Saturday, June 13, 2009

MIRLN --- 24 May – 13 June 2009 (v12.08)

• Insurance Coverage for Data Security Breaches: First Bank v. Federal Insurance Co.
• Bloomberg Forbids Mentioning Competitors, or Linking to Them
• Risk Calculators: Finance Geeks Use Open API to Crunch Market Numbers
• eBay Wins Europe Court Fight Against L’Oreal Over Fake Products
• Web Site has a Read On Digital Book Sales
• ITU Calls for Global Cybersecurity Measures
• Appeals Court Upholds No Exclusive Cable Rights in Apartments
• Judge Sotomayor is First Nominee with Cyberlaw Record
• Savvis Faces Bank Lawsuit over Cardsystems Data Breach
• Violating Facebook ToS to Access User Data Actionable as Copyright Infringement
• EFF Gives Copyright Education a Crack with New Curriculum
• TRO in Web Advertising Case Could Augur Major Problem for Search Engines and ISPS
• Id-Theft Ruling: Set Your Own Fraud Alerts
• Obama’s Public-Private Cybersecurity Challenge
• US Grapples With How to Retaliate in Cyber Attacks
• Another Court Ruling in Spain Finds Personal File Sharing to be Legal
• Report: Social Networking Up 83 Percent for U.S.
• New Programs Put Crime Stats on the Map
o Map of Disputes Between WTO Members
• Web Series Tied to ‘Blade Runner’ is in the Works
• Federal IT Security Recommendations Released in Final NIST Draft
• Web Privacy Study Finds Widespread Data Sharing, ‘Web Bugs’
• Web Site Tracks Policy Changes at Popular Sites
o iAwful, the Internet Advocates Watchlist for Ugly Laws
• The New Student Excuse?
• Judge Reprimanded for Friending Lawyer and Googling Litigant
• San Francisco Twitters with Citizens to Fix City
• Swedish Pirate Party Enters EU Parliament: Partial Results
• Army Orders Bases to Stop Blocking Twitter, Facebook, Flickr
• Magazine Cover Ads, Subtle and Less So
• Agencies Issue Frequently Asked Questions on Identity Theft Rules

PODCASTS | RESOURCES | BOOK REVIEW | FUN | LOOKING BACK | NOTES

**** NEWS ****

INSURANCE COVERAGE FOR DATA SECURITY BREACHES: FIRST BANK V. FEDERAL INSURANCE CO. (Perkins Coie, 16 April 2009) - On March 23, 2009, First Bank filed a breach of contract claim against its insurer, Federal Insurance Company (Chubb). First Bank v. Federal Insurance Company, No. 4:09-cv-00532 (Mo. Cir. Ct.). The case, although a classic insurance coverage dispute, deals with a relatively new policy form and relatively new type of insurance. The policy at issue is CyberSecurity by Chubb, and is meant to cover, among other things, losses stemming from data security breaches. In late 2007, First Bank had such a loss. The First Bank complaint highlights not only the importance of having specialized insurance coverage for data security breaches, but it also previews some of the defenses an insurer might use in resisting payment when there is a loss stemming from a data security breach. http://www.perkinscoie.com/datasecurity/blogQ.aspx?entry=5529

BLOOMBERG FORBIDS MENTIONING COMPETITORS, OR LINKING TO THEM (ValleyWag, 22 May 2009) - Bloomberg has distributed a policy to newsroom staff on blogging, Twittering and Facebook updating. And in keeping with the company’s tyrannical management culture, the rules are far more authoritarian than similar admonitions recently dispensed at the Wall Street Journal, New York Times and elsewhere. A mole forwarded us the excerpt below. It all but bans personal Web posts and status updates of all sorts. First it outlaws discussion of any topic covered by Bloomberg News. The financial wire covers a huge swath of events — “companies, markets, industries, economies and governments,” per its own marketing materials, plus “Arts and culture” and food — leaving little else to talk about. And even if a Bloomberg journalist does find an allowed topic, he would be hard-pressed to link to or even describe any relevant content, since company policy says staff may not “direct Internet traffic to media competitors or discuss them” (emphasis added). http://gawker.com/5266146/bloomberg-forbids-mentioning-competitors-or-linking-to-them

RISK CALCULATORS: FINANCE GEEKS USE OPEN API TO CRUNCH MARKET NUMBERS (Wired, 22 May 2009) - When AAA-rated companies began crumbling like sand castles in an earthquake last year, Jesper Andersen and Toby Segaran had the same thought: There has to be a better way of measuring corporate credit risk. Bond rating is plagued by insularity, they argue. Agencies like Moody’s and Standard & Poor’s lack transparency, use narrow data sets, and rely on too few models (one of which was the notorious Gaussian copula formula featured on Wired’s March cover). Worst of all, they’re paid by the firms they evaluate—an obvious incentive for grade inflation. “No one can pay for this and keep it fair,” Segaran says. The partners’ solution: a volunteer army of finance geeks. Their project, Freerisk.org, provides a platform for investors, academics, and armchair analysts to rate companies by crowdsourcing. The site amasses data from SEC filings (in XBRL format) to which anyone may add unstructured info (like footnotes) often buried in financial documents. Users can then run those numbers through standard algorithms, such as the Altman Z-Score analysis and the Piotroski method, and publish the results on the site. But here’s the really geeky part: The project’s open API lets users design their own risk-crunching models. The founders hope that these new tools will not only assess the health of a company but also identify the market conditions that could mean trouble for it (like the housing crisis that doomed AIG). http://www.wired.com/techbiz/people/magazine/17-06/st_alphageek

EBAY WINS EUROPE COURT FIGHT AGAINST L’OREAL OVER FAKE PRODUCTS (SiliconValley.com, 22 May 2009) - A British court today ruled that Internet marketplace eBay is not liable for bogus beauty products sold on its Web site, dealing a blow to cosmetics company L’Oreal’s campaign against the online auction giant. L’Oreal SA has taken San Jose-based eBay to court across Europe, suing in Britain, Germany, France, Belgium and Spain over the sale of fake fragrances and cosmetics on the site. L’Oreal claims there is an increasing volume of counterfeit goods being sold on eBay. The online auctioneer said negotiations between the companies on the issue broke down because L’Oreal was being unreasonable. Justice Richard David Arnold ruled in London’s High Court that eBay Europe was not liable for trademark infringements committed by its users. EBay said in a statement that the British ruling was “a victory for consumers and the thousands of entrepreneurs who sell legitimate goods on eBay every day.” A call placed with L’Oreal’s London office seeking comment was not immediately returned. Earlier this month, a French court ordered L’Oreal and eBay to settle their differences, giving them until May 25 to come up with a mediated settlement. Other cases elsewhere in Europe are still pending. http://www.siliconvalley.com/news/ci_12428403?nclick_check=1

WEB SITE HAS A READ ON DIGITAL BOOK SALES (SiliconValley.com, 24 May 2009) - Scribd is proposing to do for books what iTunes did for music — let readers buy only what they want to read. Eight years ago, Apple turned the music industry upside-down when it launched iTunes, an online music store that let listeners cherry-pick one or two songs instead of having to buy an entire album. Now Scribd is giving readers the option of buying content, including paying a few dollars for a chapter or two from a travel guide or a how-to book. That’s just one example of the flexibility that digital book purveyors are experimenting with as printed content migrates to the digital format. Another is the pricing model. Paperbacks largely have been priced about $10 to $15, while hardcovers are $25 to $30. With digital books, that price could be any amount. Scribd takes 20 percent of whatever price publishers and authors set for their works; the rest goes to the writer or publisher. Some authors, for example, are releasing their books on Scribd for $2. http://www.siliconvalley.com/news/ci_12442826

ITU CALLS FOR GLOBAL CYBERSECURITY MEASURES (H Security, 24 May 2009) - The International Telecommunication Union ITU has published its proposals for harmonising global cybersecurity legislation on the periphery of a conference on the information society in Geneva. At a discussion session, ITU General Secretary Hamadoun TourĂ© stated that the document, advertised as a “Cybersecurity Toolkit” is “no Bible and no Koran”, instead offering a list of best practices from existing legislation. Drafting of the document was entrusted to an expert group commissioned by the ITU and led by the American Bar Association’s Privacy and Computer Crime Committee (PACC). In Geneva, PACC boss Jody Westby emphasised that legislation from many different countries was considered in producing the document, which is intended as a model for national legislation. In addition to the Council of Europe’s ‘Convention on Cybercrime’, their search for model regulations also took in legislation from Australia, Canada, China and many other countries. http://www.h-online.com/security/ITU-calls-for-global-cybersecurity-measures--/news/113360 Information about the “Toolkit” is here: http://www.itu.int/ITU-D/cyb/cybersecurity/projects/cyberlaw.html

APPEALS COURT UPHOLDS NO EXCLUSIVE CABLE RIGHTS IN APARTMENTS (SiliconValley.com, 26 May 2009) - A federal appeals court says cable companies cannot have exclusive rights to provide service in apartment buildings that they wire. The decision today from the Court of Appeals in Washington upholds a Federal Communications Commission ruling that banned the exclusive agreements as anticompetitive. The deals involved a company exchanging a valuable service like wiring a multiunit building for cable in exchange for the exclusive right to provide service to all the residents. The commission said cable operators could no longer enter into such deals and existing ones could not be enforced. Associations representing cable companies and apartment building owners sued. But the appeals court sided with the FCC. http://www.siliconvalley.com/news/ci_12450859

JUDGE SOTOMAYOR IS FIRST NOMINEE WITH CYBERLAW RECORD (BNA’s Thomas O’Toole blog, 26 May 2009) - President Obama’s choice today for Associate Supreme Court Justice, Sonia Sotomayor, authored a handful of cyberlaw opinions while on the Second Circuit. All business disputes and a privacy case, but nothing (I hope) that could provide ammunition for the World’s Greatest Deliberative Body. About Judge Sotomayor I will venture this: If confirmed, she will be the first justice who has written cyberlaw-related opinions before joining the court. I looked just now and couldn’t find where Chief Justice Roberts or Associate Justice Alito had written a cyberlaw opinion while serving as appellate judges. (Then-Judge Alito missed both ACLU v. Reno and Playboy Entertainment Group, Inc. v. United States, a pair of new media cases that were decided initially by special three-judge panels in the Third Circuit.) I don’t think any of the following means much as far was what Judge Sotomayor will do as an Associate Supreme Court Justice. I’m passing it along for conversational purposes only. Judge Sotomayor wrote the court’s 2002 opinion in Specht v. Netscape Communications Corp., an important online contracting case. In Specht, the Second Circuit declined to enforce contract terms that were available behind a hyperlink that could only be seen by scrolling down on a Web page. A “reasonably prudent” user would not have learned of the existence of the terms before responding to an invitation to download free software, Judge Sotomayor wrote. http://pblog.bna.com/techlaw/2009/05/judge-sotomayor-is-first-nominee-with-cyberlaw-record.html

SAVVIS FACES BANK LAWSUIT OVER CARDSYSTEMS DATA BREACH (FinExtra, 26 May 2009) - Merrick Bank has launched a multi-million dollar lawsuit against Savvis, accusing the vendor of erroneously telling it that CardSystems Solutions complied with Visa and MasterCard security regulations less than a year before the payment processor’s systems were hacked, compromising up to 40 million credit card accounts. Atlanta-based CardSystems - now owned by Pay By Touch - identified a security incident in May 2005 that exposed more than 40 million credit cards to hackers. The following year the company agreed to settle federal charges that it failed to protect the financial data of millions of consumers. The US Federal Trade Commission (FTC) said the breach “led to millions of dollars in fraudulent purchases”. The FTC concluded CardSystems created unnecessary risks to the information by storing it and failed to ensure that its network was secure from attacks. Merrick, which is an acquiring bank for around 125,000 merchants, has now filed a federal complaint claiming the breach cost it around $16 million in payments to Visa and MasterCard for using a processor that did not meet their standards as well as payouts to affected banks and legal fees. Before the breach Merrick agreed to use CardSystems for processor and independent sales services if it proved compliance with Visa and MasterCard security requirements. The processor asked Savvis to assess and certify its compliance and got the all clear, and consequently the Merrick contract. http://www.finextra.com/fullstory.asp?id=20067

VIOLATING FACEBOOK TOS TO ACCESS USER DATA ACTIONABLE AS COPYRIGHT INFRINGEMENT (BNA’s Internet Law News, 28 May 2009) - BNA’s Electronic Commerce & Law Report reports that a federal court in California has ruled that accessing the Facebook social network through automated means to scrape personal data in violation of the Facebook terms of service is actionable as copyright infringement. The court allowed a copyright infringement claim against a social networking conglomeration service to survive a motion to dismiss. Case name is Facebook Inc. v. Power Ventures Inc.

EFF GIVES COPYRIGHT EDUCATION A CRACK WITH NEW CURRICULUM (ArsTechnica, 28 May 2009) - Teaching copyright to schoolkids is a recent innovation, one spurred in large part by the fantastical growth and amazing ease of digital copying—both legal and illegal. Most such programs have been drawn up by rightsholders in a not-so-subtle attempt to bolster their business models. For instance, “Think First, Copy Later: Respecting Creative Ownership” may have some educational value, but the title makes clear that this is not the kind of dispassionate material that belongs in our nation’s classrooms. Now, the Electronic Frontier Foundation has launched a curriculum of its own in an effort to “give students the real story about their digital rights and responsibilities on the Internet and beyond.” But if the rightsholder-produced material stresses the “responsibilities” side of the equation a bit too heavily, the EFF leans predictably the other way. The Web-based EFF curriculum is called, simply, “Teaching Copyright.” It makes clear that students should not infringe copyright, but this is secondary to extended discussions about the VCR, the photocopier, audio cassettes, and blank CDs—technologies that each posed challenges to copyright holders. In a classroom exercise on P2P music sharing, the class is asked to consider the case of a “12-year-old girl in Toledo” who is sued for file-sharing. “The 12-year-old girl downloaded the songs, but she didn’t know she was doing anything illegal,” we are told. “She found the files on a site that was free to access, but there were no warning signs that the bands didn’t authorize the site. She’s a huge fan of these bands—she owns all of their CDs and just wanted to hear the new songs.” As for the bands she downloaded, we learn that one wants her to pay for the music but the other “has a different perspective and supports music file-sharing technology, even encouraging fans to download its latest album of MP3s for free or for whatever they want to pay. Band B believes P2P file-sharing helps promote its music and encourages an even wider spectrum of music to be heard.” Needless to say, these are not the sort of perspectives stressed in “Think First, Copy Later.” The material is all accurate, as is the curricula of most rightsholders. But it’s striking just how different the emphases are in these materials. The EFF’s curriculum rightly says that P2P isn’t just for copyright infringement because “NASA is using BitTorrent to distribute massive photographs; BitTorrent is used to cheaply distribute the Linux operating systems that are free to users.” This is absolutely true, and absolutely important. But the material glosses quickly over the absolutely epic levels of infringement taking place on P2P networks. Perhaps those are just “fair use,” perhaps they should be monetized through a blanket license, but they are the major concern of rightsholders and seem at least worth discussing in more depth. http://arstechnica.com/tech-policy/news/2009/05/eff-gives-copyright-education-a-crack-with-new-curriculum.ars

TRO IN WEB ADVERTISING CASE COULD AUGUR MAJOR PROBLEM FOR SEARCH ENGINES AND ISPS (Steptoe & Johnson’s E-Commerce Law Week, 28 May 2009) - The Federal Trade Commission has won a temporary restraining order barring Yahoo!, Microsoft Network’s Live Search, AltaVista, and AllTheWeb from running certain deceptive advertisements -- even though the FTC did not name these search engines as defendants. The FTC’s complaint alleges that one or more unknown defendants violated the “deceptive acts or practices” prong of the FTC Act by purchasing search engine advertising that falsely suggested that the defendants were affiliated with the federal government’s “Making Home Affordable” program; however, clicking on the displayed links directed consumers to commercial websites that collected personal information and offered “paid home loan modification or foreclosure relief services.” In addition to directly enjoining the defendants from placing their deceptive ads, the TRO also requires the four search engines to: (1) “identify all persons” who paid them to place the ads; (2) “refuse to place paid advertisements that contain active hyperlinks that are labeled MakingHomeAffordable.gov, or any other domain name containing the top level domain name ‘gov,’ for any such person”; and (3) send the FTC copies of all ads placed by such persons, along with the conditions for triggering the ads, the number of times the hyperlinks in the ads were clicked, and the amount paid for each ad. The court explained that it was imposing these requirements on the search engines pursuant to Rule 65(d)(2)(C) of the Federal Rules of Civil Procedure, which states that a preliminary injunction may bind persons who receive notice of the injunction and “are in active concert or participation with” the parties to a case. http://www.steptoe.com/publications-6130.html FTC order here: http://www.ftc.gov/os/caselist/0923147/090518tro.pdf

ID-THEFT RULING: SET YOUR OWN FRAUD ALERTS (SiliconValley.com, 29 May 2009) - Companies that sell “identity-theft protection” present an alluring but questionable proposition. For as much as about $100 per year, the main thing they do is set fraud alerts that force banks to call people before new lines of credit are opened in their names. The alerts can be useful, but people can set them themselves, for free. Now even that function could be taken away from the ID theft-prevention services. A federal court in California has blocked Tempe, Ariz.-based LifeLock, one of the industry’s biggest players, from setting fraud alerts with Experian, one of the three main credit-reporting agencies that manage the fraud alerts. Experian is suing LifeLock, claiming that LifeLock’s automatic renewal of customers’ fraud alerts — which happens every 90 days, when they expire — costs Experian millions of dollars in processing expenses. In a ruling last week, a judge agreed with one of Experian’s central arguments, which is that LifeLock isn’t authorized to set alerts for consumers, and that federal law requires consumers to set alerts themselves by contacting credit bureaus directly. The ruling has caused at least one ID-theft prevention service, Debix, to announce it plans to drop fraud alerts and offer credit monitoring instead. The trend is likely to play out across the industry. http://www.siliconvalley.com/news/ci_12479986

OBAMA’S PUBLIC-PRIVATE CYBERSECURITY CHALLENGE (Business Week, 30 May 2009) - As part of its effort to address national cybersecurity concerns, the Obama Administration is urging closer cooperation between the government and private industry. In a 38-page report released May 29 on the government’s 60-day review of cyberspace policy, the Administration said the nation is at a “crossroads,” where digital information permeates national life, but that it’s also using infrastructure which is inherently insecure and vulnerable to attacks that can cause devastating disruptions. To overcome these weaknesses, the report calls for closer cooperation and more robust information-sharing between itself and private industry. While the government has the responsibility to protect and defend the country against attacks, it’s the private sector that builds and operates most of the systems, from computers and the software running on them to the telecommunications networks that connect them. “Private-sector engagement is required to help address the limitations of law enforcement and national security,” the report says. It goes on to say that leaders of various industries need to share more information about attacks and their financial impact. Security experts say the report struck a familiar tone. “It’s a fresh coat of paint on the same old stuff,” says John Pescatore, vice-president for information security research at Gartner (IT). Eleven years ago, President Bill Clinton signed Presidential Decision Directive 63, which among other things called for public-private partnerships to protect critical infrastructure. The main result was the creation of several Information Sharing & Analysis Centers, or ISACs, meant to bring together executives from private industry and government to share information about attacks and vulnerabilities. Several ISACs were created in industries such as electricity, water, and public transportation. All of them, except for the one created for the financial industry, effectively failed, Pescatore says. “In the ISACs, the government basically wanted companies to give it lots of information without getting anything back in return,” he says. And companies that have participated are loath to disclose sensitive information about attacks because doing so might also lead to the disclosure of trade secrets and other proprietary information. Companies reporting data theft often don’t trust the government to keep their sensitive information out of the hands of the public and competitors; many computer crimes go unreported as a result. Some companies have also worried that sharing too much information with participating competitors might be interpreted as collusion under antitrust laws. http://www.businessweek.com/technology/content/may2009/tc20090529_293343.htm?chan=technology_technology+index+page_top+stories Cybersecurity report here: http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf

US GRAPPLES WITH HOW TO RETALIATE IN CYBER ATTACKS (Washington Post, 2 June 2009) - In the murky world of computer espionage, the U.S. faces hard choices on how to retaliate when government or privately owned networks come under cyber attack, senior military and intelligence officials said Tuesday. As the administration grapples with how best to defend its computer networks, debate is raging over how far the U.S. can go in pursuit of cyber criminals, and even what constitutes a digital act of war. The most immediate challenge is identifying the hacker, terrorist or enemy nation that launched the attack in vast and anonymous cyberspace, officials said. That hurdle is complicated by privacy debates over how deeply the government can wade into privately owned systems to investigate threats, and how it should handle attacks against a company, as opposed to a federal agency. U.S. law allows “hot pursuit” of criminals, said former Air Force Secretary Michael Wynne, so computer users “may have to tolerate some hot pursuit” through their digital world so authorities can track and ultimately respond to cyber crimes. http://www.washingtonpost.com/wp-dyn/content/article/2009/06/02/AR2009060203037.html

ANOTHER COURT RULING IN SPAIN FINDS PERSONAL FILE SHARING TO BE LEGAL (TechDirt, 2 June 2009) - While the entertainment industry has been working over time to try to stop file sharing in Spain, court ruling after court ruling has found that personal file sharing is perfectly reasonable and legal -- and that sites that merely link to content rather than host it (i.e., search engines and trackers) aren’t breaking copyright law either. In the latest such case, a judge found that a guy who downloaded and shared over 3,000 movies wasn’t violating copyright law, because it was all for personal use with no intent to profit. http://techdirt.com/articles/20090531/2312145072.shtml

REPORT: SOCIAL NETWORKING UP 83 PERCENT FOR U.S. (CNET, 3 June 2009) - The explosion in social networking may be even greater than imagined. The time that people in the U.S. spend on social network sites is up 83 percent from a year ago, according to a report from market researcher Nielsen Online. Facebook enjoys the top spot among social networks, with people having spent a total of 13.9 billion minutes on the service in April of this year, 700 percent more than in April 2008, Nielsen said. Minutes spent on Twitter soared a whopping 3,712 percent to almost 300 million, versus around 7.8 million from the same month a year ago. Former top dog MySpace watched its usage drop nearly one-third to around 4.9 billion minutes, from 7.2 billion in April 2008. MySpace still scored the number one spot for online video among the top 10, thanks to its users streaming more than 120 million videos from the site for April of this year. But the report also offered a cautionary note: the social networking user can be fickle, quickly bouncing from one service to another. “Remember Friendster? Remember when MySpace was an unbeatable force? Neither Facebook nor Twitter are immune,” said Gibs. “Consumers have shown that they are willing to pick up their networks and move them to another platform, seemingly at a moment’s notice.” Despite its growth and popularity, Twitter may be especially vulnerable to users who don’t stick around. Another Nielsen report from April found that 60 percent of Twitter users--dubbed Twitter Quitters by the media--abandon their tweets after only one month of use. Only about 30 percent of users on MySpace and Facebook jump ship. http://news.cnet.com/8301-1023_3-10255626-93.html?tag=mncol

NEW PROGRAMS PUT CRIME STATS ON THE MAP (Wall Street Journal, 3 June 2009) - When a burglar broke into a home on the outskirts of Riverdale Park, Md., last month, some locals quickly received an email alert about the incident. Once police confirmed the crime on the scene, they followed up with a more thorough email disclosing the time, location and type of crime. The alert is part of a crime-information service that the Riverdale Park police department provides its residents about illegal activity in their neighborhoods. “It helps us keep the public informed,” says Teresa Chambers, police chief of Riverdale Park, a suburb of Washington, D.C. “It’s also a way for us to solicit help [from residents] in solving some of these crimes.” Across the country, Americans can increasingly track crime trends block by block as more police departments contract with Internet-based crime-mapping services. Since 2007, more than 800 police departments have begun working with Web sites like CrimeMapping.com, CrimeReports.com and EveryBlock.com. The services take live feeds from police record-keeping systems and automatically post the data on their sites. While the Web sites are free for consumers, they charge police departments about $200 a month to participate and they also sell advertising. Police say they use the sites to help change citizens’ behavior toward crime and encourage dialogue with communities so that more people might offer tips or leads. Some of the sites have crime-report blogs that examine activity in different locales. They also allow residents to offer tips and report crimes under way. http://online.wsj.com/article/SB124398235596978969.html

- and -

MAP OF DISPUTES BETWEEN WTO MEMBERS (WTO website, June 2009) - The World Trade Organization has recently posted on its website an interactive map that depicts disputes between its member states. The top of the webpage shows a list of highlight-able choices among types of member-state involvement in disputes: as complainant, respondent, or either. The accompanying map shows member-state areas of the world in a color range of whitish pink to red, to indicate the range in the number of disputes (0-100), and non-member-state areas in gray; the United States is bright red. http://www.wto.org/english/tratop_e/dispu_e/dispu_maps_e.htm

WEB SERIES TIED TO ‘BLADE RUNNER’ IS IN THE WORKS (New York Times, 4 June 2009) - Here is some news that will make fans of the 1982 science-fiction cult film “Blade Runner” shudder with either anticipation or trepidation. On Thursday the film’s director, Ridley Scott, announced that a new division of his commercials company, RSA Films, was working on a video series called “Purefold.” The series of linked 5- to 10-minute shorts, aimed first at the Web and then perhaps television, will be set at a point in time before 2019, when the Harrison Ford movie takes place in a dystopian Los Angeles. Mr. Scott, his brother Tony and his son Luke are developing the project in conjunction with the independent studio Ag8, which is run by one of the creators of “Where are the Joneses?” a British Web sitcom that solicited storyline suggestions from the audience. Similarly, “Purefold” will harvest story input from its viewers, in conjunction with the social media site FriendFeed. But the series won’t be hewing too closely to the specific characters or situations in “Blade Runner.” Some of that material stemmed from the Philip K. Dick novel “Do Androids Dream of Electric Sheep?” which the “Purefold” creators do not have rights to. “We don’t take any of the canon or copyrighted assets from the movie,” said David Bausola, founding partner of Ag8, who said he hoped the series would debut later this summer and that the first episodes would depict events about two years into the future. “It’s actually based on the same themes as ‘Blade Runner.’ It’s the search for what it means to be human and understanding the notion of empathy. We are inspired by ‘Blade Runner.’” Other partners in the project include the ad and marketing agencies WPP, Publicis, Aegis Media and Naked Communications. They will bring in advertisers whose products and brands — or hypothetical future versions of them — could be featured in the series. In an indication that the filmmakers are interested in exploring a new kind of collective, social creativity, the episodes in the series will be released under a Creative Commons license, marking the first time a major Hollywood director has embraced that alternative licensing scheme. The license means fans of the series can take the episodes and remix or otherwise repurpose them, and even make their versions available commercially under the same license. http://bits.blogs.nytimes.com/2009/06/04/web-series-tied-to-blade-runner-is-in-the-works/

FEDERAL IT SECURITY RECOMMENDATIONS RELEASED IN FINAL NIST DRAFT (GCN, 4 June 2009) - The National Institute of Standards and Technology has collaborated with the military and intelligence communities to produce the first set of security controls for all government information systems, including national security systems. The controls are included in the final draft version of Special Publication 800-53, Revision 3, titled “Recommended Security Controls for Federal Information Systems and Organizations,” released yesterday. NIST called the document, which is expected to be finalized July 1, historic. “For the first time, and as part of the ongoing initiative to develop a unified information security framework for the federal government and its contractors, NIST has included security controls in its catalog for both national security and non-national-security systems,” NIST said. “The updated security control catalog incorporates best practices in information security from the United States Department of Defense, intelligence community and civil agencies, to produce the most broad-based and comprehensive set of safeguards and countermeasures ever developed for information systems.” SP 800-53 is part of a series of documents setting out standards, recommendations and specifications for implementing the Federal Information Security Management Act. This revision is the first major update of these guidelines since its initial publication in December 2005. This document specifies the baseline security controls needed to meet the mandatory requirements of Federal Information Processing Standard (FIPS) 199, titled “Standards for Security Categorization of Federal Information and Information Systems,” and FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems.” http://gcn.com/Articles/2009/06/04/Cybersecurity-NIST-final-draft-SP-800-53.aspx SP 800-53/3 here: http://csrc.nist.gov/publications/drafts/800-53/800-53-rev3-FPD-clean.pdf

WEB PRIVACY STUDY FINDS WIDESPREAD DATA SHARING, ‘WEB BUGS’ (RedOrbit, 4 June 2009) - Researchers at the University of California, Berkeley’s School of Information released a report late Monday (June 1) showing that the most popular Web sites in the United States all share data with their corporate affiliates and allow third parties to collect information directly by using tracking beacons known as “Web bugs” - despite the sites’ claims that they don’t share user data with third parties. A key focus of the School of Information report is the use of Web bugs. Web analytics companies and advertising servers use Web bugs to track users for improved marketing or behavioral profiling. A Web bug is typically a small graphic embedded in a Web page, usually in the form of a 1-by-1 pixel image that is invisible to the naked eye. It turns out that a handful of tracking companies operating Web bugs have an incredible breadth of coverage, the researchers said. For example, five tracking companies were represented on more than half of the top 100 Web sites examined in the study, while Web bugs from Google and its subsidiaries were found on 92 of the top 100 Web sites and 88 percent of the approximately 400,000 unique domains examined in the study. “Web bugs are ubiquitous,” said Soltani. During the month of March 2009, the researchers found at least one Web bug on each of the top 50 Web sites, while most sites had several Web bugs and some had as many as 100. http://www.redorbit.com/news/technology/1700809/web_privacy_study_finds_widespread_data_sharing_web_bugs/

WEB SITE TRACKS POLICY CHANGES AT POPULAR SITES (AP, 4 June 2009) - A new Web site unveiled Thursday will track policies imposed by popular Internet sites such as Facebook and Google, hoping to help users spot potentially harmful changes. TOSBack.org, the brainchild of privacy advocacy group Electronic Frontier Foundation, will track terms of service modifications within hours of an update. The site will compare old and new policies side by side and highlight changes. With about two dozen sites covered already, TOSBack.org plans to add more agreements, from credit card, bank, cable TV and other companies. Tim Jones, the EFF’s activism and technology manager, hopes the site will help avoid debacles such as the one faced by Facebook in February. Changes to Facebook’s terms of use over control of content went unnoticed at first. But amid protests that Facebook might hold sway over content indefinitely, the company agreed to solicit user feedback. The site reverted to the previous terms of use policies as it tried to resolve the issues raised. Ultimately, Facebook let users vote on revised terms, which clarify that users own their information, not Facebook. But Jones said many Web sites change their terms of service all the time and often don’t notify their users. “Terms of service policies are obviously really important. They form the foundation of your relationship with almost every site you visit on the Internet,” he said. “But almost no one really has time to read them or the legal background to read them.” TOSBack.org aims to make the general public more aware of user agreements and how it affects them, Jones said. http://tech.yahoo.com/news/ap/20090604/ap_on_hi_te/us_tec_web_site_policies_2 For TOSBack: http://www.TOSBack.org

- and -

iAWFUL, THE INTERNET ADVOCATES WATCHLIST FOR UGLY LAWS (NetChoice initiative) - Reckless and misguided laws, often originating at the state level, threaten to undermine the foundation of the free and open Internet. Some of the most serious threats to the Internet come in the form of lawmakers trying to ‘fix’ it. Knee-jerk, overly prescriptive laws can destroy whole business models or stifle innovative new forms of communication before they have a chance to emerge. Too many laws are proposed without considering unintended harm they may cause to thousands of Internet companies and millions of Internet users. NetChoice is dedicated to fighting these attacks on core Internet principles. Through this site, the Internet Advocates’ Watchlist For Ugly Laws (iAWFUL) will track dangerous legislation and mobilize citizens to defeat bills and proposals that threaten the future of ecommerce and online communication. The list will be continually updated to reflect the most immediate dangers, based on regulatory severity and likelihood of passage. http://netchoice.org/iawful/ Launch coverage by SiliconValley.com: http://www.siliconvalley.com/news/ci_12555124

THE NEW STUDENT EXCUSE? (InsideHigherEd, 5 June 2009) - Most of us have had the experience of receiving e-mail with an attachment, trying to open the attachment, and finding a corrupted file that won’t open. That concept is at the root of a new Web site advertising itself (perhaps serious only in part) as the new way for students to get extra time to finish their assignments. Corrupted-Files.com offers a service -- recently noted by several academic bloggers who have expressed concern -- that sells students (for only $3.95, soon to go up to $5.95) intentionally corrupted files. Why buy a corrupted file? Here’s what the site says: “Step 1: After purchasing a file, rename the file e.g. Mike_Final-Paper. Step 2: E-mail the file to your professor along with your ‘here’s my assignment’ e-mail. Step 3: It will take your professor several hours if not days to notice your file is ‘unfortunately’ corrupted. Use the time this website just bought you wisely and finish that paper!!!” http://www.insidehighered.com/news/2009/06/05/corrupted

JUDGE REPRIMANDED FOR FRIENDING LAWYER AND GOOGLING LITIGANT (ABA Journal, 5 June 2009) - A North Carolina judge has been reprimanded for “friending” a lawyer in a pending case, posting and reading messages about the litigation, and accessing the website of the opposing party. Judge B. Carlton Terry Jr. and lawyer Charles Shieck both posted messages about the child custody and support case heard last September, the Lexington Dispatch reports. Terry also accessed the website of the opposing litigant and cited a poem she had posted there, according to the April 1 public reprimand by the North Carolina Judicial Standards Commission. The opinion says Terry and Shieck first discussed Facebook in chambers in the presence of the opposing lawyer in the case, Jessie Conley, who said she didn’t know what Facebook was and didn’t have time for it. After the discussion, Terry and Shieck friended each other. Shieck later posted a Facebook reference to the issue of whether his client had had an affair, saying “How do I prove a negative?” according to the opinion. Shieck also wrote, “I have a wise judge.” Terry told Conley about Shieck’s posts the day after he read them. The same day during court proceedings he referenced the poem he found and posted a Facebook message that the case was in its last day of trial. After the hearing concluded, Terry disclosed to both parties that he had visited the website of Conley’s client, where he found the poem, and then disqualified himself at the request of Conley. Terry told investigators the poem had suggested that Conley’s client was not as bitter as he first thought and had given him hope for the litigants’ children. He also cooperated in the investigation, the opinion says. The opinion says the ex parte communications and the independent gathering of information indicated a disregard of the principles of judicial conduct. http://www.abajournal.com/mobile/judge_reprimanded_for_friending_lawyer_and_googling_litigant Reprimand here: http://www.aoc.state.nc.us/www/public/coa/jsc/publicreprimands/jsc08-234.pdf

SAN FRANCISCO TWITTERS WITH CITIZENS TO FIX CITY (InformationWeek, 8 June 2009) - In San Francisco, if you see a pothole that needs fixing or garbage on the sidewalk, don’t just complain about it -- tweet it. The city launched a program to allow people to send Twitter messages to city government for any nonemergency communications -- requesting garbage pickup, road repair, inquiring about where to get a copy of your marriage certificate, and more. The service connects the city’s 311 call center through Twitter. To sign up, users must go to sftwitter.sfgov.org and click on “Follow Me,” and then send a direct message to “d SF311” to talk to the city. Some examples: * * * http://www.informationweek.com/news/internet/social_network/showArticle.jhtml?articleID=217702151&cid=RSSfeed_IWK_News

SWEDISH PIRATE PARTY ENTERS EU PARLIAMENT: PARTIAL RESULTS (AFP, 8 June 2009) - A Swedish party that wants to legalise Internet filesharing and beef up web privacy scored a big victory Sunday by winning a European parliament seat, results showed. The Pirate Party won 7.1 percent of votes, taking one of Sweden’s 18 seats in the European parliament, with ballots in 5,659 constituencies out of 5,664 counted. The party was founded in January 2006 and quickly attracted members angered by controversial laws adopted in Sweden that criminalised filesharing and authorised monitoring of emails. Its membership shot up after a Stockholm court on April 17 sentenced four Swedes to a year in jail for running one of the world’s biggest filesharing sites, The Pirate Bay. Prime Minister Fredrik Reinfeldt’s conservative Moderates won 18.8 percent of votes and four seats, close to its score in the European election in 2004 but down sharply from the 26.1 percent it won in Sweden’s 2006 general election. http://www.google.com/hostednews/afp/article/ALeqM5ibr-ao4NgG8fOxsXiyjTJBNDdpnw

ARMY ORDERS BASES TO STOP BLOCKING TWITTER, FACEBOOK, FLICKR (Wired, 10 June 2009) - The Army has ordered its network managers to give soldiers access to social media sites like Facebook, Flickr, and Twitter, Danger Room has learned. That move reverses a years-long trend of blocking the web 2.0 locales on military networks. Army public affairs managers have worked hard to share the service’s stories through social sites like Flickr, Delicious and Vimeo. Links to those sites featured prominently on the Army.mil homepage. The Army carefully nurtured a Facebook group tens of thousands strong, and posted more than 4,100 photos to a Flickr account. Yet the people presumably most interested in these sites — the troops — were prevented from seeing the material. Many Army bases banned access to the social networks. An operations order from the Army’s 93rd Signal Brigade to all domestic Directors of Information Management, or DOIMs, aims to correct that. Issued on May 18th “for official use only,” the document has not been made public until now. It is “the intent of senior Army leaders to leverage social media as a medium to allow soldiers to ‘tell the Army story’ and to facilitate the dissemination of strategic, unclassified information,” says the order, obtained by Danger Room. Therefore, “the social media sites available from the Army homepage will be made accessible from all campus area networks. Additionally, all web-based email will be made accessible.” http://www.wired.com/dangerroom/2009/06/army-orders-bases-stop-blocking-twitter-facebook-flickr/

MAGAZINE COVER ADS, SUBTLE AND LESS SO (New York Times, 11 June 2009) - ADS have been creeping onto magazine covers lately. Sometimes it’s blatant, as at Scholastic Parent & Child, which has been running actual ads on covers. Sometimes it’s subtle, as at Entertainment Weekly, which recently made its cover into a pocket, where it inserted a pull-out ad. In its July issue, Popular Science is taking a different approach. It has created a cover sponsored by General Electric. But the G.E. affiliation becomes obvious only when the cover is held up to a Web camera. Although other magazine publishers have used cover ads to generate cash, Popular Science did not charge G.E. for the cover. Ads on covers violate rules set by the American Society of Magazine Editors, which requires a clear separation between editorial space and advertising space. Though the repercussions for putting ads on the cover are not severe — the society sends a letter of reprimand, and occasionally bars the publication from competing in the National Magazine Awards — magazines have gone to great lengths to avoid clear-cut cover advertisements. The Popular Science cover depicts windmills that look like something out of “Star Wars,” and promotes articles about energy. A box announces that the cover is three-dimensional. When a reader holds it up to a computer Webcam, it signals the computer to display Flash-based imagery. The computer shows a 3-D scene of windmills over the cover, and the reader can blow on the computer microphone to move the windmills’ blades. The technology is called augmented reality. It combines a real image with a virtual one, and viewers can adjust the real image to change the virtual one. To kick-start the technology, the providers ask viewers to hold up a trigger image — the cover, in this case — to a Webcam. (People without the Popular Science cover can go to www.popsci.com/imagination beginning Tuesday to print out a copy of the cover and use the program.) http://www.nytimes.com/2009/06/12/business/media/12adco.html?_r=1&ref=business

AGENCIES ISSUE FREQUENTLY ASKED QUESTIONS ON IDENTITY THEFT RULES (FTC, 11 June 2009) - Six federal agencies issued a set of frequently asked questions (FAQs) today to help financial institutions, creditors, users of consumer reports, and issuers of credit cards and debit cards comply with federal regulations on identity theft and discrepancies in changes of address. The “Red Flags and Address Discrepancy Rules,” which implement sections of the Fair and Accurate Credit Transactions Act of 2003, were issued jointly on November 9, 2007, by the Board of Governors of the Federal Reserve System (FRB), Federal Deposit Insurance Corporation (FDIC), National Credit Union Administration (NCUA), Office of the Comptroller of the Currency (OCC), Office of Thrift Supervision (OTS), and Federal Trade Commission (FTC). The rules require financial institutions and creditors to develop and implement written Identity Theft Prevention Programs and require issuers of credit cards and debit cards to assess the validity of notifications of changes of address. The rules also provide guidance for users of consumer reports regarding reasonable policies and procedures to employ when consumer reporting agencies send them notices of address discrepancy. The agencies developed answers to these FAQs to provide guidance on numerous aspects of the rules, including which types of entities and accounts are covered, establishment and administration of an Identity Theft Prevention Program, address validation requirements applicable to card issuers, and the obligations of users of consumer reports upon receiving a notice of address discrepancy. The FTC also has developed a Web site, www.ftc.gov/redflagsrule, with additional resources and guidance for creditors and financial institutions that are within its jurisdiction. http://ftc.gov/opa/2009/06/redflags.shtm

**** NOTED PODCASTS ****
ARE WE IN CONTROL OF OUR OWN DECISIONS? (TED Talk by Dan Ariely, 19 May 2009) - Behavioral economist Dan Ariely, the author of Predictably Irrational, uses classic visual illusions and his own counterintuitive (and sometimes shocking) research findings to show how we’re not as rational as we think when we make decisions. http://www.ted.com/talks/dan_ariely_asks_are_we_in_control_of_our_own_decisions.html [Editor: pretty interesting 10-minute presentation, with implications for election ballot design.]

**** RESOURCES ****
E-POLICY PROGRAMS: ESSENTIAL FOR IP PROTECTION (ABA’s Landslide Magazine, March/April 2009; article by V. Polley) - Fourteen years ago the Internet was a novelty. Back then, communications were largely face-to-face, they used the U.S. mails or telephone, and they had some parties making limited use of early email systems. Intellectual property was little threatened by mass communication or espionage. Fourteen years later Internet-enabled workplace tools are everywhere, and they are continuing to evolve in unanticipated ways. Like an unpredictable teenager disrupting your home, they require rules and discipline. But it’s also important to listen to your teenager—simply telling her to behave is unlikely to succeed. Moreover, she probably has a better understanding than her parents of these kinds of new tools: by listening to her you can get early warning of problems. IP protection is similarly complicated in 2009, and the appropriate response comes from a measured combination of rules, discussion, and tolerance. http://files.knowconnect.com/public/E_Policy_Programs_for_IP_Protection_Landslide_MarchApril_2009.pdf; follow-on 15 minute audio interview of Polley by LawCast (April 2009) available here: http://files.knowconnect.com/public/LawCast_Polley_on_IP_Protection_thru_ECPs.mp3

INFORMAL CORPORATE DISCLOSURE IN THE AGE OF TWITTER (McDermott Will & Emery, 20 May 2009) - For public companies listed on the New York Stock Exchange (NYSE), the long-standing mandatory use of press releases as a means of disseminating material company information has finally given way to the immediacy and near-ubiquity of the internet. Effective May 7, 2009, NYSE-listed companies are no longer required to use press releases to distribute material information, but only encouraged to do so. Instead, the amended NYSE Immediate Release Policy provides that, subject to certain conditions, material information required to be released promptly can be disclosed by means of any Regulation FD compliant method.1 Considered long overdue by many—the Nasdaq Stock Market made a similar change several years ago—the change is most notable for removing a relatively minor but symbolically significant obstacle to broader use of advanced technologies by public companies in their communications with investors and the public at large. The change to the NYSE’s Immediate Release Policy is consistent with guidance (the Website Guidance2) issued in 2008 by the U.S. Securities and Exchange Commission (SEC) on how company websites can be primary vehicles for communicating with investors without violating the SEC’s general antifraud rule, Rule 10b-5, or Regulation FD, which proscribes the selective disclosure of material nonpublic information. The Website Guidance, in which the SEC encouraged the use of company websites for disclosure, is not considered a change in SEC regulation, but rather a principles-based interpretation of existing relevant law and regulation applied to the challenges and opportunities faced by emerging technologies. Whether the legal framework articulated in the Website Guidance is sufficient to address the accelerating adoption by millions of corporate and individual users of communications tools and social networking sites, such as Twitter, blogs, LinkedIn and Facebook, remains to be seen, but it is essential that public companies appreciate and appropriately manage the legal risks associated with the use of these activities, and those still to emerge, in the distribution of material information to investors. http://www.mwe.com/info/news/wp0509b.pdf [Editor: useful white paper.]

**** BOOK REVIEW ****
DISCOVERING THE DIGITAL RECORD—THE QUESTIONS FOR EXAMINATION (by Jeffrey Ritter and David Gaston) -- Nearly 200 pages, the book presents a comprehensive, integrated asset that pulls together the legal and technology knowledge required for lawyers to develop and execute competent and effective electronic discovery. “Discovering the Digital Record is designed for lawyers and IT professionals with limited e‐discovery experience,” Ritter observed. “Through training over 750 professionals in the last year, we have learned that there is a critical need to transfer to lawyers the knowledge and tools they need to effectively investigate the authenticity of digital records offered for the truth. Our new book delivers the same knowledge and tools that have been described by our students and readers as ‘remarkable, awesome, and invaluable!’”, Ritter said. “With this book, we can enable lawyers to construct efficient, powerful discovery requests that ask for the right information for proving the truth of any business record.” http://www.wec-llc.com/Discovering%20the%20Digital%20Record--Press%20Release.pdf

**** FUN ****
WI-FI SIGNAL STATUS FOR YOU AND THE WORLD! (ThinkGeek product ad) - Here at ThinkGeek we’re pretty lazy when it comes to technology. We expect our gadgets to do all the busywork while we focus on the high level important tasks like reading blogs. That’s why we hate to have to crack open our laptops just to see if there is any wi-fi internet access about... and keychain wi-fi detectors, we would have to actually remove them from our pockets to look at them. But now thanks to the ingenious ThinkGeek robot monkeys you can display the current wi-fi signal strength to yourself and everyone around you with this stylish Wi-Fi Detector Shirt. The glowing bars on the front of the shirt dynamically change as the surrounding wi-fi signal strength fluctuates. Finally you can get the attention you deserve as others bow to you as their reverential wi-fi god, while geeky chicks swoon at your presence. You can thank us later. Product Features
• Glowing animated shirt dynamically displays the current wi-fi signal strength.
• Shows signal strength for 802.11b or 802.11g
• Black 100% Cotton T-Shirt
http://www.thinkgeek.com/tshirts-apparel/interactive/991e/

SOME THOUGHTS ON THE PLEASURES OF BEING A RE-READER (NYT Editorial Observer, 30 May 2009) - I’ve always admired my friends who are wide readers. A few even pride themselves on never reading a book a second time. I’ve been a wide reader at times. When I was much younger, I spent nearly a year in the old Reading Room of the British Museum, discovering in the book I was currently reading the title of the next I would read. But at heart, I’m a re-reader. The point of reading outward, widely, has always been to find the books I want to re-read and then to re-read them. In part, that’s an admission of defeat, an acknowledgement that no matter how long and how widely I read, I will only ever make my way through a tiny portion of the world’s literature. (The British Museum was a great place to learn that lesson.) And in part, it’s a concession to the limits of my memory. I forget a lot, which makes the pleasure of re-reading all the greater. The love of repetition seems to be ingrained in children. And it is certainly ingrained in the way children learn to read — witness the joyous and maddening love of hearing that same bedtime book read aloud all over again, word for word, inflection for inflection. Childhood is an oasis of repetitive acts, so much so that there is something shocking about the first time a young reader reads a book only once and moves on to the next. There’s a hunger in that act but also a kind of forsaking, a glimpse of adulthood to come. The work I chose in adulthood — to study literature — required the childish pleasure of re-reading. When I was in graduate school, once through Pope’s “Dunciad” or Berryman’s “The Dream Songs” was not going to cut it. A grasp of the poem was presumed to lie on the far side of many re-readings, none of which were really repetitions. The same is true of being a writer, which requires obsessive re-reading. But the real re-reading I mean is the savory re-reading, the books I have to be careful not to re-read too often so I can read them again with pleasure. It’s a miscellaneous library, always shifting. It has included a book of the north woods: John J. Rowlands’s “Cache Lake Country,” which I have re-read annually for many years. It may still include Raymond Chandler, though I won’t know for sure till the next time I re-read him. It includes Michael Herr’s “Dispatches” and lots of A.J. Liebling and a surprising amount of George Eliot. It once included nearly all of Dickens, but that has been boiled down to “The Pickwick Papers” and “Great Expectations.” There are many more titles, of course. This is not a canon. This is a refuge. Part of the fun of re-reading is that you are no longer bothered by the business of finding out what happens. Re-reading “Middlemarch,” for instance, or even “The Great Gatsby,” I’m able to pay attention to what’s really happening in the language itself — a pleasure surely as great as discovering who marries whom, and who dies and who does not. The real secret of re-reading is simply this: It is impossible. The characters remain the same, and the words never change, but the reader always does. Pip is always there to be revisited, but you, the reader, are a little like the convict who surprises him in the graveyard — always a stranger. I look at the books on my library shelves. They certainly seem dormant. But what if the characters are quietly rearranging themselves? What if Emma Woodhouse doesn’t learn from her mistakes? What if Tom Jones descends into a sodden life of poaching and outlawry? What if Eve resists Satan, remembering God’s injunction and Adam’s loving advice? I imagine all the characters bustling to get back into their places as they feel me taking the book down from the shelf. “Hurry,” they say, “he’ll expect to find us exactly where he left us, never mind how much his life has changed in the meantime.” http://www.nytimes.com/2009/05/30/opinion/30sat4.html?_r=1&ref=opinion

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
GROUP APPROVES CONTROVERSIAL SOFTWARE LAW -- The National Conference of Commissioners on Uniform State Laws (NCCUSL) voted Thursday in favor of the controversial UCITA proposal that would create common licensing rules for software and other IT transactions. The vote does not make UCITA law, but experts say that most state legislatures adopt laws recommended by the organization. Critics say UCITA would rob IT companies and other software customers of their rights and leave them at the whim of software vendors. The law deregulates product licensing and addresses software, multimedia interactive products, data and databases, and the Internet and online information. It also contains provisions to allow vendors to shut down software remotely if they suspect a violation of the licensing terms, make shrink-wrapped licensing terms enforceable even though the buyer will not see the license until after the software is purchased, ban reverse engineering, and allow vendors to disclaim warranties. (InfoWorld Electric 07/29/99) -- see also

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, May 23, 2009

MIRLN --- 3-23 May 2009 (v12.07)

• Wiki Operator Sues Apple Over Bogus Legal Threats
• Ottawa Courtroom Joins Twitter Age for Mayor’s Trial
• Mini-Links to Web Sites are Multiplying
• Owned? Legal Terms of Video Hosting Services Compared
• HHS Guidance Could Set Encryption Standard
• $12.6 Million Spent so far to Respond to Heartland Breach
• Hackers Want Millions for Data on Prescriptions
o UC Berkeley Computers Hacked, 160,000 at Risk
• EC Wants Software Makers Held Liable for Code
• A Twitter Code of Conduct
• Linden Labs Gets Zapped in Lawsuit by Taser for Hosting the Sale of “Virtual Goods” that Look Like the Real Thing
• Flickr Creates New License for White House Photos
• Dell Bans E-Waste Export to Developing Countries
• Google Unveils New Search Products
• Up to 24 Percent of Software Purchases Now Open Source
• Google Re-Shoots Japan Scenes after Privacy Complaints
• Financial Industry Regulator Fines Firm for Data Security Failings
• FTC Drops Antitrust Claim Against Rambus
• New iPhone App Helps You Keep Tabs on Politicians’ Voting Records
o A Million Downloads: Free Stanford Course on Creating iPhone Apps Takes off at a Furious Pace
• GM Stakes Virtual Property on Case of Bankruptcy
• Fourth Circuit Limits SCA Statutory Damages
• Crackho.Com DNS Prank Ruffles Sarah Palin’s Feathers
o Six Simple Steps You Can Take to Protect Your Gripe or Parody Site
• Google Liberalizes US Trademark Policy: “What, Me Worry?” Part 2
• Olympic Blogs Get Go-Ahead for Vancouver
• Safety Act Offers both Liability Protection and Liability Avoidance for Companies, Directors and Officers, and Preservation of Stockholders’ Value
• Track Business Executives’ Tweets with Exectweets
• Who Owns Your Name on Twitter?
o Newt Gingrich’s Lawyer Displays Ignorance of Both Twitter and the Law in Sending C&D
• UMICH First to Sign Up Under Google Books Settlement Terms
• IT Managers Under Pressure to Weaken Web Security Policy
• FTC Reaches Data Security Settlement with Mortgage Company
• Bloggers, Beware: What You Write Can Get You Sued

PODCASTS | RESOURCES | LOOKING BACK | NOTES

**** NEWS ****

WIKI OPERATOR SUES APPLE OVER BOGUS LEGAL THREATS (EFF, 27 April 2009) - The Electronic Frontier Foundation (EFF) filed suit against Apple Inc. today to defend the First Amendment rights of an operator of a noncommercial, public Internet “wiki” site known as BluWiki. Late last year, after BluWiki users began a discussion about making some Apple iPods and iPhones interoperate with software other than Apple’s own iTunes, Apple lawyers demanded removal of the content. In a letter to OdioWorks, the attorneys alleged that the discussions constituted copyright infringement and a violation of the Digital Millennium Copyright Act’s (DMCA’s) prohibition on circumventing copy protection measures. Fearing legal action by Apple, OdioWorks took down the discussions from the BluWiki site. Filed in federal court in San Francisco, the suit seeks a declaratory judgment that the discussions do not violate any of the DMCA’s anti-circumvention provisions, and do not infringe any copyrights owned by Apple. The discussions on the BluWiki site focused on how hobbyists might enable iPods and iPhones to work with desktop media management software other than Apple’s own iTunes software. The discussions were apparently spurred by Apple’s efforts prevent the iPod Touch and iPhone from working with competing media management software such as WinAmp and Songbird. “Apple’s legal threats against BluWiki are about censorship, not about protecting their legitimate copyright interests,” said Senior Staff Attorney Fred von Lohmann. “Wikis and other community sites are home to many vibrant discussions among hobbyists and tinkerers. It’s legal to engage in reverse engineering in order to create a competing product, it’s legal to talk about reverse engineering, and it’s legal for a public wiki to host those discussions.” http://www.eff.org/press/archives/2009/04/27 EFF’s complaint here: http://www.eff.org/files/filenode/odio_v_apple/Final%20Complaint.pdf

OTTAWA COURTROOM JOINS TWITTER AGE FOR MAYOR’S TRIAL (Ottawa Citizen, 4 May 2009) - Television cameras are barred from the criminal trial of Ottawa Mayor Larry O’Brien, but observers are free to use BlackBerrys, laptops and other forms of electronic text messaging to report live on the proceedings. In a small breakthrough for new media technologies, Judge J. Douglas Cunningham rejected concerns about “putting the genie back in the bottle” and said he would allow journalists to send messages from his courtroom directly to the Internet. Cunningham, who is associate chief justice of the Ontario Superior Court, cautioned that the ruling applies only to this particular trial. The new technologies could raise other concerns in a jury trial, he said. The ruling will allow Canwest News Service and other news organizations to provide moment-by-moment coverage of the trial via the popular Internet messaging service Twitter. It applies to anyone who attends, not just journalists. http://www.canada.com/news/Ottawa+courtroom+joins+Twitter+mayor+trial/1561931/story.html

MINI-LINKS TO WEB SITES ARE MULTIPLYING (New York Times, 4 May 2009) - If you have spent any time on the Internet in the last few months, chances are you have clicked on a shortened link Web address. URL shorteners, which abbreviate unwieldy Web addresses into bite-size links, have been around for years. The most popular service, TinyURL.com, was started in 2002 by a unicyclist named Kevin Gilbertson. But the tools have soared in popularity recently, in part because of microblogging sites like Twitter and Facebook, where messages are limited in length and every character counts. URL shorteners are easy to build, and dozens of competitors have proliferated, with minimalist, character-conserving names like Bit.ly, Is.gd and Tr.im. Most of them are simple tools created as a labor of love with no real business model behind them. Shorteners, however, could have real value beyond making Web addresses more manageable, said Danny Sullivan, editor of the blog Search Engine Land. They have the ability to keep track of use — how many times a particular link was clicked and the geographic location of the clickers — which could be valuable to marketers, news outlets and companies looking to measure the impact of a link, tweet or mention online. “The tracking element is very important,” said Mr. Sullivan. Some tools even highlight comments posted to Facebook or FriendFeed about a particular link — features that standard tools like Google Analytics may not be able to provide. One popular link shortening service, Bit.ly, is trying to build a business around that kind of data. Betaworks Studios is a New York technology incubator that has invested in Tumblr, a microblogging tool; OMGPOP, a social gaming site; and Outside.in, a hyperlocal news aggregator. It developed Bit.ly as an internal tool for its portfolio of companies to use. Because Bit.ly tracks its clipped URLs in real time, no matter where they are posted — instant messages, Twitter, Facebook, blogs or e-mail — the service could become “a real source for extracting information about how people are using the Web,” Mr. Sacca said. In addition to tracking links, Bit.ly uses a service called Calais, developed by Thomson Reuters, that can extract semantic terms from the Web pages that Bit.ly users are redirected to. This allows Bit.ly track the most popular topics being shared across the Web, as well as zero in on a specific category like finance or health care and retrieve the most popular Web sites shared on that subject in the last 24 hours. The company hopes that being able to track the “social distribution of information in real-time,” as Mr. Borthwick describes it, could potentially be relevant to the future of Web search. Although Bit.ly is not yet sure how to make money from all this data, “there’s a business model here,” Mr. Borthwick said. “We can smell it.” For all the convenience of short URLs, some Internet security experts worry that they could be used to camouflage spam and phishing attacks and redirect people to malicious Web sites. “People have no way to know where they’re going,” said Patrik Runald, chief security advisor at F-Secure Security Labs, a maker of security software. “These services are great and they serve a purpose, but at the same time, there is a darker side.” And if a shortening site shuts down, any links funneled through it would be lost forever, Mr. Runald said. http://www.nytimes.com/2009/05/04/technology/start-ups/04short.html?partner=rss&emc=rss

OWNED? LEGAL TERMS OF VIDEO HOSTING SERVICES COMPARED (Markus Weiland, 6 May 2009) - For the Air Canada article I was researching a video hosting service that would match my requirements of:
• Which rights of my work I would have to give away,
• What usage rights I could assign to my viewers,
• What level of privacy I could expect in terms of disclosure of my data, and
• Where a service had its legal residence in case of a dispute.
I’ve decided to collect and extend my findings in this post in the hope that it can help others in choosing their preferred video hosting service. A summary is provided at the end of this post, based on my understanding of the legal terms as a non-lawyer. All excerpts were made on April 25, 2009 unless otherwise stated. Emphasis and comments mine. http://advancingusability.wordpress.com/2009/05/06/owned-legal-terms-of-video-hosting-services-compared/ [Referenced in Larry Lessig’s blog on 13 May 2009]

HHS GUIDANCE COULD SET ENCRYPTION STANDARD (Steptoe & Johnson’s E-Commerce Law Week, 7 May 2009) - New Department of Health and Human Services guidance on “render[ing] protected health information unusable, unreadable, or indecipherable to unauthorized individuals” could help establish a national standard for the use of encryption to protect sensitive information. As we previously reported, the guidance applies to two sets of notification requirements for breaches of electronic health records that were created by the American Recovery and Reinvestment Act of 2009. One set is administered by HHS (for entities covered by the Health Insurance Portability and Accountability Act, or HIPAA, and their business associates), while the other is administered by the Federal Trade Commission (for non-HIPAA entities). But both sets state that covered entities will not be required to notify individuals if the breached information was secured using “technologies and methodologies” specified in the HHS guidance. This guidance sets forth two approved methods of security -- encryption and destruction. This is in line with breach notification laws already in force in many states, which often provide safe harbor if the information that has been accessed has been encrypted or otherwise rendered unreadable. However, the HHS guidance goes further by limiting the encryption methods that may be used to claim safe harbor to specified “encryption processes” that have been tested and approved by the National Institute of Standards and Technology. http://www.steptoe.com/publications-6100.html

$12.6 MILLION SPENT SO FAR TO RESPOND TO HEARTLAND BREACH (SC Magazine, 8 May 2009) - The chief executive of Heartland Payment Systems said Thursday that the payment processor so far has spent $12.6 million in responding to the massive data breach that was announced in January. But additional fines, legal fees and the cost of repairing a reputation potentially tarnished by the break-in will cost Heartland millions more, experts told SCMagazineUS.com on Friday. More than half of the $12.6 million cost is related to a MasterCard fine levied against Heartland’s sponsor banks, Chairman and CEO Robert Carr said Thursday during a conference call announcing the company’s first-quarter earnings. The fine, which is passed by the sponsor banks to Heartland, was issued because MasterCard alleged that Heartland failed to take proper actions after it learned of a possible breach and after it disclosed the incident to the public, Carr said, according to a transcript of the call. Heartland already is defending itself against at least two lawsuits, including a suit filed in New Jersey that accuses Heartland of failing to protect consumer data. The processor also will face continued costs of retaining or gaining new merchant clientele, Spinney said. “If they want to regain the trust of their customers, that’s going to cost some money, not only in PR and marketing, but also in increasing their investment in security technologies, procedures and training,” Spinney said. To the technology point, Heartland is “on schedule” to deploy its end-to-end encryption solution, Carr said. http://www.scmagazineus.com/126-million-spent-so-far-to-respond-to-Heartland-breach/article/136491/

HACKERS WANT MILLIONS FOR DATA ON PRESCRIPTIONS (Washington Post, 8 May 2009) - The FBI and Virginia State Police are searching for hackers who demanded that the state pay them a $10 million ransom by Thursday for the return of millions of personal pharmaceutical records they say they stole from the state’s prescription drug database. “This was an intentional criminal act against the commonwealth by somebody who was trying to harm others,” Gov. Timothy M. Kaine (D) said. “There are breaches that happen by accident or glitches that you try to work out. It’s difficult to foil every criminal that may want to do something against you.” State officials say it is unclear whether the hackers were able to view the patient records, as they have claimed. If the theft is real, it would be the most serious cybercrime the state has faced in recent history. State officials learned April 30 that hackers had replaced the site’s home page with a ransom note demanding the payment in exchange for a password needed to retrieve the records, according to a posting on Wikileaks.org, an online clearinghouse for leaked documents. “For $10 million, I will gladly send along the password,” the ransom note read. “You have 7 days to decide. If by the end of 7 days, you decide not to pony up, I’ll go ahead and put this baby out on the market and accept the highest bid.” The program’s computer system has been shut down since last week’s breach, but all data were backed up and those files have been secured, Whitley Ryals said. Virginians are still able to get prescriptions filled. http://www.washingtonpost.com/wp-dyn/content/article/2009/05/07/AR2009050702515.html?wprss=rss_technology The data were backed up: http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9132678

- and -

UC BERKELEY COMPUTERS HACKED, 160,000 AT RISK (CNET, 8 May 2009) - Hackers broke into the University of California at Berkeley’s health services center computer and potentially stole the personal information of more than 160,000 students, alumni, and others, the university announced Friday. At particular risk of identity theft are some 97,000 individuals whose Social Security numbers were accessed in the breach, but it’s still unclear whether hackers were able to match up those SSNs with individual names, Shelton Waggener, UCB’s chief technology officer, said in a press conference Friday afternoon. The attackers accessed a public Web site and then bypassed additional secured databases stored on the same server. In addition to SSNs, the databases contained health insurance information and non-treatment medical information, such as immunization records and names of doctors patients had seen. No medical records (i.e. patient diagnoses, treatments, and therapies) were taken, as they are stored in a separate system, emphasized Steve Lustig, associate vice chancellor for health and human services. “Their ID has not been stolen,” he added. “Some data has been stolen.” The server breach began on October 9, 2008, and continued through April 9, when a campus computer administrator doing routine maintenance discovered messages left by the attackers. http://news.cnet.com/8301-1009_3-10236793-83.html

EC WANTS SOFTWARE MAKERS HELD LIABLE FOR CODE (ZDnet, 8 May2009) - Software companies could be held responsible for the security and efficacy of their products, if a new European Commission consumer protection proposal becomes law. Commissioners Viviane Reding and Meglena Kuneva have proposed that EU consumer protections for physical products be extended to software. The suggested change in the law is part of an EU action agenda put forward by the commissioners after identifying gaps in EU consumer protection rules. A priority area for possible EU action is “extending the principles of consumer protection rules to cover licensing agreements of products like software downloaded for virus protection, games or other licensed content”, according to the commissioners’ agenda. “Licensing should guarantee consumers the same basic rights as when they purchase a good: the right to get a product that works with fair commercial conditions.” EU consumer commissioner Kuneva said that more accountability for software makers, and for companies providing digital services, would lead to greater consumer choice. http://news.zdnet.co.uk/software/0,1000000121,39649689,00.htm

A TWITTER CODE OF CONDUCT (Business Week, 8 May 2009) - During a recent tour of interactive ad agency Tocquigny’s Austin (Tex.) headquarters, Chief Executive Yvonne Tocquigny was confronted by her guest, an executive from a large energy company who was a potential client. The visitor had recently learned that Tocquigny was wooing one of his company’s competitors—by seeing a message that one of Tocquigny’s employees had posted to Twitter “It took me by surprise,” says Tocquigny. “I realized that we needed to be more cautious about what we throw out there in to the universe.” Twitter can be a great business tool. But as use of the Web site for 140-character messages spreads to workplaces around the world, companies are also discovering the risks. Now, instead of just worrying about a dubious blog post or an embarrassing photo of the boss being posted to Facebook, employers have to contend with staffers shooting off frequent blasts of personal insight into a public and traceable sphere. “The concept of [workers] posting inappropriate material that could be harmful has been around for a while, but Twitter accelerates the problem because of its immediacy and volume,” says Mark Rasch, a former head of the U.S. Justice Dept.’s computer crime unit who now consults with companies on creating policies to address employees’ use of technology. To prevent sensitive information leaks, blemishes on a reputation, and other potential liabilities of a Twittering workforce, companies are drafting new employee codes of conduct and educating workers about what they should and shouldn’t say on the site. The basic rule: Don’t be stupid. http://www.businessweek.com/managing/content/may2009/ca2009058_089205.htm?campaign_id=mag_May14&link_position=link47

LINDEN LABS GETS ZAPPED IN LAWSUIT BY TASER FOR HOSTING THE SALE OF “VIRTUAL GOODS” THAT LOOK LIKE THE REAL THING (Cobalt Law, 11 May 2009) - Linden Labs, the host of the immensely popular site Second Life, an online virtual world, has been sued in an Arizona district court for trademark infringement and unfair competition. The complaint, filed by Taser International, makers of non-lethal (and sometimes lethal) weapons, claims Linden Labs allows third parties to sell TASER guns inside the virtual world. Just so we’re clear, no one on Second Life is actively selling real TASER guns; rather Taser is suing Linden (who doesn’t sell anything), for letting people sell virtual (digitally created) guns that look like TASER weapons, and that use the TASER brand. The suit also alleges unfair competition, trade dress infringement, and false designation of origin, among other claims. It’s not the first time a company has sued Linden; neither is it the first time a company has sued a hosting site for trademark infringement by third parties (think: Google). It may, however, be the first time a company has sued another company for hosting a site where third parties selling products that aren’t even real. Is it time for a Digital Millennium Trademark Act? Practice Note: Notwithstanding the fact that there is no DMTMA, companies may want to consider adopting a policy that allows them to stay an arms length away from disputes between users when it comes to trademarks. It’s not a fail-safe method of safe harbor protection, but it may make would-be plaintiffs feel they have an option short of filing a lawsuit, for getting hard-to-find users to stop using their marks. http://www.cobaltlaw.com/news/linden-labs-gets-zapped-in-lawsuit-by-taser-for-hosting-the-sale-of-”virtual-goods”-that-look-like-the-real-thing

FLICKR CREATES NEW LICENSE FOR WHITE HOUSE PHOTOS (Wired, 11 May 2009) - Official White House photos are now officially in the public domain, thanks to a licensing change made quietly over the weekend by the Obama administration and the photo-sharing site Flickr. The White House began posting striking photos of President Barack Obama from its official photographer Pete Souza to the Web 2.0 site in early May. The White House chose to license them using the ultra-liberal Creative Commons Attribution license that lets people reuse, reprint and remix the photos just as long as they credit the original photographers. But as Creative Commons, the Electronic Frontier Foundation and other online commenters noted, that license won’t work — even for Obama’s official photographer — because government works can’t be copyright. Someone must have been listening, because sometime over the weekend, the licenses changed, and now the photos are labeled “United States Government Work” and link to an explanation on copyright.gov. The White House, however, continues to use the Creative Commons Attribution 3.0 license for all third-party content published on the www.whitehouse.gov site. The change marks a first for Flickr, which to date has not had a license for government works, other than a “No Known Copyright Restriction” license that is used on photos from its Commons project, which includes photos from some of the world’s greatest museums and libraries. Those photos include ones from the Library of Congress, for instance, that never were copyright since they were made or paid for by the federal government. http://www.wired.com/epicenter/2009/05/flickr-creates-new-license-for-white-house-photos/ and http://www.eff.org/deeplinks/2009/05/white-house-photos-u

DELL BANS E-WASTE EXPORT TO DEVELOPING COUNTRIES (SiliconValley.com, 12 May 2009) - PC maker Dell on Tuesday formally banned the export of broken computers, monitors and parts to developing countries amid complaints that lax enforcement of environmental and worker-safety regulations have allowed an informal and often hazardous electronic-waste recycling industry to emerge. Although Dell’s announcement does not mark a significant change in the PC maker’s behavior, environmental groups hope that by making its standards public, Dell will raise the bar for other electronics makers. In the absence of U.S. regulations, those groups are banking on competitive pressure to make companies improve their e-waste practices. Environmental groups like Greenpeace and the Basel Action Network have tracked shipments of e-waste intended for recycling to countries such as China, Ghana and Nigeria and found computers, TVs and other electronics being dismantled by smashing or burning, exposing people to mercury, lead and other toxic chemicals. No one knows exactly how much of the electronics turned over to recyclers ends up in such conditions, but Greenpeace and others say it could be 50 percent to 80 percent of the items collected in the U.S. for recycling. That’s despite broad acceptance of the Basel Convention, an international treaty that controls the movement of hazardous waste across borders. The U.S. has yet to ratify the Basel Convention. http://www.siliconvalley.com/news/ci_12351533?nclick_check=1

GOOGLE UNVEILS NEW SEARCH PRODUCTS (PC Magazine, 12 May 2009) - Days before the planned launch of the Wolfram Alpha search engine, Google on Tuesday announced a series of new search products intended to provide more relevant results. The new offerings include Google Search Options, Google Squared, Rich Snippets, and an astrology-related Android app. Google Search Options is a “rich set of tools that let you slice and dice your results,” Marissa Mayer, vice president of search products and user experience, said during a presentation at Google’s Mountain View headquarters. Specifically, once you conduct a normal Web search, you can drill down with different genres, including elements of time, visualization tools, recently added, blogs, or images, combining a variety of Google search products into one. The idea is to combine relevancy and “recentcy”, she said. Doing a normal search for “shuttle launch” could turn up results from any number of shuttle launches in countries around the world. Using Search Options, you can choose to search Web sites or blogs that were updated in the past 24 hours or week, increasing the chance that it will include results pertinent to this week’s launch. Choosing “images from the page”, meanwhile, will display pictures pulled from the site alongside search results. During the demo, Mayer and her team also searched for “solar oven” to demonstrate another feature of Search Options, dubbed sentiment analysis. If you are searching for reviews of solar ovens, for example, the program will try to determine if a particular review is positive, negative, or neutral and display that in the search results. Search Options also includes a timeline that displays the popularity of the topic searched over time. Search Options also includes a feature known as the Wonder Wheel. The term “solar oven” would be displayed in the middle of this wheel, with related searches branching out from it in a circle. In the same way that you might weave your way from a Wikipedia page on Google to a page about tropical fish thanks to the hundreds of links within Wikipedia posts, you can click on the various Wonder Wheel “arms” and crawl into a nice little search wormhole. Next up was Google Squared, a Labs project set to debut later this month. It is similar to Search Options in that you can drill down your search results, but Squared lets you add or delete results to produce the most useful “square” of information that you can save to your Google account and refer back to later. http://tech.yahoo.com/news/zd/20090512/tc_zd/240266 [To invoke, click “Show Options” at top-left of a search results page]

UP TO 24 PERCENT OF SOFTWARE PURCHASES NOW OPEN SOURCE (CNET, 12 May 2009) - Open source has become big business, suggests an article in the Investors Business Daily, but it has done so by becoming more like the proprietary-software world it purports to leave behind. The article cites recent research from IDC indicating that CIOs allocated up to 24 percent of their budgets to open-source software in 2008, up from 10 percent in 2007--a finding that jibes with recent data from Forrester. This open-source growth is propelling Red Hat to grow “at two to three times the rate of the broader software industry over a multiyear horizon,” according to research from Piper Jaffray. http://news.cnet.com/8301-13505_3-10238426-16.html?part=rss&subj=news&tag=2547-1_3-0-20

GOOGLE RE-SHOOTS JAPAN SCENES AFTER PRIVACY COMPLAINTS (Globe & Mail, 13 May 2009) - Internet search engine Google said it would re-shoot all Japanese pictures for its online photo map service, Street View, using lower camera angles after complaints about invasion of privacy. Google’s Street View, which offers 360-degree views of streets around the world using photos taken by cruising Google vehicles, has already run into privacy complaints in other countries and activists have tried to halt the service in Japan. Google said in a statement today it would lower the cameras on its cars by 40 cm after complaints they were capturing images over fences in private homes. But it said it would continue filming in Japan, where it has so far covered 12 cities. Google said it has also blurred car number plates in the pictures, as it has done in Europe, but the new steps did not convince Japanese campaigners. Britain’s privacy watchdog has rejected calls to shut Street View down there, where concerns have ranged from images such as someone throwing up outside a pub to media reports that a woman filed for divorce after her husband’s car was pictured outside another woman’s house. http://www.theglobeandmail.com/servlet/story/RTGAM.20090513.wgoogle0513/BNStory/Technology/home

FINANCIAL INDUSTRY REGULATOR FINES FIRM FOR DATA SECURITY FAILINGS (Steptoe & Johnson’s E-Commerce Law Week, 14 May 2009) - As if financial institutions don’t have enough to worry about these days, now they’ve got another regulator interested in enforcing its own notions of adequate data security practices. The Financial Industry Regulatory Authority (FINRA) recently announced that it has fined Centaurus Financial, Inc., $175,000 for failing to protect confidential customer information. FINRA is a non-governmental entity thata regulates securities firms doing business in the United States . It was established pursuant to the Securities Exchange Act of 1934, which gives FINRA the authority as a “self-regulatory organization” to sanction firms and individuals that violate its rules. FINRA found that Centaurus’ “improperly configured … firewall” and “ineffective username and password” systems allowed unauthorized persons to gain access to a server that “stored images of faxes that included confidential customer information, such as social security numbers, account numbers, dates of birth and other sensitive, personal and confidential data.” The hackers then commandeered the Centaurus server and used it to host a phishing scam. FINRA also found that Centaurus’ investigation into the breach was “inadequate,” and concluded that the breach notification letter that Centaurus sent to affected customers was “misleading.” http://www.steptoe.com/publications-6111.html FINRA announcement: http://www.finra.org/Newsroom/NewsReleases/2009/P118550

FTC DROPS ANTITRUST CLAIM AGAINST RAMBUS (SiliconValley.com, 14 Amy 2009) - The Federal Trade Commission has dropped its antitrust action against Rambus following the U.S. Supreme Court’s decision earlier this year not to review the agency’s 2006 claim that the Los Altos company had acted deceptively to obtain patents for its memory-chip technology. The FTC had contended that Rambus, whose technology improves the performance of computer memory chips, had acted to monopolize the market by failing to disclose that it was patenting technology adopted as an industry standard by the Joint Electron Device Engineering Council. That is a big victory for Rambus because the claim that it had acted anti-competitively is one of the major defenses that chip makers Hynix Semiconductor, Micron Technology, Nanya Technology and Samsung have used in battling Rambus’ ongoing patent claims against them. http://www.siliconvalley.com/news/ci_12368597

NEW IPHONE APP HELPS YOU KEEP TABS ON POLITICIANS’ VOTING RECORDS (NY Daily News, 14 May 2009) - A brand new application - called Visible Vote, made for iPhone, Blackberry and Facebook - allows users to track their representatives’ voting records, find out where they stand on the issues - and even send an e-mail to let them know exactly how they’re doing. Here’s how the app works: After downloading Visible Vote, the app will ask you to enter your e-mail address, state and zip code (no GPS support in version 1.0, apparently). It will then retrieve your local Senators and Representatives and a list of issues they’ve voted on recently. For each issue - everything from taxing AIG bonuses to alternative energy incentives - the app provides more detail and then asks for YOUR vote - Yes, No, or Don’t Care. It then takes your stance and compares it to the members of Congress - showing you how much their votes match with your interests. Don’t like the results? Wanna praise your favorite politician for sticking to his or her guns? The app lets you write them directly, with a simple interface that allows you to e-mail any combination of your Senators or Representatives - from one at a time to all at once. The app also promises to provide elected officials with weekly reports on how users are voting - and to send users an overview of the candidates when the next election rolls around. http://www.nydailynews.com/tech_guide/2009/05/14/2009-05-14_visible_vote.html

- and -

A MILLION DOWNLOADS: FREE STANFORD COURSE ON CREATING IPHONE APPS TAKES OFF AT A FURIOUS PACE (Stanford, 20 May 2009) - Free videos of Stanford’s wildly popular course on creating applications for the iPhone and iPod touch have now been downloaded a remarkable million times from Stanford’s site on iTunes U in the iTunes Store. And all of the million downloads have come in just seven weeks, since the course began on April 1. The way the downloads have taken off like a rocket makes the iPhone Application Programming videos the fastest to reach the 1 million milestone in the history of iTunes U, which hosts offerings from hundreds of colleges and universities around the world. http://news.stanford.edu/news/2009/may20/million-052009.html

GM STAKES VIRTUAL PROPERTY IN CASE OF BANKRUPTCY (Reuters, 15 May 2009) - General Motors has quietly roped off a bit of virtual real estate with an address similar to one used by Chrysler, that could serve as an information clearinghouse if GM seeks bankruptcy protection. GM registered gmrestructuring.com and gm-restructuring.com in early April. Chrysler LLC filed for bankruptcy last month and Epiq Systems Inc, a claims agent that processes court documents for the company’s bankruptcy case, registered and set up chryslerrestructuring.com for free access to certain court documents and details in that case. Other large cases with public dockets include lehman-docket.com, also registered by Epiq, and delphidocket.com, registered by Kurtzman Carson Consultants, according to domain registry information from Network Solutions. GM has not put any information on the sites. Others have scooped up sites related to automakers. Gmbankruptcy.com has been registered since 2005 by Jon Jerman of Hackensack, New Jersey, and gmfiat.com was registered to an Italian address last week. http://tech.yahoo.com/news/nm/20090515/wr_nm/us_gm_website_1

FOURTH CIRCUIT LIMITS SCA STATUTORY DAMAGES (Wiley Rein, 15 May 2009) - The Stored Communications Act (SCA) authorizes criminal and private civil actions against a person who “intentionally accesses without authorization a facility through which an electronic communications service is provided” and obtains “access to a wire or electronic communication while it is in electronic storage.” 18 U.S.C. § 2701(a). This offense encompasses intentionally accessing other people’s stored email without permission. On March 18, the Fourth Circuit announced a potentially important decision construing the SCA’s civil remedies. Van Alstyne v. Electronic Scriptorium, Ltd., 2009 WL 692512; 2009 U.S. App. Lexis 5548, although it oddly designated the case as non-precedential. Rejecting broader interpretations previously applied by several U.S. District Courts, the Fourth Circuit panel held that statutory damages may be awarded only where a plaintiff has suffered “actual damages.” Thus, statutory damages may not be awarded when the plaintiff does not allege or does not prove that he or she suffered actual damages from the violation. This ruling could limit the amount of civil litigation under the SCA, but additional judicial analysis of the SCA’s punitive damages remedy, in light of the Fourth Circuit’s construction of it, will be needed before the picture becomes clear. http://www.wileyrein.com/publication_newsletters.cfm?sp=newsletter&year=2009&ID=10&publication_id=14402&keyword=

CRACKHO.COM DNS PRANK RUFFLES SARAH PALIN’S FEATHERS (Ars Technica, 15 May 2009) - A simple DNS prank against former GOP VP nominee and current Alaska Governor Sarah Palin has finally come to the attention of Alaskan authorities, resulting in a cease-and-desist order as well as somewhat misdirected copyright claims. The owner of the site in question has caved to legal pressure, although one has to admit that the whole series of events was worth a chuckle. Houston-based DJ Shu Latif registered Crackho.com ages ago (according to a Whois search, 1998), but decided to give the site a fresh face in 2008 after Governor Palin was chosen as the Republican Vice President nominee. She changed the DNS settings so that all traffic to Crackho.com would go directly to Sarah Palin’s official website. The change apparently flew under the radar until earlier this month, when Alaska’s Attorney General Michael Barnhill sent a letter to Latif demanding that she knock it off. Clearly, Barnhill and gang have no real understanding of DNS and URL redirects in general, because the letter asserts that Crackho.com made illegal use of the official seal of the State of Alaska without permission, and that Latif was in violation of the federal Copyright Act. Nevermind that the seal was on Palin’s own site. Latif must have been feeling especially kind, because she has since changed crackho.com so that it does not redirect to the governor’s website. Instead, she merely uses an illustration of Palin and a link to the site instead. However, we can’t help but wonder what would happen if she chose to push back—she wasn’t misusing any copyrighted images or even hosting anything herself, though it’s possible that Palin’s lawyers might argue that she somehow “misrepresented” the site and its trademarks by directing traffic through Crackho.com. http://arstechnica.com/web/news/2009/05/crackhocom-dns-prank-ruffles-sarah-palins-feathers.ars The AG’s demand letter is here: http://media.houstonpress.com/3373356.0.pdf

- and -

SIX SIMPLE STEPS YOU CAN TAKE TO PROTECT YOUR GRIPE OR PARODY SITE (EFF, 15 May 2009) - Here’s a story we hear a lot at EFF: You think BadCo, Inc. is a bad actor and you’ve developed a really cool site to tell the world why. Maybe just by griping about them or maybe through a bit of parody. Fast forward two weeks: you’re basking in the pleasure of calling BadCo out when bam! You find out your site’s been shut down. You call your internet service provider to find out what’s going on. After way too much time climbing phone trees and sitting on hold you get an answer—Badco has claimed that your site violates its intellectual property rights. All too often, the targets of critics and parodists try to strike back with accusations of copyright or trademark infringement. While such accusations may be something of a badge of honor--after all, at the very least, it means you’ve got your target’s attention--they can also be frustrating and intimidating. And, if you rely on a service provider with little interest in protecting free speech, allegations of infringement can result in your site being shut down with little or no warning. Fortunately, there are several steps you can take to either preempt or significantly dilute gripes about your gripe (or parody) site. We lay out those steps in a new white-paper, Avoiding Gripes About Your Gripe (or Parody) Site. To be clear, you don’t have to follow any of these suggestions to have a perfectly legal site, and following them won’t guarantee you won’t get complaints. But taking these steps should help minimize your legal risk, so you can focus on the primary task of raising public awareness about the issues that are important to you. And if you get hit with improper legal threats anyway? Well, you know where to find us. http://www.eff.org/deeplinks/2009/05/six-simple-steps-you Guide here: http://www.eff.org/wp/gripe-or-parody-sites

GOOGLE LIBERALIZES US TRADEMARK POLICY: “WHAT, ME WORRY?” PART 2 (Eric Goldman, 15 May 2009) - In my Deregulating Relevancy article from a few years ago, I explained how trademark law was having pernicious consequences for online conversations. Among other unwanted effects, trademark law hinders online discussions about trademarks even when both conversationalists found the discussion relevant. I don’t think things have gotten better since I wrote the article in 2005. Perhaps we have a better understanding of trademark law’s capacity for harm, but we continue to see misguided lawsuits from trademark owners and mixed results from judges. While the courts do not automatically support online trademark-mediated discourse, the bigger practical threat to online trademark law comes from extrajudicial privately enforced trademark policies, such as the search engines’ “voluntarily” adopted trademark policies. These policies minimize search engines’ exposure to trademark liability for their ad sales, but they effectively resolve a huge percentage of trademark owners’ “problems,” almost always in the trademark owner’s favor, without any judicial oversight at all. Thus, I was delighted to see Google’s announcement that it was liberalizing its trademark policy to allow a group of “special” advertisers to reference third party trademarks in the advertisers’ ad copy, even if the trademark owner objects. See Google’s official announcement. The “special advertisers” includes resellers, review sites, and sellers of compatible/complementary/replacement products. In practice, this means that these advertisers and consumers can now use the same trademark to speak with each other. In contrast, today, the advertiser can purchase the trademark as the triggering keyword but can’t use the trademark to explain why the consumer was seeing the ad. Personally, I had always thought the “blind” nature of the ad copy had the potential to confuse consumers, and Google has taken a big step forward in solving that apparent problem. Having said that, I wish Google had gone further. There are two obvious groups of advertisers who should be able to reference the trademark in the ad copy but still will not be able to do so: (1) competitors making comparative claims, and (2) gripers who wish to complain about a trademark owner’s practices. These two advertiser groups can still buy third party trademarks, but they will still be forced to speak in code in the ad copy to explain why they did so. Nevertheless, we shouldn’t let these omissions detract from what is otherwise very good news from Google. http://blog.ericgoldman.org/archives/2009/05/google_liberali.htm

OLYMPIC BLOGS GET GO-AHEAD FOR VANCOUVER (Sports Journalists Assn, 19 May 2009) - The International Olympic Committee has issued a four-page guide to competitors which acknowledges the realities of 21st century communications by allowing “athletes’ blogs” at the 2010 Vancouver Winter Games, in a move which could make athlete-authored columns much easier to arrange for newspaper websites than at previous Olympics. The new guidelines will be scrutinised closely during the Winter Olympics, and are sure to form the basis for the rules to be applied at the 2012 London Games. “The IOC considers blogging, in accordance with these guidelines, as a legitimate form of personal expression and not as a form of journalism,” the new guidelines say. According to a report on the subscription website AroundtheRings.com, those who break the rules could lose their Olympic accreditation cards and may face legal action for damages. The restrictions were approved by the IOC’s Executive Board earlier this year. They will come into effect with the opening of the Vancouver Olympic Village next February. The guidelines are the latest development in IOC rules which have had to evolve rapidly, reflecting the growing appetite for first-hand accounts from Olympic competitors, and they mark a sea-change from the rules issued from Lausanne ahead of the 2000 Sydney Olympics, where athletes were banned from blogging altogether. http://www.sportsjournalists.co.uk/blog/?p=1848

SAFETY ACT OFFERS BOTH LIABILITY PROTECTION AND LIABILITY AVOIDANCE FOR COMPANIES, DIRECTORS AND OFFICERS, AND PRESERVATION OF STOCKHOLDERS’ VALUE (Duane Morris Client Alert, 19 May 2009) - Although the SAFETY Act1 can cap a company’s liability exposure at a predetermined amount of insurance, and even eliminate a company’s liability exposure altogether, “it remains one of the most underreported and underutilized”2 risk management and litigation management tools for companies in any industry that uses security products, services, software, shopping center security guards, professional security certification programs, assessments and emergency response plans. Passed in response to the massive liability encountered in lawsuits stemming from September 11, 2001,3 as well as those lawsuits that held the Port Authority of New York and New Jersey liable for the 1993 World Trade Center attacks,4 the SAFETY Act provides two classifications designed to incentivize companies to develop and deploy anti-terrorism products and services by limiting or eliminating liability should an act of terrorism occur involving those products and services. By submitting an application to the U.S. Department of Homeland Security (DHS), a company’s products, services, threat-assessment best-practices, threat response plans and control center operations, among others, can gain “designation.” A designation of “Qualified Anti-Terrorism Technology” provides a company the following significant benefits:
• No punitive damage exposure;
• Claims against the seller are capped at an amount no greater than the limits of liability insurance coverage required to be maintained by the seller through DHS;
• Exclusive federal court jurisdiction;
• Plaintiff’s recovery is reduced by amounts from collateral sources; and
• No joint and several liability for noneconomic damages.
• A company may obtain additional protections by simultaneously seeking the second classification of DHS “certification.”
http://www.duanemorris.com/alerts/alert3271.html#1

TRACK BUSINESS EXECUTIVES’ TWEETS WITH EXECTWEETS (CNET, 19 May 2009) - Are you trying to climb the corporate ladder? Hard work helps, but it couldn’t hurt to have some insight from those who have reached the top. ExecTweets for iPhone aggregates the Twitter feeds of nearly 100 top executives. Those execs include top brass from companies such as Best Buy, Digg, Microsoft, and Zappos. Following them nets you nuggets of business wisdom, links to stories they consider important, random thoughts (this is Twitter, after all), and even notable quotables (not sure why, but execs are really into quoting). The application makes it a snap to browse the tweets, with separate views for All, Featured, and Most Popular. You can also peruse “hot topics” (which lets you sort by selected keywords) and browse broad categories like government, health care, and technology. http://reviews.cnet.com/8301-19512_7-10244619-233.html?tag=mncol;title

WHO OWNS YOUR NAME ON TWITTER? (Wall Street Journal, 19 May 2009) - Social networks can be friendly places, but they are not democracies. Nor are they free markets. They are authoritarian regimes with whimsical and arbitrary rules. Nowhere is this fact more evident than in the doling out of domain names. On the Web, domain names are available for sale on a first-come, first-serve basis. If someone else buys your name first, you can try to buy it from them. If you’ve trademarked a name, you can fight for the name in the Internet Corporation for Assigned Names and Numbers’ domain-name court system. This makes sense: money and the law are acceptable remedies in our capitalist democracy. But social media domain names – such as Twitter.com/yourname – are a whole different ballgame. They can be doled out arbitrarily. Even if you get a name first on a social network, you are not allowed to sell it and it can be reclaimed by the social network at any time. Legal remedies for dealing with imposters or trademark issues range from murky to nonexistent. Since domain names are free on social media sites, it makes sense to grab yours quickly, even if you don’t plan to use it immediately. Many sites dole out domain names on a first-come, first-serve basis. The most democratic is LinkedIn, which hands out “vanity URLs,” such as LinkedIn.com/in/JuliaAngwin, to the first person who asks for it. As long as the URL is really your name, you can keep it. Even celebrities can’t jump the line at LinkedIn. During the presidential campaign, Sen. John McCain wanted his LinkedIn URL but it was already taken by another person named John McCain – so the senator was out of luck, according to LinkedIn spokeswoman Kay Luo. MySpace and Twitter are similarly democratic in doling out names – but they offer few assurances about preventing celebrities from cutting in line. Twitter reserves the right to reclaim names that are trademarked or are “non-parody impersonations.” MySpace generally honors the first person to claim a name – but reserves the right to reclaim URLs on behalf of advertisers or celebrities with just 72 hours notice. http://online.wsj.com/article/SB124269417597532869.html

- and -

NEWT GINGRICH’S LAWYER DISPLAYS IGNORANCE OF BOTH TWITTER AND THE LAW IN SENDING C&D (TechDirt, 20 May 2009) - It really was just a few weeks ago that we were told that lawyers knew better than to send a clueless cease-and-desist letter... and then we get this story. Apparently a group that is in favor of a certain law that Newt Gingrich opposes sent out a Twitter message that included the @newtgingrich username to stir up some interest in a petition they were working on. This is part of how you use Twitter to communicate with others and get attention from certain people. But apparently Gingrich’s lawyer was upset that Gingrich’s name was being “used” in a message in favor of a law Gingrich opposes, and sent a ridiculously bad cease-and-desist letter that the folks at the Citizen Media Law Project dubbed: “How to Make Your Client Look Bad, in Three Easy Steps.” First, the lawyer clearly didn’t understand Twitter and how it works since using @newtgingrich is the equivalent of sending a public letter “Dear Newt Gingrich” -- which certainly wouldn’t be an abuse of his name. Second, the lawyer not only didn’t understand Section 230, but insisted that Tucows, the registrar behind the site that hosted the petition (and also republished the tweet) was somehow responsible for the content of the Twitter message: “continued display of the offending tweet ‘can expose any and all involved parties (including Twitter, ContactPrivacy.com and/or TuCows) to substantial ongoing, and even personal liability.’” Of course, that’s not even close to true. Then, on top of that, the lawyer basically tried to throw in claims on every law he could think up: “trademark infringement, violation of Gingrich’s and Anuzis’ publicity rights, false advertising, false designation of origin, tortious interference with prospective economic advantage and contractual relations, common law and computer trespass (could Twitter trespass upon its own computer?), conversion, traditional fraud and wire fraud, breach of contract (i.e., Twitter’s terms of service), violation of the Computer Fraud and Abuse Act, and even RICO violations.”http://techdirt.com/articles/20090519/1921274936.shtml C&D letter here: http://www.thetruthaboutefca.org/3648_001.pdf

UMICH FIRST TO SIGN UP UNDER GOOGLE BOOKS SETTLEMENT TERMS (CNET, 20 May 2009) - The University of Michigan has signed up as the first library to participate in Google’s book-scanning project under the terms of Google’s proposed settlement with library groups. Google and UM have been working together since 2004 on digitizing the university’s library collection, but the Google Book Search settlement would allow Michigan to offer its books online as part of a subscription, or in some cases for free. The settlement has drawn reported attention from the government as well as library groups worried over the costs associated with access to such a large digital library amassed by a single company. In exchange for participating in the project, however, Google plans to subsidize the cost of the university’s subscription to the digital library. Michigan was also able to negotiate the right for future participants to review the cost of the institutional subscriptions from time to time. “If they determine that prices are too high, University of Michigan and other participating libraries who sign these collective terms can challenge the prices through arbitration, and Google will be required to work with the (Book Rights) Registry to adjust the pricing accordingly,” the university said on its Web site. Authors have until September to decide if they want to opt out of the settlement and withhold their works from the digital library. The settlement would have Google install a free public terminal in libraries around the country for access to digital copies of public domain works, copyright works that Google is authorized to reproduce, and out-of-print titles. Other libraries would then be offered a subscription to the digital library for their own patrons. http://news.cnet.com/8301-1023_3-10245611-93.html

IT MANAGERS UNDER PRESSURE TO WEAKEN WEB SECURITY POLICY (Search Security, 20 May 2009) - IT professionals are under pressure from upper level executives to open the floodgates to the latest Web-based platforms, relaxing Web security policy, according to a new survey of 1,300 IT managers. Nearly all those surveyed said they allow access to some Web-based services, such as webmail, mashups and wikis. But more employees are turning to online collaboration platforms; some are turning to Google Apps, which are integrated with Google’s Gmail platform, and others are turning to popular social networking sites, such as Twitter and Facebook. Some users are bypassing Web security policy to access the services, according to 47% of those surveyed. Pressure to relax Web security policy is increasing as well. The survey found that 86% of IT managers reported feeling pressure to allow more access to social networking websites, online collaboration tools and other cloud-based technologies. The pressure is coming from multiple sources, including C-level executives, marketing departments and sales. Despite the pressures, 80% are confident in their organizations Web security practices. However, the survey found many organizations lack Web application firewalls and other tools for defending against Web-based attacks. Sixty-eight percent said they lacked the ability to conduct real-time analysis of Web content to prevent data leakage, nearly 60% lacked the ability to prevent URL redirects and more than half had no tools to detect embedded malicious code on trusted websites. http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1356896,00.html#

FTC REACHES DATA SECURITY SETTLEMENT WITH MORTGAGE COMPANY (Steptoe & Johnson’s E-Commerce Law Week, 21 May 2009) - The Federal Trade Commission has reached another settlement with a company that allegedly failed to provide “reasonable” security for personal information. In an agreement announced in early May, home mortgage firm James B. Nutter & Company (JBN) agreed to establish and maintain “a comprehensive information security program” and submit to ten years of biennial assessments of its data security in order to settle charges that its lax data security practices had violated the Privacy and Safeguards Rules promulgated under the Gramm-Leach-Bliley Act. Among other things, the FTC’s complaint stressed JBN’s storage of personal information “in clear readable text,” suggesting once again that encrypting can help a company avoid the long arm of the FTC’s data security cops. http://www.steptoe.com/publications-6121.html

BLOGGERS, BEWARE: WHAT YOU WRITE CAN GET YOU SUED (Wall Street Journal, 21 May 2009) - Be careful what you post online. You could get sued. In March 2008, Shellee Hale of Bellevue, Wash., posted in several online forums about a hacker attack on a company that makes software used to track sales for adult-entertainment Web sites. She claimed that the personal information of the sites’ customers was compromised. About three months later, the software company -- which contends that no consumer data were compromised -- sued Ms. Hale in state court in New Jersey, accusing her of embarking “on a campaign to defame and malign the plaintiffs” in chat-room posts. In her legal response, Ms. Hale, 46 years old, claims she is covered by so-called shield laws that protect reporters from suits, because she was acting as a journalist and was investigating the hacker attack while researching a story on adult-oriented spam. Bloggers are increasingly getting sued or threatened with legal action for everything from defamation to invasion of privacy to copyright infringement. In 2007 -- the most recent data available -- 106 civil lawsuits against bloggers and others in social networks and online forums were tallied by the Citizen Media Law Project at the Berkman Center for Internet & Society at Harvard University, up from just 12 in 2003. There have been about $17.4 million in trial awards against bloggers to date, according to the Media Law Resource Center in New York, a nonprofit clearinghouse that tracks free-speech cases. Many lawsuits are thrown out of court or settled before trial, but not before causing headaches for the accused. Though the likelihood of a plaintiff winning a lawsuit is not high, “you could go bankrupt” just from defending against them, says Miriam Wugmeister, a partner at Morrison & Foerster LLP and a privacy and data-security law expert. The number of blogger lawsuits is likely to keep rising as the number of people who post online continues to grow, says Sandra Baron, executive director of the Media Law Resource Center and a media-law attorney. Social-networking sites such as LinkedIn, Facebook and MySpace -- which is owned by News Corp., the parent company of The Wall Street Journal -- and microblogging services like Twitter are making it easy for impetuous remarks to reach thousands of users in a matter of minutes. In March, fashion designer Dawn Simorangkir sued rocker Courtney Love for libel in Los Angeles Superior Court, accusing Ms. Love of posting disparaging remarks about the designer on Twitter and MySpace. http://online.wsj.com/article/SB124287328648142113.html

**** NOTED PODCASTS ****
RICHARD SUSSKIND ON “THE END OF LAWYERS?” (Berkman Center, 22 April 2009) - Richard Susskind, author of The End of Lawyers? Rethinking the Nature of Legal Services predicts that the legal profession will be driven by two forces in the coming decade: by a market pull towards the commoditization of legal services, and by the pervasive development and uptake of new and disruptive legal technologies. But this could result in quite different law jobs emerging which may be highly rewarding, even if very different from those of today. 2 STARS. http://blogs.law.harvard.edu/mediaberkman/2009/04/22/richard-susskind-on-the-end-of-lawyers/**** RESOURCES ****
Two 2006 ethics opinions essentially laying the ground work for lawyers’ use of “cloud” storage tools… NJ: http://lawlibrary.rutgers.edu/ethics/acpe/acp701_1.html NV: http://lawlibrary.rutgers.edu/ethics/acpe/acp701_1.html

FREE EBOOK: ‘IDENTITY IN THE AGE OF CLOUD COMPUTING’ (Aspen Institute, 8 May 2009) – The next-generation Internet’s impact on business, governance and social interaction (image above), 110 pages, May 2009: a look at the next-generation Internet and how it will impact all facets of society.
http://www.socialmedia.biz/2009/05/08/free-ebook-identity-in-the-age-of-cloud-computing/

PROMOTING PRIVACY AND FREE SPEECH IS GOOD BUSINESS (ACLU, May 2009) - This Guide will help you make smart, proactive decisions about privacy and free speech so you can protect your customers’ rights while bolstering the bottom line. Failing to take privacy and free speech into proper account can easily lead to negative press, government investigations and fines, costly lawsuits, and loss of customers and business partners. By making privacy and free speech a priority when developing a new product or business plan, your company can save time and money while enhancing its reputation and building customer loyalty and trust. http://www.aclunc.org/docs/technology/privacy_and_free_speech_it’s_good_for_business.pdf

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
PRIVACY GROUP SUES NSA OVER SPY NET (ZDNet -- 4 December 1999) -- Americans could learn more about the degree to which the secretive National Security Agency -- the government body charged with cracking codes and protecting critical information -- has been spying on U.S. citizens, if a suit filed on Friday by the Electronics Privacy Information Center garners results. “The charter of the National Security Agency does not authorize domestic intelligence gathering,” said Marc Rotenberg, director of EPIC, in a statement on Friday. “Yet we have reason to believe that the NSA is engaged in the indiscriminate acquisition and interception of domestic communications taking place all over the Internet.” The questions arose from reports to the European Union last year that the United Kingdom and Australia, among other countries, had cooperated with the United States to collect electronic communications across national borders. In the report, the spy network was dubbed “Echelon.” “We are concerned less with Echelon in particular and more with the NSA’s eavesdropping practices in particular,” said David Sobel, general counsel for EPIC. ‘Interesting questions’ On Friday, EPIC filed a suit in federal court to free up documents regarding the legal justification for any surveillance that NSA had performed regarding U.S. citizens. These same documents were requested earlier this year by the House Intelligence Subcommittee, but the NSA refused to provide them.

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.