Saturday, March 21, 2009

MIRLN --- 1-21 March 2009 (v12.04)

• Judge Orders Defendant to Decrypt PGP-Protected Laptop
• Media Need Not Reveal Web Posters’ Identities
• Volunteers Put The Economist Into Chinese
• White House Responds to Privacy Complaints?
• Web Behavioral Advertising Goes to Court
o Google to Offer Ads Based on Interests
• Diebold Voting System Has ‘Delete’ Button for Erasing Audit Logs
o Criminals Sneak Card-Sniffing Software on Diebold ATMS
• Obama Picks Net Neutrality Backer as FCC Chief
• Docs Seek Gag Orders to Stop Patients’ Reviews
• Industry Group Drops Effort to Craft Principles for Data Privacy Legislation
• Stimulus Creates New Breach Notification Requirements for Entities that Handle Health Information
• Twitter Boosts Public Access to Federal Courtrooms
o As Jurors Turn to Web, Mistrials Are Popping Up
• Government Cyber Security Chief Resigns Amid Turf War
• Australian Police May Get Hacking Powers
• Sketch Comedy Troupe Proposes a EULA for Friendship
• Companies Get Checklist for Complying with PCI Standard
• CIA, NSA Adopting Web 2.0 Strategies
o Government 2.0 Meets Catch-22
• Court Rules that Disloyal Employees’ Access to Employer’s Information Violated CFAA
• Online Networking More Popular than Email
• Copyright Treaty is Classified for ‘National Security’
• CBS to Offer Upcoming “March Madness” Streaming to iPhone
• Creative Commons Adds a ‘No Copyright At All’ Option
• DC Bar Association Claims Lawyer Rating Site Infringes Its Copyright
• Obama’s Gift to British Prime Minister Rendered Useless by DRM
• Internet Filter List of Porn Exposed

PODCASTS | RESOURCES | LOOKING BACK | NOTES

**** NEWS ****
JUDGE ORDERS DEFENDANT TO DECRYPT PGP-PROTECTED LAPTOP (CNET, 26 Feb 2009) - A federal judge has ordered a criminal defendant to decrypt his hard drive by typing in his PGP passphrase so prosecutors can view the unencrypted files, a ruling that raises serious concerns about self-incrimination in an electronic age. In an abrupt reversal, U.S. District Judge William Sessions in Vermont ruled that Sebastien Boucher, who a border guard claims had child porn on his Alienware laptop, does not have a Fifth Amendment right to keep the files encrypted. “Boucher is directed to provide an unencrypted version of the Z drive viewed by the ICE agent,” Sessions wrote in an opinion last week, referring to Homeland Security’s Immigration and Customs Enforcement bureau. Police claim to have viewed illegal images on the laptop at the border, but say they couldn’t access the Z: drive when they tried again nine days after Boucher was arrested. Boucher’s attorney, Jim Budreau, already has filed an appeal to the Second Circuit. That makes it likely to turn into a precedent-setting case that creates new ground rules for electronic privacy, especially since Homeland Security claims the right to seize laptops at the border for an indefinite period. Budreau was out of the office on Thursday and could not immediately be reached for comment. The Fifth Amendment says nobody can be “compelled in any criminal case to be a witness against himself,” which Magistrate Judge Jerome Niedermeier ruled in November 2007 prevented Boucher from being forced to divulge his passphrase to prosecutors. Originally, the U.S. Department of Justice asked the magistrate judge to enforce a subpoena requiring Boucher to turn over “passwords used or associated with” the computer. In their appeal to Sessions, prosecutors narrowed their request and said they only want Boucher to decrypt the contents of his hard drive before the grand jury, apparently by typing in his passphrase in front of them. At issue in this case is whether forcing Boucher to type in that PGP passphrase--which would be shielded from and remain unknown to the government--is “testimonial,” meaning that it triggers Fifth Amendment protections. The counterargument is that since defendants can be compelled to turn over a key to a safe filled with incriminating documents, or provide fingerprints, blood samples, or voice recordings, unlocking a partially-encrypted hard drive is no different. Barry Steinhardt, director of the ACLU’s technology and liberty program, said on Thursday that the opinion reached the wrong conclusion and that Boucher “should have been able to assert his Fifth Amendment rights. It’s not the same thing as asking him to turn over the Xeroxed copy of a document.” http://news.cnet.com/8301-13578_3-10172866-38.html?tag=pop

MEDIA NEED NOT REVEAL WEB POSTERS’ IDENTITIES (Washington Post, 28 feb 2009) - Operators of newspaper Web sites, blogs and chat rooms that allow readers to post anonymous comments using pseudonyms do not have to readily reveal the posters’ identities in defamation suits, Maryland’s highest court ruled yesterday, further shaping an emerging area of First Amendment law in the Internet age. The Maryland Court of Appeals reversed a lower court ruling and ordered that NewsZap.com, an online forum run by Independent Newspapers, does not have to disclose the identities of forum participants who engaged in an online exchange about the cleanliness of a Dunkin’ Donuts shop in 2006. More broadly, however, the court used the case to recommend a strict, five-step process for judges to follow “to balance the First Amendment right to anonymous speech on the Internet with the opportunity on the part of the object of that speech to seek judicial redress for alleged defamation.” The process, which closely matches one set out by a New Jersey court in 2002, requires a plaintiff claiming defamation from an online comment to try to notify the anonymous poster that the person is the subject of a subpoena -- including by posting a message on the relevant online message board. The plaintiff must then identify in court filings the exact statements purportedly made by each anonymous poster, as well as show how those comments have caused damage. Maryland’s court also went further than New Jersey’s, adding that the plaintiff might have to provide specific evidence supporting each element of the defamation claim. Finally, it indicated that judges also have to balance the anonymous poster’s right of free speech against the need to disclose a defendant’s identity. Sam Bayard, assistant director of the Citizen Media Law Project at Harvard Law School, said that, taken together, this and other recent state court cases show a convergence of law surrounding the right to online anonymity. http://www.washingtonpost.com/wp-dyn/content/article/2009/02/27/AR2009022702876.html?hpid=sec-metro

VOLUNTEERS PUT THE ECONOMIST INTO CHINESE (New York Times, 1 March 2009) - Every day, Chinese fans produce unauthorized translations of Western pop culture products and put them online, like subtitled episodes of “Heroes” or the final Harry Potter novel. But a group calling itself the Eco Team has picked a more cerebral target: the British newsweekly The Economist. Every two weeks, the online Eco Weekly carries two issues of The Economist translated by volunteers. With each new issue, the group’s members work together to sharpen their language skills by translating the magazine from cover to cover. The group meets on a message board at ecocn.org/bbs that is led by Shi Yi, a 39-year-old insurance broker in Beijing. “Different people come from different backgrounds with their own purpose,” Mr. Yi said. “But we all like the style of The Economist.” Thirty to 40 of the group’s members work on each issue, Mr. Yi said. On the message board, they interweave paragraphs of English and Chinese text and collaborate on the translations. The final versions are bundled into Eco Weekly, a publication in the PDF format that is released biweekly and can be freely downloaded and printed. So far, neither the Chinese authorities nor The Economist has tried to stop the noncommercial, volunteer effort. Mr. Yi said that he had met members of the magazine’s staff, including its editor, John Micklethwait, and that they had granted their approval. A spokesman for The Economist, Justin Hendrix, was unable to confirm that arrangement as of Sunday night. http://www.nytimes.com/2009/03/02/business/media/02economist.html?partner=rss&emc=rss

WHITE HOUSE RESPONDS TO PRIVACY COMPLAINTS? (EFF, 2 March 2009) - This morning it seemed that complaints from EFF and other privacy advocates and journalists had apparently helped created a change in White House policy concerning the use of cookies and tracking technologies on whitehouse.gov. We were ready to give kudos to the Obama Administration for listening to privacy advocates, something we rarely get to do. Now the Obama Administration says that their privacy-protective step was just “an experiment.” If so, it’s an experiment we hope they continue. Over the weekend, the White House quietly shifted from using YouTube-hosted videos and delivered the president’s Saturday address using Flash-based video hosted on government servers. As a result, visitors to whitehouse.gov no longer had third party cookies that enable tracking of their web use placed on their computers when they choose to view a video. EFF raised the issue of cookies and other tracking technologies on government sites earlier this year, following reports on the issue from CNet blogger Chris Soghoian and Columbia professor Steve Bellovin. In a letter to White House Counsel Gregory Craig, we asked the Obama administration to find a technical solution that would protect the privacy of visitors to government sites and also requested the waivers given to whitehouse.gov that allowed it to circumvent long-standing rules that bar the use of cookies on government sites, as well as supporting information. http://www.eff.org/deeplinks/2009/03/white-house-responds-privacy-complaints

WEB BEHAVIORAL ADVERTISING GOES TO COURT (Law.com, 2 March 2009) - Big Brother may be at it again. Behavioral advertising -- the tracking of consumer’s Internet surfing activity to create tailored ads -- has triggered an intense legal controversy that has law firms scrambling to stay on top of a burgeoning practice. Attorneys say that behavioral advertising is raising privacy, litigation and regulation fears among consumer advocates, the electronic commerce and advertising industries and legislators. Law firms are busy helping companies come up with a transparent way of letting consumers know that their online activities are being tracked and possibly shared. “Lawmakers and companies are having a tough time keeping up with this new frontier of Internet privacy issues, and there is growing consumer unrest about behavioral advertising, leading in some cases to consumer rebellion,” said Lisa Sotto, a partner and head of the privacy and security data group in the New York office of Richmond, Va.-based Hunton & Williams. “Consumers find this type of tracking intrusive, and businesses are starting to take the consumer reaction seriously,” she said. The buzz over behavioral advertising has been building since congressional hearings that were held last year, during which Congress called on Internet service providers (ISPs) to testify about a highly controversial advertising practice known as “deep-packet inspection.” Meanwhile, the Federal Trade Commission this month released a report in which it announced that it would adhere to its self-regulation policy when it comes to behavior advertising -- at least for now. Within the report, the FTC also released revised behavioral-advertising guidelines calling for more rigorous self-policing, and it strongly advised the industry to follow the guidelines or brace for more regulation and legislation. Those guidelines call for more disclosure and transparency with consumers about tracking and data-collection practices, the ability of consumers to choose whether to allow data collection, and keeping promises regarding the use of consumer data. They also suggest that companies store data “only as long as is necessary to fulfill a legitimate business or law enforcement need.” And when obtaining sensitive data, consent must be obtained. Attorneys note that it’s the collection of sensitive data -- such as financial, health and other personal information -- that has fueled privacy fears with regard to behavioral advertising. “The bigger concern is what happens with this data ... . Not only do you not know what information is being collected, you don’t know who is collecting it,” said Jacqueline Klosek, counsel to the privacy and data security practice in the New York office of Boston’s Goodwin Procter, who advises business clients about complying with FTC guidelines. http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202428691751&rss=newswire

- and -

GOOGLE TO OFFER ADS BASED ON INTERESTS (New York Times, 11 March 2009) - Google will begin showing ads on Wednesday to people based on their previous online activities in a form of advertising known as behavioral targeting, which has been embraced by most of its competitors but has drawn criticism from privacy advocates and some members of Congress. Perhaps to forestall objections to its approach, Google said it planned to offer new ways for users to protect their privacy. Most notably, Google will be the first major company to give users the ability to see and edit the information that it has compiled about their interests for the purposes of behavioral targeting. Like rivals such as Yahoo, it also will give users the choice to opt out from what it calls “interest-based advertising.” Google will use a cookie, a small piece of text that resides inside a Web browser, to track users as they visit one of the hundreds of thousands of sites that show ads through its AdSense program. Google will assign those users to categories based on the content of the pages they visit. For example, a user may be pegged as a potential car buyer, sports enthusiast or expectant mother. Google will then use that information to show people ads that are relevant to their interests, regardless of what sites they are visiting. An expectant mother may see an ad about baby products not only on a parenting site but also, for example, on a sports or fashion site that uses AdSense or on YouTube, which is owned by Google. Google said that it planned to segment users along 20 categories and nearly 600 subcategories, and would not create categories for certain “sensitive” interests, including race, religion, sexual orientation or certain types of financial or health concerns. It does not plan to associate the cookie of users with search data or with information from other Google services, like Gmail. Google won’t notify users that it has begun to show them ads based on their behavior, but users who click on the “Ads By Google” link, which appears on thousands of Web pages, will be taken to a site where the technique is explained. There, they will also be able to tap into what Google calls the Ads Preferences Manager, to see and edit the ad categories that have been associated with their browser. http://www.nytimes.com/2009/03/11/technology/internet/11google.html?_r=1&ref=technology [The Google explanation appears to be here: http://www.google.com/ads/preferences]

DIEBOLD VOTING SYSTEM HAS ‘DELETE’ BUTTON FOR ERASING AUDIT LOGS (Wired, 3 March 2009) - After three months of investigation, California’s secretary of state has released a report examining why a voting system made by Premier Election Solutions (formerly known as Diebold) lost about 200 ballots in Humboldt County during November’s presidential election. But the most startling information in the state’s 13-page report (.pdf) is not why the system lost votes, which Wired.com previously covered in detail, but that some versions of Diebold’s vote tabulation system, known as the Global Election Management System (Gems), include a button that allows someone to delete audit logs from the system. Auditing logs are required under the federal voting-system guidelines, which are used to test and qualify voting systems for use in elections. The logs record changes and other events that occur on voting systems to ensure the integrity of elections and help determine what occurred in a system when something goes wrong. “Deleting a log is something that you would only do in de-commissioning a system you’re no longer using or perhaps in a testing scenario,” said Princeton University computer scientist Ed Felten, who has studied voting systems extensively. “But in normal operation, the log should always be kept.” Yet the Diebold system in Humboldt County, which uses version 1.18.19 of Gems, has a button labeled Clear, that “permits deletion of certain audit logs that contain — or should contain — records that would be essential to reconstruct operator actions during the vote-tallying process,” according to the California report. The button is positioned next to the Print and Save As buttons (see image above), making it easy for an election official to click on it by mistake and erase crucial logs. In fact, the report says, this occurred recently in a California county when an official, while attempting to print out a copy of a so-called “poster log,” inadvertently deleted it instead. http://blog.wired.com/27bstroke6/2009/03/ca-report-finds.html

- and -

CRIMINALS SNEAK CARD-SNIFFING SOFTWARE ON DIEBOLD ATMS (ComputerWorld, 17 March 2009) - Diebold Inc. has released a security fix for its Opteva automated teller machines after cybercriminals apparently broke into the systems at one or more businesses in Russia and installed malicious software. Diebold learned of the incident in January and sent out a global security update to its ATM customers using the Windows operating system. It is not releasing full details of what happened, including which businesses were affected, but said criminals had gained physical access to the machines to install their malicious program. After studying samples submitted to the VirusTotal Web site, security vendor Sophos reported Tuesday that the code has been in circulation since at least November 2008. http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9129819&source=NLT_AM

OBAMA PICKS NET NEUTRALITY BACKER AS FCC CHIEF (CNET, 3 March 2009) - President Obama on Tuesday nominated Julius Genachowski as the nation’s top telecommunications regulator, picking a campaign advisor who has divided his career between Washington, D.C., political jobs and working as an Internet executive. Genachowski had been mentioned as a likely candidate for the Federal Communications Commission post, in part because he participated in the Obama campaign’s Internet efforts and previously worked as chief counsel to Democratic FCC Chairman Reed Hundt. http://news.cnet.com/8301-13578_3-10187067-38.html

DOCS SEEK GAG ORDERS TO STOP PATIENTS’ REVIEWS (AP, 4 March 2009) - The anonymous comment on the Web site RateMDs.com was unsparing: “Very unhelpful, arrogant,” it said of a doctor. “Did not listen and cut me off, seemed much too happy to have power (and abuse it!) over suffering people.” Such reviews are becoming more common as consumer ratings services like Zagat’s and Angie’s List expand beyond restaurants and plumbers to medical care, and some doctors are fighting back. They’re asking patients to agree to what amounts to a gag order that bars them from posting negative comments online. “Consumers and patients are hungry for good information” about doctors, but Internet reviews provide just the opposite, contends Dr. Jeffrey Segal, a North Carolina neurosurgeon who has made a business of helping doctors monitor and prevent online criticism. Some sites “are little more than tabloid journalism without much interest in constructively improving practices,” and their sniping comments can unfairly ruin a doctor’s reputation, Segal said. Segal said such postings say nothing about what should really matter to patients — a doctor’s medical skills — and privacy laws and medical ethics prevent leave doctors powerless to do anything it. His company, Medical Justice, is based in Greensboro, N.C. For a fee, it provides doctors with a standardized waiver agreement. Patients who sign agree not to post online comments about the doctor, “his expertise and/or treatment.” “Published comments on Web pages, blogs and/or mass correspondence, however well intended, could severely damage physician’s practice,” according to suggested wording the company provides. Segal’s company advises doctors to have all patients sign the agreements. If a new patient refuses, the doctor might suggest finding another doctor. Segal said he knows of no cases where longtime patients have been turned away for not signing the waivers. Doctors are notified when a negative rating appears on a Web site, and, if the author’s name is known, physicians can use the signed waivers to get the sites to remove offending opinion. http://news.yahoo.com/s/ap/20090304/ap_on_he_me/med_gagging_patients;_ylt=AggTrqnvCNj.mAbu6TaBAYADW7oF

INDUSTRY GROUP DROPS EFFORT TO CRAFT PRINCIPLES FOR DATA PRIVACY LEGISLATION (BNA’s Internet Law News, 5 March 2009) - BNA’s Electronic Commerce & Law Report reports that an industry coalition that includes leading technology companies, such as Microsoft Corp., has decided to abandon efforts to develop a set of principles for omnibus U.S. privacy legislation. Instead, the coalition is now focused on crafting an industry-wide self-regulatory framework that can be tested over time with a broad range of organizations that collect and use consumers’ personal data, according to Microsoft Chief Privacy Strategist Peter Cullen.

STIMULUS CREATES NEW BREACH NOTIFICATION REQUIREMENTS FOR ENTITIES THAT HANDLE HEALTH INFORMATION (Steptoe & Johnson’s E-Commerce Law Week, 5 March 2009) - There’s something for everyone in President Obama’s stimulus package -- including advocates of improved data security for health records. Subtitle D of Title XIII of the American Recovery and Reinvestment Act of 2009 (ARRA) requires entities that are covered by the Health Insurance Portability and Accountability Act (HIPAA) and suffer a breach of “unsecured protected health information” to notify all affected individuals “without unreasonable delay and in no case later than 60 calendar days after the discovery of a breach.” The ARRA also requires covered entities to “immediately” notify the Secretary of the Department of Health and Human Services if the breach involves “500 or more individuals”; smaller breaches must be recorded in a log and submitted to the Secretary annually. The ARRA’s breach notification requirements also apply to several entities that are not covered by HIPAA, including “vendors of personal health records,” “entities that offer products or services through the website” of such a vendor, and “entities that access information in a personal health record or send information to a personal health record.” However, instead of notifying the HHS Secretary, these entities are required to notify the Federal Trade Commission if they suffer a breach of any size; the FTC will then relay this notification to the HHS Secretary. These breach notification requirements are effective 30 days after the HHS Secretary (for HIPAA entities) or FTC (for non-HIPAA entities) publish implementing regulations. http://www.steptoe.com/publications-5965.html

TWITTER BOOSTS PUBLIC ACCESS TO FEDERAL COURTROOMS (AP, 6 March 2009) - In a victory for news technology in federal courts, a judge is allowing a reporter to use the microblogging service Twitter to provide constant updates from a racketeering gang trial this week. It’s not the first time online streaming has been allowed in courtrooms, but the practice is still rare in the federal system, especially in criminal cases. A couple of lawyers voiced concern about the possibility that a juror might visit the online site to read the posts from Ron Sylvester, a reporter for the Wichita Eagle, but U.S. District Judge J. Thomas Marten said jurors are always told to avoid newspaper, broadcast and online reports. Sylvester has been using Twitter for a year to cover hearings and trials in state courts, but the racketeering trial of six Crips gang defendants that he’s covering online this week is his first in federal court. Among those who have signed up to follow Sylvester’s Twitter posts is the father of one of the defendants. He lives in Houston, Sylvester said, and can’t attend the trial. Across the country, tech-savvy federal judges are becoming increasingly receptive to live courtroom media coverage using emerging technologies. Such coverage from journalists reporting from trials in state courts is already common. Federal judges have wide discretion on how to run trials when it comes to emerging online technologies. http://news.yahoo.com/s/ap/20090306/ap_on_re_us/courtroom_tweets_4

- but -

AS JURORS TURN TO WEB, MISTRIALS ARE POPPING UP (New York Times, 17 March 2009) - Last week, a juror in a big federal drug trial in Florida admitted to the judge that he had been doing research on the case on the Internet, directly violating the judge’s instructions and centuries of legal rules. But when the judge questioned the rest of the jury, he got an even bigger shock. Eight other jurors had been doing the same thing. The federal judge, William J. Zloch, had no choice but to declare a mistrial, a waste of eight weeks of work by federal prosecutors and defense lawyers. It might be called a Google mistrial. The use of BlackBerrys and iPhones by jurors gathering and sending out information about cases is wreaking havoc on trials around the country, upending deliberations and infuriating judges. Last week, a building products company asked an Arkansas court to overturn a $12.6 million judgment, claiming that a juror used Twitter to send updates during the civil trial. And on Monday, defense lawyers in the federal corruption trial of a former Pennsylvania state senator, Vincent J. Fumo, demanded before the verdict that the judge declare a mistrial because a juror posted updates on the case on Twitter and Facebook. The juror had even told his readers that a “big announcement” was coming on Monday. But the judge decided to let the deliberations continue, and the jury found Mr. Fumo guilty. His lawyers plan to use the Internet postings as grounds for appeal. Jurors are not supposed to seek information outside of the courtroom. They are required to reach a verdict based on only the facts the judge has decided are admissible, and they are not supposed to see evidence that has been excluded as prejudicial. But now, using their cellphones, they can look up the name of a defendant on the Web or examine an intersection using Google Maps, violating the legal system’s complex rules of evidence. They can also tell their friends what is happening in the jury room, though they are supposed to keep their opinions and deliberations secret. “It’s really impossible to control it,” said Douglas L. Keene, president of the American Society of Trial Consultants. Judges have long amended their habitual warning about seeking outside information during trials to include Internet searches. But with the Internet now as close as a juror’s pocket, the risk has grown more immediate — and instinctual. Attorneys have begun to check the blogs and Web sites of prospective jurors. http://www.nytimes.com/2009/03/18/us/18juries.html?_r=1&ref=us

GOVERNMENT CYBER SECURITY CHIEF RESIGNS AMID TURF WAR (Washington Post, 9 March 2009) - The federal government’s director for cyber security has resigned after less than a year on the job, citing a lack of support and funding, and an over-reliance on the National Security Agency for combating threats to the nation’s computer systems. Former Silicon Valley entrepreneur Rod A. Beckstrom said in his resignation letter to Department of Homeland Security Secretary Janet Napolitano, a copy of which was published by The Wall Street Journal on Friday, that it was a “bad strategy” to give the NSA such a dominant role. Beckstrom was appointed last March to head the National Cyber Security Center, a new inter-agency group charged with coordinating the federal government’s efforts to protect its computer networks from organized cyber attacks. But recently, Beckstrom said, efforts have been underway to fold his group into a facility at the NSA. Reached by phone Sunday evening, Beckstrom confirmed that his last day would be March 13. He declined to veer far from the points he laid out in his letter, but said the purpose of his group was to coordinate -- not be subsumed by -- cyber efforts of various federal agencies. “This is a coordination body and it resides alongside or above the other centers, but certainly not below them,” Beckstrom said. “In my view, it is very important that there be independence for the NCSC, and that it be able to carry out its role.” http://www.washingtonpost.com/wp-dyn/content/article/2009/03/09/AR2009030901213.html?wprss=rss_technology

AUSTRALIAN POLICE MAY GET HACKING POWERS (CNET, 9 March 2009) - The government of the Australian state of New South Wales has unveiled plans to give state police the power to hack into computers remotely, with owners potentially remaining in the dark about the searches for up to three years. The new powers are part of a package introduced into parliament last week by Premier Nathan Rees. Broadly, they aim to give police the right to apply for covert search warrants from the Supreme Court to gather evidence in cases that could involve serious indictable offenses punishable by at least seven years’ imprisonment. Judges issuing the new warrants could authorize owners not being told about the searches for up to three years (under exceptional circumstances), NSW Police Minister Tony Kelly said in a statement, with police having to apply for several extensions to get the full period. Rees said the laws would enable computers to be searched, including access to “computers networked to a computer at the premises being searched.” “Police will also be able to gain remote access to computers for seven days at a time, up to a total of 28 days or longer in exceptional circumstances, to allow them, to undertake forensic off-site examiniation,” Rees said. Offenses covered by the new laws include the supply, manufacture, or cultivation of drugs; possession, manufacture or sale of firearms; money laundering; car or boat re-birthing; and unauthorized access to or modification of computer data or electronic communications. Also included are theft (if carried out on an organized basis); violence causing grievous bodily harm or wounding; possession, manufacture or supply of false instruments; corruption; destruction of property; homicide; and kidnapping. The news comes after similar moves in Europe have recently been gathering pace. For example, in January the U.K. government said it had agreed to work with the European Union parliament on plans to extend police powers to conduct remote searches of computers. http://news.cnet.com/8301-1009_3-10191514-83.html

SKETCH COMEDY TROUPE PROPOSES A EULA FOR FRIENDSHIP (Boing Boing, 9 March 2009) - AlexanderDitto sez, “This week’s LoadingReadyRun video addresses combining restrictive End-User License Agreements with Friendships. Results: pain. Also laughs!” http://blip.tv/file/1857716 and http://loadingreadyrun.com/videos/view/420/-Terms-of-Friendship [Editor: very funny.]

COMPANIES GET CHECKLIST FOR COMPLYING WITH PCI STANDARD (Network World, 10 March 2009) - The organization responsible for administering the Payment Card Industry Data Security Standard is offering new guidance to companies on how to focus their PCI DSS compliance efforts so as to more quickly them in position to meet the rules on protecting credit and debit card data. PCI Security Standards Council LLC, which was set up by Visa, MasterCard, American Express and other credit-card companies in 2006, last week released a document detailing a Prioritized Approach framework that lists the most efficient order for companies to implement the 12 security controls mandated under PCI DSS. The framework groups the controls under six specific milestones that companies can use as a road map towards compliance, according to council officials. http://www.networkworld.com/news/2009/031009-companies-get-checklist-for-complying.html?nlhtsec=rn_031109&nladname=031109securityal Framework document here: https://www.pcisecuritystandards.org/education/docs/Prioritized_Approach_PCI_DSS_1_2.pdf

CIA, NSA ADOPTING WEB 2.0 STRATEGIES (Information Week, 10 March 2009) - While the United States intelligence community may have gotten a lot of publicity for its Wikipedia-like Intellipedia Web site, agencies like the Central Intelligence Agency and National Security Agency are ramping up their use of other social and Web-inspired software as well. Intellipedia has been a success -- with 830,000 pages, it’s the crown jewel of the intelligence community’s proof that information sharing is better in the wake of the 9/11 attacks -- but Michael Kennedy, director of enterprise solutions for the intelligence community, said the government can’t rest on its laurels. He admits criticism that Intellipedia has matured, and while it remains a centerpiece, he said the government also needs to keep moving onto the next big thing. We talked with Tim Breidigan, Eventful VP business development, about the service and how it helps connect users and events. “We don’t know what the next great tool is going to be for the users,” he said during a panel discussion Tuesday at the FOSE conference in Washington, D.C. “We just know there will be one very soon, and we want to be there, whatever it is.” For example, intelligence agency employees now exchange about 5 million daily instant messages via Jabber and IBM Sametime. A search engine based on Google technologies has indexed 92 million documents and handles 2 million queries every month. A new site allows employees to share and analyze photos and videos of events like a test last year that destroyed a failing satellite with a missile. This year, the community is working on a number of new initiatives, such as ramping up search capabilities. For example, the agencies are now working with a vendor -- Kennedy wouldn’t say who -- that provides it with the ability to draw a picture and then search for similar images. Semantic search capabilities to analyze sentiment and summarize documents are coming soon, too, but for now Kennedy and his colleagues aren’t yet confident in the ability of commercial tools on which it will rely. Another key focus for the intelligence community’s social and information-sharing initiatives this year is a common one: SharePoint. “It’s one of those products we can’t get by without anymore,” Kennedy said, adding that SharePoint is used for everything from unclassified to highly classified intelligence. Kennedy and his colleagues hope the new tools will accelerate problem solving, since intelligence agency employees can now immediately post and share information they are receiving about events, and since the tools can bring subject matter experts like a CIA agent and an NSA signal intelligence analyst together to work on documents and analysis more deeply than they may have been able to do in the past. http://www.informationweek.com/news/internet/web2.0/showArticle.jhtml?articleID=215801627&cid=RSSfeed_IWK_News

- and -

GOVERNMENT 2.0 MEETS CATCH 22 (New York Times, 17 March 2009) - “Do I need to P.I.A. Facebook?” said the perplexed bureaucrat squished into a narrow basement hotel conference room in Washington DC. P.I.A. stands for Privacy Impact Assessment, a procedure that federal agencies must go through every time they create a new computer system. It was one of many questions about how the government can use the tools of Web 2.0 raised in a session of a privacy conference last week. Organizations of all sorts have been trying to figure out how they can adapt social networks, blogs, wiki’s and other Web tools to their traditional operating methods in order to connect to customers and partners. But it is tough. “We have a Facebook page,” said one official of the Department of Homeland Security. “But we don’t allow people to look at Facebook in the office. So we have to go home to use it. I find this bizarre.” There are many other procedures at government agencies that aren’t just tradition, they are the law. For example, the mostly harmless feature of Facebook that allows users to specify their religious and political views, may run afoul of the Privacy Act. That law prevents the government from using the site because a provision in the Privacy Act bans it from keeping records related to how people exercise their first amendment rights. “We are stodgier” than the private sector, said Alex Joel, the civil liberties protection officer for the Office of the Director of National Intelligence, who moderated the session at the annual meeting of the International Association of Privacy Professionals, the trade group for corporate and government privacy officers. “We have our own way of doing things.” Speaking of the First Amendment, one person asked, does the government have the right to remove offensive comments on a blog or social network page? And if it does, must it keep copies of the deleted material under the Federal Records Act and provide them to people making Freedom of Information Act Requests? Yes, it can remove comments that violate posted policies about decency and so on, and yes, it must keep them for a specified time, other participants said. http://bits.blogs.nytimes.com/2009/03/17/government-20-meets-catch-22/

COURT RULES THAT DISLOYAL EMPLOYEES’ ACCESS TO EMPLOYER’S INFORMATION VIOLATED CFAA (Steptoe & Johnson’s E-Commerce Law Week, 12 March 2009) - Another court has weighed in on whether a disloyal employee’s use of his employer’s computer system is “without authorization” or “exceed[s] authorized access,” in violation of the Computer Fraud and Abuse Act (CFAA), and whether “lost business” constitutes a cognizable loss under the statute. Courts have reached conflicting decisions on both questions. In Ervin & Smith Advertising and Public Relations, Inc. v. Ervin, a federal court in Nebraska ruled in favor of the plaintiff employer on both issues, finding that employees who access company computers for personal gain and against the employer’s interests exceed their authorized access, and that any resulting loss of business is a cognizable loss under the CFAA. Resolution of the split in the courts on these issues seems unlikely anytime soon, underscoring the importance to employers of a friendly venue and careful pleading. http://www.steptoe.com/publications-5982.html Ruling here: http://www.steptoe.com/assets/attachments/3745.pdf

ONLINE NETWORKING MORE POPULAR THAN EMAIL (Washington Post, 12 March 2009) - Are you spending hours and hours on Facebook? If so, you are not alone. Networking and blogging sites account for almost ten percent of time spent on the internet -- more than on email. Time on the sites ranked fourth, after online searching, general interest sites, and software sites, according to a study released by Nielsen Online. One in every 11 minutes spent online globally is on networking sites. Between December 2007 and December 2008, the time spent on the sites climbed 63 percent to 45 billion minutes. The figure was even higher for the world’s most popular networking site, Facebook, where members spent 20.5 billion minutes, up 566 percent from 3.1 percent the previous year, according to the study. http://www.washingtonpost.com/wp-dyn/content/article/2009/03/12/AR2009031200223.html

COPYRIGHT TREATY IS CLASSIFIED FOR ‘NATIONAL SECURITY’ (CNET, 12 March 2009) - Last September, the Bush administration defended the unusual secrecy over an anti-counterfeiting treaty being negotiated by the U.S. government, which some liberal groups worry could criminalize some peer-to-peer file sharing that infringes copyrights. Now President Obama’s White House has tightened the cloak of government secrecy still further, saying in a letter this week that a discussion draft of the Anti-Counterfeiting Trade Agreement and related materials are “classified in the interest of national security pursuant to Executive Order 12958.” The 1995 Executive Order 12958 allows material to be classified only if disclosure would do “damage to the national security and the original classification authority is able to identify or describe the damage.” Jamie Love, director of the nonprofit group Knowledge Ecology International, filed the Freedom of Information Act request that resulted in this week’s denial from the White House. The denial letter was sent to Love on Tuesday by Carmen Suro-Bredie, chief FOIA officer in the White House’s Office of the U.S. Trade Representative. Love had written in his original request on January 31--submitted soon after Obama’s inauguration--that the documents “are being widely circulated to corporate lobbyists in Europe, Japan, and the U.S. There is no reason for them to be secret from the American public.” The White House appears to be continuing the secretive policy of the Bush administration, which wrote to the Electronic Frontier Foundation (PDF) on January 16 that out of 806 pages related to the treaty, all but 10 were “classified in the interest of national security pursuant to Executive Order 12958.” http://news.cnet.com/8301-13578_3-10195547-38.html

CBS TO OFFER UPCOMING “MARCH MADNESS” STREAMING TO IPHONE (ArsTechnica, 13 March 2009) - As Divison I men’s college basketball teams are fighting for the right to play in the tournament that will eventually crown the national champion, CBS has released an iPhone application that will stream audio and or video of every game, depending on the available connection. Beginning on March 19, customers who purchase the application for $4.99 will be able to stream live audio of all games over 3G or EDGE, or audio and video over WiFi. CBS March Madness On Demand will give fans up-to-the-moment scores, bracket results, and highlights. The release comes on the heels of announcements that Silverlight will be powering the streaming of the tournament on the Web, and that EA would have a special XBox Live version of NCAA Basketball especially for the tournament. http://arstechnica.com/apple/news/2009/03/cbs-to-offer-upcoming-march-madness-streaming-to-iphone-1.ars

CREATIVE COMMONS ADDS A ‘NO COPYRIGHT AT ALL’ OPTION (TechDirt, 13 March 2009) - Just two months ago, we were pointing out how difficult it was to opt-out of copyright and put content into the public domain. We noted that it wasn’t solved by Creative Commons -- who had a series of licenses that all relied on copyright, and none that removed all restrictions. Looks like the CC folks were listening (not to me, necessarily, but to others who raised similar issues). They have now released a new offering to help content creators declare their work to be in the public domain. They’re calling it CC0. While it looks just like other CC licenses, it’s not actually a “license,” but a waiver/declaration that the content is in the public domain. http://techdirt.com/articles/20090312/1534364096.shtml

DC BAR ASSOCIATION CLAIMS LAWYER RATING SITE INFRINGES ITS COPYRIGHT (TechDirt blog, 17 March 2009) - There’s been no shortage of stories about misplaced anger (and sometimes lawsuits) filed against all kinds of rating sites lately, and the latest situation is equally questionable. Against Monopoly points us to the news that the Washington DC Bar Association has sent a cease-and-desist letter to lawyer-rating site, Avvo, claiming that Avvo’s use of information on the DC Bar’s website violates copyright and privacy rights. It would be great if some lawyers chimed in, but I have a hard time seeing either claim making any sense. On the copyright side, the information appears to mostly be factual information, which isn’t covered by copyright. On the privacy side (and local privacy laws do differ), if the information is public information, it’s difficult again to explain how anyone’s privacy is being violated. http://techdirt.com/articles/20090312/1718164101.shtml

OBAMA’S GIFT TO BRITISH PRIME MINISTER RENDERED USELESS BY DRM (TechDirt, 19 March 2009) - A few years back, it emerged that US Senator Ted Stevens had been given an iPod by his daughter, and it had changed the way he saw the RIAA and the measures for which it lobbied. It’s always seemed to me that once politicians -- at least those not beholden to the entertainment industry -- experienced the stupidity and frustration of the locks and controls that groups like the RIAA and MPAA put on content and want backed up by law, they’d realize they were little more than attempts to frustrate consumers and prop up outmoded business models. Maybe the UK is prepared for a similar political inflection point: its Prime Minister, Gordon Brown, was recently given a gift of 25 DVDs of classic American movies by US President Barack Obama. When Brown sat down to watch one of them, he found he couldn’t -- because Obama had given him Region 1 DVDs, unplayable in Brown’s Region 2 DVD player. http://techdirt.com/articles/20090319/1337464182.shtml

INTERNET FILTER LIST OF PORN EXPOSED (Australian IT, 20 March 2009) - THE Rudd Government’s plans for a nationwide internet filter are in jeopardy after its top-secret blacklist of banned web pages was leaked. The list, published on the internet, reads like a White Pages of porn and its release has provided a handy guide for young people to access the very material the Government wishes to banish from their eyes. The secret blacklist, which was leaked to the whistle-blower website Wikileaks, is purportedly the same list the Australian Communications and Media Authority distributes to vendors of approved internet filters to ban offensive material -- such as child pornography, bestiality and violence. ACMA and Communications Minister Stephen Conroy yesterday attempted to hose down concerns about the published blacklist, saying it was not the official list used by the communications regulator. Of the 2395 web pages on the leaked list, approximately half relate to child porn -- one of the key targets of the federal Government’s planned mandatory internet filter. Many more web pages relate to online poker sites, YouTube links, pornography sites, Wikipedia entries and even links to a Queensland boarding kennel and a Queensland dentist. “While Wikileaks is used to exposing secret government censorship in developing countries, we now find Australia acting like a democratic backwater,” the website notes. http://www.australianit.news.com.au/story/0,24897,25214571-15306,00.html

**** NOTED PODCASTS ****
PATTIE MAES & PRANAV MISTRY: UNVEILING THE “SIXTH SENSE,” GAME-CHANGING WEARABLE TECH (TED Talks, Feb 2009) - This 9-minute demo -- from Pattie Maes’ lab at MIT, spearheaded by Pranav Mistry -- was the buzz of TED. It’s a wearable device with a projector that paves the way for profound interaction with our environment. Imagine “Minority Report” and then some. http://www.ted.com/index.php/talks/pattie_maes_demos_the_sixth_sense.html [Editor: wow!]

SECURING PERSONAL DATA IN THE GLOBAL ECONOMY (FTC, 16-17 March 2009) - The United States Federal Trade Commission (FTC), along with co-organizers APEC and OECD, held an international conference on March 16-17, 2009 on the trans-border aspects of data security. This conference, first discussed at an OECD brainstorming session to identify current global privacy challenges, brought together regulators and civil enforcers, consumer advocates, industry representatives, technology experts, and academics from around the world to address these issues. The conference focused in particular on business organization’s data security practices in a global economy, rather than on the law enforcement and criminal law dimensions of the issue. [Windows Media Player streams of the panel programs is available here (for free): http://htc-01.media.globix.net/COMP008760MOD1/ftc_web/FTCindex.html#Mar16_09; see, e.g., the segment on “Data Security Practices in Industry”]

**** RESOURCES ****
SURVEILLANCE SELF DEFENSE (EFF, March 2009) - The Electronic Frontier Foundation (EFF) has created this Surveillance Self-Defense site to educate the American public about the law and technology of government surveillance in the United States, providing the information and tools necessary to evaluate the threat of surveillance and take appropriate steps to defend against it. Surveillance Self-Defense (SSD) exists to answer two main questions: What can the government legally do to spy on your computer data and communications? And what can you legally do to protect yourself against such spying? After an introductory discussion of how you should think about making security decisions — it’s all about risk management — we’ll be answering those two questions for three types of data: First, we’re going to talk about the threat to the data stored on your computer posed by searches and seizures by law enforcement, as well as subpoenas demanding your records. Second, we’re going to talk about the threat to your data on the wire — that is, your data as it’s being transmitted — posed by wiretapping and other real-time surveillance of your telephone and Internet communications by law enforcement. Third, we’re going to describe the information about you that is stored by third parties like your phone company and your Internet service provider, and how law enforcement officials can get it. In each of these three sections, we’re going to give you practical advice about how to protect your private data against law enforcement agents. https://ssd.eff.org/

LEGAL GUIDE FOR BLOGGERS (EFF, February 2009) - Whether you’re a newly minted blogger or a relative old-timer, you’ve been seeing more and more stories pop up every day about bloggers getting in trouble for what they post. Like all journalists and publishers, bloggers sometimes publish information that other people don’t want published. You might, for example, publish something that someone considers defamatory, republish an AP news story that’s under copyright, or write a lengthy piece detailing the alleged crimes of a candidate for public office. The difference between you and the reporter at your local newspaper is that in many cases, you may not have the benefit of training or resources to help you determine whether what you’re doing is legal. And on top of that, sometimes knowing the law doesn’t help - in many cases it was written for traditional journalists, and the courts haven’t yet decided how it applies to bloggers. But here’s the important part: None of this should stop you from blogging. Freedom of speech is the foundation of a functioning democracy, and Internet bullies shouldn’t use the law to stifle legitimate free expression. That’s why EFF created this guide, compiling a number of FAQs designed to help you understand your rights and, if necessary, defend your freedom. http://www.eff.org/issues/bloggers/legal

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
ECHELON, THE UK-USA COMMUNICATIONS MONITORING PROGRAM INVESTIGATED BY CONGRESSIONAL PANEL -- Echelon is one name of the analysis programs developed by the US and British intelligence organizations to monitor voice and data messages throughout the world. Two weeks ago, the House Committee on Intelligence requested that the NSA and CIA provide a detailed report outlining the legal standards used to monitor communication of American citizens. http://www.nytimes.com/library/tech/99/05/cyber/articles/27network.html

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, February 28, 2009

MIRLN --- 8-28 February 2009 (v12.03)

• Ponemon Study Shows Data Breach Costs Continue to Rise
• Lords: Rise of CCTV is Threat to Freedom
• NIST Updates Recommendations for IT Security Controls
• Change You Can Download
• ABA Social Network Fails to Connect
• Web 2.0 Defamation Lawsuits Multiply
• Congressman’s Twittering Raises Security Concerns
• More than 150 Banks Affected by Heartland Data Breach Thus Far
• Video Site’s Investors Not, On Role Alone, Liable for Alleged Infringements
• YouTube Goes Offline
• In ‘Fig Leaf’ Settlement with Jones Day, Website Agrees to Adjust Use of Links
• Where You’ve Been on Net Not Private, Canadian Judge Rules
• E-Invoicing in Europe
• How Attackers Use Your Metadata Against You
• Massachusetts Extends Compliance Deadline on Data Security Rules – Again
• Ninth Circuit Makes it More Difficult for Individuals to Challenge Government Searches of the Workplace
• As Data Collecting Grows, Privacy Erodes
• Facebook’s Users Ask Who Owns Information
o Facebook Backtracks on Terms of Use After Protests
o Facebook Opens Governance of Service and Policy Process to Users
• Let My Board and Me Become As One: The Wii Balance Board/Google Earth Mashup
• Visual Computer Forensic Analysis
• CVS Caremark Settles FTC Charges: Failed to Protect Medical and Financial Privacy of Customers and Employees; CVS Pharmacy Also Pays $2.25 Million to Settle Allegations of HIPAA Violations
• DHS Names Chief Privacy Officer
• Surprise: America is No. 1 in Broadband
• Exiting Workers Taking Confidential Data With Them
• Cybersecurity Audit Guidelines Recommended
• Listen Up and Discover Audio Recordings
• Ten Steps for Mitigating Data Risk During a Merger
• Posting YouTube Video Without Subjects’ Consent Draws Fine From Spanish DPA
• Obama Administration Supports Telco Spy Immunity
• Judge Orders Defendant to Decrypt PGP-Protected Laptop


LOOKING BACK | PODCASTS | NOTES

**** NEWS ****

PONEMON STUDY SHOWS DATA BREACH COSTS CONTINUE TO RISE (PGP Corporation, February 2009) - PGP Corporation, a global leader in enterprise data protection, and the Ponemon Institute, a privacy and information management research firm, today announced results of the fourth annual U.S. Cost of a Data Breach Study. According to the study which examined 43 organizations across 17 different industry sectors, data breach incidents cost U.S. companies $202 per compromised customer record in 2008, compared to $197 in 2007. Within that number, the largest cost increase in 2008 concerns lost business created by abnormal churn, meaning turnover of customers. Since the study’s inception in 2005, this cost component has grown by more than $64 on a per victim basis, nearly a 40% increase. The annual U.S. Cost of Data Breach Study tracks a wide range of cost factors, including expensive outlays for detection, escalation, notification and response along with legal, investigative and administrative expenses, customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit monitoring subscriptions. http://www.pgp.com/insight/newsroom/press_releases/2008_annual_study_cost_of_data_breach.html [There are separate studies for the US, the UK, and Germany – download them here: http://www.encryptionreports.com/]

LORDS: RISE OF CCTV IS THREAT TO FREEDOM (The Guardian, 6 Feb 2009) - The steady expansion of the “surveillance society” risks undermining fundamental freedoms including the right to privacy, according to a House of Lords report published today. The peers say Britain has constructed one of the most extensive and technologically advanced surveillance systems in the world in the name of combating terrorism and crime and improving administrative efficiency. The report, Surveillance: Citizens and the State, by the Lords’ constitution committee, says Britain leads the world in the use of CCTV, with an estimated 4m cameras, and in building a national DNA database, with more than 7% of the population already logged compared with 0.5% in the America. The cross-party committee which includes Lord Woolf, a former lord chief justice, and two former attorneys general, Lord Morris and Lord Lyell, warns that “pervasive and routine” electronic surveillance and the collection and processing of personal information is almost taken for granted. Although many surveillance practices and data collection processes are unknown to most people, the expansion in their use represents “one of the most significant changes in the life of the nation since the end of the second world war”, the report says. The committee warns that the national DNA database could be used for “malign purposes”, challenges whether CCTV cuts crime and questions whether local authorities should be allowed to use surveillance powers at all. The peers say privacy is an “essential prerequisite to the exercise of individual freedom” and the growing use of surveillance and data collection needs to be regulated by executive and legislative restraint at all times. http://www.guardian.co.uk/uk/2009/feb/06/surveillance-freedom-peers

NIST UPDATES RECOMMENDATIONS FOR IT SECURITY CONTROLS (GCN, 6 Feb 2009) - The National Institute of Standards and Technology has released an initial draft for public comment of a revised version of its Recommended Security Controls for Federal Information Systems and Organizations. Although this is Revision 3 of Special Publication (SP) 800-53, NIST calls it the first major update of the guidelines since its initial publication in December 2005. NIST tries to revisit its security guidance every two years and update them as needed, said senior computer scientist Ron Ross. But revising a 200-plus-page comprehensive set of recommendations is expensive and time-consuming. SP 800-53 is part of a series of documents setting out standards, recommendations and specifications for implementing the Federal Information Security Management Act (FISMA). It is intended to answer these questions:
• What security controls are needed to adequately mitigate the risk incurred by the use of information and information systems in the execution of organizational missions and business functions?
• Have the selected security controls been implemented or is there a realistic plan for their implementation?
• What is the desired or required level of assurance (i.e. grounds for confidence) that the selected security controls, as implemented, are effective in their applications?
This update also is part of an effort to harmonize security requirements across government. NIST guidance typically does not apply to government information systems identified as national-security systems. http://gcn.com/articles/2009/02/06/nist-updates-sp-800-53.aspx Draft here: http://csrc.nist.gov/publications/drafts/800-53/800-53-rev3-IPD.pdf

CHANGE YOU CAN DOWNLOAD (Wikileaks, 8 Feb 2009) - Wikileaks has released nearly a billion dollars worth of quasi-secret reports commissioned by the United States Congress. The 6,780 reports, current as of this month, comprise over 127,000 pages of material on some of the most contentious issues in the nation, from the U.S. relationship with Israel to the financial collapse. Nearly 2,300 of the reports were updated in the last 12 months, while the oldest report goes back to 1990. The release represents the total output of the Congressional Research Service (CRS) electronically available to Congressional offices. The CRS is Congress’s analytical agency and has a budget in excess of $100M per year. Open government lawmakers such as Senators John McCain (R-Arizona) and Patrick J. Leahy (D-Vermont) have fought for years to make the reports public, with bills being introduced--and rejected--almost every year since 1998. The CRS, as a branch of Congress, is exempt from the Freedom of Information Act.
Although all CRS reports are legally in the public domain, they are quasi-secret because the CRS, as a matter of policy, makes the reports available only to members of Congress, Congressional committees and select sister agencies such as the GAO. http://thepiratebay.org/torrent/4713076/Wikileaks_Document_Release__Congressional_Reports_Service_Feb_20 [This is said to be the entire CRS electronic body of work back to 1990 in one slug – 2.16 gigs. CRS reports are here: http://wikileaks.org/wiki/Category:Congressional_Research_Service and here: http://wikileaks.org/wiki/CRS_reports_by_date] Some examples: “Border Searches of Laptop Computers and Other Electronic Storage Devices”; “Broadband Internet Regulation and Access: Background and Issues”; “2008-2009 Presidential Transition: National Security Considerations and Options”; “Fair Use on the Internet: Copyright’s Reproduction and Public Display Rights”; “A Sketch of Supreme Court Recognition of Fifth Amendment Protection for Acts of Production”.

ABA SOCIAL NETWORK FAILS TO CONNECT (Law.com, 9 Feb 2009) - The American Bar Association has jumped on the social networking bandwagon with a site of its own, LegallyMinded. The ABA hopes to separate its site from the professional networking pack by combining the best features of the top social networking sites with substantive legal information from the ABA’s library. Ambitious as it is, the site falls short on execution. It jettisons features that should be central and weighs itself down with others that are useless or redundant. It is as if the ABA came late to a crowded race, barefoot and with bricks in its backpack. “We set out to do something different,” said Fred Faulkner, the ABA’s manager of interactive services in Chicago, in an article in the ABA Journal. “We looked at a lot of the professional and social networks, and the gap we found was that there truly wasn’t a good site that was a cross between professional and personal networking,” he said. I interviewed Faulkner, who explained that the goal was to combine the best features of sites such as LinkedIn and Facebook with high-quality content from the ABA and other sources. Given this, it is unfathomable why the ABA chose not to include the one feature that defines social networking sites -- connections. Users have no way to link with each other. Instead, a user’s only option is to add other members to a private “contacts” list that only the user can see. http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202428079272

WEB 2.0 DEFAMATION LAWSUITS MULTIPLY (SF Gate, 9 Feb 2009) - The Web 2.0 movement, which ushered in an interactive Internet, sought to put power in the hands of the people by tapping the so-called wisdom of the crowds to change the world - and to keep such a digital democracy in check. A decade later, as defamation lawsuits have begun to mount, some are questioning the wisdom of the crowds, and wondering if it hasn’t turned into mob rule. “I don’t know why this has taken so long,” said Andrew Keen, author of a controversial book, “The Cult of the Amateur: How Today’s Internet is Killing Our Culture.” “The Internet is a culture of rights rather than responsibilities. We have no coherent theory of digital responsibility. The issue has broken through, broken out of Silicon Valley - now it affects real people with real reputations to defend.” Just last week, Juicy Campus - a Web site that was banned from some colleges for its postings of vicious anonymous gossip - abruptly shut down, its traffic redirected to a site called College Anonymous Confession Board, whose owner said he hosts “a higher level of discourse.” Meanwhile, the review site Yelp, based in San Francisco, has found itself in the crosshairs of the free e-speech debate. Yvonne Wong, a pediatric dentist in Foster City, recently sued Los Altos couple Tai Jing and Jia Ma after they criticized her treatment of their son in a posting on Yelp. They questioned her use of laughing gas and said they were angry she had used fillings containing mercury. Wong’s lawyer, Marc TerBeek of Oakland, said the review is false, and Yelp has since taken it down. Legal scholars have started to ask whether that law - the Communications Decency Act - should be modified, on the grounds that it allows too much irresponsible speech. “We may put our photos on Flickr and our e-mail on Google and our personal experiences on Facebook,” said Brewster Kahle, who founded the Internet Archive, a nonprofit digital library in San Francisco. “But who’s responsible for this content? If you want things to go away, does it really?” http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2009/02/08/MNOJ15F979.DTL&feed=rss.news See also http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=100343

CONGRESSMAN’S TWITTERING RAISES SECURITY CONCERNS (SiliconValley.com, 11 Feb 2009) - The top Republican on the House intelligence committee landed in hot water this week after using his Twitter page to update the public on his precise whereabouts while traveling through Iraq and Afghanistan. The revelation prompted the Pentagon to review its policy, which regards such information as sensitive, and lit up the liberal blogosphere with accusations of hypocrisy. Rep. Pete Hoekstra says he did nothing wrong. He pointed to announcements by other high-ranking officials, including House Speaker Nancy Pelosi, which list the countries they plan to visit. “The policy that we have and that we did on this trip is consistent and well restrained from what other folks have done in the past,” said Hoekstra, R-Mich. But Hoekstra, who has decried the unauthorized leaking of classified information, provided far more details than a general itinerary, including at least a 12-hour heads-up that he was headed to Iraq. http://www.siliconvalley.com/news/ci_11680013?nclick_check=1

MORE THAN 150 BANKS AFFECTED BY HEARTLAND DATA BREACH THUS FAR (ComputerWorld, 11 Feb 2009) - The number of financial institutions that have said they were affected by the data breach disclosed last month by Heartland Payment Systems Inc. is growing longer by the day and now includes banks in 40 states as well as Canada, Bermuda and Guam, according to the BankInfoSecurity.com news portal. The Web site today published a list containing the names of 157 institutions that it said have publicly disclosed to customers that they were victimized as a result of the breach at Heartland, a large payment processor in Princeton, N.J. The list includes two banks in Bermuda, plus one each in Canada and Guam. Meanwhile, in another indication of the fallout from the breach, 83% of the 512 banks that responded to an informal “quick poll” survey conducted in late January by the Independent Community Bankers of America (ICBA) trade group said that credit or debit cards they had issued were compromised in the incident at Heartland. http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9127822&source=NLT_PM

VIDEO SITE’S INVESTORS NOT, ON ROLE ALONE, LIABLE FOR ALLEGED INFRINGEMENTS (BNA’s Internet Law News, 12 Feb 2009) - BNA’s Electronic Commerce & Law Report reports that a federal court in California has ruled that investors who appear to have done little more than serve on the board of directors for an online video-sharing service cannot be held liable for the service’s alleged copyright infringement. The court said that a leadership role in a video-sharing corporation was not itself enough to substantiate claims of contributory or vicarious copyright infringement. Case name is UMG Recordings Inc. v. Veoh Networks Inc.

YOUTUBE GOES OFFLINE (YouTube and Larry Lessig’s blog, 12 Feb 2009) - We are always looking for ways to make it easier for you to find, watch, and share videos. Many of you have told us that you wanted to take your favorite videos offline. So we’ve started working with a few partners who want their videos shared universally and even enjoyed away from an Internet connection. Many video creators on YouTube want their work to be seen far and wide. They don’t mind sharing their work, provided that they get the proper credit. Using Creative Commons licenses, we’re giving our partners and community more choices to make that happen. Creative Commons licenses permit people to reuse downloaded content under certain conditions. We’re also testing an option that gives video owners the ability to permit downloading of their videos from YouTube. Partners could choose to offer their video downloads for free or for a small fee paid through Google Checkout. Partners can set prices and decide which license they want to attach to the downloaded video files (for more info on the types of licenses, take a look here). For example, universities use YouTube to share lectures and research with an ever-expanding audience. In an effort to promote the sharing of information, we are testing free downloads of YouTube videos from Stanford, Duke, UC Berkeley, UCLA, and UCTV (broadcasting programs from throughout the UC system). YouTube users who are traveling or teachers who want to show these videos in classrooms with limited or no connectivity should find this particularly useful. http://www.youtube.com/blog?entry=Mp1pWVLh3_Y

IN ‘FIG LEAF’ SETTLEMENT WITH JONES DAY, WEBSITE AGREES TO ADJUST USE OF LINKS (ABA Journal, 12 Feb 2009) - In a “fig leaf” settlement entered into by BlockShopper after it racked up a six-figure legal defense bill in a controversial federal trademark infringement lawsuit, the website has agreed to alter the way it describes home purchases by Jones Day attorneys. Instead simply “deep linking” the name of a Jones Day attorney buying a home to his or her law firm biography, BlockShopper has agreed to do so in a manner specified by the law firm, reports the Cleveland Plain Dealer. A copy of the settlement agreement is provided by the Am Law Daily. Under the new format agreed to in the settlement, BlockShopper will link the Jones Day law firm biography to a spelled-out law firm Web address following the lawyer’s name, Brian Timpone, the website’s founder, tells the ABA Journal. “In other words,” the Plain Dealer explains, “instead of writing ‘Daniel P. Malone Jr. is an associate in the Chicago office of Jones Day,’ “—and linking the law firm biography to Malone’s name—”BlockShopper must write ‘Malone (www.jonesday.com/dpmalone) is an associate ... .’ “ http://www.abajournal.com/news/in_fig_leaf_settlement_with_jones_day_website_agrees_to_adjust_use_of_links Settlement agreement here: http://amlawdaily.typepad.com/Blockshopper.pdf [Editor: seems predicated on the assumption that people actually read complex URLs. Not a happy-ending. Acerbic TechDirt story here: http://techdirt.com/articles/20090219/0013353822.shtml]

WHERE YOU’VE BEEN ON NET NOT PRIVATE, CANADIAN JUDGE RULES (National Post, 13 Feb 2009) - An Ontario Superior Court ruling could open the door to police routinely using Internet Protocol addresses to find out the names of people online, without any need for a search warrant. Justice Lynne Leitch found that there is “no reasonable expectation of privacy” in subscriber information kept by Internet service providers (ISPs), in a decision issued earlier this week. The decision is binding on lower courts in Ontario and it is the first time a Superior Court-level judge in Canada has ruled on whether there are privacy rights in this information that are protected by the Charter. The ruling is a significant victory for police investigating crimes such as possession of child pornography, while privacy advocates warn there are broad implications even for law-abiding users of the Internet. The ruling by Judge Leitch was made in a possession of child pornography case in southwestern Ontario. A police officer in St. Thomas faxed a letter to Bell Canada in 2007 seeking subscriber information for an IP address of an Internet user allegedly accessing child pornography. The court heard that it was a “standard letter” that had been previously drafted by Bell and the officer “filled in the blanks” with a request that stated it was part of a child sexual exploitation investigation. Bell provided the information without asking for a search warrant. http://www.nationalpost.com/news/story.html?id=1283120

E-INVOICING IN EUROPE (McGinnis Lochridge, 13 Feb 2009) - On 28 January, 2009 the Commission of the European Union proposed an overhaul of the 2006 EU Directive on Invoicing (Directive 2006/112/EC). If approved, this new Directive will fundamentally change how electronic invoicing is conducted in Europe and will affect all companies doing business in Europe. The proposed new Directive would make electronic invoices equivalent in all respects to paper ones. It would eliminate the requirement that advanced electronic signatures be used in electronic invoices and would eliminate the requirement that the recipient of the invoice consent to receive it in electronic form. Observing that the Member States’ disparate requirements for advanced electronic signatures have created significant obstacles to the adoption of electronic invoices, the Commission now wishes to harmonize member state requirements for electronic invoices by, among other things, abolishing the need for invoices to include advanced electronic signatures. In the original 2006 Directive on VAT Invoicing, Title XI, Chapter 3, Section 5 governed the use of electronic invoices. Article 232 of the original directive allowed enterprises to use electronic invoices only if the recipient consented to receive electronic invoices. Article 233 required electronic invoices to assure integrity of content and authenticity of origin by means of either an advanced electronic signature, EDI or “other electronic means allowed by the Member States” . The proposed new Directive would amend Article 232 to say that invoices can always be sent by paper or “made available” electronically, thus deleting the requirement of recipient consent. The new directive would delete Article 233 and the requirement to use advanced electronic signatures entirely.This new Directive will fundamentally change how electronic invoicing is conducted in Europe. http://www.mcginnislaw.com/pub_pres/272_e_invoicing_-_phillip_schmandt.pdf Proposed new Directive is here: http://ec.europa.eu/taxation_customs/taxation/vat/traders/invoicing_rules/index_en.htm

HOW ATTACKERS USE YOUR METADATA AGAINST YOU (DarkReading, 13 Feb 2009) - To steal your identity, a cybercriminal doesn’t have to have direct access to your bank account or other personal information. Often, he collects information about you from a variety of seemingly innocuous sources, then uses that data to map out a strategy to crack your online defenses and drain your accounts. Such methods are well-known to security professionals. But what those same professionals often overlook is this approach also can be used to crack the defenses of sensitive business files, as well. Rather than trying to gain access to your data, itself, the bad guys are analyzing the so-called harmless information about your files -- collectively known as metadata -- and using it to develop attacks that can drain your business of its most sensitive information. Armed with this data, an attacker can target users, as well as the computing environment within their enterprises. Several instances of metadata mishaps have been in the news in recent years. In one case, attackers used data they collected from the “track changes” feature in Microsoft Word. In another case, they took advantage of failed attempts to black out data in PDF files. These cases make it clear: Once your documents leave the internal network -- either through email or Web publishing -- those files and the metadata they contain are fair game for attackers. Many security professionals know about metadata, but they don’t really know how it can be used against their organizations. The first stage of leveraging metadata for an attack is gathering it. Both attackers and pen testers have a bevy of tools available solely for this purpose. Two readily-available hacking tools -- MetaGooFil and CeWL -- were created to expedite the collection process by automating the search, download, and extraction of metadata from documents available on the Internet. MetaGooFil was the first tool on the scene, and it uses Google to search for files of specific type. Once it finds and downloads files, the metadata is extracted and displayed in a HTML report that shows the information found in each file. The end of the report includes a summary of authors and file paths -- information that can be important later on, during other attack phases. CeWL takes a different approach, spidering a Website to create a word list that can be used for password brute-forcing. It can also collect email addresses, authors, and user names from metadata found in Microsoft Office documents. Included with CeWL is a “Files Already Bagged” (FAB) tool that processes files already acquired. Metadata is also helpful in social engineering attacks. Knowing the five different authors of a document, an attacker can “drop names” via the phone to make his scheme seem more credible. Similarly, location information contained in photos could be mentioned, making the calls seem more legit. Spear-phishing email could target all of the authors who worked on one particular document. Knowing which version of software was used to create the file, an attacker could also email client-side exploits to individuals who use particularly vulnerable versions of Microsoft Word or PowerPoint. Metadata can also help with physical theft. For example, users may post images to Flickr or Twitter from a phone that enables geotagging. This information can give attackers the location about a target’s home or business, and where he might be on a daily basis. Similarly, the MAC address of the system can indicate the type of hardware used, making it easier to identify mobile workers who are likely to have laptops that are kept in places where they might be easy to steal. http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=214200389&cid=nl_DR_DAILY_T

MASSACHUSETTS EXTENDS COMPLIANCE DEADLINE ON DATA SECURITY RULES - AGAIN (ComputerWorld, 13 Feb 2009) - For the second time in three months, Massachusetts officials have pushed back the deadline for companies to comply with a controversial set of data security regulations that the state announced last September. In addition to the deadline extension, which was announced late yesterday, the state’s Office of Consumer Affairs and Business Regulation (OCABR) also revised a key provision in the regulations that had prompted considerable concern within the business community both inside and outside of Massachusetts. Under the new deadline, businesses now have until the start of next year to comply with the regulations, which are aimed at protecting the personal data of Massachusetts residents. Prior to the extension, the compliance deadline was May 1. That date was set in November, when the OCABR extended its original deadline of Jan. 1. In a statement yesterday, OCABR undersecretary Daniel Crane said that given the importance of the data-protection mandate, state officials decided it was necessary to give companies more time to make the necessary changes to their systems and business processes. Crane also cited the economic recession. http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9127961&intsrc=news_ts_head

NINTH CIRCUIT MAKES IT MORE DIFFICULT FOR INDIVIDUALS TO CHALLENGE GOVERNMENT SEARCHES OF THE WORKPLACE (Steptoe & Johnson’s E-Commerce Law Week, 14 Feb 2009) - A ruling handed down by the Ninth Circuit early this month could make it more difficult for a business owner or employee to challenge a government search of her workplace and its computers. In United States v. SDI Future Health, Inc., the Ninth Circuit ruled that, “except in the case of a small, family-run business over which an individual exercises daily management and control, an individual challenging a search of workplace areas beyond his own internal office must generally show some personal connection to the places searched and the materials seized.” The dispute in this case centered around a warrant the government was granted to search the offices and computers of SDI Future Health for evidence that it had engaged in Medicare fraud. Based on evidence seized during its search, the government won an indictment against SDI, its president and part-owner Todd Kaplan, and SDI officer and part-owner Jack Brunk. A district court granted the defendants’ motion to suppress evidence obtained using the search warrant on the ground that the warrant was vague and overbroad. On appeal, the Ninth Circuit agreed that some portions of the warrant were overbroad, but held that the district court had not properly established that Kaplan and Brunk had standing to challenge the search. http://www.steptoe.com/publications-5911.html Decision here: http://www.ca9.uscourts.gov/datastore/opinions/2009/01/27/0710261.pdf

AS DATA COLLECTING GROWS, PRIVACY ERODES (New York Times, 16 Feb 2009) – There are plenty of people who can muster outrage at Alex Rodriguez, the Yankees third baseman who is the latest example of win-at-any-cost athletes. But I’d prefer to see him as at the cutting edge of another scourge — the growing encroachment on privacy. The way Mr. Rodriguez’s positive steroid test result became public followed a path increasingly common in the computer age: third-party data collection. We are typically told that personal information is anonymously tracked for one reason — usually something abstract like making search results more accurate, recommending book titles or speeding traffic through the toll booths on the thruways. But it is then quickly converted into something traceable to an individual, and potentially life-changing. In Mr. Rodriguez’s case, he participated in a 2003 survey of steroid use among Major League Baseball players. No names were to be revealed. Instead, the results were supposed to be used in aggregation — to determine if more than 5 percent of players were cheating — and the samples were then to be destroyed. It is odd that most of the news coverage described the tests as “anonymous.” If the tests were truly anonymous, of course, Mr. Rodriguez would still be thought of as a clean player — as he long had insisted he was. But when federal prosecutors came calling, as part of a steroid distribution case, it turned out that the “anonymous” samples suddenly had clear labels on them. As a friend put it in an e-mail message: “Privacy is serious. It is serious the moment the data gets collected, not the moment it is released.” To Jonathan Zittrain, a professor of Internet law at Harvard, there is an obvious explanation for this kind of repurposing of information — there is so much information out there. Supply creates demand, he argues. “This is a broader truth about the law,” he writes in an e-mail message. “There are often no requirements to keep records, but if they’re kept, they’re fair game for a subpoena.” And we are presented with what Professor Zittrain calls the “deadbeat dad” problem. There are government investigators, divorcing spouses, even journalists, who have found creative ways to exploit the material. “So many databases,” he writes, “as simple as highway toll collection records or postal service address changes, lend themselves to other uses, such as finding parents behind on their child support payments.” Perhaps a more direct explanation is that data collection is part of what Cindy Cohn, the legal director of the Electronic Frontier Foundation, calls “the surveillance business model.” That is, there is money to be made from knowing your customers well — with a depth unimaginable before Internet cookies allowed companies to track obsessively online behavior. http://www.nytimes.com/2009/02/16/technology/16link.html?_r=1&scp=1&sq=data%20collecting&st=Search

FACEBOOK’S USERS ASK WHO OWNS INFORMATION (New York Times, 16 Feb 2009) - Reacting to an online swell of suspicion about changes to Facebook’s terms of service, the company’s chief executive moved to reassure users on Monday that the users, not the Web site, “own and control their information.” The online exchanges reflected the uneasy and evolving balance between sharing information and retaining control over that information on the Internet. The subject arose when a consumer advocate’s blog shined an unflattering light onto the pages of legal language that many users accept without reading when they use a Web site. The pages, called terms of service, generally outline appropriate conduct and grant a license to companies to store users’ data. Unknown to many users, the terms frequently give broad power to Web site operators. This month, when Facebook updated its terms, it deleted a provision that said users could remove their content at any time, at which time the license would expire. Further, it added new language that said Facebook would retain users’ content and licenses after an account was terminated. Mark Zuckerberg, the chief executive of Facebook, said in a blog post on Monday that the philosophy “that people own their information and control who they share it with has remained constant.” Despite the complaints, he did not indicate the language would be revised. The changes in the terms of service had gone mostly unnoticed until Sunday, when the blog Consumerist cited them and interpreted them to mean that “anything you upload to Facebook can be used by Facebook in any way they deem fit, forever, no matter what you do later.” Given the widespread popularity of Facebook — by some measurements the most popular social network with 175 million active users worldwide — that claim attracted attention immediately. The blog post by Consumerist, part of the advocacy group Consumers Union, received more than 300,000 views. Users created Facebook groups to oppose the changes. To some of the thousands who commented online, the changes meant: “Facebook owns you.” Facebook moved swiftly to say it was not claiming to own the material that users upload. It said the terms had been updated to better reflect user behavior — for instance, to acknowledge that when a user deletes an account, any comments the user had posted on a page remain visible. http://www.nytimes.com/2009/02/17/technology/internet/17facebook.html?_r=1&scp=1&sq=facebook%20users&st=cse Consumerist blog posting here: http://consumerist.com/5150175/facebooks-new-terms-of-service-we-can-do-anything-we-want-with-your-content-forever

- and -

FACEBOOK BACKTRACKS ON TERMS OF USE AFTER PROTESTS (Law.com, 18 Feb 2009) - In an about-face following a torrent of online protests, Facebook is backing off a change in its user policies while it figures how best to resolve questions like who controls the information shared on the social networking site. The site, which boasts 175 million users from around the world, had quietly updated its terms of use -- its governing document -- a couple of weeks ago. The changes sparked an uproar after popular consumer rights advocacy blog Consumerist.com pointed them out Sunday, in a post titled “Facebook’s New Terms Of Service: ‘We Can Do Anything We Want With Your Content. Forever.’” Facebook has since sought to reassure its users -- tens of thousands of whom had joined protest groups on the site -- that this is not the case. And on Wednesday morning, users who logged on to Facebook were greeted by a message saying that the site is reverting to its previous terms of use policies while it resolves the issues raised. Facebook spelled out, in plain English rather than the legalese that prompted the protests, that it “doesn’t claim rights to any of your photos or other content. We need a license in order to help you share information with your friends, but we don’t claim to own your information.” http://www.law.com/jsp/article.jsp?id=1202428366838&rss=newswire Jonathan Zittrain’s musings on all this: http://futureoftheinternet.org/facebooks-privacy-storm [Editor: at a Berkman lunch last week, a notable observed that nobody reads terms-of-service. In acting as our watchdog, the Consumerist, and like organizations, serve an important public service.]

- and -

FACEBOOK OPENS GOVERNANCE OF SERVICE AND POLICY PROCESS TO USERS (Facebook PR, 26 Feb 2009) - Facebook today announced a new approach to site governance that offers its users around the world an unprecedented role in determining the future policies governing the service. Facebook released the first proposals subject to these new procedures – The Facebook Principles, a set of values that will guide the development of the service, and Statement of Rights and Responsibilities that make clear Facebook’s and users’ commitments related to the service. Over the coming weeks, users will have the opportunity to review, comment and vote on these documents. An update to the Privacy Policy is also planned and this change will be subject to similar input. “As people share more information on services like Facebook, a new relationship is created between Internet companies and the people they serve,” said Mark Zuckerberg, founder and CEO of Facebook. “The past week reminded us that users feel a real sense of ownership over Facebook itself, not just the information they share.” “Companies like ours need to develop new models of governance,” Zuckerberg added. “Rather than simply reissue a new Terms of Use, the changes we’re announcing today are designed to open up Facebook so that users can participate meaningfully in our policies and our future.” http://www.facebook.com/press/releases.php?p=85587

LET MY BOARD AND ME BECOME AS ONE: THE WII BALANCE BOARD/GOOGLE EARTH MASHUP (Offworld.com, 17 Feb 2009) - With just a touch smoother scrolling (chalked up, surely, to the program itself), this could feel amazing: Germany’s Research Center for Artificial Intelligence has hacked together a Wii balance board with Google Earth to go surfing, as Kottke says, “like the Silver Surfer.”
Or, if you please, the same interaction can be used in Second Life, or -- as made the rounds earlier last year -- World of Warcraft’s Azeroth, but there’s nothing better than their tour-glide over Munich from 300 feet. http://www.offworld.com/2009/02/let-my-board-and-me-become-as.html [Editor: pretty cool demo video. Even cooler is Johnny Lee’s Wii-3D headtracking demo from 21 December 2007 out of CMU: http://www.youtube.com/watch?v=Jd3-eiid-Uw]

VISUAL COMPUTER FORENSIC ANALYSIS (Law.com, 17 Feb 2009) - Computer forensics is a slow process. Examiners typically embark on a tedious file review process to determine each file’s relevance to a particular case. This can quickly add hours and extra costs to computer forensics. However, recent research presented at the Black Hat 2008 conference in Las Vegas may curb that trend. Researchers Greg Conti and Erik Dean from the United States Military Academy, West Point, adapted a new concept to computer forensics: visualization. The researchers demonstrated how visual computer forensic methods can dramatically reduce the time it takes to review files. To understand the benefits of visual forensic analysis, one must understand the state of the art in computer forensic analysis. A typical computer investigation requires an individual analysis of each file on a computer system. Some files can easily be ruled out by matching them to known files that have already been analyzed, such as system files. Unfortunately, the hundreds of thousands of files remaining must be analyzed by an examiner. A typical file examination requires that the file be examined in its native application (or a suitable viewer). Therefore, examination of one file can be different than the examination of another. For example, a JPEG file is loaded into an image viewer. A Microsoft Word document is loaded into its associated viewer instead of an image viewer. An executable (program or application) file can be examined in a debugging tool called a disassembler. And a pure binary file can be viewed with a hexadecimal viewer. The process above begins to break down when the examiner analyzes a file type that he or she cannot readily determine or identify. There are some ways an examiner can attempt to determine a file’s type with signature analysis or an educated guess based on the file extension. But neither of these approaches guarantees the correct answer the first time. Visual computer forensics lends a hand to this problem. By loading the unknown file into the free visual forensics tools developed by Conti and Dean, an unknown file can be identified by the way the data looks. This is different than standard matching techniques currently used today which involve matching a few bytes of the beginning and end of a file to known values of known file types. Structured files, such as Internet browsing history files, tend to have discrete structures within their contents, while compressed or encrypted files have high levels of entropy due to the nature of how compression and encryption algorithms work. The visualized contents of compressed or encrypted files tend to look random when compared with uncompressed or unencrypted files. The following screenshots show the difference between structured files and compressed/encrypted files when viewed with a visual computer forensics tool developed by Conti and Dean: [Editor: there’s much more.] http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202428248638&rss=newswire

CVS CAREMARK SETTLES FTC CHARGES: FAILED TO PROTECT MEDICAL AND FINANCIAL PRIVACY OF CUSTOMERS AND EMPLOYEES; CVS PHARMACY ALSO PAYS $2.25 MILLION TO SETTLE ALLEGATIONS OF HIPAA VIOLATIONS (FTC, 18 Feb 2009) - CVS Caremark has agreed to settle Federal Trade Commission charges that it failed to take reasonable and appropriate security measures to protect the sensitive financial and medical information of its customers and employees, in violation of federal law. In a separate but related agreement, the company’s pharmacy chain also has agreed to pay $2.25 million to resolve Department of Health and Human Services allegations that it violated the Health Insurance Portability and Accountability Act (HIPAA). The FTC’s complaint charges that CVS Caremark failed to implement reasonable and appropriate procedures for handling personal information about customers and employees, in violation of federal laws. In particular, according to the complaint, CVS Caremark did not implement reasonable policies and procedures to dispose securely of personal information, did not adequately train employees, did not use reasonable measures to assess compliance with its policies and procedures for disposing of personal information, and did not employ a reasonable process for discovering and remedying risks to personal information. http://www.ftc.gov/opa/2009/02/cvs.shtm

DHS NAMES CHIEF PRIVACY OFFICER (CNET, 19 Feb 2009) - U.S. Homeland Security Secretary Janet Napolitano announced on Thursday she is appointing attorney Mary Ellen Callahan as the department’s chief privacy officer. “Homeland security and privacy are not mutually exclusive, and having a seasoned professional like Mary Ellen on the team further ensures that privacy is built in to everything we do,” Napolitano said. “Our Privacy Office is viewed as a leader in the federal government in public outreach and as model for Privacy Impact Assessments. I look forward to the skill and experience Mary Ellen will bring to this robust and important office.” Callahan currently serves as a partner at the law firm Hogan & Hartson, where she counsels online companies, trade associations, and other corporations on antitrust, e-commerce, and privacy-related issues. She has helped companies draft their Web site privacy policies and terms of use and counsels corporations on developing legally compliant e-mail marketing campaigns. http://news.cnet.com/8301-13578_3-10167897-38.html

SURPRISE: AMERICA IS NO. 1 IN BROADBAND (New York Times, 23 Feb 2009) - There is a constant refrain that the United States is falling behind in broadband, as if the speed of Internet service in Seoul represents a new Sputnik that is a challenge to national security. It’s certainly true that in some countries, like South Korea, far more homes have broadband connections than in the United States. And the speeds in some countries are far higher than is typical here. But there are many ways to measure the bandwidth wealth of nations. At the Columbia/Georgetown seminar on the broadband stimulus yesterday, I heard Leonard Waverman, the dean of the Haskayne School of Business at the University of Calgary, describe a measure he developed called the “Connectivity Scorecard.” It’s meant to compare countries on the extent that consumers, businesses and government put communication technology to economically productive use. Even after deducting the untold unproductive hours spent on Facebook and YouTube, the United States comes out on top in Mr. Waverman’s ranking of 25 developed countries. The biggest reason is that business in the United States has made extensive use of computers and the Internet and it has a technically skilled work force. Also, as dusty as your local motor vehicle office may seem, government use of communications technology is as good in the United States as anywhere in the world, according to Mr. Waverman’s rankings. After the United States, the ranking found that Sweden, Denmark, the Netherlands, and Norway rounded out the five most productive users of connectivity. Japan ranked 10, and Korea, 18. And while wired and wireless broadband networks used by consumers lagged other countries, the United States ranked No. 1 in the world for technology use and skills by consumers. (This was measured by comparing countries on five measures: The penetration of Internet use, penetration of Internet banking, wired and wireless voice minutes per capita, SMS messages per capita, and consumer software spending.) http://bits.blogs.nytimes.com/2009/02/23/surprise-america-is-no-1-in-broadband/ Report here: http://www.connectivityscorecard.org/images/uploads/media/TheConnectivityReport2009.pdf

EXITING WORKERS TAKING CONFIDENTIAL DATA WITH THEM (CNET, 23 Feb 2009) - As layoffs continue apace, a survey released on Monday shows what many companies fear--exiting workers are taking a lot more with them than just their personal plants and paperweights. Of about 950 people who said they had lost or left their jobs during the last 12 months, nearly 60 percent admitted to taking confidential company information with them, including customer contact lists and other data that could potentially end up in the hands of a competitor for the employee’s next job stint. “I don’t think these people see themselves as being thieves or as stealing,” said Larry Ponemon, founder of the Ponemon Institute, which conducted the online survey last month. “They feel they have a right to the information because they created it or it is useful to them and not useful to the employer.” The survey also found a correlation between people who took data they shouldn’t have taken and their attitude towards the company they are leaving. More than 60 percent of those who stole confidential data also reported having an unfavorable view of the company. And nearly 80 percent said they took it without the employer’s permission. Most of the data takers (53 percent) said they downloaded the information onto a CD or DVD, while 42 percent put it on a USB drive and 38 percent sent it as attachments via e-mail, according to the survey. The survey also found that many companies seem to be lax in protecting against data theft during layoffs. Eighty-two percent of the respondents said their employers did not perform an audit or review of documents before the employee headed out the door and 24 percent said they still had access to the corporate network after leaving the building. http://news.cnet.com/8301-1009_3-10170006-83.html

CYBERSECURITY AUDIT GUIDELINES RECOMMENDED (FCW, 23 Feb 2009) - A group of cybersecurity experts today recommended twenty specific security controls that the government and industry should deploy to block or lessen the consequences of cyberattacks that come from inside and outside threats. The recommended controls are meant to provide a standard baseline for measuring computer security. The recommendations, the Consensus Audit Guidelines, were agreed to by federal and private industry cybersecurity officials and are based on specific experiences in dealing with particular attacks directed at government and the defense industrial base’s information systems. The group also detailed the types of cyberattacks that a recommended security controls could thwart, how a recommended security control could be implemented and how to evaluate its effectiveness. Alan Paller, the director of research at the SANS Institute who worked on the guidelines, said the strategy is significant because it has specific actions for agencies to take and a way to measure their effectiveness, something he said the Government Accountability Office has been requesting. He said the project, started in early 2008, was inspired by the realization that the defense industrial base’s systems had been deeply penetrated. http://fcw.com/Articles/2009/02/23/cyber-controls.aspx CAG/guidelines here: http://www.sans.org/cag/ [Editor: this may be a very big deal – the CAG potentially will become “best-practice” and de facto requirements.]

LISTEN UP AND DISCOVER AUDIO RECORDINGS (Law.com, 25 Feb 2009) - As most IT professionals already know, courtesy of the Federal Rules of Civil Procedure Rule 34(a), audio files are now fully discoverable. This has led many IT professionals to create and implement procedures that will record and store telephonic conversations and other electronic interactions originating from and connected to their company client orders. These new protocols specifically address sound content from call desks, trading desks, phone systems and, of course, VoIP. IT professionals have enacted these procedures in an effort to keep up with one of the newest trends in mainstream e-discovery: sound recordings. The necessity for IT professionals to haul audio recordings into their general e-discovery process is gaining awareness because of situations that may -- at first glance -- appear harmless. Think about scenarios where a company employee is having a phone dialogue with a customer and at the same time sending e-mails to another. This may seem innocuous on the surface; the two interactions seem separate and unconnected with no suggestion of any illegality. However, if one pays attention to the audio in the milieu of the e-mail exchange, it may paint an absolutely different picture. In reality, the entire picture may demonstrate that the company employee was using the data received from the person with whom he or she was exchanging instant messages or e-mails to his or her advantage when speaking with the other customer on the phone. Nevertheless, connecting these two actions together is nearly impossible via conducting a discovery of solely written messages. IT professionals are now tasked with bridging this gap by creating an integrated business information system that will account for all business written and audio content. Failure by IT professionals to enact such an integrated data management system can be fatal. The absence of a viable, synchronized information protocol results in businesses pursuing various recording discovery procedures that are distinct from the ordinary chain of custody mandate. Consequently, sound recordings and e-mails are not tagged in a similar fashion, and there is no method to directly connect them to one another. Furthermore, the ability to fashion a timeline as to when these exchanges happened becomes more complicated for IT professionals to generate. This in turn leaves in-house counsel at a palpable loss and incapable of viewing the interconnectedness between the diverse messages. http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202428560876&rss=newswire

TEN STEPS FOR MITIGATING DATA RISK DURING A MERGER (InfoWorld, 25 Feb 2009) - Merger and acquisition activity stands to increase as global markets struggle to stay afloat during the worst economic slowdown in decades. What will you do when you find out you’re about to acquire or consolidate with another firm or division? Are you aware of the risks you may be inheriting? What data is going to demand the highest availability? What IT regulations will you have to address and how do you know if existing controls already address them? Below are 10 “data health” checks a CIO can conduct to answer these questions before giving a green light to a merger, acquisition, or consolidation.
Step one: Assess your data From a data perspective, the first step needs to be an assessment of the independent data assets of each organization participating in the merger. If you do not know what data exists before the acquisition, gaining this understanding after combining the data, if it can be combined at all, will be extremely difficult. The task at hand will be simpler if both organizations practiced strong data governance. This is rarely the case though.
Step two: Plug the governance gaps After completing an honest assessment of where each organization stands in terms of data governance, the next step needs to be plugging the gaps. Work toward creating a definition of data that is not well understood or undocumented. Do not turn this into a long process; define what data you have and where it is stored. Consider using tools like data dictionaries and repositories and consult the subject matter experts (business users, programmers, data architects, etc.) at each organization for this information.
Step three: Leverage the M&A for governance improvements Use the acquisition as a springboard for instituting new or stronger data governance policies and procedures. Lack of insight into important business data can be a strong motivational tool for implementing improved data management practices. http://www.infoworld.com/article/09/02/25/Ten_steps_for_mitigating_data_risk_during_a_merger_1.html?source=rss&url=http://www.infoworld.com/article/09/02/25/Ten_steps_for_mitigating_data_risk_during_a_merger_1.html

POSTING YOUTUBE VIDEO WITHOUT SUBJECTS’ CONSENT DRAWS FINE FROM SPANISH DPA (Steptoe & Johnson’s E-Commerce Law Week, 26 Feb 2009) - The Spanish Data Protection Agency (DPA) recently ruled that individuals who post pictures or videos of “identifiable persons” without the consent of those photographed or filmed face liability under Spain’s Law 15/1999, On the Protection of Personal Data (LOPD). The Spanish DPA held that, by posting a video of several youths taunting an allegedly paranoid schizophrenic individual to YouTube without the consent of those depicted, an individual identified as “Mr. R.R.R.” committed a “serious” violation of the LOPD. While such violations are punishable by more than € 60,000 in fines, the Spanish DPA chose to impose a reduced penalty of € 1,500, stressing that the poster of the video had promptly removed it of his own accord after it was reported on by the news media. But even this diminished fine could scare Spanish users away from posting images or movies to social networking and other public websites, potentially cutting off the flow of the user-generated content on which these websites depend. http://www.steptoe.com/publications-5920.html

OBAMA ADMINISTRATION SUPPORTS TELCO SPY IMMUNITY (Wired, 26 Feb 2009) - The Obama administration vigorously defended congressional legislation late Wednesday that immunizes U.S. telecommunication companies from lawsuits about their participation in the Bush administration’s domestic spy program. It was the first time the Obama administration weighed in on a federal court challenge questioning the legality of the legislation President Barack Obama voted for as an Illinois senator in July. “Accordingly, the court should now promptly dismiss these actions,” the Justice Department wrote U.S. District Judge Vaughn Walker of San Francisco late Wednesday. Obama opposed immunity but voted for it because it was included in a new spy bill that gave the U.S. presidency broad, warrantless-surveillance powers. Justice Department spokesman Matthew Miller said in a statement that the immunity bill “is the law of the land, and as such the Department of Justice defends it in court.” http://blog.wired.com/27bstroke6/2009/02/obama-adminis-1.html DOJ letter here: http://blog.wired.com/27bstroke6/files/obamaspybrief.pdf

JUDGE ORDERS DEFENDANT TO DECRYPT PGP-PROTECTED LAPTOP (CNET, 26 Feb 2009) - A federal judge has ordered a criminal defendant to decrypt his hard drive by typing in his PGP passphrase so prosecutors can view the unencrypted files, a ruling that raises serious concerns about self-incrimination in an electronic age. In an abrupt reversal, U.S. District Judge William Sessions in Vermont ruled that Sebastien Boucher, who a border guard claims had child porn on his Alienware laptop, does not have a Fifth Amendment right to keep the files encrypted. “Boucher is directed to provide an unencrypted version of the Z drive viewed by the ICE agent,” Sessions wrote in an opinion last week, referring to Homeland Security’s Immigration and Customs Enforcement bureau. Police claim to have viewed illegal images on the laptop at the border, but say they couldn’t access the Z: drive when they tried again nine days after Boucher was arrested. Boucher’s attorney, Jim Budreau, already has filed an appeal to the Second Circuit. That makes it likely to turn into a precedent-setting case that creates new ground rules for electronic privacy, especially since Homeland Security claims the right to seize laptops at the border for an indefinite period. Budreau was out of the office on Thursday and could not immediately be reached for comment. At issue in this case is whether forcing Boucher to type in that PGP passphrase--which would be shielded from and remain unknown to the government--is “testimonial,” meaning that it triggers Fifth Amendment protections. http://news.cnet.com/8301-13578_3-10172866-38.html

**** LOOKING BACK ****
U.S. AGENCIES EARN D-PLUS ON COMPUTER SECURITY (SiliconValley.com, 16 Feb 2005) -- The overall security of computer systems inside the largest U.S. government agencies improved marginally since last year but still merits only a D-plus on the latest progress report from Congress. The departments of Transportation, Justice and the Interior made remarkable improvements, according to the rankings, which were compiled by the House Government Reform Committee and based on reports from each agency’s inspector general. But seven of the 24 largest agencies received failing grades, including the departments of Energy and Homeland Security. The Homeland Security Department encompasses dozens of agencies and offices previously elsewhere in government but also includes the National Cyber Security Division, responsible for improving the security of the country’s computer networks. ``Several agencies continue to receive failing grades, and that’s unacceptable,” said Rep. Tom Davis, R-Va., the committee’s chairman. ``We’re also seeing some exceptional turnarounds.” Davis said troubling areas included lax security at federal contractor computers, which could be used to break into government systems; a lack of contingency plans for broad system failures and little training available for employees responsible for security. The Transportation Department improved from a D-plus to an A-minus; the Interior Department, which failed last year, improved to a C-plus; and the Justice Department rose from a failing grade to B-minus. The poor grades effectively dampen efforts by U.S. policy makers to impose new laws or regulations to compel private companies and organizations to enhance their own security. Industry groups have argued that the government needs to improve its own computer security before requiring businesses to make such changes. http://www.siliconvalley.com/mld/siliconvalley/news/editorial/10915463.htm

**** NOTED PODCASTS ****
NEW ERA OF COMPUTING: THE OPPORTUNITIES AND CHALLENGES OF CLOUD-BASED SOFTWARE AND SERVICES (Berkman Center, 17 Feb 2009; Lisa Tanzi of Microsoft) - The IT industry is at the cusp of a new era of computing - one in which cloud computing will play a central role. Lisa will highlight key innovations that are driving this new computing era, the essential roles of cloud computing and software (i.e. software + services) in it, and the benefits it will provide. She also will also focus on several legal and policy issues that industry and governments will need to grapple with in this new era, including the movement of data across borders (and associated privacy and law enforcement issues), security of information, and the application of traditional telecommunications rules in a world where computing and communications technologies are converging. http://wilkins.law.harvard.edu/events/luncheons/2009-02-17_tanzi/2009-02-17_tanzi.mp3 [Editor: illustrates that even Microsoft can’t solve the associated jurisdictional issues; does do a good job of illuminating the problems; recommended for those of you who represent multinational entities.] … See also …

REPORT CITES POTENTIAL PRIVACY GOTCHAS IN CLOUD COMPUTING (Computerworld, 25 Feb 2009) - Companies looking to reduce their IT costs and complexity by tapping into cloud computing services should first make sure that they won’t be stepping on any privacy land mines in the process, according to a report released this week by the World Privacy Forum. The report runs counter to comments made last week at an IDC cloud computing forum, where speakers described concerns about data security in cloud environments as overblown and “emotional.” But the World Privacy Forum contends that while cloud-based application services offer benefits to companies, they also raise several issues that could pose significant risks to data privacy and confidentiality. http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9128636&source=rss_topic146

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.