records from businesses and other institutions without a judge’s sign-off if they declared that the material was needed as part of a foreign intelligence investigation. The proposal, part of a broader plan to extend antiterrorism powers under the law known as the USA Patriot Act, was concluded in recent days by Republican leaders on the Senate Select Committee on Intelligence in consultation with the Bush administration, Congressional officials said. Administration and Congressional officials who support the idea said the proposal would give the F.B.I. a much-needed tool to track leads in terrorism and espionage investigations that would be quicker and less cumbersome than existing methods. They pointed out that the administrative subpoena power being sought for the F.B.I. in terror cases was already in use in more than 300 other types of crimes, including health care fraud, child exploitation, racketeering and drug trafficking. http://www.nytimes.com/2005/05/19/politics/19terror.html?ex=1274155200&en=f6615ca026642d9a&ei=5090&partner=rssuserland&emc=rss
US TECH CO’S WANT CLICKWRAPS OUT OF HAGUE CONVENTION (BNA’s Internet Law News, 19 May 2005) -- BNA’s Electronic Commerce & Law Report reports that U.S. ISPs and other technology companies have urged State Department negotiators to exclude “clickwrap” agreements from the Draft Hague Convention on Exclusive Choice of Court Provisions in B2B Agreements. Negotiators are set to meet next month at the Hague Conference on Private International Law to discuss the convention. Article at http://pubs.bna.com/ip/BNA/eip.nsf/is/a0b0w5h0d9
ISRAELI COURT RULES DIRECTORS HAVE COPYRIGHT IN THEIR MOVIES (BNA’s Internet Law News, 19 May 2005) -- After a protracted five-year legal battle, the Tel Aviv District Court recently ruled that directors have copyrights to movies they have directed, as they have contributed their creativity to the productions. This is viewed as a landmark decision because until now no court had ruled on the question of directors’ copyrights to their works. http://www.haaretzdaily.com/hasen/spages/577805.html
**** RESOURCES ****
A RARE NEWSBITES BOOK REVIEW: SILENCE ON THE WIRE (SANS NewsBytes, 27 April 2005) -- We rarely do book reviews, but this is an extraordinary collection of information on passive reconnaissance and the publisher is fairly unknown, so if we didn’t bring “Silence on the wire” to your attention it might get missed. If you are involved in information warfare, or in charge of security at an organization with high value assets you should be aware of this book: http://www.amazon.com/exec/obidos/tg/detail/-/1593270461/qid=1114558699/sr=8-1/ref=pd_csp_1/103-9311674-6721424?v=glance&s=books&n=507846
SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. David Evan’s “Internet and Computer News”, http://www.abanet.org/scripts/listcommands.jsp?parm=subscribe/at-internet
10. Readers’ submissions, and the editor’s discoveries.
PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.
Subscribe to:
Posts (Atom)