Sunday, February 12, 2006

MIRLN -- Misc. IT Related Legal News [22 January – 12 February 2006; v9.02]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of KnowConnect, Inc. (www.knowconnect.com) and the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

**** PROGRAM ANNOUNCEMENTS ****
ABA Cyberspace Law Committee spring meeting (April 6-9, 2006, in Tampa, Florida). Details at http://www.abanet.org/buslaw/2006spring/index.html; Cyberspace committee activities will be blogged at http://aba-cyberspace.blogspot.com/

NEW OPEN-SOURCE LICENSE DRAFT LESS CONTROVERSIAL THAN FEARED FOR BUSINESS (Information Week, 16 Jan 2006) -- The first draft of the General Public License 3 is less controversial and more pro-business than expected, observers say. Unveiled at a conference at Massachusetts Institute of Technology on Monday, the Free Software Foundation’s much anticipated GPL3 extends license compatibility to other open source licenses, prevents commercial firms from imposing unfair patent restrictions on open source software and contains provisions to remove loopholes that could enable commercial vendors to hijack the GPL for its own purposes. Yet the GPL 3 falls far short of the draconian treatise some had feared, observers said. As proposed, the document will not force Google or eBay to distribute source code along with binary source code, as rumored, or undermine commercial vendors with large patent portfolios such as Linux-proponent IBM, observers said. “It will be less controversial than some thought. It’s measured,’ said Ciaran O’Riordan, the Brussels representative of the Free Software Foundation Europe. “The new patent protection and DRM clause is quite reasonable.” Slated to be finished sometime in 2007, version 3 will be the first significant revision of the general public license in 14 years. GPL 2, which debuted in 1991, governs open source software development and is used by leading projects such as Linux, Samba, and MySQL. The GPL 3’s terms announced on Monday are part of the first draft and are subject to change. Nevertheless, Richard Stallman, founder and president of the Free Software Foundation, said the intent is to ensure users and developers with continued rights to use, copy, modify and share open source code, while also not imposing “harsh” restrictions that interrupt commercial use. GPL3 also includes a narrow kind of patent “retaliation” that would prohibit a situation in which a company modifies a version of GPL-covered program, gets a patent and then threatens to take legal action anyone else that makes such a modified version. Version 3 states that any company attempting such control would lose its right to make any further modifications under the GPL and thus its commercial viability. http://www.informationweek.com/story/showArticle.jhtml?articleID=177100643&cid=RSSfeed_IWK_news

FILLING IN GAPS IN INTERNET COVERAGE -- ENHANCED POLICIES OFFER PROTECTION NOT FOUND IN STANDARD FORMS (Business Insurance, 16 Jan 2006) -- The increasing reliance on the Internet exposes many businesses to risks not previously associated with their traditional risk profiles, including computer hacking, liability for trademark and copyright infringement, defamation and privacy claims. Unfortunately, traditional insurance forms such as property and commercial general liability and standard technology errors and omissions insurance policies do not cover many of the risks associated with cyberspace. The following is a brief summary of how some of these insurance policies do-and do not-respond to such risks:
• Property policies cover only tangible property and not data. Additionally, property policies tend to focus on the perils that are typically involved in losses to tangible property, such as fire, explosion and wind. Business interruption insurance that is sold as part of such property policies tends to define property and perils similarly. While the form may cover the loss of income when a business sustains a fire loss, it will not cover the loss of electronic revenues due to a distributed denial of service.
• Standard crime forms safeguard only against losses resulting from fraud related to or the theft of money, securities or other tangible property. Computer fraud and information theft that results in damage or deleted information assets are deemed intangible and, therefore, are not covered.
• Commercial general liability policies cover claims for physical injury to tangible property, including the loss of the use of such property. They also cover claims for the loss of the use of tangible property that has not been physically damaged. CGL policies do not cover property damage to or the loss of the use of intangible property, nor do they cover the loss of the use of tangible property that has not been physically injured when the loss of the use arises out of a defect, deficiency, inadequacy or dangerous condition in the insured’s product. Additionally, while the standard CGL policy includes coverage for personal and advertising injury, coverage does not apply if the insured is in the business of advertising, broadcasting, publishing, telecasting, telemarketing, etc. Any information on a Web site, including banner ads, can create legal third-party exposure to alleged libel, slander or defamation, copyright, title or trademark infringement or invasion of privacy.
Most standard technology errors and omissions forms provide coverage for property damage to or the loss of use of intangible property and the loss of use of tangible property that has not been physically damaged when the loss of use arises out of a defect, deficiency, inadequacy or dangerous condition in an insured’s product. However, E&O forms typically exclude losses arising from breaches of security and/or failures to prevent unauthorized access. A breach of network security can result in claims from customers whose client information was stolen and denial of service claims from customers who could not access a site, as well as claims from anyone to whom a deadly computer virus was transmitted. With respect to the additional exposures created by the use of the Internet, a specialized sector of the insurance industry has developed enhanced forms to fill the gaps in the property, CGL and technology E&O forms. The forms are nonstandard in approach, yet most will offer some of the following components [more online] http://www.businessinsurance.com/cgi-bin/article.pl?articleId=18200&print=Y

THE iPOD TOOK MY SEAT (LA Times, 17 Jan 2006) -- Americ Azevedo taught an “Introduction to Computers” class at UC Berkeley last semester that featured some of the hottest options in educational technology. By visiting the course’s websites, the 200 enrolled students could download audio recordings or watch digital videos of the lectures, as well as read the instructor’s detailed lecture notes and participate in online discussions. But there was one big problem: So many of the undergraduates relied on the technology that, at times, only 20 or so actually showed up for class. Skipping classes, particularly big lectures where an absence is likely to go undetected, is a time-honored tradition among college undergraduates who party too late or swap notes with friends. These days, however, some professors are witnessing a spurt in absenteeism as an unintended consequence of adopting technologies that were envisioned as learning aids. Already, even as many academics embrace the electronic innovations, others are pushing back. To deter no-shows, they are reverting to lower-tech tactics such as giving more surprise quizzes or slashing their online offerings. “Too much online instruction is a bad thing,” said Terre Allen, a communication studies scholar and director of a center that provides teaching advice to professors at Cal State Long Beach. This last term, Allen experimented with posting extensive lecture notes online for her undergraduate course, “Language and Behavior.” One goal was to relieve students of the burden of furiously scribbling notes, freeing them to focus on the lectures’ substance. Yet the result, Allen said, was that only about one-third of her 154 students showed up for most of the lectures. In the past, when Allen put less material online, 60% to 70% of students typically would attend. http://www.latimes.com/technology/la-me-noshow17jan17,1,3883942.story

COMPUTER CRIME COSTS $67 BILLION, FBI SAYS (CNET, 19 Jan 2006) -- Dealing with viruses, spyware, PC theft and other computer-related crimes costs U.S. businesses a staggering $67.2 billion a year, according to the FBI. The FBI calculated the price tag by extrapolating results from a survey of 2,066 organizations. The survey, released Thursday, found that 1,324 respondents, or 64 percent, suffered a financial loss from computer security incidents over a 12-month period. The average cost per company was more than $24,000, with the total cost reaching $32 million for those surveyed. Often survey results can be skewed, because poll respondents are more likely to answer when they have experienced a problem. So, when extrapolating the survey results to estimate the national cost, the FBI reduced the estimated number of affected organizations from 64 percent to a more conservative 20 percent. http://news.com.com/2100-7349_3-6028946.html

YAHOO! WINS BY LOSING IN LATEST ROUND OF NAZI PARAPHERNALIA CASE (Steptoe & Johnson’s E-Commerce Law Week, 21 January 2006) -- Yahoo!’s long-running battle against a French court order requiring Yahoo! to restrict access to Nazi paraphernalia and propaganda in France has been marked by twists, turns, and tactical retreats on both sides for more than five years. At issue is how globally accessible Internet portals deal with content restrictions in foreign countries that would violate the First Amendment in the United States. This issue has been popping up a lot lately, particularly with regard to China and its effort to censor the speech of media outlets and dissidents, and is sure to remain a hot topic in 2006. But the Yahoo! case was the first to bring this issue to the fore, so its seeming dénouement may be instructive on the broader issue. On January 12, the Ninth Circuit, sitting en banc, narrowly decided that Yahoo!’s request for a declaratory judgment that the French court’s order violated the First Amendment should be dismissed. The court vote was 6-5, but the majority couldn’t agree on a single rationale: three judges believed dismissal was appropriate for lack of personal jurisdiction over the French defendants, while three others thought the case was not ripe for judicial review. Despite superficial appearances, this case is not really a loss for Yahoo! All it means is that conflicts over content restrictions are unlikely to be resolved by any neat legal solutions in the near future, but instead will be decided by a murky mix of business considerations and customer sentiment. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=11583&siteId=547

EDITING TIPS FROM THE NSA (CNET, 25 Jan 2006) -- Hiding confidential information with black marks works on printed copy, but not with electronic documents, the National Security Agency has warned government officials. The agency makes the point in a guidance paper on editing documents for release, published last month following several embarrassing incidents in which sensitive data was unintentionally included in computer documents and exposed. The 13-page paper is called: “Redacting with confidence: How to safely publish sanitized reports converted from Word to PDF. “Instead of covering up digital text with black boxes, it is better to delete any information you don’t want to share, the NSA suggested. “The key concept for understanding the issues that lead to...inadvertent exposure is that information hidden or covered in a computer document can almost always be recovered,” the NSA wrote in the Information Assurance Division paper, dated Dec. 13 but only recently posted to the Web. “The way to avoid exposure is to ensure that sensitive information is not just visually hidden or made illegible, but is actually removed.” There are a number of pitfalls for people trying to amend a sensitive Word document for public release as a PDF. Covering text, charts, tables or diagrams with black rectangles, or highlighting text in black...is not effective, in general, for computer documents distributed across computer networks (i.e. in “softcopy” format). The most common mistake is covering text with black. Covering up parts of an image with separate graphics such as black rectangles, or making images “unreadable” by reducing their size, has also been used for redaction of hardcopy printed materials. It is generally not effective for computer documents distributed in softcopy form. In addition to the visible content of a document, most office tools, such as (Microsoft) Word, contain substantial hidden information about the document. This information is often as sensitive as the original document, and its presence in downgraded or sanitized documents has historically led to compromise. The unintended disclosure of metadata, resulting in high-profile leaks of secrets, has led to red faces at businesses and government bodies in the past. In March 2004, a gaffe by the SCO Group revealed which companies it had considered targeting in its legal campaign against Linux users. More recently, pharmaceutical giant Merck was put in the hot seat because of changes made to a document regarding the painkiller Vio. xxThere have also been document data leaks at the White House, the Pentagon, the United Nations and others, according to compiled research from Workshare, a maker of software that strips tell-tale hidden data out of files. http://news.com.com/2102-1029_3-6030745.html?tag=st.util.print; NSA guidance paper at http://www.nsa.gov/snac/vtechrep/I333-TR-015R-2005.PDF

COURT RULES GOOGLE CACHE CONSTITUTES FAIR USE (BNA’s Internet Law News, 26 Jan 2006) -- A federal district court in Nevada has ruled that the Google Cache feature does not infringe U.S. copyright law. The ruling clarifies the legal status of several common search engine practices and could influence future court cases, including the lawsuits brought by book publishers against the Google Library Project. Case name is Field v. Google. Decision at http://www.eff.org/IP/blake_v_google/google_nevada_order.pdf

CHOICEPOINT TO PAY $15 MILLION FOR DATA BREACH (InfoWorld.com, 26 Jan 2006) -- ChoicePoint Inc., the data broker that set off a national debate after disclosing a data breach early in 2005, will pay US$15 million in fines and other penalties for lax security standards, the U.S. Federal Trade Commission (FTC) announced Thursday. ChoicePoint’s $10 million fine is the largest civil fine in the FTC’s history, the FTC said. Under a settlement with the FTC, the Georgia company will also set up a $5 million fund to aid victims of identity theft that resulted from the data breach, and the company has agreed to implement new security measures and have an independent auditor review its security every other year until 2026, said FTC Chairwoman Deborah Platt Majoras. http://www.infoworld.com/article/06/01/26/74829_HNchoicepointfine_1.html

THE CRUMBS YOU LEAVE BEHIND (New York Times, 28 Jan 2006) -- The Justice Department may not prevail in its effort to force Google to hand over its raw search data to help the government solve the mystery of how people find pornography on the Internet. But the issue has raised the surfing public’s awareness, and in the last couple of weeks, the idea has widely circulated that on the Internet, there really is no privacy. Even if the government does not find out what you do online, lots of other people may. But there are measures that Net users can take to protect themselves. Wired News (Wired.com) offers a FAQ, “How to Foil Search Engine Snoops,” that declares the first priority of the privacy-minded should be cookie management. Cookies are pieces of software that many Web sites load onto your computer. They are used to save passwords and other data, and can also be used to track where you go and what you do online. Unless you sign up for something on the site using your real name, it is unlikely that anyone would tie your Internet activity to your identity, but it is possible. “Those who want to avoid a permanent record should delete their cookies at least once a week” according to Wired News. “Other options might be to obliterate certain cookies when a browser is closed and avoid logging in to other services, such as Web mail, offered by a search engine.” As the article notes, however, eliminating cookies means you cannot save your preferences, and you have to log in every time you revisit the site. Search Engine Watch (searchenginewatch.com) offers a useful guide, “Protecting Your Search Privacy: A Flowchart to Tracks You Leave Behind,” that takes a comprehensive look at search privacy, from your computer to your Internet service provider to the search engine itself to third parties that traffic in search information. Also on Search Engine Watch: “Private Searches Versus Personally Identifiable Searches,” which explains that “there’s an important difference between private information and private information that can be actually linked to an individual with confidence.” http://www.nytimes.com/2006/01/28/technology/28online.ready.html?ex=1296104400&en=42f30f1982abc258&ei=5090&partner=rssuserland&emc=rss

WHO’S THE LEAD AGENCY FOR CYBERSECURITY? DHS? GUESS AGAIN. (Steptoe & Johnson’s E-Commerce Law Week, 28 Jan 2006) -- For three years, we’ve been waiting for the Department of Homeland Security (DHS) to give us a sense of how it plans to fulfill the cybersecurity responsibilities assigned to it by Congress and the President, including tasks such as promoting public awareness and outreach and improving public/private information sharing. But while DHS continues to dither and dawdle, the Federal Trade Commission (FTC) has quietly but effectively made itself into a cybersecurity powerhouse. The FTC’s enforcement actions against companies that it deems to have “inadequate” information security have begun to create a de facto standard for industry, which in turn is influencing legislation in Congress and in state capitals. On January 10, the FTC unveiled a new element in its cybersecurity campaign: a comprehensive website, dubbed “OnGuard Online,” that provides “practical tips” on how to “guard against Internet fraud, secure your computer, and protect your personal information.” This is a joint endeavor by the FTC with several other agencies and private sector entities. It’s not the substance of the site that we find noteworthy. Rather, it is the fact that, with this effort, the FTC has established itself as a key player in the cliché-ridden but still important realm of “public-private partnerships” and simultaneously as a focal point for interagency cybersecurity efforts. In Washington, DC, those two roles give the FTC a legitimate claim on a leadership role, and make it the player to watch in 2006. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=11612&siteId=547

BLOG-AHOLICS (The Atlantic, Jan/Feb 2006) -- Most of us will admit to wasting some time at work. But three new studies suggest that more time is lost now than ever before. According to a survey by the magazine Advertising Age, a leading culprit is Weblogs. The survey indicates that one in four U.S. workers reads blogs regularly while at work, losing, on average, some nine percent of the workweek. This amounts to 551,000 years of labor lost in 2005 alone. If only the bloggers whose words seem so compelling were the ones sending us e-mail: 34 percent of workers surveyed by Information Mapping, Inc. reported wasting thirty to sixty minutes a day trying to interpret “ineffectively” written messages. A third study offers comfort—or at least a way to pass the buck for all the lost time. Having examined productivity in nine countries, it concludes that 37 percent of the time spent at work is wasted—but that poor management and inadequate supervision are largely to blame. http://www.theatlantic.com/doc/200601/primarysources/2

PATENT SPAT FORCES BUSINESSES TO UPGRADE OFFICE (CNET, 30 Jan 2006) -- Microsoft has begun e-mailing its corporate customers worldwide, letting them know that they may need to start using a different version of Office as a result of a recent legal setback. The software maker said Monday that it has been forced to issue new versions of Office 2003 and Office XP, which change the way Microsoft’s Access database interacts with its Excel spreadsheet. The move follows a verdict last year by a jury in Orange County, Calif., which found in favor of a patent claim by Guatemalan inventor Carlos Armando Amado. Microsoft was ordered to pay $8.9 million in damages for infringing Amado’s 1994 patent. That award covered sales of Office between March 1997 and July 2003. “It was recently decided in a court of law that certain portions of code found in Microsoft Office Professional Edition 2003, Microsoft Office Access 2003, Microsoft Office XP Professional and Microsoft Access 2002 infringe a third-party patent,” Microsoft said in an e-mail to customers. “As a result, Microsoft must make available a revised version of these products with the allegedly infringing code replaced.” Although existing customers can keep using older versions on current machines, any new installations of Office 2003 will require Service Pack 2, released by Microsoft in September. Office XP will need to be put into use with a special patch applied. Microsoft is also recommending that customers update their existing software with the new code. http://news.com.com/Patent+spat+forces+businesses+to+upgrade+Office/2100-1014_3-6032870.html?tag=nefd.lede

UK: ICO PUBLISHES GOOD PRACTICE NOTE ON EMPLOYMENT REFERENCES (Hunton & William’s Privacy & E-Commerce Alert, 31 Jan 2006) -- In early January, the Information Commissioner’s Office released a guide including good practice recommendations to help employers understand how the Data Protection Act applies to employee references. In particular, it clarifies when employment references should and should not be released. For further information, please consult: http://www.ico.gov.uk/cms/DocumentUploads/Subject_access_and_employment_references.pdf

GROUP SUES AT&T OVER ALLEGED SURVEILLANCE (AP, 31 Jan 2006) -- A civil liberties group sued AT&T Inc. on Tuesday for its alleged role in helping the National Security Agency spy on the phone calls and other communications of U.S. citizens without warrants. The class-action lawsuit, filed in U.S. District Court in San Francisco by the Electronic Frontier Foundation, seeks to stop the surveillance program that started shortly after the 2001 terrorist attacks. It also seeks billions of dollars in damages. The EFF claims the San Antonio-based telecommunications company not only provided direct access to its network that carries voice and data but also to its massive databases of stored telephone and Internet records that are updated constantly. President Bush has acknowledged authorizing the super-secret NSA to eavesdrop on international phone calls and e-mails of people within U.S. borders without the approval of a court, as required by existing surveillance and wiretapping laws. The White House has vigorously defended the program, saying the president acted legally under the constitution and a post-Sept. 11 congressional resolution that granted him broad power to fight terrorism. Democrats and civil libertarians disagree with the program’s defenders, and it has already resulted in lawsuits against the federal government and plans for congressional hearings. In its lawsuit, the EFF claims AT&T violated U.S. law and the privacy of its customers as part of the “massive and illegal program to wiretap and data-mine Americans’ communications.” The group said it identified AT&T through news reports and its own investigation. Michael Balmoris, an AT&T spokesman, said the company does not comment on matters of national security or on pending litigation. http://news.yahoo.com/s/ap/20060201/ap_on_hi_te/domestic_spying_lawsuit

DHS WANTS TO IMPROVE SOFTWARE SECURITY (FCW.com, 1 Feb 2006) -- The Homeland Security Department wants public comment on two draft documents that are part of a federal program to improve software security, according to today’s Federal Register. The documents are part of the Software Assurance Program that DHS created as part of the National Strategy to Secure Cyberspace. The program is designed to reduce vulnerabilities and exploitation of weaknesses to improve software security, particularly in software that critical infrastructure uses. One document, “Security in the Software Lifecycle,” aims to help developers and project managers of software applications establish strategies to make sure new software products are more secure. The second, “Secure Software Assurance – Common Body of Knowledge,” would help colleges and the private sector create curricula to train people in software assurance. Comments on the two documents are due by Feb. 21. http://www.fcw.com/article92172-02-01-06-Web

IRS COMPUTERS CAN’T HANDLE GATES’ TAXES (Forbes.com, 2 Feb 2006) -- The annual headache of doing our taxes is one that fills most citizens with customary, chronic foreboding. But if the idea of endless form-filling and number crunching seems bad, spare a thought for the poor souls at the Internal Revenue Service. America’s principal bean counters must regularly face the gargantuan monstrosity that is Bill Gates’ tax return, an undertaking of such magnanimously complex proportions that the agency has had to keep the information of the billionaire’s vast fortune on a “special computer.” The perpetrator himself, Microsoft co-founder and Chairman Gates revealed all at a conference in Lisbon: “Their normal computers can’t deal with the numbers,” he said of the hapless taxmen. “So I am constantly getting these notices telling me I haven’t paid something, when really it is just on the wrong computer.” Gates explained the glitch is then followed by charade of correspondence: “Then they will send me another notice telling me how bad they feel, that they sent me a notice that was a mistake.” According to an IRS spokeman, the agency’s main computers do not use the Windows operating system. http://www.forbes.com/facesinthenews/2006/02/02/gates-irs-microsoft-cx_po_0202autofacescan03.html?partner=rss

COMPUTER BUSINESS RECORDS WITHOUT FOUNDATION? (ABA Cyberspace Committee blog, 3 Feb 2006) -- A recent decision out of the 9th Circuit (sitting as the U.S. Bankruptcy Appellate Panel) should be of interest to Cyberspace lawyers. While all of us are familiar with the usual litany of how to get business records admitted under the relevant exception to the hearsay rule, many of us have long wondered if there was too much of a leap of faith in the process where the records were computerized. Well, the naysayers finally have a case to lean on. In In re Vinhnee, (2005 WL 3609376) the district court had refused to admit evidence proffered by a credit card company regarding the debtor’s credit card transactions. The refusal was on the ground of defective evidentiary foundation. The trial court suggested that determining the authenticity of proffered electronic records “necessitated, in addition to the basic foundation for a business record, an additional authentication foundation regarding the computer and software utilized in order to assure the continuing accuracy of the records.” Even after the proponent was given a second bite at the apple (by being allowed to file a post-trial declaration to lay sufficient foundation), the court found the witness statements to be overly conclusory and the witnesses themselves to be of unproven qualifications. On that basis, the evidence was not admitted, the proponent lost its case because of the evidence issue, and the appeal ensued. The appeal affirmed the decision (notably on an abuse of discretion standard, which the court said might allow for a “trial court that is finicky about settled authentication requirements [to be] sustained...”). The court noted some scholarship on point, equating computer evidence to be a form of scientific evidence, and suggested that the problem is more complex than it seems. “The ‘built-in safeguards to ensure accuracy and identify errors’ ... subsume details regarding computer policy and system control procedures, including control of access to the database, control of access to the program, recording and logging of changes, backup practices, and audit procedures to assure the continuing integrity of the records.” In this instance, the best the proponent of the evidence could come up with (even after being allowed to go home and do its homework!) was to list off the brand of computers and software the business used, and restate a conclusory opinion that the system was reliable. The trial court determined that this did not meet its requirements for foundation, and the evidence was tossed. http://aba-cyberspace.blogspot.com/2006/02/computer-business-records-without.html

NIST ISSUES GUIDELINES FOR DATA REMOVAL (Government Computer News, 6 Feb 2006) -- Wonder no longer about how to remove sensitive data from the hard drives and optical disks you are about to toss. The National Institute of Standards and Technology has issued a set of draft guidelines on how to safely remove information from obsolete forms of storage. Matthew Scholl, Richard Kissel, Steven Skolochenko and Xing Li of the NIST Information Technology Laboratory authored Special Publication 800-88, “Guidelines for Media Sanitization: Recommendations of the National Institute of Standards and Technology,” which was sponsored by the Homeland Security Department. “When storage media are transferred, become obsolete or are no longer usable or required by an information system, it is important to ensure that residual magnetic, optical or electrical representation of data that has been deleted is not easily recoverable,” the guidelines stated. Although the publication summarizes the ways to remove data, it emphasizes that a proper disposal methodology should not be based on the type of storage being disposed, but rather on the confidentiality of the material the medium contains. http://appserv.gcn.com/cgi-bin/udt/im.display.printable?client.id=gcndaily2&story.id=38206 NIST Guidelines at http://csrc.nist.gov/publications/drafts/DRAFT-sp800-88-Feb3_2006.pdf

SENATORS CAUGHT REWRITING WIKIPEDIA (NewsFactor.com, 9 Feb 2006) -- Online reference compendium Wikipedia has found that employees working in the U.S. Congress have made several changes to political biographies, removing facts considered negative and tweaking language to portray politicians in a better light. Wikipedia began an investigation after a Democratic representative, Marty Meehan, admitted that he had spiffed up his online biography page. It was found that articles on other senators had been changed, sometimes significantly, and that the edits could be traced to computers on Capitol Hill. Although Wikipedia is a collectively run reference, and can be edited by any of its users, those who run the site attempt to police changes to make sure they adhere to fact and not opinion or prejudice. In its investigation, Wikipedia examined the public edit history on the political biography pages in question. Researchers discovered the links to the U.S. Senate and began checking the biographies that had been visited. Half a dozen pages were changed, according to Wikipedia, including those of California Senator Dianne Feinstein, Iowa Senator Tom Harkin, and Minnesota Senator Norm Coleman. Senator’s Coleman staff confirmed the changes, noting that they had made several changes, such as a description of the senator in college. Where he had once been described as a “liberal,” the staff edited the listing to dub him an “activist.” Staff members of Senator Harkin removed a paragraph noting that Harkin had claimed falsely to have been in combat in North Vietnam, a claim he later recanted. http://news.yahoo.com/s/nf/20060209/bs_nf/41526

‘CSI EFFECT’ ON CROOKS SEEN BY PROSECUTORS (National Law Journal, 9 Feb 2006) -- District attorneys across the nation are grumbling about a new kind of “CSI effect” that makes their jobs tougher. Not only are juries requiring more sophisticated scientific evidence linking defendants to crimes, but suspects have learned how to destroy that evidence by watching the CBS “crime scene investigation” TV shows, according to prosecutors. Techniques such as bleaching away DNA, scrubbing away fingerprints-even those on a neck limp from strangulation-and torching bodies and crimes scenes top the list. Christie Stanley, a Santa Barbara County, Calif., assistant district attorney, said that as a result of such shows, the increasing sophistication of defendants in destroying crime-scene evidence requires more rigorous investigations, more preparation on the part of prosecutors, additional experts and longer trials. http://www.law.com/jsp/nlj/PubArticleNLJ.jsp?id=1139479512222 (Subscription required)

PRIVACY FEARS HIT GOOGLE SEARCH (BBC, 10 Feb 2006) -- The Electronic Frontier Foundation said the latest version of Google Desktop posed a risk to privacy. This is because a feature in the software lets Google keep personal data on its servers for up to 30 days. Google says it plans to encrypt all data transferred from users’ hard drives and restrict access. The new version of its desktop search software comes as Google is battling efforts by the US Department of Justice to force it to hand over data about what people are looking for. The case has focused attention on the issue of personal information held by internet companies. “Coming on the heels of serious consumer concern about government snooping into Google’s search logs, it’s shocking that Google expects its users to now trust it with the contents of their personal computers,” said EFF staff attorney Kevin Bankston. “Unless you configure Google Desktop very carefully, and few people will, Google will have copies of your tax returns, love letters, business records, financial and medical files, and whatever other text-based documents the desktop software can index. “The government could then demand these personal files with only a subpoena rather than the search warrant it would need to seize the same things from your home or business,” he said. http://news.bbc.co.uk/2/hi/technology/4700002.stm [Editor: Not sure I understand/believe this story, but if it’s true that your desktop search-index is exported outside your machine, that would be very bad. SEE also Robert Ambrogli’s blog on this, and it’s implications vis a vis attorney confidentiality obligations at http://www.legaline.com/2006/02/lawyers-beware-googles-desktop-search.html]

DHS WEATHERS CYBER STORM (TechWeb.com, 10 Feb 2006) -- The U.S. Department of Homeland Security still has to evaluate how well it fared through a series of simulated cyber attacks this week, but government and private companies avoided real-world damage and complications during their preparedness exercise. More than 100 public, private and international groups participated in mock attacks replicating the invasion of a utility company’s computer system and the disruption of power grids. The exercise, called Cyber Storm, was designed to test the abilities of private companies and government agencies to deal with a major cyber security incident. DHS announced the completion of the exercise on Friday but has yet to fully evaluate how effectively the groups communicated, cooperated and responded. John Sabo, director of security and privacy initiatives for CA, said he believes the initiative benefits his company and the public. “We’re forming industry sector-to-sector relationships and also bridging IT attacks and physical attacks,” he said during an interview Friday. Sabo, also the president of the International Security, Trust and Privacy Alliance and Vice President of the Information Technology-Information Sharing and Analysis Center, said that the groups involved will continue examining ways to improve operations, communications and “situational awareness capabilities,” through training exercises. http://news.yahoo.com/s/cmp/20060211/tc_cmp/179103522

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
8. McGuire Wood’s Technology & Business Articles of Note, http://www.ggtech.com
9. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, January 21, 2006

MIRLN -- Misc. IT Related Legal News [1-21 January 2006; v9.01]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of KnowConnect, Inc. (www.knowconnect.com) and the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

**** PROGRAM ANNOUNCEMENTS ****
ABA Cyberspace Law Committee winter working meeting (January 27-28, 2006, in Wilmington, Delaware). Details at http://www.abanet.org/buslaw/committees/CL320000pub/meetings.shtml; meeting activities will be blogged at http://aba-cyberspace.blogspot.com/

DOCUMENT MANAGEMENT SYSTEMS GO TO COURT (InfoWorld, 27 Dec 2005) -- Two proposed amendments to the federal Rules of Civil Procedure, if passed by Congress, will have a major impact on corporations and their IT departments. One expert I spoke with called the situation a legal Chernobyl. The two proposals are specifically targeted at electronic discovery. First, the proposed amendments to Rule 26 will require attorneys for both parties to a litigation in Federal court to sit down prior to the proceedings to discuss their clients’ document management systems. That’s right; you read that correctly. The rule also requires each company to designate a spokesperson for its IT group. This is the first time the courts are bringing IT directly into litigation, according to Trent Dickey, attorney with Sills, Cummis, Epstein & Gross. Next up, Rule 37(f), also called a safe harbor rule, says that corporations that have lost information but have otherwise acted in good faith cannot be sanctioned. Congress is expected to take action on this rule, one way or the other, by December 2006. It is probably easiest to comprehend the importance of the changes to Rules 26 and 37(f) by looking at what happens when you don’t manage documents properly. In Zubulake v. UBS Warburg, the judge instructed the jury that it was legitimate to presume that the information Warburg could not provide due to lost backup tapes and e-mails was probably damaging to the company’s case. Zubulake was awarded $20 million. According to Dickey, both this case and the more widely known Morgan Stanley case, which resulted in fines of $1.45 billion under similar circumstances, were decided 100 percent due to technology -- or rather, due to lack of good technology. If the changes to Rule 26 pass Congress and Rule 37(f) is shot down, next year there could be an awful lot of companies in the same boat as UBS Warburg and Morgan Stanley. http://www.infoworld.com/article/05/12/27/01OPreality_1.html?source=NLC-GOV2005-12-27

2005 WORST YEAR FOR BREACHES OF COMPUTER SECURITY (USA Today, 28 Dec 2005) -- Data breaches disclosed at Marriott International, Ford Motor, ABN Amro Mortgage Group and Sam’s Club this month capped what computer experts call the worst year ever for known computer-security breaches. At least 130 reported breaches have exposed more than 55 million Americans to potential ID theft this year. Security experts warn that wayward personal data, such as Social Security and credit card numbers, could end up in the hands of criminals and feed a growing problem. An adviser for the Treasury Department’s Office of Technical Assistance estimates cybercrime proceeds in 2004 were $105 billion, greater than those of illegal drug sales. The breaches come at a time when the Department of Homeland Security’s research budget for cybersecurity programs was cut 7%, to $16 million, for 2005. ID theft-related bills are stalled in Congress, and data brokers such as ChoicePoint, itself a victim of fraud this year, remain unregulated, “so it is likely that many more serious breaches have gone unreported,” says Avivah Litan, a security analyst at Gartner. As a result, the Bush administration has drawn the ire of the Cyber Security Industry Alliance, which represents high-tech heavyweights Symantec, McAfee and RSA Security. “Attacks are taking place every day,” says Paul Kurtz, a former Bush administration cybersecurity official who is executive director of CSIA. http://www.usatoday.com/tech/news/computersecurity/2005-12-28-computer-security_x.htm

-- and --

COMPUTER CRIME COSTS $67 BILLION, FBI SAYS (CNET, 19 Jan 2006) -- Dealing with viruses, spyware, PC theft and other computer-related crimes costs U.S. businesses a staggering $67.2 billion a year, according to the FBI. The FBI calculated the price tag by extrapolating results from a survey of 2,066 organizations. The survey, released Thursday, found that 1,324 respondents, or 64 percent, suffered a financial loss from computer security incidents over a 12-month period. The average cost per company was more than $24,000, with the total cost reaching $32 million for those surveyed. Often survey results can be skewed, because poll respondents are more likely to answer when they have experienced a problem. So, when extrapolating the survey results to estimate the national cost, the FBI reduced the estimated number of affected organizations from 64 percent to a more conservative 20 percent. “This would be 2.8 million U.S. organizations experiencing at least one computer security incident,” according to the 2005 FBI Computer Crime Survey. “With each of these 2.8 million organizations incurring a $24,000 average loss, this would total $67.2 billion per year.” By comparison, telecommunication fraud losses are about only $1 billion a year, according to the U.S. Secret Service. Also, the overall cost to Americans of identity fraud reached $52.6 billion in 2004, according to Javelin Strategy & Research. Other surveys have attempted to put a dollar amount on cybersecurity damages in the past, but the FBI believes its estimate is the most accurate because of the large number of respondents, said Bruce Verduyn, the special agent who managed the survey project. “The data set is three or four times larger than in past surveys,” he said. “It is obviously a staggering number, but that is the reality of what we see.” http://news.com.com/2100-7349_3-6028946.html

2005 PRIVACY YEAR IN REVIEW (EPIC, 1 Jan 2006) -- It’s been an eventful year in privacy, right up to the end, with revelations of government surveillance of activists, warrantless wiretaps by the National Security Agency, and a Congressional staring contest over the renewal of the Patriot Act. And the months preceding this one were no less impressive, with data security laws, RFID, and voter privacy making headlines. Here are the Top Ten Privacy Stories of 2005 from the Electronic Privacy Information Center (EPIC): [one-paragraph summaries follow each of these subjects]:
• PATRIOT Act Reauthorization Falls Short
• Security Breaches on the Rise
• Defense Department Ignores Privacy Laws
• In Federal Court, a Good E-mail Privacy Decision
• Privacy for Voters
• State Department Drops Hi-Tech Passport Plan, But Problems Remain
• NSA Domestic Spying Disclosed
• Problems Remain with Travel Screening Plans
• Credit Freeze Laws on the Rise
• Surveillance of Activists Revealed
http://www.epic.org/alert/EPIC_Alert_yir2005.html

CIA OFFSHOOT TAPS FORMER U.S. CYBERSECURITY CHIEF (CNET, 4 Jan 2006) -- Former U.S. cybersecurity chief Amit Yoran has been appointed president and CEO of In-Q-Tel, the CIA venture capital arm charged with funding and developing new technologies for the intelligence community. He took over Tuesday from previous chief Gilman Louie, who plans to start up his own San Francisco-based venture capital firm, In-Q-Tel said in a statement. Yoran resigned as director of the National Cyber Security Division of the Department of Homeland Security in late 2004, after less than one year in the post. Earlier, he was CEO of Riptech, a venture-backed network security company he cofounded, and then a managed security executive at Symantec. He also did a stint overseeing the vulnerability assessment program for the U.S. Computer Emergency Readiness Team (US-CERT). http://news.com.com/CIA+offshoot+taps+former+U.S.+cybersecurity+chief/2110-7350_3-6018575.html?tag=nefd.hed

GOVERNMENT WEB SITES FOLLOW VISITORS’ MOVEMENTS (CNET, 5 Jan 2006) -- Dozens of federal agencies are tracking visits to U.S. government Web sites in violation of long-standing rules designed to protect online privacy, a CNET News.com investigation shows. From the Air Force to the Treasury Department, government agencies are using either “Web bugs” or permanent cookies to monitor their visitors’ behavior, even though federal law restricts the practice. Some departments changed their practices this week after being contacted by CNET News.com. The Pentagon said it wasn’t aware that its popular Defenselink.mil portal tracked visitors--in violation of a privacy notice--and said it would fix the problem. So did the Defense Threat Reduction Agency and the U.S. Chemical Safety and Hazard Investigation Board. The practice of tracking Web visitors came under fire last week when the National Security Agency was found to use permanent cookies to monitor visitors, a practice it halted after inquiries from the Associated Press. The White House also was criticized last week for employing WebTrends’ tracking mechanism that used a tiny GIF image. http://news.com.com/Government+Web+sites+follow+visitors+movements/2100-1028_3-6018702.html?tag=nefd.lede

EMPLOYER HAD DUTY TO STOP WORKER’S PORN SURFING (ABA Journal, 6 Jan 2005) -- When an employer has actual or imputed knowledge that an employee is using a computer at work to “access pornography, possibly child pornography, [the company] has a duty to investigate … and to take prompt and effective action to stop the unauthorized activity,” a New Jersey appellate court has ruled. Doe v. XYC Corp., No. A-2909-04T2 (Dec. 27). The ruling by the Superior Court of New Jersey, Appellate Division, involved a man who later admitted he uploaded nude photographs of his stepdaughter to a child pornography Web site. But as distasteful as the crime is, several employment law experts find the decision unpalatable as well. “I think the decision is awful,” says Charles A. Sullivan, an employment law professor at Seton Hall University in Newark, N.J. “It imposes a big duty on employers, and it’s a huge infringement on employees’ privacy rights.” “It’s a horrible opinion,” concurs Laurie Leader, a professor of clinical practice at Chicago-Kent College of Law who specializes in labor and employment law. “I think this court is out on a limb. It’s almost imposing some kind of strict liability on employers.” But the plaintiff’s attorney, Kevin Kovacs of Bedminster, N.J., defends the court’s opinion as “an important decision and a good decision for potential victims of child pornography.” “The defendant argued that my position turns employers into police departments. But it doesn’t,” Kovacs says. “We never argued that there should be full-out monitoring of employees’ Internet activities. We argued that in limited circumstances, where the company has information, it has to investigate, and when there’s child pornography, it has to report it because there’s potential harm employees can do to third parties.” http://www.abanet.org/journal/ereport/j6porn.html

-- and --

YOU COULD BE LIABLE FOR YOUR EMPLOYEE’S PORN ADDICTION Steptoe & Johnson’s E-Commerce Law Week, 7 Jan 2006) -- Employers’ monitoring of their employees’ online activity is nothing new. And neither is reprimanding an employee for visiting pornography websites at the office. But thanks to a recent court decision, employers may now have a legal obligation to halt such activity by employees, or they could be liable if that activity “result[s] in harm to innocent third parties.” On December 27, in Doe v. XYC Corp., the Superior Court of New Jersey, Appellate Division, ruled that “an employer who is on notice that one of its employees is using a workplace computer to access pornography, possibly child pornography, has a duty to investigate the employee’s activities and to take prompt and effective action to stop the unauthorized activity.” The court held that no privacy interest of the employee stood in the way of this duty. Although the ruling has serious implications for any company that offers Internet service in the workplace, it may be of special interest to Internet service providers -- who already have their own child pornography notification obligations under 42 U.S.C. § 13032, and who may come across illegal activity not only on the part of their employees but also on the part of their subscribers. And the court’s reasoning could extend beyond pornography to any illegal or harmful conduct engaged in by employees from their work computers. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=11542&siteId=547

MICROSOFT SHUTS DOWN BLOG IN CHINA (CNN, 6 Jan 2006) -- Microsoft Corp. has shut down the Internet journal of a Chinese blogger that discussed politically sensitive issues, including a recent strike at a Beijing newspaper. The action came amid criticism by free-speech activists of foreign technology companies that help the communist government enforce censorship or silence dissent in order to be allowed into China’s market. Microsoft’s Web log-hosting service shut down the blog at the Chinese government’s request, said Brooke Richardson, group product manager with Microsoft’s MSN online division at company headquarters in Redmond, Wash. Although Beijing has supported Internet use for education and business, it fiercely polices content. Filters block objectionable foreign Web sites and regulations ban subversive and pornographic content and require service providers to enforce censorship rules. “When we operate in markets around the world, we have to ensure that our service complies with global laws as well as local laws and norms,” Richardson said. Richardson said the blog was shut down December 30 or December 31 for violating Microsoft’s code of conduct, which states that users must be in compliance with local laws in the country in which the user is based. http://www.cnn.com/2006/WORLD/asiapcf/01/06/china.blog.shutdown.ap/index.html

-- but --

CHINESE BAN ON WIKIPEDIA PREVENTS RESEARCH, USERS SAY (GlobeAndMail.com, 10 Jan 2006) -- Chinese students and intellectuals are expressing outrage at Beijing’s decision to prohibit access to Wikipedia, the fast-growing on-line encyclopedia that has become a basic resource for many in China. Wikipedia, which offers more than 2.2 million articles in 100 languages, has emerged as an important source of scholarly knowledge in China and many other countries. But its stubborn neutrality and independence on political issues such as Tibet and Taiwan has repeatedly drawn the wrath of the Communist authorities. The latest blocking of the website, the third shutdown of the site in China in the past two years, has now continued for more than 10 weeks without any explanation and without any indication whether the ban is temporary or permanent. http://www.theglobeandmail.com/servlet/story/RTGAM.20060110.gtwikipedia10/BNStory/Technology/

-- and --

INTERNET COMPANIES ‘MUST RESPECT FREE SPEECH’ (ZDnet, 10 Jan 2006) -- Reporters without Borders has called on companies such as Microsoft and Yahoo to respect human rights, even if the countries they are operating in don’t. IT companies operating in countries with repressive regimes should face tighter regulation when it comes to supporting freedom of speech, according to a leading anti-censorship organisation. Press freedom group Reporters without Borders issued a report late last week calling on the US government and US regulators to help develop a voluntary code of conduct for IT companies operating in countries such as China, Tunisia and Burma. One recommendation made by the group is that US companies should be prevented from hosting email servers in a countries with repressive regimes. This would ensure that any requests for information from the authorities of a repressive regime would have to pass through the US judicial system, the group claims. http://news.zdnet.co.uk/business/0,39020645,39246544,00.htm

QWEST THREATENS USERS WITH $5-PER-SPAM CHARGE (TechWorld, 9 Jan 2006) -- Qwest has added a new clause in its ISP contract that threatens to charge customers $5 for every spam message sent by their computer - even if they are not aware of it. The addition to a subscriber agreement [pdf] has been noticed and blown up on a Net discussion by consumer and small business users of its High Speed Internet service. The contentious paragraph in Qwest’s Acceptable Use Policy threatens to levy a $5 charge for every spam sent from a PC if this results in damages being awarded against Qwest itself. This is regardless of whether the owner of the PC was aware that their PC was sending spam, as would be the unfortunate case if it had been hijacked by a Trojan to act as a spam relay. The main provision of the agreement forbids the sending of unsolicited e-mail, as is normal in such ISP agreements. However, it goes an important step further in its wording. “You will pay Qwest’s actual damages in any way arising from, or related to, any spam transmitted by, or in any way connected to, you, to the extent that such damages can be calculated,” the document states. “If actual damages cannot be calculated reasonably, you agree to pay Qwest liquidated damages of five US dollars ($5.00) for each piece of spam transmitted from or otherwise connected with your account.” Users are believed to have been notified of the agreement in recent weeks, though they would need to delve into the 14-page agreement carefully to notice the addition. http://www.techworld.com/security/news/index.cfm?RSS&NewsID=5116

CREATE AN E-ANNOYANCE, GO TO JAIL (CNET, 9 Jan 2006) -- It’s no joke. Last Thursday, President Bush signed into law a prohibition on posting annoying Web messages or sending annoying e-mail messages without disclosing your true identity. In other words, it’s OK to flame someone on a mailing list or in a blog as long as you do it under your real name. Thank Congress for small favors, I guess. This prohibition, which would likely imperil much of Usenet, is buried in the so-called Violence Against Women and Department of Justice Reauthorization Act. Criminal penalties include stiff fines and two years in prison. “The use of the word ‘annoy’ is particularly problematic,” says Marv Johnson, legislative counsel for the American Civil Liberties Union. “What’s annoying to one person may not be annoying to someone else.” Buried deep in the new law is Sec. 113, an innocuously titled bit called “Preventing Cyberstalking.” It rewrites existing telephone harassment law to prohibit anyone from using the Internet “without disclosing his identity and with intent to annoy.” http://news.com.com/Create+an+e-annoyance,+go+to+jail/2010-1028_3-6022491.html?part=rss&tag=6022491&subj=news

LEVI’S OFFERS iPOD JEANS (Macworld, 10 Jan 2006) -- Is that a joystick in your pocket? Why, yes it is. Levi’s announced its new line of RedWire DLX Jeans, available worldwide in fall 2006. The jeans feature a built-in iPod docking cradle, joystick and retractable headphones. Designed for both men and women, the jeans are designed to be compatible with most iPod systems. A special joystick is built into the jeans’ watch pocket, with four-way controls to allow the wearer to play, pause, track forward, track back and adjust the volume control without ever removing the iPod from the pocket. http://www.macworld.com/news/2006/01/10/ipodlevis/index.php?lsrc=mwrss [Editor: Sorry; couldn’t resist.]

NEW YORK CITY STARTS TO MONITOR DIABETICS (Washington Post, 11 Jan 2006) -- New York City is starting to monitor the blood sugar levels of its diabetic residents, marking the first time any government in the United States has begun tracking people with a chronic disease. Under the program, the city is requiring laboratories to report the results of blood sugar tests directly to the health department, which will use the data to study the disease and to prod doctors and patients when levels run too high. The unprecedented step is being hailed by many health experts as a bold attempt to improve care for diabetes, one of the nation’s biggest medical problems, which is burgeoning into a crisis because of the aging population and the obesity epidemic. Some public health experts, ethicists and privacy advocates, however, say that the initiative raises serious concerns about confidentiality and is an alarming government intrusion into people’s medical care. Both sides agree that the decision is probably a harbinger of a trend in which the government will apply tactics traditionally reserved primarily for infectious diseases to chronic conditions such as diabetes, heart disease, asthma and cancer, which have supplanted communicable illnesses as the most pressing public health concerns. http://www.washingtonpost.com/wp-dyn/content/article/2006/01/10/AR2006011001625.html [Editor: Has similarities with the DOJ’s subpoena of Google’s search records (reported on 20 Jan 2006). Maybe my legal instincts are off, but this continues a troubling trend of government using private industry as a proxy for collecting sensitive personal information.]

AMERICAN COMPANIES SHOW AN EDGE IN PUTTING INFORMATION TO WORK (New York Times, 12 Jan 2006) -- Productivity just keeps humming along. Growth in output per hour in the third quarter of 2005 was a striking 5.4 percent. In fact, output per hour has grown at an average annual rate of nearly 3.5 percent over the last three years. These are large numbers by historical terms. From 1974 to 1995, productivity grew at around 1.4 percent a year. Productivity growth in the United States accelerated to about 2.5 percent a year from 1995 to 2000. Since then, productivity has grown at a bit over 3 percent a year, with the last few years looking particularly strong. Unlike the United States, European countries have not seen the same surge in productivity growth in the last 10 years. Why the difference? The answer, according to Nick Bloom, Raffaella Sadun and John Van Reenen, researchers at the Center for Economic Performance at the London School of Economics, is that American companies make much more effective use of information technology than European companies. (A selection of their studies can be downloaded from http://cep.lse.ac.uk/research/innovation/ict.asp.) Nowadays, most economists agree that information technology is a significant part of the explanation for the post-1995 productivity surge in the United States. In fact, when you look at productivity statistics by industry, those industries that make and use information and communications technologies intensively in the United States have accounted for the bulk of the productivity growth, with other industries showing little change. The story is quite different in the European Union. In the late 1990’s, when productivity growth in the United States was accelerating, productivity growth in Europe was static. But Europe has access to the same information technology that the United States does, at more or less the same prices. Why didn’t those countries get the same increase in productivity? http://www.nytimes.com/2006/01/12/business/12scene.html?ex=1294722000&en=7c3cfa4784251f7b&ei=5090&partner=rssuserland&emc=rss

CREDIT CARD RIVALS TO UNITE IN DATA PROTECTION EFFORT (New York Times, 12 Jan 2006) -- Two longtime rivals in the credit card business are working together to create a private group that would set new industrywide security standards as early as the middle of this year, a MasterCard executive said yesterday. Security officials from Visa USA and MasterCard International began quietly meeting early last year to discuss the best way to improve data security. But the high-profile disclosure of a security breach at CardSystems Solutions, a tiny payment processor that left 40 million cardholder accounts exposed to fraud, has given the effort a new push. Visa and MasterCard executives have separately proposed the idea of an independent standard-setting body that can certify that member banks and merchants have met certain guidelines and standards. “We have had preliminary conversations, and it would be a good idea to have these P.C.I. standards in an open standards body,” said Chris Thom, Mastercard’s chief risk officer, referring to the payment card industry rules. “There is no reason that this shouldn’t be done.” At a Visa-sponsored security conference in October, the company’s chief executive, John Philip Coghlan, publicly floated a similar idea. Still, the extent of the proposed agency’s enforcement power, if any, is unclear, as is the potential makeup of the group’s representatives. And it is also too early to determine how the new security standards would differ from the payment card industry’s existing ones, which outline a common set of rules with slight differences among the card companies. Although Discover Financial and American Express do not appear to be participating in the discussions, Visa and MasterCard, whose cardholders are responsible for roughly 80 percent of all credit and debit transactions, may have the power to bring a new standard-setting body into being. http://www.nytimes.com/2006/01/12/business/12cards.html?ex=1294722000&en=6a33fed927e253db&ei=5090&partner=rssuserland&emc=rss

APPLE’S ITUNES UNDER FIRE FOR PRIVACY ISSUES (NewsFactor, 13 Jan 2006) -- Apple Computer has come under fire because the new version of its iTunes music software is able to monitor listening habits. The iTunes software update, which was issued on January 10, incorporates a feature that recommends songs according to the tracks you play. Critics say that Apple needs to be more transparent about user data that is being collected, especially because the iTunes song recommendations use unique identifiers for a computer and an iTunes account. In Internet postings, bloggers are warning about the data that iTunes passes back to Apple, particularly the data being transmitted to Apple that enables it to make song recommendations and uniquely identify a computer and an iTunes account. http://news.yahoo.com/s/nf/20060113/bs_nf/40917

WIKI OFFERS ANONYMOUS BLOGGING TIPS (TechWeb, 13 Jan 2006) -- A new collaborative Web site offers tips on blogging more anonymously for people who live in countries that restrict free speech -- or for those who want to write freely about their companies without the risk of getting fired. The wiki, launched this week, is called anoniblog (http://anoniblog.pbwiki.com). The site offers no guarantees of complete anonymity but bills itself as a starting point. Users, like those who visit Wikipedia, are encouraged to add and edit guidelines. It warns that bloggers can’t be completely safe, but it offers information about risks in each country and tips for minimizing risks. http://news.yahoo.com/s/cmp/20060113/tc_cmp/175804123

NSA AND BUSH’S ILLEGAL EAVESDROPPING (essay by Bruce Schneier, 15 Jan 2006) -- When President Bush directed the National Security Agency to secretly eavesdrop on American citizens, he transferred an authority previously under the purview of the Justice Department to the Defense Department and bypassed the very laws put in place to protect Americans against widespread government eavesdropping. The reason may have been to tap the NSA’s capability for data-mining and widespread surveillance. Illegal wiretapping of Americans is nothing new. In the 1950s and ‘60s, in a program called “Project Shamrock,” the NSA intercepted every single telegram coming into or going out of the United States. It conducted eavesdropping without a warrant on behalf of the CIA and other agencies. Much of this became public during the 1975 Church Committee hearings and resulted in the now famous Foreign Intelligence Surveillance Act (FISA) of 1978. The purpose of this law was to protect the American people by regulating government eavesdropping. Like many laws limiting the power of government, it relies on checks and balances: one branch of the government watching the other. The law established a secret court, the Foreign Intelligence Surveillance Court (FISC), and empowered it to approve national-security-related eavesdropping warrants. The Justice Department can request FISA warrants to monitor foreign communications as well as communications by American citizens, provided that they meet certain minimal criteria. The FISC issued about 500 FISA warrants per year from 1979 through 1995, and has slowly increased subsequently -- 1,758 were issued in 2004. The process is designed for speed and even has provisions where the Justice Department can wiretap first and ask for permission later. In all that time, only four warrant requests were ever rejected: all in 2003. (We don’t know any details, of course, as the court proceedings are secret.) The NSA’s ability to eavesdrop on communications is exemplified by a technological capability called Echelon. Echelon is the world’s largest information “vacuum cleaner,” sucking up a staggering amount of voice, fax, and data communications -- satellite, microwave, fiber-optic, cellular and everything else -- from all over the world: an estimated 3 billion communications per day. These communications are then processed through sophisticated data-mining technologies, which look for simple phrases like “assassinate the president” as well as more complicated communications patterns. Supposedly Echelon only covers communications outside of the United States. Although there is no evidence that the Bush administration has employed Echelon to monitor communications to and from the U.S., this surveillance capability is probably exactly what the president wanted and may explain why the administration sought to bypass the FISA process of acquiring a warrant for searches. Perhaps the NSA just didn’t have any experience submitting FISA warrants, so Bush unilaterally waived that requirement. And perhaps Bush thought FISA was a hindrance -- in 2002 there was a widespread but false belief that the FISC got in the way of the investigation of Zacarias Moussaoui (the presumed “20th hijacker”) -- and bypassed the court for that reason. Most likely, Bush wanted a whole new surveillance paradigm. You can think of the FBI’s capabilities as “retail surveillance”: It eavesdrops on a particular person or phone. The NSA, on the other hand, conducts “wholesale surveillance.” It, or more exactly its computers, listens to everything. An example might be to feed the computers every voice, fax, and e-mail communication looking for the name “Ayman al-Zawahiri.” This type of surveillance is more along the lines of Project Shamrock, and not legal under FISA. As Sen. Jay Rockefeller wrote in a secret memo after being briefed on the program, it raises “profound oversight issues.” It is also unclear whether Echelon-style eavesdropping would prevent terrorist attacks. In the months before 9/11, Echelon noticed considerable “chatter”: bits of conversation suggesting some sort of imminent attack. But because much of the planning for 9/11 occurred face-to-face, analysts were unable to learn details. The fundamental issue here is security, but it’s not the security most people think of. James Madison famously said: “If men were angels, no government would be necessary. If angels were to govern men, neither external nor internal controls on government would be necessary.” Terrorism is a serious risk to our nation, but an even greater threat is the centralization of American political power in the hands of any single branch of the government. [Editor: There’s more, and it’s worth reading.] http://www.schneier.com/crypto-gram-0601.html#12

HEY, BABY BELLS: INFORMATION STILL WANTS TO BE FREE (New York Times, 15 Jan 2006) – At the top of my wish list for next year’s Consumer Electronics Show is this: the introduction of broadband service across the country that is as up to date as that 103-inch flat-screen monitor just introduced by Panasonic. The digital lifestyle I see portrayed so alluringly in ads is not possible when the Internet plumbing in our homes is as pitiful as it is. The broadband carriers that we have today provide service that attains negative perfection: low speeds at high prices. It gets worse. Now these same carriers - led by Verizon Communications and BellSouth - want to create entirely new categories of fees that risk destroying the anyone-can-publish culture of the Internet. And they are lobbying for legislative protection of their meddling with the Internet content that runs through their pipes. These are not good ideas. Slow broadband seems to be our cursed lot. Until we get an upgrade - or rather an upgrade to an upgrade - the only Americans who will enjoy truly fast and inexpensive service will be those who leave the country. In California, Comcast cable broadband provides top download speeds of 6 megabits a second for a little more than $50 a month. That falls well short, however, of Verizon’s 15-megabit fiber-based service offered on the East Coast at about the same price. But what about the 100-megabit service in Japan for $25 month? And better, much better: Stockholm’s one-gigabit service - that is, 1,000 megabits, or more than 1,300 times faster than Verizon’s entry-level DSL service - for less than 100 euros, or $120, a month. One-gigabit service is not in the offing in the United States. What the network carriers seem most determined to sell is a premium form of Internet service that offers a tantalizing prospect of faster, more reliable delivery - but only if providers like Google, Yahoo and Microsoft pay a new charge for special delivery of their content. (That charge, by the way, would be in addition to the regular bandwidth-based Internet connection charges that their carriers already levy.) An executive vice president of Verizon, for example, said last week that the proliferation of video programs offered via the Internet opens a new opportunity for his company: a new class of premium online delivery for Web sites wishing to pay extra to give smooth video streams to their customers in the Verizon service area. The executive, Thomas J. Tauke, said that a fast lane for premium content providers would not reduce the quality of regular service for everyone else, and that sites could choose not to sign up without suffering retribution. “To the best of my knowledge,” he said, “there’s no negative.” From the consumer’s perspective, given the dismal state of the status quo, shouldn’t any service improvement be welcomed? The short answer is: not necessarily. http://www.nytimes.com/2006/01/15/business/yourmoney/15digi.html?ex=1294981200&en=7e187115d2191158&ei=5090&partner=rssuserland&emc=rss

FEDS AFTER GOOGLE DATA (SiliconValley.com, 19 Jan 2006) -- The Bush administration on Wednesday asked a federal judge to order Google to turn over a broad range of material from its closely guarded databases. The move is part of a government effort to revive an Internet child protection law struck down two years ago by the U.S. Supreme Court. The law was meant to punish online pornography sites that make their content accessible to minors. The government contends it needs the Google data to determine how often pornography shows up in online searches. In court papers filed in U.S. District Court in San Jose, Justice Department lawyers revealed that Google has refused to comply with a subpoena issued last year for the records, which include a request for 1 million random Web addresses and records of all Google searches from any one-week period. The Mountain View-based search and advertising giant opposes releasing the information on a variety of grounds, saying it would violate the privacy rights of its users and reveal company trade secrets, according to court documents. Nicole Wong, an associate general counsel for Google, said the company will fight the government’s effort ``vigorously.” ``Google is not a party to this lawsuit, and the demand for the information is overreaching,” Wong said. The case worries privacy advocates, given the vast amount of information Google and other search engines know about their users. http://www.siliconvalley.com/mld/siliconvalley/13657386.htm
Good New York Times story at: http://www.nytimes.com/2006/01/20/technology/20google.html?ex=1295413200&en=66c6a0f87da7e56d&ei=5090&partner=rssuserland&emc=rss
DOJ application at: http://www.siliconvalley.com/multimedia/mercurynews/news/GoogleMcElvain.pdf

**** RESOURCES ****
A CHRONOLOGY OF DATA BREACHES REPORTED SINCE THE CHOICEPOINT INCIDENT (Privacy Rights Clearinghouse, 17 Jan 2006). http://www.privacyrights.org/ar/ChronDataBreaches.htm

ANTI-SPYWARE STRATEGIES, PART 1: CLEAN OUT YOUR SYSTEM (Information Week, 6 Jan 2006) – [Reasonably straightforward 5-step process for finding and removing various kinds of spyware on your PC. Alternative approach: use a Macintosh.] http://www.informationweek.com/shared/printableArticle.jhtml?articleID=175802722

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. Gordon & Glickson’s Articles of Note, http://www.ggtech.com
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Friday, December 30, 2005

MIRLN -- Misc. IT Related Legal News [11 - 31 Dec 2005; v8.16]

**************Introductory Note**********************

MIRLN (Misc. IT Related Legal News) is a free product of KnowConnect, Inc. (www.knowconnect.com) and the American Bar Association’s Cyberspace Law Committee. Please feel free to distribute this message.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.buslaw.org/cgi-bin/controlpanel.cgi?committee=CL320000 (click on “Settings” beside Members-Only Listserve Discussion). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN editions are archived at www.vip-law.com and in the public materials section of the Cyberspace Committee’s collaboration space at http://lawplace.metadot.com.

**************End of Introductory Note***************

LAW FIRMS NOT LIABLE IN ALLEGED WEB HACKING CASE (Law.com, 9 Dec 2005) -- Two law firms that allegedly surreptitiously accessed the password-protected Web site of an expert witness in order to show a judge that the witness violated a gag order cannot be held liable under the Digital Millennium Copyright Act. A District of Columbia federal judge has dismissed the suit by Boston occupational illness expert Dr. David Egilman, who accused the law firms Jones Day and Keller & Heckman of Washington, and Keller attorney Douglas Behr, of misappropriating his protected work. Egilman accused the Keller firm and Behr of hacking into his Web site by acquiring a password and sharing it with Jones Day lawyers in the midst of a 2001 landmark Colorado state toxics trial. Egilman had testified on behalf of the first four of 50 workers at Rocky Flats nuclear weapons plant who unsuccessfully claimed that the federal government colluded with the world’s largest beryllium maker, Brush Wellman Inc., to hide the health dangers of the metallic element. Despite a broad gag order by a Colorado state court judge, Frank Plaut, in Ballinger v. Brush Wellman Inc., No. 96-CV-2532, Egilman had posted critical material about Jones Day and Brush Wellman on his password-protected Web site in what Plaut ruled was a violation of the gag order. Plaut ordered jurors to disregard Egilman’s testimony as a sanction after learning from Jones Day that the posting included accusations of potential illegal conduct by Jones Day, and allegations that a Brush Wellman medical doctor was educated in Nazi Germany, according to press accounts at the time. Egilman, who has testified in dozens of toxics trials and was the expert in the recent Texas Vioxx trial that resulted in a $253 million verdict, limited Web site access to his staff and his Brown University students. He posted uncensored information on occupational illness and related litigation, including previously confidential corporate internal documents related to many toxic torts. Egilman sued Jones Day and Keller & Heckman, first in Texas and later in the District of Columbia, saying that his reputation was besmirched and his effectiveness compromised. He argued that the law firms and Behr circumvented measures installed to deny access to his copyright-protected work on the Web site, in violation of the 1978 Digital Millennium Copyright Act. U.S. District Judge Henry Kennedy Jr. in D.C. ruled that obtaining a username and password from a third party that has authorized access does not violate the DMCA. Kennedy cited the only other court to rule on improper use of a legitimate password, holding that gaining access to a third party’s legitimate password is not the same as hacking. http://www.law.com/jsp/printerfriendly.jsp?c=LawArticle&t=PrinterFriendlyArticle&cid=1134036310706

FTC HARE CONTINUES TO SPEED AHEAD OF CONGRESSIONAL TORTOISE ON INFORMATION SECURITY REGULATION (Steptoe & Johnson’s E-Commerce Law Week, 10 Dec 2005) -- When it comes to regulating industry information security practices, Congress and the Federal Trade Commission (“FTC”) seem to be reenacting Aesop’s fable of the tortoise and the hare. While Congress plods methodically along with various security-related bills, with nothing likely to be enacted before year’s end, the FTC continues to race ahead, setting de facto security standards for industry through enforcement actions based on its general authority to prevent “unfair . . . acts or practices in or affecting commerce.” 15 U.S.C. § 45(a)(1). On December 1, shoe retailer DSW, Inc., settled FTC charges that the company’s data security failures earlier this year -- which had allowed hackers to access the credit card, debit card information of more than 1.4 million consumers and the checking account information of 96,000 customers -- constituted an “unfair practice.” Notably, the case marks only the second time that the FTC has based a data security enforcement action on the FTC Act’s “unfairness” prong (the first being the Commission’s action against BJ’s Wholesalers this past June). In previous security breach cases, the FTC had based its allegations on the “deceptive practices” prong of the Act -- targeting, for instance, companies that failed to follow their own privacy policies, and thus allegedly deceived customers. The DSW case, like the BJ’s case before it, demonstrates the FTC’s continuing willingness to take action against companies that do not have a specific statutory obligation to safeguard personal information and have never promised customers that their personal information would be secure in the first place. In Aesop’s fable, the hare gets bored and falls asleep while the tortoise crosses the finish line. But the FTC is not likely to stop racing ahead unless and until a company refuses to settle and challenges the FTC’s statutory authority. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=11414&siteId=547

D.C. CIRCUIT NARROWS FTC’S JURISDICTION UNDER GRAMM-LEACH-BLILEY (Steptoe & Johnson’s E-Commerce Law Week, 10 Dec 2005) -- Hear that wind blowing outside? No, it’s not another winter storm. It’s the entire legal profession breathing a collective sigh of relief, as it avoids the FTC’s jurisdictional claws under the Gramm Leach Bliley Act (GLBA). On December 6, the U.S. Court of Appeals for the D.C. Circuit rejected the FTC’s claim of jurisdiction under the GLBA to regulate law firms as “financial institutions.” American Bar Ass’n v. FTC (No. 04-5257). The appeals court affirmed a district court ruling that the FTC’s decision to subject attorneys to GLBA privacy requirements “exceeded the statutory authority” of the FTC and “was therefore invalid as a matter of law.” This ruling represents a rare defeat for the FTC in a jurisdictional challenge, and provides a useful reminder that there are indeed limits to the types of activities and entities that are covered by the GLBA. The D.C. Circuit’s decision also could bode well for any companies that muster the intestinal fortitude to challenge the FTC’s assertion of jurisdiction in other areas, such as its claim that it can effectively enact and enforce industry information security standards under the “unfair practices” prong of the FTC Act (as discussed above). The American Bar Association case, though not directly relevant to that issue, illustrates just how to frame a successful jurisdictional challenge. http://www.steptoe.com/index.cfm?fuseaction=ws.getItem&pubItemId=11414&siteId=547

ARIZ. TOWN WILL GO WALL-TO-WALL WIRELESS (AP, 11 Dec 2005) -- Call it a municipal status symbol in the digital age: a city blanketed by a wireless Internet network, accessible at competitive prices throughout the town’s homes, cafes, offices and parks. Tempe, the Phoenix suburb that is home to Arizona State University, is due to have wireless Internet available for all of its 160,000 residents in February, becoming the first city of its size in the United States to have Wi-Fi throughout. Tempe officials hope that by making high-speed Internet as accessible as water or electricity across its 40 square miles, it will attract more technology and biotech companies — and the young, upwardly mobile employees they bring. An increasing number of the nation’s cities are looking at using Internet access as an economic development tool. Few cities have gotten as far as installing systems, “but most cities are realizing that it may be something that they want to do,” said Cheryl Leanza, legislative counsel for the National League of Cities. Philadelphia is developing a citywide high-speed system with EarthLink Inc. Unlike Philly or Tempe, New Orleans is building a free system, though the network speed will be limited. The Tempe network is being installed by NeoReach Wireless, a subsidiary of Bethesda, Md.-based MobilePro Corp. Roughly 400 antenna boxes mounted on light poles throughout the city will be used to stitch together the network, to which NeoReach will sell access, primarily through other providers. The network uses a so-called “mesh” setup, meaning it passes wireless signals from pole to pole and automatically reroutes transmissions if one of the transmitters breaks down. Speeds will vary depending on the number of users logged into the same access point. The network is strong enough only to be picked up outdoors or through one wall, meaning those who want service in their businesses or homes will need a box that serves as a signal booster and router. The city of Tempe gave the company access to its light poles in exchange for use of the network in transmitting data to and from city offices and vehicles, said Karrie Rockwell, a spokeswoman for NeoReach. Two hours of free access each day also will be available for Internet users on the Arizona State campus or the nearby Mill Avenue retail district, where the network began a year ago as a pilot project and has proven popular. Robert Jenkins, 50, sits at a coffee house on Mill Avenue a couple of times a week with his laptop, downloading larger files that take too long at home when he uses his mobile phone to access the Internet. NeoReach will directly sell service to outdoor users for $3.95 per hour or $29.95 per month. The resellers of NeoReach access have not yet announced pricing, but Rockwell said it will be cheaper than DSL or cable Internet access. Cable operator Cox Communications Inc. charges $49.95 per month for customers who don’t get Cox phone or TV service. Qwest Communications International Inc. charges $44.99 and $54.99 per month, depending on the speed. Tempe signed a contract with NeoReach after asking for bids — which prevented it from having to start its own utility and probably quelled potential objections to the city’s involvement in a WiFi network. http://news.yahoo.com/s/ap/20051211/ap_on_hi_te/wireless_city

EMPLOYEES LEAKING TRADE SECRETS VIA EMAIL: LACK OF CORPORATE POLICY REACHES WORRYING PROPORTIONS (VNUNet, 12 Dec 2005) -- A study by market research firm Radicati Group has shown that over one in 20 employees has sent company secrets to third parties via email. The Corporate Email User Habits study found that a quarter of those surveyed had forwarded corporate email to their personal accounts for later use, and nearly two thirds use their personal email for company business. “While six per cent may seem like a small number, in a 10,000-user organisation it translates to 600 employees leaking intellectual property,” said Sara Radicati, president of the Radicati Group. “Companies should take a hard look at educating their workforce on its official email policy, and put in place outbound filtering and monitoring technology that can block confidential or sensitive emails before they leave the corporate network, as well as report violations.” Only 22 per cent of companies surveyed had any policy on monitoring outgoing mail, and only half had any kind of internal policy regarding email use. http://www.vnunet.com/vnunet/news/2147460/employees-weakest-link Study at http://www.mirapoint.com/pdfs/whitepapers/End-User-Study-on-Email-Hygiene.pdf ABA’s “Employee Use of the Internet and E-Mail: A Model Corporate Policy With Commentary on Its Use in the U.S. and Other Countries” (shameless plug—I was co-editor) at http://www.abanet.org/abastore/index.cfm?section=main&fm=Product.AddToCart&pid=5070395

-- and --

FIRMS COUNT THE COST OF SECURITY THREATS (ElectronicNews.net, 12 Dec 2005) -- According to the State of Information Security 2005 report from PricewaterhouseCoopers and CIO Magazine, not only are security-related events up 22.4 percent on last year’s figures, but the number of organisations reporting financial losses as a result of the attacks is also surging. Twenty-two percent of companies said they had been hit financially, compared with last year’s 7 percent. But despite the growing security threat to businesses, only 37 percent of respondents have a security plan in place, with only 24 percent saying that they expected to develop one in the coming year. However, organisations with a chief information security officer (CISO) or chief security officer (CSO) fare a little better, with 62 percent implementing a security plan. More companies are employing a CISO or CSO, with 40 percent of respondents in the survey having one on the payroll compared with 31 percent in 2004. Security spending is slightly increasing to compensate for the growing threat, accounting for 13 percent of an organisation’s IT budget this year, compared with 11 percent last year. Malicious hackers are the top culprits to carry out the attacks, with 63 percent of events attributed to them compared with 66 percent last year. However, the number of employee-related attacks is also up, at 33 percent compared with 2004’s 28 percent. Former employees remain a likely source of the security threats, representing 20 percent of events. Meanwhile, computer viruses still top the charts as the most common type of attack, rising to 59 percent of attacks from 53 percent the previous year. http://www.enn.ie/frontpage/news-9658009.html

MICHIGAN CONSIDERS REQUIRING HIGH-SCHOOL STUDENTS TO TAKE AT LEAST ONE ONLINE COURSE (Chronicle of Higher Education, 13 Dec 2005) -- The Michigan State Board of Education is set to approve a new graduation requirement today that would make every high-school student in the state take at least one online course before receiving a diploma. The new requirement would appear to be the first of its kind in the nation. Mike Flanagan, the Michigan state superintendent of public instruction, said he proposed the online-course requirement, along with other general requirements, to make sure students were prepared for college and for jobs, which are becoming more technology-focused. While most high-school students are adept at using the Internet, Mr. Flanagan said, few of them take courses online. But today’s high-school students are increasingly likely to encounter online courses as more colleges turn to online education, he said. The online-education proposal is included with several other proposed statewide requirements -- including four years of English courses, three years of mathematics, and three years of science. Currently, the only state-required course for graduation in Michigan is a one-semester class in civics, although many of the state’s local school districts have much tougher requirements. If the state Board of Education approves the proposals, they will still need the assent of both the State Legislature and the governor. Mr. Flanagan said he already had strong support for the online proposal in the Legislature. http://chronicle.com/free/2005/12/2005121301t.htm

EUROPEAN REPORT FINDS LITTLE IMPACT FROM DATABASE DIRECTIVE (BNA’s Internet Law News, 14 Dec 2005) -- The EU DG Internal Market and Services has published an evaluation report on the EU’s Database Directive. The report acknowledges that the directive “has had no proven impact on the production of databases” and that the evidence casts doubt on the necessity of the database protection for a thriving database industry. Report at http://europa.eu.int/comm/internal_market/copyright/docs/databases/evaluation_report_en.pdf

EU PARLIAMENT ADOPTS ANTI-TERRORISM DATA RULES (Reuters, 14 Dec 2005) -- The European Parliament on Wednesday adopted new rules drawn up by the European Union to store phone and Internet data for up to two years to fight terrorism and other serious crime. But some EU lawmakers criticised the assembly saying it had caved in to pressure from member states, and arguing that the new rules would allow authorities to do what they wanted with the data. The parliament voted by 378 to 197 with 30 abstentions for a package already agreed between the assembly’s two biggest groups and member states, with European Commission backing. Earlier this month, Britain secured a deal among the EU’s 25 member states that would force telecommunications companies to store data for between six and 24 months. The rules, proposed by the European Commission in September, are part of the EU’s response to attacks in Madrid in 2004 and London this year. The version adopted on Wednesday is tougher than that recommended by the parliament’s civil liberties committee which wanted the data to be stored for one year. The committee’s recommendation was by-passed by the deal struck between member states and the assembly’s right-wing European People’s Party and socialists. The new rules still need to be formally approved by EU member states. Telecom firms have warned that the new rules will be costly to implement, but lawmakers and member states ditched a European Commission proposal that member states pay for extra data storage costs. http://uk.news.yahoo.com/14122005/80/eu-parliament-adopts-anti-terrorism-data-rules.html

IS THE PENTAGON SPYING ON AMERICANS? (MSNBC, 13 Dec 2005) – A year ago, at a Quaker Meeting House in Lake Worth, Fla., a small group of activists met to plan a protest of military recruiting at local high schools. What they didn’t know was that their meeting had come to the attention of the U.S. military. A secret 400-page Defense Department document obtained by NBC News lists the Lake Worth meeting as a “threat” and one of more than 1,500 “suspicious incidents” across the country over a recent 10-month period. The Defense Department document is the first inside look at how the U.S. military has stepped up intelligence collection inside this country since 9/11, which now includes the monitoring of peaceful anti-war and counter-military recruitment groups. “I think Americans should be concerned that the military, in fact, has reached too far,” says NBC News military analyst Bill Arkin. The Department of Defense declined repeated requests by NBC News for an interview. A spokesman said that all domestic intelligence information is “properly collected” and involves “protection of Defense Department installations, interests and personnel.” The military has always had a legitimate “force protection” mission inside the U.S. to protect its personnel and facilities from potential violence. But the Pentagon now collects domestic intelligence that goes beyond legitimate concerns about terrorism or protecting U.S. military installations, say critics. Four dozen anti-war meetings The DOD database obtained by NBC News includes nearly four dozen anti-war meetings or protests, including some that have taken place far from any military installation, post or recruitment center. One “incident” included in the database is a large anti-war protest at Hollywood and Vine in Los Angeles last March that included effigies of President Bush and anti-war protest banners. Another incident mentions a planned protest against military recruiters last December in Boston and a planned protest last April at McDonald’s National Salute to America’s Heroes — a military air and sea show in Fort Lauderdale, Fla. The Fort Lauderdale protest was deemed not to be a credible threat and a column in the database concludes: “US group exercising constitutional rights.” Two-hundred and forty-three other incidents in the database were discounted because they had no connection to the Department of Defense — yet they all remained in the database. The DOD has strict guidelines, adopted in December 1982, that limit the extent to which they can collect and retain information on U.S. citizens. Still, the DOD database includes at least 20 references to U.S. citizens or U.S. persons. Other documents obtained by NBC News show that the Defense Department is clearly increasing its domestic monitoring activities. One DOD briefing document stamped “secret” concludes: “[W]e have noted increased communication and encouragement between protest groups using the [I]nternet,” but no “significant connection” between incidents, such as “reoccurring instigators at protests” or “vehicle descriptions.” http://msnbc.msn.com/id/10454316/print/1/displaymode/1098/ DOD Guidelines at http://msnbcmedia.msn.com/i/msnbc/sections/news/DOD.1982.IntelligenceCollectionOnU.S.Persons.pdf

-- and --

PENTAGON WILL REVIEW DATABASE ON U.S. CITIZENS (Washington Post, 15 Dec 2005) -- Pentagon officials said yesterday they had ordered a review of a program aimed at countering terrorist attacks that had compiled information about U.S. citizens, after reports that the database included information on peace protesters and others whose activities posed no threat and should not have been kept on file. http://www.washingtonpost.com/wp-dyn/content/article/2005/12/14/AR2005121402528.html

BETTING ON BIRD FLU (Salon, 13 Dec 2005) -- On Nov. 1, Intrade, a Web site that allows people to bet on the likelihood of future events, issued a press release titled “Trading on Bird Flu -- 65% probability of U.S. case by March 2006!” The release announced that the trading activity on the exchange’s bird flu contracts -- offering savvy “investors” a chance to gamble on when the first strain of the deadly H5N1 will be confirmed in the United States -- had doubled in the last month. The report, put out by Intrade P.R. executive Mike Knesevitch, ended with an ominous, sobering claim: “Can these markets give us insight into global events like pandemics, hurricanes and politics? In the short history Intrade has put together, the answer is YES.” If these predictive markets are as startlingly accurate as they say, this spring the U.S. will get its first case of bird flu and some of us may die. Intrade launched its two bird flu contracts -- one predicting that the potentially deadly, pandemic-causing Asian bird flu will hit the U.S. in December, the other that it will hit in March -- on Oct. 18. (The December contract is now trading at 6, meaning the market is currently predicting a 6 percent chance of the flu hitting the U.S. on or before Dec. 31, the March at 29.6.) Now, with close to $34,000 worth of investor money wrapped up in them, the bird flu contracts are among the most popular on the futures markets site, and company spokesman Brian Keating says he expects betting on the bird flu only to increase as the contracts’ closing dates -- Dec. 31 and March 31, respectively -- approach and as more cases of the bird flu crop up around the world. Contracts on the Intrade exchange can be bought or sold between other members, just as with any other stock exchange, but if an investor chooses to hold on to a contract price until closing, that investor can lose the entire amount invested -- or make a tidy profit. In the five years since its inception, Intrade has been accurate in predicting elections, the new pope, the impact of Hurricane Katrina, and the capture of Saddam Hussein. A recent example occurred on Oct. 21 with Supreme Court nominee Harriet Miers’ confirmation contract. At approximately 8:30 that morning, traders monitoring the Harriet Miers confirmation process began aggressively selling contracts betting against her confirmation -- dropping her stock price 42 points in early trading. The following Thursday, Miers withdrew her nomination from the high court. The Intrade market allows, even thrives, on insider information. Knesevitch confirms that a lot of the market’s members work for government entities and often have the ability to move the market on national events well before news of them has filtered through the media. Dave Saigel, from the Centers for Disease Control, who says he was not aware of the bird flu market, concedes that it might be a useful prediction tool -- and may also help build awareness of the dangers of the disease and its spread. What’s more, he says, the markets have “picked great months for their contracts. December and March are prime flu months.” Jack Marshall, president of Pro Ethics, a consulting firm used to educate organizations on ethical dilemmas in the workplace, agrees that futures markets -- and betting on things like the bird flu -- may be more beneficial than hurtful to society. “It would be different if, say, after 9/11 people are betting on where the next person’s remains would be found, but this is far less sinister than that,” he says. “In postmodernist America we have a black humor and a detachment from a lot of catastrophe anyway. Betting on an abstract event, buying futures in abstraction doesn’t necessarily make things any worse.” Marshall argues that even the New York Stock Exchange allows people to profit from other people’s misery. And Marshall says he loves the whole “wisdom of crowds” aspect of futures markets. He says these types of markets offer valid projections about events and do so without any sort of bias -- and he finds more credibility in these markets than any kind of scientific facts. http://www.salon.com/ent/feature/2005/12/13/birdflu/

BEIJING CASTS NET OF SILENCE OVER PROTEST (New York Times, 14 Dec 2005) -- One week after the police violently suppressed a demonstration against the construction of a power plant in China, leaving as many as 20 people dead, an overwhelming majority of the Chinese public still knows nothing of the event. In the wake of the biggest use of armed force against civilians since the Tiananmen massacre in 1989, Chinese officials have used a variety of techniques - from barring reports in most newspapers outside the immediate region to banning place names and other keywords associated with the event from major Internet search engines, like Google - to prevent news of the deaths from spreading. Beijing’s handling of news about the incident, which was widely reported internationally, provides a revealing picture of the government’s ambitions to control the flow of information to its citizens, and of the increasingly sophisticated techniques - a combination of old-fashioned authoritarian methods and the latest Internet technologies - that it uses to keep people in the dark. http://www.nytimes.com/2005/12/14/international/asia/14china.html?ex=1292216400&en=fe07535b1db7c3a1&ei=5090&partner=rssuserland&emc=rss

BUSH LETS U.S. SPY ON CALLERS WITHOUT COURTS (New York Times, 16 Dec 2005) -- Months after the Sept. 11 attacks, President Bush secretly authorized the National Security Agency to eavesdrop on Americans and others inside the United States to search for evidence of terrorist activity without the court-approved warrants ordinarily required for domestic spying, according to government officials. Under a presidential order signed in 2002, the intelligence agency has monitored the international telephone calls and international e-mail messages of hundreds, perhaps thousands, of people inside the United States without warrants over the past three years in an effort to track possible “dirty numbers” linked to Al Qaeda, the officials said. The agency, they said, still seeks warrants to monitor entirely domestic communications. The previously undisclosed decision to permit some eavesdropping inside the country without court approval was a major shift in American intelligence-gathering practices, particularly for the National Security Agency, whose mission is to spy on communications abroad. As a result, some officials familiar with the continuing operation have questioned whether the surveillance has stretched, if not crossed, constitutional limits on legal searches. “This is really a sea change,” said a former senior official who specializes in national security law. “It’s almost a mainstay of this country that the N.S.A. only does foreign searches.” Nearly a dozen current and former officials, who were granted anonymity because of the classified nature of the program, discussed it with reporters for The New York Times because of their concerns about the operation’s legality and oversight. The White House asked The New York Times not to publish this article, arguing that it could jeopardize continuing investigations and alert would-be terrorists that they might be under scrutiny. After meeting with senior administration officials to hear their concerns, the newspaper delayed publication for a year to conduct additional reporting. http://select.nytimes.com/gst/abstract.html?res=F00F1FFF3D540C758DDDAB0994DD404482 [Editor: This is the story-of-the-decade for me; separation of powers and Article II supremacy. I’m astounded that the Times sat on it for a year. Reminds me of a senior DOD lawyer who carries a copy of the Constitution in his suit coat pocket, and pulls it out several times a day to cite Article II authority, as if there weren’t two centuries of statutory, regulatory, and case-law gloss.] Related story at http://www.salon.com/news/feature/2005/12/23/bamford/print.html ; interesting legal analysis/blog at http://balkin.blogspot.com/#113526050457460564.

-- but --

OUR DOMESTIC INTELLIGENCE CRISIS (by Judge Richard Posner, Washington Post, 21 Dec 2005) -- We’ve learned that the Defense Department is deeply involved in domestic intelligence (intelligence concerning threats to national security that unfold on U.S. soil). The department’s National Security Agency has been conducting, outside the framework of the Foreign Intelligence Surveillance Act, electronic surveillance of U.S. citizens within the United States. Other Pentagon agencies, notably the one known as Counterintelligence Field Activity (CIFA), have, as described in Walter Pincus’s recent articles in The Post, been conducting domestic intelligence on a large scale. Although the CIFA’s formal mission is to prevent attacks on military installations in the United States, the scale of its activities suggests a broader concern with domestic security. Other Pentagon agencies have gotten into the domestic intelligence act, such as the Information Dominance Center, which developed the Able Danger data-mining program. These programs are criticized as grave threats to civil liberties. They are not. Their significance is in flagging the existence of gaps in our defenses against terrorism. The Defense Department is rushing to fill those gaps, though there may be better ways. The collection, mainly through electronic means, of vast amounts of personal data is said to invade privacy. But machine collection and processing of data cannot, as such, invade privacy. Because of their volume, the data are first sifted by computers, which search for names, addresses, phone numbers, etc., that may have intelligence value. This initial sifting, far from invading privacy (a computer is not a sentient being), keeps most private data from being read by any intelligence officer. http://www.washingtonpost.com/wp-dyn/content/article/2005/12/20/AR2005122001053.html

CAN-SPAM WORKING - FTC (The Register, 21 Dec 2005) -- Legal action and email filtering are helping to minimise the nuisance of spam, according to US federal regulators. In a report (PDF) to Congress on the effectiveness of the US Federal CAN-SPAM Act, the Federal Trade Commission (FTC) concludes that technology has reduced the amount of junk email reaching consumers’ in-boxes. Meanwhile rigorous law enforcement has had a deterrent effect on spammers. “Consumers are receiving less spam now than they were receiving in 2003” when the CAN-SPAM Act was enacted, the FTC concludes. The regulators’ upbeat assessment that the war against spam - if not won - is going in the right direction is supported by figures from some security vendors cited in its report. According to email firm MX Logic, spam accounted for 67 per cent of the email it processed in the first eight months of 2005, down nine percentage points from the 76 per cent spam-rate MX faced in the same period last year. The FTC has brought 21 cases under CAN-SPAM compared to 62 cases against spammers it filed before the enactment of the law. Several important steps can be taken to improve the efficacy of the CAN-SPAM Act, the FTC advises. Laws and needed to help the FTC and other regulators in their quest to trace spammers and sellers who operate outside of the US. Improved user education on spam prevention and continued improvement in filtering tools and techniques to trace spammers will also assist in the fight against junk mail, the FTC reckons. http://www.theregister.co.uk/2005/12/21/can-spam/ Report at http://www.ftc.gov/reports/canspam05/051220canspamrpt.pdf

3RD CIRCUIT UPHOLDS PRIVATE SUITS FOR ECPA VIOLATIONS (BNA’s Internet Law News, 20 Dec 2005) -- The 3rd Circuit Court of Appeals has ruled that a private right action exists for violation of the Electronic Communications Privacy Act. Case name is DirecTV v. Pepe. Decision at http://caselaw.findlaw.com/data2/circs/3rd/044333p.pdf

FRENCH PARLIAMENT VOTES TO LEGALIZE P2P FILE SHARING (Reuters, 23 Dec 2005) -- The lower house of the French parliament voted to legalize peer-to-peer (P2P) file sharing of movies and music via the Internet. It is a vote that is certain to reverberate around the globe and draw severe criticism from the nation’s film and music industries as well as from actors and recording artists. The vote has been called a revolt again Culture Minister Renaud Donnedieu de Vabres’ draft legislation that would have established steep penalties for individuals convicted of pirating copyrighted materials with a fine of $360,000 and as much as three years of jail time. Several days prior to the matter being taken up on the floor of the parliament, consumer activists delivered a petition with 110,000 signatures criticizing the draft proposal to Vabres. A small group of legislators attached two amendments to Vabres’ bill to establish a monthly global licensing fee of 7 euros (around $8.50). The subscription charge would entitle users to unlimited downloads and legalize what most Western countries have heretofore considered a modern-day scourge. The amendment passed with a small majority, 30 to 28, with only 10 percent of the 577 assembly members actually present. The measure has yet to pass in the upper house. “We are trying to bring the law up to date with reality,” Patrick Bloche, a Socialist representative from Paris who co-authored the amendments, told the New York Times. “It is wrong to describe the eight million French people who have downloaded music from the Internet as delinquents.” http://news.yahoo.com/s/nf/20051223/bs_nf/40473

FLA. ATTORNEY GENERAL SAYS HIS E-MAILS AREN’T SPAM (Reuters, 24 Dec 2005) -- Florida’s attorney general has spearheaded an aggressive campaign against unsolicited e-mails, or spam. But as a candidate for governor, he appears to be generating some unwanted Internet clutter himself. Charlie Crist was a staunch defender of a tough anti-spam law passed by the state legislature last year, under which violators can be fined up to $500 for every e-mail they send. But a report in Thursday’s St. Petersburg Times said Crist, a Republican gubernatorial candidate, had annoyed some residents of the state by sending them unwanted e-mails promoting his candidacy and soliciting campaign donations. Joe Spooner, a 41-year-old investment adviser, told the newspaper he had no idea how the Crist campaign got his e-mail address but repeatedly tried to unsubscribe. After his fifth request to be removed, Spooner sent the Crist campaign an e-mail of his own. He accused Crist of hypocrisy because of the way he seemed to have forgotten all about his vocal crackdown on spammers. ‘Do I need to file a complaint with the attorney general’s office?” Spooner wrote. The newspaper quoted other people who had received unsolicited e-mails from Crist’s campaign. Crist was not immediately available for comment. http://news.yahoo.com/s/nm/20051223/wr_nm/email_dc

SOUTH KOREA: UR INDICTED. BCNU. (New York Times, 27 Dec 2005) -- South Koreans may look at their cellphones with some trepidation in the new year because prosecutors will start telling people they have been indicted via text messages. In a country where about 75 percent of the population carry cellphones, prosecutors felt it was time to move away from sending legal notices on paper and send them electronically instead, said Lee Young Pyo, an administrative official. “This is a more definite way for the individuals to know they have received a legal notice,” he said. http://www.nytimes.com/2005/12/27/international/27briefs.html

US MILITARY FINDS SOLDIERS’ BLOGS TOO CLOSE FOR COMFORT (Sydney Morning Herald, 28 Dec 2005) – Anyone wanting to hear daily insights into what it is like to be in a convoy hit by an explosion or ordered to pick up the body parts of comrades dismembered by a suicide bomber does not have to be there in person any more. Instead they just need to log on to the internet from the safety of their home or office. In a development that is worrying US military commanders in Iraq, a growing number of US soldiers - 200 at the last count - have set up their own blogs, or internet diaries, and are updating them from the battlefield. The phenomenon, helped by internet cafes at almost all US camps to permit soldiers regular contact with home, has for the first time allowed personal reports of the reality of combat to be read as they happen. Most of the sites started as simple diaries intended to keep in touch with friends and family. But some quickly developed a fan base of thousands. Websites now exist to direct viewers to blogs from specific units or locations. It is a phenomenon that has inevitably raised concern among commanders. In April the US military published its first policy memorandum on websites maintained by soldiers, requiring them to have official approval before starting internet postings. In July the first soldier was punished for publishing information considered sensitive, which includes mention of incidents under investigation or names of servicemen killed or wounded. http://www.smh.com.au/news/world/us-military-worried-by-soldiers-blogs/2005/12/27/1135445571736.html

**** RESOURCES ****
Chris Hoofnagle is the West Coast Director for EPIC. This is his consumer privacy top 10 – http://west.epic.org/archives/2005/11/hoofnagles_cons.html

“The new law of information security: What companies need to do now.” – good article by Thomas Smedinghoff -- http://www.technologyexecutivesclub.com/PDFs/ArticlePDFS/infosecurity.pdf

**** IN MEMORIAM ****
My father, Ira Polley, passed away last week at the age of 88. I’ll miss his laugh, outlook, and guidance. More information at http://www.vip-law.com/irapolleyobit.htm

SOURCES:
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. Internet Law & Policy Forum, http://www.ilpf.org.
6. BNA’s Internet Law News, http://ecommercecenter.bna.com.
7. The Ifra Trend Report, http://www.ifra.com/website/ifra.nsf/html/ITR-HTML.
8. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
9. Gordon & Glickson’s Articles of Note, http://www.ggtech.com
10. Readers’ submissions, and the editor’s discoveries.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.