Saturday, August 15, 2009

MIRLN --- 26 July – 15 August 2009 (v12.11)

• NYT Co.’s Top Lawyer Doubts that Aggregation is a Copyright Issue
• Will Bloggers be at Risk in AP Content Crackdown?
• 15 Top Privacy Policies, Analyzed
• Expert: iPhone 3GS Crypto is Easily Crackable
• Great .GOV Web Sites
• Study: Who’s On Which Social Nets
• Eleven-Word Snippets can Infringe Copyright, Rules ECJ
• Monitoring Employees’ Personal Emails? Not So Fast, Says New Jersey Court
• Finding Accurate Law Text Online Nearly Impossible, Panelists Say
• Serendipity, Lost in the Digital Deluge
• NIST Releases ‘Historic’ Final Version of Special Publication 800-53
o NIST Lab Director Tackles Cybersecurity, Cloud Computing
• Legal Ethics of Facebook, Twitter & Cloud Computing
o Facebooking Judge Catches Lawyer in Lie, Sees Ethical Breaches
o Study Reveals High Levels of Twitter Use at Conferences
o UK Government Advice Urges Tweeting
o NSO to Try Beethoven’s Tweet Suite
o The N.F.L. Has Identified the Enemy and it is Twitter
o DOD Rethinking Social-Media Access
• Data Security Breach Notification Law Update
• Heartland Says Breach has Cost it $32 Million this Year
• Cyber Attackers Empty Business Accounts in Minute
• Publicis Groupe to Buy Microsoft’s Razorfish
• Bank Will Allow Customers to Deposit Checks by iPhone
• Care to Write Army Doctrine? With ID, Log On

NEWS | PODCASTS | DIFFERENT | LOOKING BACK | NOTES

**** NEWS ****
NYT CO.’S TOP LAWYER DOUBTS THAT AGGREGATION IS A COPYRIGHT ISSUE (Nieman Journalism Lab, 22 July 2009) - It’s been four months since Josh predicted that a news organization would sue The Huffington Post for copyright violation over its aggregation of headlines, ledes, and article summaries. The interim has been marked by saber-rattling, settlements, and dubious proposals for changes to federal law. But I’m still hoping to see that lawsuit — not because I think The Huffington Post is necessarily in the wrong but because a major case of that sort could begin to clarify the increasingly muddled issues of copyright on the Internet. For instance, how do you apply a 91-year-old legal doctrine known as “hot news” to a website that never heard of news that isn’t sizzling? Well, I’m no copyright lawyer, but UCLA professor Doug Lichtman is, and he just released a wonderful, hourlong podcast on what intellectual property means in the context of news reporting. Most of the program focuses on the dueling lawsuits over Shepard Fairey’s use of an Associated Press photograph in his iconic Obama “Hope” poster. Lichtman interviews lawyers from both sides and offers a more thoughtful discussion of the case than I’ve seen anywhere else. But my interest was really piqued by his chat with The New York Times Co.’s general counsel, Ken Richieri, who considers whether news aggregators are protected by “fair use,” the legal standard that permits reproduction of copyrighted material under guidelines that, as Richieri says, “work a lot better in the analog world than they do in a digital world.” http://www.niemanlab.org/2009/07/nyt-cos-top-lawyer-doubts-that-aggregation-is-a-copyright-issue/

- and -

WILL BLOGGERS BE AT RISK IN AP CONTENT CRACKDOWN? (ABA Journal, 24 July 2009) - The Associated Press plans to add software to its articles to track how they are used online. The aim is for those who use AP articles to pay for them, AP president and chief executive Tom Curley told the New York Times. AP maintains that just publishing an article headline and a link requires a licensing agreement, the story says. The Times notes that headlines and links are often used by search engines like Google, news aggregators and blogs. Google has argued in the past that its use of AP articles is protected by the doctrine of fair use, according to the blog Today @ PC World. But Curley apparently expects payment. “If someone can build multibillion-dollar businesses out of keywords, we can build multihundred-million businesses out of headlines, and we’re going to do that,” he told the Times. Today @ PC World questions whether bloggers will be targeted. Jane Seagrave, senior vice president for global product development at AP, told Information Week that the intent was to deter those who engage in large-scale copying of AP content rather than bloggers who use too many paragraphs from an AP story. “It’s not aimed at people who use part of stories periodically,” Seagrave told Information Week. “It’s aimed at being affirmative about how we allow our content to be used.” http://www.abajournal.com/news/ap_to_crack_down_on_use_of_its_content/

15 TOP PRIVACY POLICIES, ANALYZED (ReadWriteWeb, 23 July 2009) - We all know no one reads privacy policies. What do the top websites really include in them? In its mission to get anonymous public data, The Common Data Project a New York City-based non-profit, is on a mission to eliminate the barriers that privacy policies pose. In a new report, they analyzed ten of the most popular Web properties on the Internet, and several more emerging ones. Here’s how what they put in their policies affects your privacy, and how other enterprises can imitate their best practices. Regardless of any similarities or differences within policies, one thing is absolutely clear: tons of data is being collected about you, though some of it may already be incidental enough to be private (such as the popularity of search terms). Privacy is certainly not an issue limited to the Web, but it facilitates the nearly limitless ability to gather data by the boatload. The question at this point isn’t if companies will acquire your data. It’s what they’ll do with it. The 15 privacy policies studied encompasses both some of the biggest online portals and retailers, non-profits, and scrappy startups. The full list includes: Google, Yahoo!, Wikipedia, Microsoft, AOL, Amazon, eBay, Facebook, Craigslist, Photobucket, NYT, WebMD, Ask, Cuil, and Ixquick. Out of the analysis, Common Data Project asked seven pointed questions about what companies will or won’t do. Here are some of the red flags found in existing privacy policies. http://www.readwriteweb.com/enterprise/2009/07/15-top-privacy-policies-analyz.php

EXPERT: IPHONE 3GS CRYPTO IS EASILY CRACKABLE (CNET, 24 July 2009) - The encryption functionality of the iPhone 3GS is so easy to crack that it is essentially “broken” as far as protecting sensitive personal data like credit card and social security numbers, according to a forensics expert and iPhone developer. “I don’t think any of us [developers] have ever seen encryption implemented so poorly before, which is why it’s hard to describe why it’s such a big threat to security,” Jonathan Zdziarski told Wired. With physical access to a 3GS iPhone and some free software data can be extracted within two minutes and an image of the entire raw disk in about 45 minutes, he said. The iPhone decrypts the data on its own once the extraction has begun, he explains in a video demonstration. Apple has been touting the encryption and other features to entice corporate users to the device. And it seems to be working. Nearly 20 percent of Fortune 100 companies have purchased 10,000 or more iPhones per company. http://news.cnet.com/8301-27080_3-10295348-245.html

GREAT .GOV WEB SITES (GCN, 27 July 2009) - Anyone who doubts the central role that the Web has taken in government life should consider all the attention paid to Recovery.gov. The General Services Administration created the site earlier this year to show the public how federal economic stimulus money was being disbursed. But the first iteration of the site proved to be too inscrutable for the public. So the agency contracted with a company to redesign the site — to the tune of $18 million over the next five years. The days of a Web presence being an optional component for agencies are long gone. For most citizens, the primary way of interacting with their government is through Web sites. By and large, agencies have responded to that demand by creating richer, more interactive sites. What follows is a compendium of 10 government Web sites that are meeting and exceeding those goals. This is not a definitive list of the 10 best government sites. The field is way too broad for any such superlatives. But they are sites that embrace the Web’s full potential, and they can offer ideas for other agencies seeking to improve their own sites:
• Data.Gov sets the tone for transparent government
• Forge.mil brings net-centric speed to software development
• Transit511 combines public transportation systems in the Bay Area
• State puts social networking to diplomatic use
• FDsys makes America’s documents current and permanent
• Utah takes its site to higher ground
• Science.gov breaks down stovepipes of research
• USPS extends its virtual post office
• HHS delivers health info users can trust
• The Web site on building better Web sites
http://gcn.com/articles/2009/07/27/gcn-great-gov-web-sites-2009.aspx

STUDY: WHO’S ON WHICH SOCIAL NETS (MediaPost, 27 July 2009) - Marketers that are frustrated with targeting specific age groups or demographics in Facebook, MySpace, Twitter and LinkedIn could glean insight from a recent study by Anderson Analytics. The study suggests that Twitter has become more popular than LinkedIn, more than half of U.S. consumers who tap social networks belong to more than one, and that those who belong to a social net are four times more vocal about products and services than those who don’t. Anderson Analytics CEO Tom Anderson says the biggest surprise from the study reveals that Twitter has become more popular than LinkedIn among social network users in the United States. Aside from posting tweets, Twitter users tend to blog frequently. In fact, more than 20% have their own blog, many of which trumpet social causes. These consumers make good evangelists for brands, he says. Anderson’s study aims to help marketers understand the type of people who frequent each social network. For example, it debunks the myth that Facebook attracts only kids. In fact, the Anderson study suggests that the ideal age group for Facebook spans from 15 to 34, but 44% of 35- to 44-year-olds and 30% of 45- to-54-year-olds say they have profiles, too. And while more people are experimenting on social networks, only 10% of users report having ever created a duplicate or experimental profile. More than half of social network users have associated their profiles with a brand, company or product. While much has been written about negative nature of Web 2.0 and blog posts, social network users are more likely to say positive things about brands, companies or products. The average user logs into a social network account about four times daily, five days a week, and spends about one hour per day on the network. About 31.8% are business users; followed by 26.3%, fun seekers; 21.8%, social media mavens; and 10.1%, leisure followers. http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=110517

ELEVEN-WORD SNIPPETS CAN INFRINGE COPYRIGHT, RULES ECJ (Outlaw.com, 27 July 2009) - The copying and reproduction of just 11 words of a news article can be copyright infringement, the European Court of Justice (ECJ) has ruled. Europe’s highest court has said that a clippings service’s copying could be unlawful. Danish clippings service Infopaq was taken to court by Danish newspaper industry body Danske Dagblades Forening (DDF) over its reproduction of 11-word snippets of news for sale to clients. The agency would scan in newspaper pages and use software to turn the image of the page into text. If pre-determined keywords that clients wanted monitored appeared in text then that word and the five words on either side of it were kept and the rest of the text thrown away. Clients were then sent the 11 words and the details of what page of what publication on what date the words appeared as well as an indication of how far into the article the words came. Infopaq conceded that acts of copying and reproduction took place in the process, but said that the use was legal because of exceptions in the European Union’s Copyright Directive for ‘transient’ copying of material and lawful copying. The ECJ said that while some parts of Infopaq’s processing could be called transient, as soon as it had printed out the 11 words on to paper the copying became too permanent to qualify for the law’s exception. “The possibility cannot be ruled out at the outset that in the first two acts of reproduction at issue in those proceedings, namely the creation of [image] files and text files resulting from the conversion of [image] files, may be held to be transient as long as they are deleted automatically from the computer memory,” said the ECJ ruling. “By the last act of reproduction in the data capture process, Infopaq is making a reproduction outside the sphere of computer technology. It is printing out files containing the extracts of 11 words and thus reproduces those extracts on a paper medium,” it said. “Once the reproduction has been affixed onto such a medium, it disappears only when the paper itself is destroyed.” “Since the data capture process is apparently not likely itself to destroy that medium, the deletion of that reproduction is entirely dependent on the will of the user of that process. It is not at all certain that he will want to dispose of the reproduction, which means that there is a risk that the reproduction will remain in existence for a longer period, according to the user’s needs,” said the judgment. Though the Court conceded that “words as such do not…constitute elements covered by the protection”, it said that copyright law would apply to extracts even if they contained just 11 words. “The possibility may not be ruled out that certain isolated sentences, or even certain parts of sentences in the text in question, may be suitable for conveying to the reader the originality of a publication such as a newspaper article, by communicating to that reader an element which is, in itself, the expression of the intellectual creation of the author of that article,” it said. “Such sentences or parts of sentences are, therefore, liable to come within the scope of the protection provided for in Article 2(a) of that directive.” http://www.out-law.com/default.aspx?page=10205

MONITORING EMPLOYEES’ PERSONAL EMAILS? NOT SO FAST, SAYS NEW JERSEY COURT (Steptoe & Johnson’s E-Commerce Law Week, 30 July 2009) - A New Jersey appellate court recently ruled that although a company may examine an employee’s personal emails where necessary to serve “a legitimate business interest,” such a policy cannot permit “an intrusion into communications otherwise shielded by the attorney-client privilege.” In Stengart v. Loving Care Agency, Inc., Marina Stengart brought an employment discrimination claim against her former employer, the Loving Care Agency (LCA). While still employed at LCA, Stengart used her work-issued laptop to send several emails pertaining to her anticipated suit to her attorneys through her “personal, web-based, password-protected Yahoo email account.” After she filed suit, attorneys for LCA obtained access to these emails and produced some of them in response to her interrogatories. Stengart’s attorneys requested that LCA’s attorneys return all such emails. They refused, prompting Stengart to apply for a temporary restraining order. The trial judge denied the motion, finding that “the emails were not protected by the attorney-client privilege because the company’s electronic communications policy put plaintiff on sufficient notice that her emails would be viewed as company property.” On appeal, the Superior Court of New Jersey, Appellate Division, reversed, finding that “[a] policy imposed by an employer, purporting to transform all private communications into company property -- merely because the company owned the computer used to make private communications or used to access such private information during work hours -- furthers no legitimate business interest.” Significantly, the court’s rationale was not limited to emails concerning the attorney-client privilege. In reaching its decision, the court announced an extremely privacy-protective rule, holding that, regardless of the wording of a company’s monitoring policy, “an employer’s rules and policies must be reasonable to be enforced,” and that the policy may be enforced by courts only if “the regulated conduct … concern[s] the terms of employment” and the policy “reasonably further[s] the legitimate business interests of the employer.” http://www.steptoe.com/publications-6267.html Ruling here: Stengart v. Loving Care Agency -- http://lawlibrary.rutgers.edu/courts/wordperfect/appellate/A3506-08.DOC [Editor: The decision is an odd one, but distinguishable on the facts. All in all, not the end of the story for permitted employer monitoring, especially if the policy is well written and communicated.]

FINDING ACCURATE LAW TEXT ONLINE NEARLY IMPOSSIBLE, PANELISTS SAY (ABA Journal, 31 July 2009) - Federal Reserve Bank of New York’s counsel, Denley Chew, slapped down some $2 bills and challenged a room of lawyers and legal researchers with laptops and iPhones to find the authoritative text of the landmark Fugitive Slave Act online. “Authoritative” was the catch. The money remained untouched. Panelists declared that finding accurate text of a law—on government websites, LexisNexis, Westlaw—is almost impossible. The recession forced state and federal governments to post laws online rather than print them. But Mary Alice Baish, government relations director for the American Association of Law Libraries, says there is no national or international body that ensures those online postings are accurate or updated with amendments. The AALL conducted a 2007 survey that discovered that eight states and the District of Columbia refer lawyers and judges seeking the text of a law to official sources so different that the versions conflict. States that posted laws online only had no consistent way of maintaining older versions of an amended law or showing errors had been corrected. “The history of law is disappearing; older versions of a law, amendments, show the thought process of a people and how they evolved,” observed ABA Legal Technology Research Center director Catherine Reach. Global Legal Information Network at the Law Library of Congress provided the hopeful glimmer. Trusted officers of the court in dozens of jurisdictions, from the Congo to Canada, authenticate legal documents from their countries with an encrypted certificate. GLIN director Janice Hyde proudly said over 170,000 legal instruments have been authenticated. http://www.abajournal.com/news/finding_accurate_law_text_online_nearly_impossible_panelists_say_abachicago/

SERENDIPITY, LOST IN THE DIGITAL DELUGE (New York Times, 1 August 2009) – We’ve gained so much in the digital age. We get more entertainment choices, and finding what we’re looking for is certainly fast. Best of all, much of it is free. But we’ve lost something as well: the fortunate discovery of something we never knew we wanted to find. In other words, the digital age is stamping out serendipity. When we walk into other people’s houses, we peruse their bookshelves, look at their CD cases and sneak a peek at their video collections (better that than their medicine cabinets). It gives us a measure of the owner’s quirky tastes and, more often than not, we find a singer, a musician or a documentary we’d never known before. But CDs have disappeared inside the iPod. And shelves of videos are rarely seen as we get discs in the mail from Netflix or downloaded from Vudu. And, one day soon, book collections may end up inside a Kindle. With an e-book reader, the person on the subway seat across from you will never know what you are reading. Ah, the techies say, no worries. We have Facebook and Twitter, spewing a stream of suggestions about what to read, hear, see and do. We come to depend on it to lead us to the funny article on TheOnion.com or the roving food cart serving goat curry. It’s useful. But that isn’t serendipity. It’s really group-think. Everything we need to know comes filtered and vetted. We are discovering what everyone else is learning, and usually from people we have selected because they share our tastes. It won’t deliver that magic moment of discovery that we imagine occurred when Elvis Presley first heard the blues, or when Michael Jackson followed Fred Astaire’s white spats across the dance floor. Many software developers are trying to recreate serendipity. StumbleUpon is a Web service that steers users toward content they are likely to find interesting. Readers tell the service about their professional interests or hobbies, and it serves up sites to match them. It’s a good try, but it is still telling readers what they want to know. http://www.nytimes.com/2009/08/02/business/02ping.html?emc=eta1

NIST RELEASES ‘HISTORIC’ FINAL VERSION OF SPECIAL PUBLICATION 800-53 (GCN, 3 August 2009) - The National Institute of Standards and Technology has collaborated with the military and intelligence communities to produce the first set of security controls for all government information systems, including national security systems. The controls are included in the final version of Special Publication 800-53, Revision 3 “Recommended Security Controls for Federal Information Systems and Organizations,” released Friday. NIST called the document historic. “For the first time, and as part of the ongoing initiative to develop a unified information security framework for the federal government and its contractors, NIST has included security controls in its catalog for both national security and non-national security systems,” the agency said. “The updated security control catalog incorporates best practices in information security from the United States Department of Defense, Intelligence Community and Civil agencies, to produce the most broad-based and comprehensive set of safeguards and countermeasures ever developed for information systems.” A draft version of the document was released in June for public comment. This is the final version of the guidelines. NIST also has released a draft of SP 800-126, “The Technical Specification for the Security Content Automation Protocol (SCAP),” for public comment. SCAP comprises specifications for the standardized organization and expression of security-related information. SP 800-126 provides an overview of SCAP, focusing on how software developers can integrate SCAP technology into their product offerings and interfaces. SP 800-53 is part of a series of documents setting out standards, recommendations and specifications for implementing the Federal Information Security Management Act. This revision is the first major update of these guidelines since its initial publication in December 2005. It specifies the baseline security controls needed to meet the mandatory requirements of Federal Information Processing Standards 199, “Standards for Security Categorization of Federal Information and Information Systems,” and FIPS 200, “Minimum Security Requirements for Federal Information and Information Systems.” http://gcn.com/Articles/2009/08/03/NIST-release-of-800-53-rev-3-080309.aspx 800-53 here: http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf

- and -

NIST LAB DIRECTOR TACKLES CYBERSECURITY, CLOUD COMPUTING (Information Week, 7 August 2009) - The National Institute of Standards and Technology’s IT Laboratory plays a key role in government cybersecurity, setting standards that federal agencies are required to follow. InformationWeek discussed NIST’s role, including the fine line between setting standards and setting policy, with Cita Furlani, director of NIST’s IT Lab. http://www.informationweek.com/news/government/enterprise-architecture/showArticle.jhtml?articleID=219100346&cid=RSSfeed_IWK_News [Editor: Interesting Q&A.]

Editor: Earlier this month I moderated an ABA panel in Chicago on lawyer-ethics issues associated with Cloud Computing. We had excellent panelists, including Chris Kelly (on leave as CPO for Facebook and candidate for California Attorney General). Here’s the ABA Journal’s blurb on the session:
LEGAL ETHICS OF FACEBOOK, TWITTER & CLOUD COMPUTING (ABA Journal, 2 August 2009) - The legal ethics challenges that will be posed by lawyer use of Facebook, Twitter and other forms of “cloud computing” services are almost as revolutionary as the services themselves, according to experts speaking at a discussion hosted Sunday by the Cyberspace Law Committee of the ABA Business Law Section. Cloud computing services store a user’s data–messages, photos, documents or any other kind of information–on a computer that is not under the user’s control. Facebook, Twitter, Flickr, YouTube, and Google Docs are all examples of the growing trend, which is sometimes also referred to as “software as a service.” The services allow users to access information from any computer connected to the Internet and to share that information either with a limited number of people or the public at large. They are quickly gaining popularity among lawyers and the clients they serve, both for their technological benefits and low cost, as reported in the August issue of the ABA Journal. But lawyers should carefully consider the legal ethics implications of that trend, according to Roland L. Trope, a partner in New York’s Trope and Schramm. He noted there’s a dramatic difference between what Google Docs–a service for creating and sharing text documents, spreadsheets and slide presentations–says in its marketing materials, and what is in its legally binding terms of service. When promoting the service, Google says it backs up users’ information almost as fast as they create it, so users always have access to their saved content. But the terms of service say Google does not guarantee any defects in the product will be fixed, and the company reserves the right to disable a user’s account without providing copies of the data the user has stored on Google’s computers. And because many cloud computer companies don’t store a user’s data in one location, or even in one country, what will happen when information from a client that is subject to U.S. export control restrictions is stored on a computer in a foreign country, Trope asked. Firms ought to disclose to clients how their data will be stored, so issues like this can be dealt with before they become a crisis, he said. http://www.abajournal.com/news/legal_ethics_of_facebook_twitter_cloud_computing_abachicago/

- and -

FACEBOOKING JUDGE CATCHES LAWYER IN LIE, SEES ETHICAL BREACHES (ABA Journal, 31 July 2009) - Galveston, Texas-area lawyers on Facebook may want to double-check their friends list, especially if they’re about to appear before Judge Susan Criss. That’s because Criss, a state court judge who is learning to adapt to social media as a way to connect with long-lost friends and is leveraging Facebook as a judicial campaign tool, has also learned a few things she didn’t expect. Biggest surprise: Even lawyers don’t fully grasp how public social media is, even when privacy controls are in place. “Anyone can cut and paste,” said Criss, who was part of a Friday ABA Annual Meeting program “Courts and Media in the 21st Century: Twitterers, Bloggers, the New Media, the Old Media, and What’s a Judge to Do?” sponsored by the ABA’s Judicial Division. Criss recalled one time that a lawyer asked for a continuance because of the death of her father. The lawyer had earlier posted a string of status updates on Facebook, detailing her week of drinking, going out and partying. But in court, in front of Criss, she told a completely different story. Then there was the lawyer who complained about having to handle a motion in Criss’s court. Criss playfully zinged her, too—on Facebook, of course. Criss has seen lawyers on the verge of crossing, if not entirely crossing, ethical lines when they complain about clients and opposing counsel. And she admonished one family member who jeopardized her own tort case by bragging online about how much money she would get from a lawsuit. http://www.abajournal.com/news/facebooking_judge_catches_lawyers_in_lies_crossing_ethical_lines_abachicago/

- and -

STUDY REVEALS HIGH LEVELS OF TWITTER USE AT CONFERENCES
(ReadWriteWeb, 27 July 2009) - A group of scholars from Germany, Austria, and the U.K. recently put together a case study about the tweeting habits of conference attendees. Entitled “How People are using Twitter during Conferences,” this research report (available on Scribd.com), reveals some interesting, although not altogether shocking, insights into the role the microblogging service plays during major events. Most notable of their findings is the number of individuals who actively use the service during conferences - a figure showing high participation levels among attendees. According to the report, the researchers were motivated to find out if using Twitter could actually help improve the interactions among the learners and enhance their learning experience when attending presentations in large groups. They looked into the motives of Twitter users, contents of tweets, and how this impacted the user’s network. The researchers found that the majority of conference attendees already had a Twitter account (95.1%) and many of those who did actively used it to tweet during the conference (67.5%). 74.1% of the attendees send between 11 and 20 messages per day and 51.2% discussed topics via @ replies and DMs. [N]early half the tweets were simple plain text messages while tweets with links to web sites only accounted for 10% of the messages. In other words, the Twitterers were using the medium to share the information they were learning at the present moment as opposed to posting links to information already available on the web. The participants were also asked open-ended questions like “Why do you think Twitter encouraged the discussion about topics?” and what the added value of Twitter at conferences was. In response, the survey participants answered that Twitter gave conference goers a greater sense of community and encouraged discussion in the backchannel, often allowing them to discuss things in more detail than the “guys on the stage.” Other participants noted that Twitter helps you connect with people who have similar interests, provides networking potential, and allows those who could not attend to gain value from your experience. Unfortunately, the data collected comes from only five conferences and forty-one different attendees, so the sample size isn’t what we would consider to be large enough to draw any definite conclusions. http://www.readwriteweb.com/archives/study_reveals_high_levels_of_twitter_use_at_conferences.php Study here: http://www.scribd.com/doc/15855075/09edumedia

- and -

UK GOVERNMENT ADVICE URGES TWEETING (BBC, 27 July 2009) - New government guidance has been published urging civil servants to use the micro-blogging site Twitter. Launched on the Cabinet Office website, the 20-page document is calling on departments to “tweet” on “issues of relevance or upcoming events”. The website is already used by Downing Street, the Foreign Office and many individual MPs. Neil Williams, of the Department for Business, Innovation and Skills (BIS), published the “template” strategy. Writing on the Cabinet Office’s digital engagement blog, Mr Williams - who is BIS’s head of corporate digital channels - conceded that 20 pages was a “a bit over the top for a tool like Twitter” but added: “I was surprised by just how much there is to say - and quite how worth saying it is.” The template had been written for BIS to consider using Twitter but could be used by other departments, he said. Publishing tweets, replying to incoming messages and monitoring the account would take less than an hour a day, according to the strategy. There would be an “add-on” to “business as usual” activity due to quick discussions of potential tweets at daily meetings, as well as e-mails between officials and digital media staff about potential content for tweets. http://news.bbc.co.uk/2/hi/uk_news/8171597.stm

- and -

NSO TO TRY BEETHOVEN’S TWEET SUITE (Washington Post, 30 July 2009) - The National Symphony Orchestra is trying an experiment. It’s tweeting Beethoven’s “Pastoral” Symphony, Thursday night at Wolf Trap. For a healthy portion of the classical music audience, Internet-related words such as “tweet” or “Twitter” cause parts of the brain to shut down. Deep breaths. Here’s what will happen: The orchestra will use the micro-blogging site Twitter to send text messages of 140 characters or fewer from conductor Emil de Cou during the performance. (Example: “In my score Beethoven has printed Nightingale = flute Quail = oboe Cuckoo = clarinet -- a mini concerto for woodwind/birds.”) The idea is that those interested will sit in a designated area on the Wolf Trap lawn with their BlackBerrys, iPhones or other mobile devices and, by following the Twitter user NSOatWolfTrap, gain a new perspective on the score. Of course, you can also follow along without actually being at Wolf Trap at all. http://www.washingtonpost.com/wp-dyn/content/article/2009/07/29/AR2009072903067.html?wprss=rss_technology

- and -

THE N.F.L. HAS IDENTIFIED THE ENEMY AND IT IS TWITTER (New York Times, 4 August 2009) - To the list of universal threats to football success — injury and indiscretion, a Tom Brady-led offense marching against your defense — the N.F.L. has added another: Twitter. As training camps opened last week, players were told that the same standard — read: paranoia — that applied to the flow of information to reporters also applied to Twitter. In Green Bay, players were told they would be fined if they texted or tweeted from team meetings or coaching sessions. When Coach Tony Sparano met with the Miami Dolphins before Sunday’s first practice, he effectively outlawed Twitter, nose tackle Jason Ferguson said. Football coaches are a password-protected lot, preferring to dispense so little information that most days, they would struggle to fill 140 characters. They worry that the casual nature of Twitter could inspire the budding bloggers in their locker rooms to inadvertently disclose more than they should about injuries, game plans and what is said behind closed doors. The N.F.L. does not have a policy about social media, although it warns players about the risks of someone impersonating them on one of the sites. Cellphones, computers and P.D.A.’s cannot be used by players, coaches or other club personnel on the sideline, in coaches’ booths or locker rooms from pregame warm-ups through the end of the game. But N.F.L. officials are working on a policy that would apply to the use of social media sites on the day of the game. http://www.nytimes.com/2009/08/04/sports/football/04twitter.html?_r=1

- and -

DOD RETHINKING SOCIAL-MEDIA ACCESS (FCW, 3 August 2009) - With concerns mounting over security and management, the Defense Department is reevaluating its policies on use of social media tools. Sites such as Facebook, MySpace and Twitter, once banned from DOD use, now play a major role for government and military public relations and recruiting. However, the threat of security breaches stemming from wide-open access could lessen Web 2.0’s appeal. U.S. Strategic Command, which oversees the use of the dot-mil network, has launched a review of the safety of the sites. The command acknowledged in media reports last week that it was doing so, but has otherwise remained mum on the topic. “There certainly are security concerns associated with social networking. But it would be a step back to ban social networks completely,” said information technology security expert Rohyt Belani, a consultant and instructor at Carnegie-Mellon University. “I think there is a middle ground that can be reached.” Security fears largely center on the familiar possibility of hackers infiltrating networks with sensitive information, particularly via phishing scams that dupe computer users into downloading viruses, clicking links to malware or entering secure information. But Web 2.0 brings an additional concern: People sharing too much information online, such as the case of incoming British intelligence chief John Sawers, whose wife posted personal information and photos on Facebook that have landed Sawers in serious hot water. http://fcw.com/articles/2009/08/03/dod-rethinking-social-media-access.aspx

DATA SECURITY BREACH NOTIFICATION LAW UPDATE (Hunton & Williams, 5 August 2009) - July saw a flurry of activity involving data security breach notification laws.
• On July 1, breach notification laws in Alaska and South Carolina went into effect.
• On July 9, Missouri became the 45th state to enact a data breach notification law. [Editor: But the Missouri law also includes health insurance and medical data in its definition of personal information.]
• On July 22, Senator Patrick Leahy reintroduced a comprehensive federal data security bill calling it one of his “highest legislative priorities.”
• On July 27, North Carolina amended its breach notification law to require notification of the state attorney general any time consumers are notified of a breach involving their personal information. The amendment also included content requirements for the attorney general’s notice. http://www.huntonprivacyblog.com/2009/08/articles/information-security/data-security-breach-notification-law-update/index.html#page=1

HEARTLAND SAYS BREACH HAS COST IT $32 MILLION THIS YEAR (StorefrontBacktalk, 6 August 2009) - Heartland Payment Systems on Aug. 4 said it spent $32 million this year paying for costs related to the major data breach it disclosed in January, including $22.1 million to cover fines from key payment card brands and a settlement offer. Heartland did not say how the $22.1 million was split between the fines and the settlement offer, but it did provide clues. http://www.storefrontbacktalk.com/securityfraud/heartland-says-breach-has-cost-it-32-million-this-year-including-22-1-million-in-card-brand-fines-settlement-offer/

CYBER ATTACKERS EMPTY BUSINESS ACCOUNTS IN MINUTE (Network World, 6 August 2009) - The criminals knew what they were doing when they hit the Western Beaver County School District. They waited until school administrators were away on holiday, and then during a four-day period between Dec. 29 and Jan. 2, siphoned US$704,610.35 out of two of the school district’s bank accounts. Western Beaver’s financial institution, ESB Bank, managed to reverse some of the transfers, but the Pennsylvania school district was out more than $441,000. On July 9, Western Beaver sued ESB to try and recover the money, but security experts say that it’s just one of many organizations that have been hit in recent months by a disturbing new type of financial fraud that can often leave the victim holding the bag. Fraudsters are taking advantage of the widely used but obscure Automated Clearing House (ACH) Network in order to pull off their attacks. This financial network is used by financial institutions to handle direct deposits, checks, bill payments and cash transfers between businesses and individuals. Criminals can make millions of dollars per day with ACH fraud, investigators say. And while consumers are protected from this type of fraud, the rules for corporations and organizations are not as clear-cut, so sometimes victims like Western Beaver find themselves having to pay. The fraud typically starts with a targeted phishing e-mail, aimed at whomever is in charge of the company’s checkbook. By tricking the victim into running software, opening a harmful attachment or visiting a malicious Web site, the criminals are able to install keylogging software and steal bank account passwords. http://www.networkworld.com/news/2009/080609-cyber-attackers-empty-business-accounts.html?source=NWWNLE_nlt_daily_am_2009-08-07

PUBLICIS GROUPE TO BUY MICROSOFT’S RAZORFISH (CNET, 9 August 2009) - French advertising group Publicis Groupe SA has agreed to acquire Internet ad agency Razorfish from Microsoft for $530 million in cash and stock. Razorfish will continue to operate under its own brand name and continue to serve as Microsoft’s “preferred provider” for Internet advertising, the companies announced Sunday in a joint statement. The deal includes a strategic alliance agreement in which Publicis Groupe will purchase display and search advertising from Microsoft over a five-year period. “The purchase of Razorfish is a new step in our strategic plan to be the unquestionable leader in digital communication,” Publicis Groupe Chief Executive Officer Maurice Levy said in the statement. “Once this acquisition is complete, about a quarter of our revenue will come from digital communication and our ability to grow and conquer will be reinforced.” Publicis Groupe is one of the world’s largest media companies, employing about 44,000 people at advertising networks Leo Burnett and Saatchi & Saatchi, as well as media buyers Starcom MediaVest Group and ZenithOptimedia. Microsoft had reportedly been shopping Razorfish around for the past few months, with top ad firms WPP, Omnicom Group, and Publicis Groupe all expressing interest in Razorfish. Talks were also held between Microsoft and agencies Interpublic Group and Dentsu. http://news.cnet.com/8301-1023_3-10306162-93.html?part=rss&subj=news&tag=2547-1_3-0-5

BANK WILL ALLOW CUSTOMERS TO DEPOSIT CHECKS BY IPHONE (New York Times, 10 August 2009) - The Internet has taken a lot of the paperwork out of banking, but there is no avoiding paper when someone gives you a check. Now one bank wants to let customers deposit checks immediately — through their phones. USAA, a privately held bank and insurance company, plans to update its iPhone application this week to introduce the check deposit feature, which requires a customer to photograph both sides of the check with the phone’s camera. “We’re essentially taking an image of the check, and once you hit the send button, that image is going into our deposit-taking system as any other check would,” said Wayne Peacock, a USAA executive vice president. Customers will not have to mail the check to the bank later; the deposit will be handled entirely electronically, and the bank suggests voiding the check and filing or discarding it. But to reduce the potential for fraud, only customers who are eligible for credit and have some type of insurance through USAA will be permitted to use the deposit feature. Mr. Peacock said that about 60 percent of the bank’s customers qualify. Three years ago, it introduced the option of depositing a check from home using a scanner. That laid the groundwork for the phone deposit feature, which USAA plans to offer on other phones this year. The deposit feature, which USAA previewed in an online video in June, puts the bank in the vanguard of the effort to turn cellphones into portable branches. http://www.nytimes.com/2009/08/10/technology/10check.html?_r=1&ref=business

CARE TO WRITE ARMY DOCTRINE? WITH ID, LOG ON (New York Times, 14 August 2009) - In July, in a sharp break from tradition, the Army began encouraging its personnel — from the privates to the generals — to go online and collaboratively rewrite seven of the field manuals that give instructions on all aspects of Army life. The program uses the same software behind the online encyclopedia Wikipedia and could potentially lead to hundreds of Army guides being “wikified.” The goal, say the officers behind the effort, is to tap more experience and advice from battle-tested soldiers rather than relying on the specialists within the Army’s array of colleges and research centers who have traditionally written the manuals. “For a couple hundred years, the Army has been writing doctrine in a particular way, and for a couple months, we have been doing it online in this wiki,” said Col. Charles J. Burnett, the director of the Army’s Battle Command Knowledge System. “The only ones who could write doctrine were the select few. Now, imagine the challenge in accepting that anybody can go on the wiki and make a change — that is a big challenge, culturally.” Under the three-month pilot program, the current version of each guide can be edited by anyone around the world who has been issued the ID card that allows access to the Army Internet system. About 200 other highly practical field manuals that will be renamed Army Tactics, Techniques and Procedures, or A.T.T.P., will be candidates for wikification. As is true with Wikipedia, those changes will appear immediately on the site, though there is a team assigned to each manual to review new edits. Unlike Wikipedia, however, there will be no anonymous contributors. http://www.nytimes.com/2009/08/14/business/14army.html?hp










**** NOTED PODCASTS ****
GOOGLE BOOK SEARCH SETTLEMENT (Google’s Alex Macgillivray at Berkman, 21 July 2009) - The proposed Google Book Search settlement creates the opportunity for unprecedented access by the public, scholars, libraries and others to a digital library containing millions of books assembled by major research libraries. But the settlement is controversial, in large part because this access is limited in major ways: instead of being truly open, this new digital library will be controlled by a single company, Google, and a newly created Book Rights Registry consisting of representatives of authors and publishers; it will include millions of so-called “orphan works” that cannot legally be included in any competing digitization and access effort, and it will be available to readers only in the United States. Alexander Macgillivray, Deputy General Counsel for Products and Intellectual Property at Google (and soon to be General Counsel of Twitter) chats about the Google Book Search Settlement, its intricacies, pros, and cons, and responds to provocative questions and comments. [Editor: ONE STAR] http://blogs.law.harvard.edu/mediaberkman/2009/07/21/alexander-macgillivray-of-google-on-the-google-book-search-settlement-audio/

**** DIFFERENT ****
WHAT’S IN A WORD? (Newsweek, 9 July 2009) - When the Viaduct de Millau opened in the south of France in 2004, this tallest bridge in the world won worldwide accolades. German newspapers described how it “floated above the clouds” with “elegance and lightness” and “breathtaking” beauty. In France, papers praised the “immense” “concrete giant.” Was it mere coincidence that the Germans saw beauty where the French saw heft and power? Lera Boroditsky thinks not. A psychologist at Stanford University, she has long been intrigued by an age-old question whose modern form dates to 1956, when linguist Benjamin Lee Whorf asked whether the language we speak shapes the way we think and see the world. If so, then language is not merely a means of expressing thought, but a constraint on it, too. Although philosophers, anthropologists, and others have weighed in, with most concluding that language does not shape thought in any significant way, the field has been notable for a distressing lack of empiricism—as in testable hypotheses and actual data. That’s where Boroditsky comes in. In a series of clever experiments guided by pointed questions, she is amassing evidence that, yes, language shapes thought. The effect is powerful enough, she says, that “the private mental lives of speakers of different languages may differ dramatically,” not only when they are thinking in order to speak, “but in all manner of cognitive tasks,” including basic sensory perception. “Even a small fluke of grammar”—the gender of nouns—”can have an effect on how people think about things in the world,” she says. http://www.newsweek.com/id/205985 [Editor: fascinating; I’ve often thought that language might channel thought.]

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
A PIECE OF SOFTWARE IS A JOY FOREVER: LINUX WINS ART PRIZE -- The top prize in the “.net” category of the prestigious international electronic-art competition Prix Ars Electronica has been awarded not to a beautiful Web page but to the Linux operating system created by Finnish programmer Linus Torvalds in 1991 and developed by scores of volunteer software developers contributing refinements to the code. Torvalds will receive the $8,260 prize. The judge says the selection of Linux was intended to send a message that “that the real material of the Web is the code” and to emphasize the Internet’s essential ability to establish online communities.” (New York Times 1 Jun 99)


************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.

Saturday, July 25, 2009

MIRLN --- 5-25 July 2009 (v12.10)

• Great Wall of Facebook: the Social Network’s Plan to Dominate the Internet — and Keep Google Out
• For Jurors in Michigan, No Tweeting (or Texting, or Googling) Allowed
• Spies Like Us: NSA to Build Huge Facility in Utah
• Another City Caught Lowering Yellow Light Times to Catch More Red Light Runners
• Weitzner to Head NTIA Policy Shop
o Twitter Nabs a Legal Eagle from Google
• Cybersecurity Plan to Involve NSA, Telecoms
• British Spy Chief’s Cover Blown on Facebook
• Court: IP Addresses Are Not ‘Personally Identifiable’ Information
• LinkedIn Reviews Can Come Back to Haunt Employers, Lawyers Say
• New Law Floods California with Medical Data Breach Reports
• Everything Ohio, and Then Some, is on New Web Site
• Easy Cybersecurity -- Publish SSNS
• Accessing Employees’ Private Internet Chatroom Violates Stored Communication & Wiretap Laws
• Prosecutor: Cloud Computing is Security’s Frontier
o Concerns Raised as LA Looks to Google Web Services
• AP Proposes New Article Formatting for the Web
• Employer Violates the National Labor Relations Act by Selectively Targeting Union Related E-Mails
• North Korean Cyberattacks
• 85 Percent of U.S. Businesses Breached
o Data Attacks More Frequent than CEOS Think
• Clearing Rights for Content: Ask First
o Legal Row Over National Portrait Gallery Images Placed on Wikipedia
• Republishing Third Party Ratings in Marketing Material Might be Copyright/Trademark Infringement
• Middle East Blackberry Update Spies on Users
• PCI Council Publishes Wireless Security Guidelines for Payment Cards
• Facebook Violates Canadian Privacy Law
• Amazon Erases Orwell Books From Kindle
• The Future Of Scholarship? Harvard Goes Digital With Scribd
• Social Networks Appeal, But Not to the Firm
• University of Michigan, Amazon Offer 400,000 Titles with Print-On-Demand


NEWS | PODCASTS | RESOURCES | LOOKING BACK | NOTES

**** NEWS ****
GREAT WALL OF FACEBOOK: THE SOCIAL NETWORK’S PLAN TO DOMINATE THE INTERNET — AND KEEP GOOGLE OUT (Wired 17.07, 22 June 2009) - Today, the Google-Facebook rivalry isn’t just going strong, it has evolved into a full-blown battle over the future of the Internet—its structure, design, and utility. For the last decade or so, the Web has been defined by Google’s algorithms—rigorous and efficient equations that parse practically every byte of online activity to build a dispassionate atlas of the online world. Facebook CEO Mark Zuckerberg envisions a more personalized, humanized Web, where our network of friends, colleagues, peers, and family is our primary source of information, just as it is offline. In Zuckerberg’s vision, users will query this “social graph” to find a doctor, the best camera, or someone to hire—rather than tapping the cold mathematics of a Google search. It is a complete rethinking of how we navigate the online world, one that places Facebook right at the center. In other words, right where Google is now. http://www.wired.com/techbiz/it/magazine/17-07/ff_facebookwall [Editor: quite interesting explication of how Facebook could leverage social connections to more-tailored/more-effective “search” and give Google a real run-for-the-money.]

FOR JURORS IN MICHIGAN, NO TWEETING (OR TEXTING, OR GOOGLING) ALLOWED (Nat’l Law Journal, 1 July 2009) - Call it the silencing of the tweets. The Michigan Supreme Court has laid the hammer down on gadget-happy jurors in banning all electronic communications by jurors during trial, including tweets on Twitter, text messages and Google searches. The ruling, which takes effect Sept. 1, will require Michigan judges for the first time to instruct jurors not to use any handheld device, such as iPhones or Blackberrys, while in the jury box or during deliberations. The state’s high court issued the new rule on Tuesday in response to prosecutors’ complaints that jurors were getting distracted by their cell phones, smart phones and PDAs, in some cases texting during trial or digging up their own information about a case and potentially tainting the judicial process. Wouldn’t common sense suggest that’s wrong? “I don’t think jurors go out and Google stuff thinking it’s wrong. Sometimes it just doesn’t click,” said Charles Koop, immediate past president of the Prosecuting Attorneys Association of Michigan, which pushed for the new rule. “I think it brings home to the conscientious jurors -- which most jurors are -- that I’m not supposed to do this.’” The new rule also helps older judges, who might not be tech-savvy, stop jurors from doing things in their courtroom that they are unaware of, said Koop, prosecuting attorney in Antrim County, Mich. “Judges of an older age may not be in tune as much as younger judges as to what’s going on out there,” Koop said, adding the constantly evolving PDAs are especially problematic for the courts. “It’s a new technology. We’re playing catch-up.” http://www.law.com/jsp/nlj/PubArticleNLJ.jsp?id=1202431952628&For_jurors_in_Michigan_no_tweeting_or_texting_or_Googling_allowed_&slreturn=1

SPIES LIKE US: NSA TO BUILD HUGE FACILITY IN UTAH (Salt Lake Tribune, 2 July 2009) - Hoping to protect its top-secret operations by decentralizing its massive computer hubs, the National Security Agency will build a 1-million-square-foot data center at Utah’s Camp Williams. The years-in-the-making project, which may cost billions over time, got a $181 million start last week when President Obama signed a war spending bill in which Congress agreed to pay for primary construction, power access and security infrastructure. The enormous building, which will have a footprint about three times the size of the Utah State Capitol building, will be constructed on a 200-acre site near the Utah National Guard facility’s runway. Congressional records show that initial construction -- which may begin this year -- will include tens of millions in electrical work and utility construction, a $9.3 million vehicle inspection facility, and $6.8 million in perimeter security fencing. The budget also allots $6.5 million for the relocation of an existing access road, communications building and training area. Officials familiar with the project say it may bring as many as 1,200 high-tech jobs to Camp Williams, which borders Salt Lake, Utah and Tooele counties. It will also require at least 65 megawatts of power -- about the same amount used by every home in Salt Lake City combined. A separate power substation will have to be built at Camp Williams to sustain that demand, said Col. Scott Olson, the Utah National Guard’s legislative liaison. He noted that there were two significant power corridors that ran though Camp Williams -- a chief factor in the NSA’s desire to build there. http://www.sltrib.com/ci_12735293

ANOTHER CITY CAUGHT LOWERING YELLOW LIGHT TIMES TO CATCH MORE RED LIGHT RUNNERS (TechDirt, 2 July 2009) - It’s been shown repeatedly that redlight cameras don’t appear to make intersections any safer, but they do act as a nice revenue generator for cities. In fact, at times it’s such a tempting revenue generator that city officials cannot resist the urge to tamper with the timing of the lights to get more people running “red” lights that really should have been yellow. The latest such case, as pointed out by Jeff Nolan, happened in Arizona. According to regulations, the yellow light at a certain intersection was required to last 4.3 seconds: 4 seconds for the road being 40 mph and another 0.3 seconds due to the way the road curves. Yet, over 1,000 motorists were ticketed, in part because the traffic light had been adjusted so that the yellow light only lasted 3 seconds, 70% of the required length. Thanks to some enterprising motorists who timed the light and complained, those who were caught are getting back their money and having the citations removed from their record. http://techdirt.com/articles/20090701/1842145429.shtml

WEITZNER TO HEAD NTIA POLICY SHOP (National Journal, 2 July 2009) - Daniel Weitzner will be the next chief of the policy office at the Department of Commerce’s National Telecommunications and Information Administration, according to government sources. Weitzner served as a technology advisor to President Obama’s campaign for president. He has been involved in the Computer Science and Artificial Intelligence Laboratory at the Massachusetts Institute of Technology and co-directs MIT’s Decentralized Information Group with Internet expert Tim Berners-Lee. Weitzner was a founder and deputy director for the Center for Democracy and Technology and has also been a senior staff counsel at the Electronic Frontier Foundation. Weitzner was among the first to advocate user control technologies such as content filtering and rating to protect children and avoid government censorship of the Internet, according to his bio on W3.org, the World Wide Web Consortium. His arguments played a critical role in the 1997 Supreme Court case Reno v. ACLU, awarding strong free speech protections to the Internet. Weitzner successfully advocated for adoption of amendments to the Electronic Communications Privacy Act creating new privacy protections for online transactional information such as Web site access logs. http://techdailydose.nationaljournal.com/2009/07/weitzner-to-head-ntia-policy-s.php

- and -

TWITTER NABS A LEGAL EAGLE FROM GOOGLE (New York Times, 11 July 21, 2009) - Twitter, the popular micro-blogging service, has stolen a prominent Google lawyer. The start-up has hired Alexander Macgillivray, deputy general counsel for products and intellectual property at Google, to be its general counsel, according to a person with knowledge of the hiring. Mr. Macgillivray has been an important member of the Google legal team, spearheading the controversial settlement with authors and book publishers over Google’s scanning of millions of out of-print library books. Mr. Macgillivray, 36, has also represented Google in a wide variety of other matters, including Viacom’s copyright lawsuit against YouTube and complaints from The Associated Press that Google improperly used its content. Before he joined Google, Macgillivray was with Wilson Sonsini Goodrich & Rosati, the prominent Silicon Valley law firm. http://bits.blogs.nytimes.com/2009/07/11/twitter-nabs-a-legal-eagle-from-google/?partner=rss&emc=rss

CYBERSECURITY PLAN TO INVOLVE NSA, TELECOMS (Washington Post, 3 July 2009) - The Obama administration will proceed with a Bush-era plan to use National Security Agency assistance in screening government computer traffic on private-sector networks, with AT&T as the likely test site, according to three current and former government officials. President Obama said in May that government efforts to protect computer systems from attack would not involve “monitoring private-sector networks or Internet traffic,” and Department of Homeland Security officials say the new program will scrutinize only data going to or from government systems. But the program has provoked debate within DHS, the officials said, because of uncertainty about whether private data can be shielded from unauthorized scrutiny, how much of a role NSA should play and whether the agency’s involvement in warrantless wiretapping during George W. Bush’s presidency would draw controversy. Each time a private citizen visited a “dot-gov” Web site or sent an e-mail to a civilian government employee, that action would be screened for potential harm to the network. Under a classified pilot program approved during the Bush administration, NSA data and hardware would be used to protect the networks of some civilian government agencies. Part of an initiative known as Einstein 3, the plan called for telecommunications companies to route the Internet traffic of civilian agencies through a monitoring box that would search for and block computer codes designed to penetrate or otherwise compromise networks. Proponents of involving the government said such efforts should harness the NSA’s resources, especially its database of computer codes, or signatures, that have been linked to cyberattacks or known adversaries. The NSA has compiled the cache by, for example, electronically observing hackers trying to gain access to U.S. military systems, the officials said. “That’s the secret sauce,” one official said. “It’s the stuff they have that the private sector doesn’t.” The pilot program has two goals. The first is to prove that the telecommunications firm can route only traffic destined for federal civilian agencies through the monitoring system. The second is to test whether the technology can work effectively on civilian government networks. The sensor box would scan e-mail messages and other content just before they enter the civilian agency networks. The classified NSA system, known as Tutelage, has the ability to decide how to handle malicious intrusions -- to block them or watch them closely to better assess the threat, sources said. It is currently used to defend military networks. http://www.washingtonpost.com/wp-dyn/content/article/2009/07/02/AR2009070202771.html?wprss=rss_technology

BRITISH SPY CHIEF’S COVER BLOWN ON FACEBOOK (Reuters, 4 July 2009) - The wife of the new head of Britain’s spy agency has posted pictures of her husband, family and friends on Internet networking site Facebook, details which could compromise security, a newspaper said on Sunday. Sir John Sawers is due to take over as head of the Secret Intelligence Service in November. The SIS, popularly known as MI6, is Britain’s global intelligence-gathering organization. In what the Mail on Sunday called an “extraordinary lapse,” the new spy chief’s wife, Lady Shelley Sawers, posted family pictures and exposed details of where the couple live and take their holidays and who their friends and relatives are. The details could be viewed by any of the many millions of Facebook users around the world, but were swiftly removed once authorities were alerted by the newspaper’s enquiries. http://tech.yahoo.com/news/nm/20090705/wr_nm/us_britain_mi6_1

COURT: IP ADDRESSES ARE NOT ‘PERSONALLY IDENTIFIABLE’ INFORMATION (MediaPost, 6 July 2009) - In a ruling that could fuel debate about online privacy, a federal judge in Seattle has held that IP addresses are not personal information. “In order for ‘personally identifiable information’ to be personally identifiable, it must identify a person. But an IP address identifies a computer,” U.S. District Court Judge Richard Jones said in a written decision. Jones issued the ruling in the context of a class-action lawsuit brought by consumers against Microsoft stemming from an update that automatically installed new anti-piracy software. In that case, which dates back to 2006, consumers alleged that Microsoft violated its user agreement by collecting IP addresses in the course of the updates. The consumers argued that Microsoft’s user agreement only allowed the company to collect information that does not personally identify users. Microsoft argued that IP addresses do not identify users because the addresses don’t include people’s names or addresses. The company also said that it did not combine IP addresses with other information that could link them to individuals. Last month, Jones sided with Microsoft and dismissed the case before trial. But some say that Jones’s decision about IP addresses is inconsistent with other recent opinions about the issue. Eric Goldman, director of the High Tech Law Institute at Santa Clara University, points out that the European Union considers IP addresses to be personal information. Last year, the EU said that search engines should expunge users’ IP addresses as soon as possible. Additionally, a court in New Jersey ruled last year that Internet service providers can’t disclose users’ IP addresses without a subpoena, on the theory that people expect their IP addresses will be kept private. Marc Rotenberg, executive director of the Electronic Privacy Information Center, criticizes the Microsoft ruling as “a silly decision.” “The judge didn’t understand the significance of the IP address or the reason that it was collected,” he says. Rotenberg adds that the judge prematurely dismissed the case, arguing that more facts were needed to determine whether IP addresses were personally identifiable. http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=109242 Ruling here: http://www.steptoe.com/assets/attachments/3869.pdf

LINKEDIN REVIEWS CAN COME BACK TO HAUNT EMPLOYERS, LAWYERS SAY (ABA Journal, 7 July 2009) - Management-side employment lawyers are advising their clients against writing recommendations for current or recent employees on LinkedIn. If an employer writes a positive review for an employee who is later fired, that review could be presented as evidence that discrimination rather than performance brought on the termination, lawyers told the National Law Journal. “Generally, my advice is that I think employers are often better served by merely stating dates of employment, positions with the company and salary, and staying away from much more because there are so many potential ramifications if they say something,” Carolyn Plump, a partner at Philadelphia’s Mitts Milavec told the National Law Journal. “If they say something negative, there could be a lawsuit. If they say something positive, there could be a lawsuit.” The story cites a recent poll from Jump Start Social Media stating that 75 percent of hiring managers use LinkedIn to research candidates. Employee-rights attorney Linda Friedman of Chicago’s Stowell & Friedman said LinkedIn recommendations can also backfire on a plaintiff. If a supervisor makes identical recommendations on LinkedIn or another website of everyone under him or her, that could disprove a discrimination claim, Friedman said. http://www.abajournal.com/weekly/linkedin_reviews_can_come_back_to_haunt_employers_lawyers_say

NEW LAW FLOODS CALIFORNIA WITH MEDICAL DATA BREACH REPORTS (Wired, 9 July 2009) - California officials have received more than 800 reports of health data breaches in the first five months after a new state law went into effect January 1. The law requires health care organizations in California to report suspected incidents of intentional and unintentional unauthorized breaches of a patient’s personally identifiable health information to the California Department of Public Health. The agency, however, says it was surprised by the large number of reports it received in such a short period, according to the Journal of the American Health Information Management Association, and expects that number to increase dramatically as organizations become more familiar with the reporting procedures. Of the cases reported, which also include complaints from patients, officials have conducted full investigations on 122 cases so far and confirmed 116 as actual breaches. The types of breaches run the gamut from unintentionally faxing a patient’s chart or test reports to the wrong phone number to intentional snooping by workers. Most of the breaches reported so far have been unintentional. Officials can fine offending organizations or individuals up to $250,000 for a breach, depending on the nature of the breach and the extent of the harm it caused. Los Angeles-based Kaiser Permanente Bellflower Medical Center was the first to be fined this amount after investigators determined that 23 hospital workers inappropriately accessed the medical records of Nadya Suleman, aka “the Octomom”. http://www.wired.com/threatlevel/2009/07/health-breaches

EVERYTHING OHIO, AND THEN SOME, IS ON NEW WEB SITE (Columbus Dispatch, 9 July 2009) - Ohio Secretary of State Jennifer Brunner fulfilled one of her 2006 campaign pledges yesterday by unveiling an online tool offering access to a plethora of information about Ohioans, their counties and their state. That includes detailed statistics for each county compiled from 18 different state and federal sources about the economy, public safety and other areas affecting quality of life. For example, it’s possible to review and compare poverty statistics, foreclosure rates and other economic indicators over time, plus data for 300 other indicators, even including the number of library visits in each county. The site is designed for researchers, chambers of commerce, nonprofit groups applying for grants, students, and state and local governments considering important public-policy decisions. The idea is to identify areas of strength and help understand challenges. The data will be updated as new information becomes available, and other sources may be added depending on demand, Brunner said. “Essentially, we look at this as a resource that will provide Ohioans with quick and easy access to information about the issues that impact all the communities in the state,” Brunner said of her “Better Lives, Better Ohio” initiative. Pursuing the initiative was one of four major goals Brunner set for the office, including restoring trust in Ohio elections. Her office held community forums to solicit input about what data should be made available on the site, and the computer work to generate it was done in-house, Brunner said. The total cost was about $100,000, mostly to hire Michelle Hussong, who has a doctorate in sociology and previously worked for the Ohio Department of Education, to oversee the effort, Brunner said. The online tool can be found at www.sos.state.oh.us/SOS/betterLives.aspx. http://www.dispatchpolitics.com/live/content/local_news/stories/2009/07/09/copy/brunner_plan.ART_ART_07-09-09_B4_H2EE1MA.html?adsec=politics&sid=101

EASY CYBERSECURITY -- PUBLISH SSNS (Stewart Baker’s blog, 8 July 2009) - Two Carnegie Mellon researchers published a study the other day “Predicting Social Security Numbers from Public Data” in which they demonstrated that it was almost trivially easy to guess the first 5 digits of a person’s social security number based on where and when they were born. Since many (most?) security functions rely on the secrecy of those 5 digits and the public confirmation of the last 4 digits by a user, it is now almost trivially easy to extrapolate a person’s full 9-digit SSN. Any company that continues to use SSNs for security features is well beyond foolish. And any user who voluntarily chooses a partner who uses SSNs as a security feature is simply courting identity theft. Why anyone would do so is beyond me ... but companies and users continue down this benighted path. Is there any way to make them stop this unwise practice? I suppose we could outlaw it and make it a crime or some such heavy handed regulatory solution. But, in keeping with my view that more transparency generally equals greater security, here’s an easier solution -- the US government should simply publish a book (call it the Green Pages, since Yellow and White are already taken) listing everyone who has a social security number and making the SSNs public. That would instantly drain the SSN of all security value and return it to its original function as an accounting identifier. At that point, anyone who continued to use SSNs for security would be so negligent that the tort lawyers would have a field day. http://www.skatingonstilts.com/skating-on-stilts/2009/07/easy-cybersecurity-publish-ssns.html

ACCESSING EMPLOYEES’ PRIVATE INTERNET CHATROOM VIOLATES STORED COMMUNICATION & WIRETAP LAWS (Ogletree Deakins, 10 July 2009) Pietrylo v. Hillstone Restaurant Group, No. 06-5754 (D.N.J., June 16, 2009) – A federal jury in Newark recently imposed compensatory and punitive damages on an employer whose managers surreptitiously monitored employees’ postings on a private Internet chatroom. The managers obtained the chatroom password from a female employee and then terminated the employees responsible for creating the chatroom. The jury found the employer liable for violating both the federal Stored Communications Act and the New Jersey Wiretapping and Electronic Surveillance Control Act, because they obtained the chatroom password by duress. This decision reminds employers that they must remain ever mindful of the employee’s expectation of privacy and the limitations it can impose on their conduct. http://www.ogletreedeakins.com/publications/index.cfm?Fuseaction=PubDetail&publicationid=856#page=1

PROSECUTOR: CLOUD COMPUTING IS SECURITY’S FRONTIER (CNET, 10 July 2009) - As data moves to the cloud, attackers and thieves will follow, a federal prosecutor said on Friday. The days of tracking down software counterfeiters in other countries who are selling pirated CDs are numbered as companies increasingly distribute software and store data online via hosted computing services, Matthew Parrella, an assistant U.S. attorney based in San Jose, Calif., said at Symantec’s Norton Cyber Crime Day. “That model of importation of software is becoming obsolete because we’re seeing on the horizon cloud computing where so many of these operations are pushed from a user’s PC or a user’s computer onto Google Docs or Salesforce.com,” he said. Looking ahead five years, “I’m thinking the attack is going to be on cloud computing centers,” said Parrella, chief of the computer hacking and intellectual property unit at the U.S. Attorney’s Office. The immediate threat will be attacks to steal data from the servers they are stored on, either remotely or by an insider or someone who gains access to the data center, he said. Later on it’s likely any stolen data could be pirated, he said. FBI agent Donna Peterson said her office had seen a “tremendous uptick in large-scale, fairly devastating data breaches,” with the biggest heist being close to $10 million stolen in 24 hours. Cyberthieves “are getting more organized and their technical sophistication is better,” she said. “They do what they need to get the job done...if they can use a 5-year-old exploit in conjunction with an exploit that they paid a programmer in another country $60,000 to (write), they will do it.” Cybercriminals can spend anywhere from two weeks to six weeks to completely own a corporate target’s computer system so completely that “you won’t even know that they’re there,” she said. Businesses have opened on a Monday morning only to discover that so much money has been stolen since employees went home on Friday that they are no longer solvent and there is no record on their systems of the activity, Peterson said. http://news.cnet.com/8301-1009_3-10284361-83.html?tag=newsEditorsPicksArea.0

- and -

CONCERNS RAISED AS LA LOOKS TO GOOGLE WEB SERVICES (SiliconValley.com, 17 July 2009) - Security and privacy concerns have been raised over a multimillion-dollar proposal by Los Angeles to tap Google’s Internet-based services for government e-mail, police records and other confidential data. At issue is the security of computerized records on everything from police investigations to potholes as the nation’s second-largest city considers dumping its in-house computer network for Google e-mail and office programs that are accessed over the Internet. Paul Weber, president of the Los Angeles Police Protective League, complained Thursday that the union had scant information on the plan or what it would mean for the safety of sensitive records, such as narcotics or gang investigations. The shift toward doing more over the Web could make it much easier for hackers to gain access to corporate or government files. No longer would someone need to try to break through layers of security firewalls. As various personal and work accounts become increasingly linked together, all one needs is a single password to access documents just like a regular employee. If approved, Los Angeles would be the second major city after Washington, D.C., to use Google’s Internet-based services, known as Google Apps. The company has been promoting the package to other government agencies, too, as a way to cut costs and ensure access to Google-developed technical innovations. Google said in a statement that more than 1.75 million businesses use the technology. An unknown number of them pay the Mountain View company $50 per user per year for a premium version designed for businesses, government agencies and other robust needs. In a statement, Google said its services, which can store information at a number of Google-run data centers around the world, are “extremely reliable, safe and secure.” http://www.siliconvalley.com/news/ci_12861716?nclick_check=1 [Editor: Reportedly, Google will not provide legally sufficient security assurances.]

AP PROPOSES NEW ARTICLE FORMATTING FOR THE WEB (Washington Post, 10 July 2009) - The Associated Press is proposing that publishers attach descriptive tags to news articles online in hopes of taming the free-for-all of news and information on the Web and generating more traffic for established media brands. Tags identifying the author, publisher and other information - as well as any usage restrictions publishers hope to place on copyright-protected materials - would be packaged with each news article in a way that search engines can more easily identify. By doing so, the AP hopes to make it easier for readers to find articles from more established news providers amid the ever-expanding pool of content online. That, in turn, could lead to more traffic and more online advertising revenue for a beleaguered news industry. http://www.washingtonpost.com/wp-dyn/content/article/2009/07/10/AR2009071002862.html

EMPLOYER VIOLATES THE NATIONAL LABOR RELATIONS ACT BY SELECTIVELY TARGETING UNION RELATED E-MAILS (Vorys, 10 July 2009) - The United States Court of Appeals in Washington, D.C., recently held that an employer committed an unfair labor practice by selectively enforcing its e-mail usage policy against an employee who sent union-related e-mails. The case, Guard Publishing Company v. National Labor Relations Board, is a reminder that e-mail policies must be carefully drafted and consistently enforced to avoid potential legal pitfalls. The employer, a daily newspaper, claimed that the union-related e-mails violated its policy prohibiting e-mails “used to solicit or proselytize for commercial ventures, religious or political causes, outside organizations, or other non-job-related solicitations.” Despite this policy, the employer routinely allowed e-mails offering tickets for sporting events and requesting services such as dogwalking. When the Union filed its initial charge with the NLRB, it argued that the National Labor Relations Act provided employees with a statutory right to use an employer’s e-mail system for certain union-related purposes. The NLRB disagreed, holding that an employer may limit non-work-related use of its e-mail system so long as it does not discriminate against protected union activity. The NLRB defined discriminatory treatment narrowly as the “unequal treatment of equals.” Applying this standard, the NLRB held that, with the exception of one e-mail that was not a solicitation, the employer did not discriminate against union-related emails. The NLRB based this decision on the theory that the employer made a distinction between personal solicitations (e.g., “My car is for sale”) and group/organization solicitations (e.g., “Girl Scout Cookies for sale”). The outcome would have been different had the employer previously allowed group/organization solicitations, only to take action when those group/ organization solicitations were union related. On appeal, the Court of Appeals held that the employer had in fact discriminated against protected union activity. The Court noted that the personal/group distinction relied on by the NLRB was not contained in the employer’s e-mail policy. Nor was it discussed in the employee’s disciplinary notice. In fact, the notice cautioned the employee against using the e-mail system for union/personal business. http://www.vorys.com/media/publication/148_Employer%20Violates%20Nat%20Labor%20Relations%20Act.pdf#page=1 See also http://faegre.com/showarticle.aspx?Show=9980

NORTH KOREAN CYBERATTACKS (Bruce Schneier essay, 13 July 2009) - To hear the media tell it, the United States suffered a major cyberattack last week. Stories were everywhere. “Cyber Blitz hits U.S., Korea” was the headline in Thursday’s Wall Street Journal. North Korea was blamed. Where were you when North Korea attacked America? Did you feel the fury of North Korea’s armies? Were you fearful for your country? Or did your resolve strengthen, knowing that we would defend our homeland bravely and valiantly? My guess is that you didn’t even notice, that -- if you didn’t open a newspaper or read a news website -- you had no idea anything was happening. Sure, a few government websites were knocked out, but that’s not alarming or even uncommon. Other government websites were attacked but defended themselves, the sort of thing that happens all the time. If this is what an international cyberattack looks like, it hardly seems worth worrying about at all. http://www.schneier.com/blog/archives/2009/07/north_korean_cy.html [Editor: thoughtful, useful essay.]

85 PERCENT OF U.S. BUSINESSES BREACHED (InternetNews.com, 13 July 2009) - The fourth annual U.S. Encryption Trends Study was released today by The Ponemon Institute. The study says that 85 percent of surveyed businesses have experienced a data breach in the past year, up from 60 percent in the 2008 study. According to the report, organizations see a need to protect mobile devices. “More than 59 percent of respondents say it is very important or important to encrypt employees’ mobile devices -- a sign that organizations recognize that valuable data is more mobile than ever,” the report said. Companies are right to be concerned about breaches, the report said, referring to an earlier study by The Ponemon Institute that found that breaches cost businesses, on average, $202 per record and, in total, an average of $6.6 million. http://www.internetnews.com/security/article.php/3829391/Report+73+Percent+of+US+Businesses+Breached.htm

- and -

DATA ATTACKS MORE FREQUENT THAN CEOS THINK (SC Magazine, 15 July 2009) - CEOs often have a rosier view of data protection in their organization than other executives, according to a study released Wednesday by the Ponemon Institute and software security vendor Ounce Labs. In the study of 213 CEOs and other senior executives, 92 percent of respondents said that their company’s data has been attacked in the past six months. But, CEOs are often more confident about their organization’s ability to prevent data breaches than are other executives, the study found. And CEOs are less aware of data breaches that have occurred, the study found. Respondents were asked how often their company’s data is attacked, and 33 percent of C-level executives -- which included COOs, CIOs and division presidents -- replied “hourly or more often,” while just 17 percent of CEOs said the same. Twenty percent of C-level executives said their data is attacked daily, while 15 percent of CEOs said the same. And, 48 percent of CEOs said their data was “rarely” attacked, compared to 32 percent of other C-level executives who said so. http://www.scmagazineus.com/Report-Data-attacks-more-frequent-than-CEOs-think/article/140117/

CLEARING RIGHTS FOR CONTENT: ASK FIRST (Law.com, 13 July 2009) - No one enjoys clearing rights. Checking that you may use content (whether on your Web site, in a publication, or for a performance) and won’t be sued over it takes time and effort. And, for e-commerce counsel clients, that means more money. Yet, applying [the] rules to using content on an e-commerce Web site is even more difficult because “commercial speech” remains an evolving area of the law. The legal rules for online content constantly evolve as copyright and other intellectual property laws struggle to adjust “rights” to the stresses caused since digital technology redefined the many ways to “copy” content. (Editor’s note: For a list of Web sites where one can request permission for a variety of content, see, “Links to Help e-Commerce Players Identify Rights Owners and Clear Rights.” The list is not comprehensive, because there are too many possible rights-owners from whom permission must be sought to cover all entities or people for every instance. A good basic resource on the mechanical process of clearing rights is “Getting Permission: How to License & Clear Copyrighted Materials Online and Off,” by Richard Stim, Esquire (Nolo Press, 2007).) http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202432184507&pos=ataglance [Editor: useful overview of the process.]

- and -

LEGAL ROW OVER NATIONAL PORTRAIT GALLERY IMAGES PLACED ON WIKIPEDIA (The Guardian, 14 July 2009) - The National Portrait Gallery has threatened legal proceedings for breach of copyright against a man who downloaded thousands of high-resolution images from its website, and placed them in an archive of free-to-use images on Wikipedia. There has been no formal response from the internet encyclopedia but Derrick Coetzee, who downloaded the images, promptly uploaded the letter from the London lawyers Farrar and Co, “to enable public discourse on the issue”. He said he was taking legal advice. Photographs of works of art are protected by copyright in the UK, but not in the US, where Coetzee lives. All the creators of the original images are long since dead, but the photographs were only taken for the NPG as part of a £1m digitisation project in the last couple of years. The gallery stressed today that they hoped to avoid taking any further legal action, and said they were not considering suing Wikipedia. It said it would be happy for the online site to use low-resolution images but was “very concerned” about loss of revenue from copyright fees for the high-resolution versions, which form a significant part of its income. http://www.guardian.co.uk/technology/2009/jul/14/national-portrait-gallery-wikipedia-row

REPUBLISHING THIRD PARTY RATINGS IN MARKETING MATERIAL MIGHT BE COPYRIGHT/TRADEMARK INFRINGEMENT (Eric Goldman, 14 July 2009) - A Colorado judge has reached the remarkable conclusion that a hospital publicizing its star ratings and other recognition from a third party rating service in its marketing material might be committing copyright and trademark infringement. This is a little like saying that it could be copyright and trademark infringement for a law school to include its US News rankings in its marketing material or for a book publisher to issue a press release announcing its ranking on the New York Times bestseller list. http://blog.ericgoldman.org/archives/2009/07/republishing_th.htm [Editor: Reminds me of the row a decade ago between Amazon and the NYT over publishing the NYT books bestseller listings. See “Looking Back” below.]

MIDDLE EAST BLACKBERRY UPDATE SPIES ON USERS (Wired, 14 July 2009) - A BlackBerry update that a United Arab Emirates service provider pushed out to its customers contains U.S.-made spyware that would allow the company or others to siphon and read their e-mail and text messages, according to a researcher who examined it. The update was billed as a “performance-enhancement patch” by the UAE-based phone and internet service provider Etisalat, which issued the patch to its 100,000 subscribers. The patch only drew attention after numerous users complained that it drained their BlackBerry battery and slowed performance, according to local publication ITP. Nigel Gourlay, a Qatar-based programmer who examined the patch, told ITP that the patch contained “phone-home” code that instructed the BlackBerries to contact a server to register. But once the patch was installed, thousands of devices tried to contact the server simultaneously, crashing it and causing their batteries to drain. “When the BlackBerry cannot register itself, it tries again and this causes the battery drain,” he said, noting that the spyware wouldn’t have drawn any attention if the company had simply configured the registration server to handle the load. The spying part of the patch is switched off by default on installation, but switching it on would be a simple matter of pushing out a command from the server to any device, causing the device to then send a copy of the user’s subsequent e-mail and text messages to the server. The spyware appears to have been developed by a U.S. company, which markets electronic surveillance software. Gourlay obtained source code for the patch after someone posted it on a BlackBerry forum. He said the code contained the name “SS8.com,” which belongs to a U.S. company that, according to its web site, provides surveillance solutions for “lawful interception” to ISPs, law enforcement and intelligence agencies around the world. http://www.wired.com/threatlevel/2009/07/blackberry-spies/ RIM denies involvement, and confirms that it’s spyware: http://www.siliconvalley.com/news/ci_12893364

PCI COUNCIL PUBLISHES WIRELESS SECURITY GUIDELINES FOR PAYMENT CARDS (NetworkWorld, 15 July 2009) - Any business accepting credit and debit cards -- and using or considering wireless LANs -- should carefully review the recommendations for use of 802.11 wireless access points that are detailed in the guidelines issued Wednesday by the Payment Card Industry Security Standards Council. In the past, the council has issued standards that have become required by Visa, MasterCard, banks and others for secure processing of payment and debit cards. Troy Leach, the council’s technical director, emphasized that the recommendations in the “PCI Data Security Standard (DSS) Wireless Guideline” are not mandatory for businesses handling payment cards and using WLANs. But he adds, “This is probably the way wireless should have been deployed all along.” http://www.networkworld.com/news/2009/071509-pci-wireless-guidelines.html?source=NWWNLE_nlt_security_strategies_2009-07-16

FACEBOOK VIOLATES CANADIAN PRIVACY LAW (The Canadian Press, 16 July 2009) - The writing is on the wall for Facebook, the popular social networking site: do more to protect the privacy of Canadian users or face the threat of court action. Privacy Commissioner Jennifer Stoddart posted that message for all to see Thursday in a report that warns the personal information of Facebook members may be at risk. Facebook, with nearly 12 million Canadian users and some 250 million worldwide, allows people to keep in touch with friends and family by updating their pages with a stream of fresh messages and photos. Stoddart said Facebook breaches federal privacy law by keeping users’ personal information indefinitely - even after members close their accounts. She also raised concerns about the sharing of users’ files with the almost one million third-party developers scattered across the globe who create Facebook applications such as games and quizzes. Stoddart applauded Facebook for making some changes, but urged the site to remedy outstanding privacy shortfalls, raising the possibility of legal proceedings if it doesn’t comply. http://ca.news.yahoo.com/s/capress/090716/national/facebook_privacy

AMAZON ERASES ORWELL BOOKS FROM KINDLE (New York Times, 17 July 2009) - In George Orwell’s “1984,” government censors erase all traces of news articles embarrassing to Big Brother by sending them down an incineration chute called the “memory hole.” On Friday, it was “1984” and another Orwell book, “Animal Farm,” that were dropped down the memory hole — by Amazon.com. In a move that angered customers and generated waves of online pique, Amazon remotely deleted some digital editions of the books from the Kindle devices of readers who had bought them. An Amazon spokesman, Drew Herdener, said in an e-mail message that the books were added to the Kindle store by a company that did not have rights to them, using a self-service function. “When we were notified of this by the rights holder, we removed the illegal copies from our systems and from customers’ devices, and refunded customers,” he said. Digital books bought for the Kindle are sent to it over a wireless network. Amazon can also use that network to synchronize electronic books between devices — and apparently to make them vanish. People who bought the rescinded editions of the books reacted with indignation, while acknowledging the literary ironies involved. “Of all the books to recall,” said Charles Slater, an executive with a sheet-music retailer in Philadelphia, who bought the digital edition of “1984” for 99 cents last month. “I never imagined that Amazon actually had the right, the authority or even the ability to delete something that I had already purchased.” Amazon appears to have deleted other purchased e-books from Kindles recently. Customers commenting on Web forums reported the disappearance of digital editions of the Harry Potter books and the novels of Ayn Rand over similar issues. Amazon’s published terms of service agreement for the Kindle does not appear to give the company the right to delete purchases after they have been made. It says Amazon grants customers the right to keep a “permanent copy of the applicable digital content.” Justin Gawronski, a 17-year-old from the Detroit area, was reading “1984” on his Kindle for a summer assignment and lost all his notes and annotations when the file vanished. “They didn’t just take a book back, they stole my work,” he said. On the Internet, of course, there is no such thing as a memory hole. While the copyright on “1984” will not expire until 2044 in the United States, it has already expired in other countries, including Canada, Australia and Russia. Web sites in those countries offer digital copies of the book free to all comers. http://www.nytimes.com/2009/07/18/technology/companies/18amazon.html?_r=1&ref=business

THE FUTURE OF SCHOLARSHIP? HARVARD GOES DIGITAL WITH SCRIBD (ArsTechnica, 17 July 2009) - Today, with the announcement that Harvard University Press will publish 1,000 digitized books on Scribd, the academic world took one more step in its glacially slow march into the digital age. Over ten years ago, when I first started my graduate work in the humanities, there was already much talk of the looming crisis in academic publishing. Print runs for academic works written by even major scholars in a given discipline are pitifully small—1,000 would be considered decent-sized. The work of junior faculty, who are trying to publish to beef up a CV, means that the runs are smaller still. It’s very hard to make money on such small print runs, which result in books with sky-high cover prices and limited availability. All of this has made it harder for scholars to publish and harder for non-specialists to justify the effort and expense of obtaining good, scholarly work. In sum, the present situation benefits nobody—scholars, the public, or the financially strapped publishing houses. But there’s a bit of a chicken-and-egg problem to moving scholarship online. Scholarly publishers, which are central to the all-important vetting and peer review process, don’t do digital, and they look down on anything published in a digital format. And that attitude pervades the academic community: scholars still pursue the peer-reviewed printed book as the ultimate CV trophy and turn their noses up a digital, giving the publishers little incentive to experiment with digital distribution. But, as HUP’s tiny little 1,000-book foray into the world of digital possibly indicates, academic publishers may be forced into the arms of digital by the same rapidly changing circumstances that are pushing regular book publishers toward outlets like Scribd. http://arstechnica.com/media/news/2009/07/the-future-of-scholarship-harvard-goes-digital-with-scribd.ars

SOCIAL NETWORKS APPEAL, BUT NOT TO THE FIRM (ABA Journal, 22 July 2009) - If the question last year was whether lawyers would ever take to the Internet’s social media, the answer this year has to be a resounding yes—on a personal level. Asked for the ABA’s 2009 Legal Technology Survey Report whether they personally maintain a presence in an online community or social network such as Facebook, LinkedIn, LegallyMinded or Legal OnRamp, 43 percent of respondents answered yes, almost triple the 15 percent positive responses in the 2008 survey. Their law firms also tripled their social network presence, but the percentages were much smaller. When asked whether their firms maintain a presence in an online community or social network, only 12 percent of respondents said yes, up from 4 percent in the 2008 survey. The ABA’s Legal Technology Resource Center has been conducting legal technology surveys since 1990. For the 2009 survey, between 778 and 928 ABA members completed questionnaires for each of the six survey volumes between January and May. Each survey volume begins with a Trend Report that summarizes the notable results and highlights changes from previous years. The Trend Report is followed by detailed charts and tables. http://www.abajournal.com/magazine/getting_personal

UNIVERSITY OF MICHIGAN, AMAZON OFFER 400,000 TITLES WITH PRINT-ON-DEMAND (SiliconValley.com, 21 July 2009) - The University of Michigan said Tuesday it is teaming up with Amazon.com to offer reprints of 400,000 rare, out-of-print and out-of-copyright books from its library. Seattle-based Amazon’s BookSurge unit will print the books on demand in soft cover editions at prices from $10 to $45. http://www.siliconvalley.com/news/ci_12885402

**** NOTED PODCASTS ****
8 THINGS WE HATE ABOUT IT (HBS podcast, 2 June 2008) - You may think that hate is too strong of a word for feelings toward a corporate department. I don’t. Yesterday, I was interviewing an executive on his perceptions of IT and he couldn’t spit his frustration out fast enough. He said, “In the quest of getting things organized, they are introducing a bunch of bureaucracy and, in the process, they’re abdicating their responsibility for making sure the right things get done.” This is completely typical of management’s frustration - no, management’s hatred - of IT. http://blogs.harvardbusiness.org/hbr/cramm/2008/06/8-things-we-hate-about-it.html [15 minute audio, recommended to me by a senior manager with experience inside and outside of IT departments.]

**** RESOURCES ****
CLOUD COMPUTING (NIST, 26 June 2009) - NIST is posting its working definition of cloud computing that serves as a foundation for its upcoming publication on the topic (available below). Computer scientists at NIST developed this draft definition in collaboration with industry and government. It was developed as the foundation for a NIST special publication that will cover cloud architectures, security, and deployment strategies for the federal government. NIST’s role in cloud computing is to promote the effective and secure use of the technology within government and industry by providing technical guidance and promoting standards. To learn more about NIST’s cloud efforts, join the NIST cloud computing announcement mailing list (very low volume) by sending an email to “listproc@nist.gov” with “subscribe cloudlist” in the message body text. http://csrc.nist.gov/groups/SNS/cloud-computing/cloud-def-v14.doc

YAMMER (Wikipedia article) – Yammer is a microblogging service launched in September 2008. Like Twitter, it allows users to post updates of their activities, follow others’ updates, tag content, and create memes. Unlike Twotter, Yammer focuses on businesses, and only individuals with the same email domain can join a given network. http://en.m.wikipedia.org/wiki/Yammer [Editor: if/when critical mass is achieved in a user organization, the company can buy a Yammer instance, and redeploy it inside the company’s security zone.]

**** LOOKING BACK - MIRLN TEN YEARS AGO ****
AMAZON SUES OVER NYT BESTSELLER LIST -- In an effort to settle the question of whether a bestseller list is proprietary and copyrightable, Amazon.com last week sued the New York Times in Seattle federal court. Since May 17, Amazon has featured the Times bestseller list on its Web site, and offered a 50% discount on the books named. On May 28 a lawyer for the Times wrote a letter asking Amazon to stop posting the list, which the Times licenses to rival bookseller BarnesandNoble.com. Amazon claims it’s making “fair use” of the list, similar to the way that a movie might be listed as having won an Academy Award, and added language clarifying that the Times didn’t endorse the Amazon site. The Times termed the modifications “inadequate.” Borders Group, which also uses the list, also has received a letter from the Times, and says it’s not sure how it will respond. (Wall Street Journal 7 Jun 99)

************** NOTES **********************
MIRLN (Misc. IT Related Legal News) is a free product for members of the American Bar Association’s Cyberspace Law Committee, et al., and is produced by KnowConnect PLLC.

Members of the ABA Cyberspace Law Committee automatically receive MIRLN postings (about every third week); members can manage their subscriptions at http://www.abanet.org/dch/committee.cfm?com=CL320000 (find the “Listserves” box; MIRLN comes through the CLCC-MEMS listserve). Others who wish to be added to the MIRLN distribution list should send email to Vince Polley (mailto:vpolley@knowconnect.com?subject=MIRLN) with the word “MIRLN” in the subject line, and similarly will be removed from the distribution list after sending email to Vince with the words “MIRLN REMOVAL” in the subject line.

Recent MIRLN issues are archived at www.knowconnect.com/mirln.

SOURCES (inter alia):
1. The Filter, a publication of the Berkman Center for Internet & Society at Harvard Law School, http://cyber.law.harvard.edu.
2. Edupage, http://www.educause.edu/pub/edupage/edupage.html.
3. SANS Newsbites, sans@sans.org.
4. NewsScan and Innovation, http://www.newsscan.com.
5. BNA’s Internet Law News, http://ecommercecenter.bna.com.
6. Crypto-Gram, http://www.schneier.com/crypto-gram.html.
7. McGuire Wood’s Technology & Business Articles of Note, http://tinyurl.com/ywsusp
8. Steptoe & Johnson’s E-Commerce Law Week, www.steptoe.com
9. Eric Goldman’s Technology and Marketing Law Blog, http://blog.ericgoldman.org/.
10. Readers’ submissions, and the editor’s discoveries.

This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 543 Howard Street, 5th Floor, San Francisco, California, 94105, USA.

PRIVACY NOTICE: E-mail addresses of individuals who subscribe to this periodic e-newsletter by sending email to Vince Polley with “MIRLN” in the subject line are kept by Vince Polley; this listing will not be provided to any other persons.