Ken Adams, proprietor of the always interesting AdamsDrafting blog and author of the best-selling ABA book A Manual of Style for Contract Drafting, had a post this morning on his blog regarding the use of EDGAR as a research tool to look at old contracts that had been filed as part of SEC filings. The Cyberspace hook for us today is the commentary on how there is a proprietary Web-based service out there that will help one to index the old contracts and find ones that might be of interest. Ken's sense is that there are many other ways to use the Web to access the same information (for example, the use of Lexis and/or Westlaw to search EDGAR filings that are under Exhibit 10). Ken also notes his skepticism on the quality of the work one might find in SEC filings -- I'll let you go read the particular choice phrase he applied to the contracts on EDGAR (this is a family blog after all...).
My only other thing to add is that in my particular practice, involving a great deal of day-to-day contracting for technology licensing and purchasing, the times I've been able to find useful work on EDGAR is almost too small to count. The EDGAR system is potentially useful if one is interested in contracts that publicly-held companies might do that rise to a certain level of materiality--Software licenses rarely fall into that bucket for either the licensor or the licensee. I've no doubt that there are exceptions to that, but combined with the fact that I think any of us who read this blog are more than capable of running rings around what we might find on EDGAR, my suggestion is to stick to our own form libraries and use our own inherent skills rather than relying on some other person's randomly-selected work.
ASIDE: The other Cyberspace angle -- Ken Adams will be joining a panel of lawyers from this Committee at the ABA Business Section's Spring Meeting this March in Washington DC. The pre-meeting CLE programs put on for the Section's Young Lawyer Forum are fantastic, and that's not just because I will be speaking for one of them! We hope to see you there.
Thursday, December 14, 2006
Tuesday, December 05, 2006
Remotely Eavesdropping on Cell Phone Microphones
A cellular telephone can be turned into a microphone and transmitter for the purpose of listening to conversations in the vicinity of the phone.
read more | digg story
FOLLOWUP THOUGHTS (Jan 4, 2007):
I can’t get paranoid about this one. It seems to me that if the bug is obtained through the auspices of a proper (4th Amendment compliant, probable cause, yadda yadda yadda) court order, it’s not all that different than any other form of bug. We can be paranoid about the cops and courts as a general rule (and should be…), but the means they use to exercise their court orders is not all that much more scary.
I couldn’t tell (and CNET obviously can’t from what I read) if the bug is one that directly transmits a signal to a receiver operated by the police, or if it transmits something via the cell network. Legally it should not be all that much different if there's been a proper court order, although you’d have to rope in the cell provider if the latter.
Technically it is interesting in that the only radio that should be in your typical cell phone is the radio that transmits to the cell network. (Blue tooth, found in an increasing number of handsets is, of course, a wild card in all of this – Let’s set that one aside for the moment though.) If we’ve got the bug set up as a purely software bug that infects the phone and has it transmitting what’s passing through the microphone over some sort of ‘radio’ then it must be going over the cell-transmission radio – And, that seems difficult to conceive other than something that would require the cooperation of the cell phone provider, since operating that radio without interacting with the cell network would be something I cannot believe would be an ‘off-the-shelf’ capability of the phone handset. If that’s the case then I’m less concerned again about non-legal hackers because it seems hard to believe that the cell networks would volunteer to allow a hacker to use the network! (It also suggests that this technique shouldn’t work against somebody sitting on an airplane, unless the FBI is suggesting that the FAA’s prohibition on cell phone use is not really a safety concern for all on the plane...)
If, as the BBC article mentioned in the CNET article linked above suggests, the cell network radio is hacked, via some kind of Malware that is sent electronically to the victim’s phone, to stay in transmit mode even where the phone seems to be turned off (or the radio has been turned off, as I can supposedly do with my BlackBerry), and even if ‘intelligence agencies’ can find ways of intercepting that signal and decode it, that would still require the spy to have physical proximity to the victim at all times (presuming the cell network isn't being used), and I find that all rather implausible as a useful source of data unless the spy is investing a LOT of money in this victim (and, if they have that much money to invest, they’d find some other way than this exploit to get what they want). We’re not going to see hackers using this tactic for random crap they might want to listen to while your talking to your best friend at the local coffee shop. (And, the cell providers would quickly come up with anti-spyware tactics for their phones if the exploit got out beyond this nefarious ‘intelligence community,’ so any win by a hacker would be short-lived at best.)
Apart from the radio that is used for purposes of the cell network, the only other ‘radio’ in a typical cell phone (off the shelf) is the Bluetooth. That might be an interesting hack (and the subject of multiple discussions already). Still, it seems hard to believe that there would be a hack that might alter the phone to NOT turn off the Bluetooth (and/or the phone itself) when I thought I’d turned it off – There would be a hell of a lot of software necessary to do that, and it would be so handset specific that, again, the investment for any one particular victim would prevent the odd private citizen hacker from taking advantage of it – We don’t have the single-source problem for cell phone operating software that we have for PCs. (I do work for that industry, and actually work on licenses for cell phone operating system software, so I speak from knowledge in that regard.) Also, since the off-the-shelf Bluetooth system in my phone does not use the microphone on the phone handset itself, but rather the microphone in my earset, it would require an even more incredible hack to get the handset to use the Bluetooth transmitter for such a non-standard function as to transmit the sounds on the microphone to a surreptitious Bluetooth listener, and to do so while also allowing the spy to circumvent whatever encryption is on the Bluetooth transmitter, and probably to do so as well while still allowing the Bluetooth transmitter to be used simultaneously for its intended purposes since otherwise one would tip off the victim of the bug. Finally, Bluetooth is even more susceptible to the need to be proximate to the victim -- That radio will reliably transmit only a few hundred feed through clean space. Again, it might be plausible for the 'intelligence community' to invest in human resources to follow somebody around who is a high-value target, but that target would be gotten one way or the other if somebody was really interested, that target would probably know well enough to take out the battery of his phone, and the rest of us are perfectly safe from the pimple-faced script kiddie.
Finally, if all that’s involved in the above is a physical bug snuck into the cell phone itself, then those paranoid executives who remove their batteries are missing the boat. And, pimple-faced kids sitting in coffee shops are still at a loss when it comes to physical invasions of people’s personal property (or I’m not all that worried about the few who would try such a thing). Regardless, the addition of using a cell phone (as opposed to slipping a bug into the back of my jacket collar) to the mix doesn’t change anything where you’ve got somebody who’s willing to commit a criminal breach of my personal effects in order to plant his bug.
In other words – I’m kind of skeptical about all of this.

But, it all leads to finding stuff on the BBC article cited by CNET, such as this actual living example of a Cone of Silence. Where’s Maxwell Smart when you need him? (If you read the BBC article, it really seems poorly thought out – For example, they find ‘experts’ who claim that a physical bug wouldn’t work since the battery would wear out, but who’s to say the bug wouldn’t be set up to use the cell phone’s own battery (duh…). And, I did check the dateline of the article – It’s not April 1, but maybe it should have been.)
read more | digg story
FOLLOWUP THOUGHTS (Jan 4, 2007):
I can’t get paranoid about this one. It seems to me that if the bug is obtained through the auspices of a proper (4th Amendment compliant, probable cause, yadda yadda yadda) court order, it’s not all that different than any other form of bug. We can be paranoid about the cops and courts as a general rule (and should be…), but the means they use to exercise their court orders is not all that much more scary.
I couldn’t tell (and CNET obviously can’t from what I read) if the bug is one that directly transmits a signal to a receiver operated by the police, or if it transmits something via the cell network. Legally it should not be all that much different if there's been a proper court order, although you’d have to rope in the cell provider if the latter.
Technically it is interesting in that the only radio that should be in your typical cell phone is the radio that transmits to the cell network. (Blue tooth, found in an increasing number of handsets is, of course, a wild card in all of this – Let’s set that one aside for the moment though.) If we’ve got the bug set up as a purely software bug that infects the phone and has it transmitting what’s passing through the microphone over some sort of ‘radio’ then it must be going over the cell-transmission radio – And, that seems difficult to conceive other than something that would require the cooperation of the cell phone provider, since operating that radio without interacting with the cell network would be something I cannot believe would be an ‘off-the-shelf’ capability of the phone handset. If that’s the case then I’m less concerned again about non-legal hackers because it seems hard to believe that the cell networks would volunteer to allow a hacker to use the network! (It also suggests that this technique shouldn’t work against somebody sitting on an airplane, unless the FBI is suggesting that the FAA’s prohibition on cell phone use is not really a safety concern for all on the plane...)
If, as the BBC article mentioned in the CNET article linked above suggests, the cell network radio is hacked, via some kind of Malware that is sent electronically to the victim’s phone, to stay in transmit mode even where the phone seems to be turned off (or the radio has been turned off, as I can supposedly do with my BlackBerry), and even if ‘intelligence agencies’ can find ways of intercepting that signal and decode it, that would still require the spy to have physical proximity to the victim at all times (presuming the cell network isn't being used), and I find that all rather implausible as a useful source of data unless the spy is investing a LOT of money in this victim (and, if they have that much money to invest, they’d find some other way than this exploit to get what they want). We’re not going to see hackers using this tactic for random crap they might want to listen to while your talking to your best friend at the local coffee shop. (And, the cell providers would quickly come up with anti-spyware tactics for their phones if the exploit got out beyond this nefarious ‘intelligence community,’ so any win by a hacker would be short-lived at best.)
Apart from the radio that is used for purposes of the cell network, the only other ‘radio’ in a typical cell phone (off the shelf) is the Bluetooth. That might be an interesting hack (and the subject of multiple discussions already). Still, it seems hard to believe that there would be a hack that might alter the phone to NOT turn off the Bluetooth (and/or the phone itself) when I thought I’d turned it off – There would be a hell of a lot of software necessary to do that, and it would be so handset specific that, again, the investment for any one particular victim would prevent the odd private citizen hacker from taking advantage of it – We don’t have the single-source problem for cell phone operating software that we have for PCs. (I do work for that industry, and actually work on licenses for cell phone operating system software, so I speak from knowledge in that regard.) Also, since the off-the-shelf Bluetooth system in my phone does not use the microphone on the phone handset itself, but rather the microphone in my earset, it would require an even more incredible hack to get the handset to use the Bluetooth transmitter for such a non-standard function as to transmit the sounds on the microphone to a surreptitious Bluetooth listener, and to do so while also allowing the spy to circumvent whatever encryption is on the Bluetooth transmitter, and probably to do so as well while still allowing the Bluetooth transmitter to be used simultaneously for its intended purposes since otherwise one would tip off the victim of the bug. Finally, Bluetooth is even more susceptible to the need to be proximate to the victim -- That radio will reliably transmit only a few hundred feed through clean space. Again, it might be plausible for the 'intelligence community' to invest in human resources to follow somebody around who is a high-value target, but that target would be gotten one way or the other if somebody was really interested, that target would probably know well enough to take out the battery of his phone, and the rest of us are perfectly safe from the pimple-faced script kiddie.
Finally, if all that’s involved in the above is a physical bug snuck into the cell phone itself, then those paranoid executives who remove their batteries are missing the boat. And, pimple-faced kids sitting in coffee shops are still at a loss when it comes to physical invasions of people’s personal property (or I’m not all that worried about the few who would try such a thing). Regardless, the addition of using a cell phone (as opposed to slipping a bug into the back of my jacket collar) to the mix doesn’t change anything where you’ve got somebody who’s willing to commit a criminal breach of my personal effects in order to plant his bug.
In other words – I’m kind of skeptical about all of this.

But, it all leads to finding stuff on the BBC article cited by CNET, such as this actual living example of a Cone of Silence. Where’s Maxwell Smart when you need him? (If you read the BBC article, it really seems poorly thought out – For example, they find ‘experts’ who claim that a physical bug wouldn’t work since the battery would wear out, but who’s to say the bug wouldn’t be set up to use the cell phone’s own battery (duh…). And, I did check the dateline of the article – It’s not April 1, but maybe it should have been.)
Monday, November 27, 2006
Cyberspace Law: We're More than Just Website Advisors!
From today's WSJ Law Blog, on the pending changes to the Federal Rules of Civil Procedure regarding electronic evidence:
Full posting here.
Gosh -- Doesn't that sound like what the Cyberspace Committee has been teaching its members since, oh, let's see--ABOUT A DECADE?
Folks from this committee who are in private practice: If you have not already made your presence and depth of knowledge known to your own firm's litigators, you are missing a great opportunity. This is one of the better 'convergence' moments in our history, so go take advantage of it!
Alvin Lindsay, a partner with Hogan & Hartson, laid out for the WSJ the implications of the new rules. “Lawyers will now have to know about their clients’ computer architecture: How do they store their data? How do their computer systems operate? This is not something they teach in law school.”
Full posting here.
Gosh -- Doesn't that sound like what the Cyberspace Committee has been teaching its members since, oh, let's see--ABOUT A DECADE?
Folks from this committee who are in private practice: If you have not already made your presence and depth of knowledge known to your own firm's litigators, you are missing a great opportunity. This is one of the better 'convergence' moments in our history, so go take advantage of it!
Wednesday, November 08, 2006
News News News
November 8, 2006 -- A busy day in the news. Not that election thing silly -- In Cyberspace news!
I had a small start when reading a squib in the BNA eCommerce Reporter this morning, which discussed a New York federal trial court decision which proclaimed that a Web site is not interactive for personal jurisdiction purposes if the interactivity is merely through password-protected activity. Whoa! I thought, since that would be a major change to the Zippo standards if it were followed. However, careful reading of the squib (as opposed to just the headline...) reveals that the New York case was one regarding general jurisdiction. As any of us who walk these cyberlaw halls knows, Zippo was a specific jurisdiction case. The law as we knew it has not changed. Cite is to C.B.C. Wood Products Inc. v. LMD Integrated Logistics Serv. Inc., E.D.N.Y., No. 06-2673, 10/7/06. {Note: For those of you who aren't lawyers and have no idea what the difference is between specific versus general jurisdiction -- Well, not to be elitist on you, but that's one of those ones I couldn't begin to explain in a sentence, particularly since you need a good grounding on the concept of 'personal jurisdiction' in the first place. You can try this outline from a law school professor on the concept if you want, or this Wikipedia article. And, if you want a cyberspace law angle, read this article by another law professor.}
The Supreme Court of Kansas has taken a look at shrink-wrap licenses, and has dealt a blow against them. In Wachter Mgmt. Co. v. Dexter & Chaney Inc., Kan., No. 95,102, 10/27/06, the court looked at a software transaction that was initially done through a paper purchase order between the parties, and then was followed by the unwrapping of a shrink-wrap license by the software user. When the user ultimately decided to claim a problem, and brought a claim in his local court in Kansas, the software developer pointed to its shrink-wrap license and the venue clause therein. Most of us might have presumed that this would ultimately have favored the developer -- But, the Kansas court revived the thinking of Step-Saver Data Sys. v. Wyse Tech. Inc., 939 F. 2d 91 (3d Cir. 1991). In Step-Saver, the shrink-wrap was ignored on the basis of its being 'a proposal for additional terms' under the UCC, and hence rejectable by the other party. The court in Kansas felt that this was the case here, and refused to enforce the shrink-wrap license. (One should note that the case was a 4-3 decision, and the dissent was clearly bothered with the revival of Step-Saver.) All that said, and whether you agree with one side or the other, this leads to a PRACTICE NOTE: When counseling clients who are using the paper followed by shrink-wrap process, advise them to have an unequivocal statement in the paper that the transaction is subject to the shrink-wrap (or click-wrap, or whatever...) terms that will follow. The Kansas court seems to suggest that this would have avoided the problem, and there is no harm in adding such statements to one's paper contracts, particularly since most of our clients will still like to hold out the possibility of doing business in Kansas!
Finally, an idea that many have bounced around has been endorsed in a U.S. District Court -- Is the transfer of a domain name from one party to another an event that should be treated as a new 'registration' by the recipient? Recall that both the Anti-Cybersquatting Protection Act and the ICANN Uniform Domain Name Dispute Resolution Policy provide that the defendant's actions in registering the domain are important to the case. In many cases, the original registration of the domain was years in the past, and may have actually been done by somebody in good faith or the facts are hard to prove from that ancient time. But, one might have easy facts to show that the subsequent registrant took and uses the domain in bad faith. Some of us wondered if we could simply look to the most recent registrant for our analysis.
In Christensen Firm v. Chameleon Data Corp., W.D. Wash., No. C06-337Z, 11/1/06, the court agreed under the ACPA that each act of transfer was a new 'registration' for the purposes of ACPA analysis. Thus, one need not trace the progeny of a domain back through to the first party that registered it, but only to the most recent (i.e., the one the complaint is all about). Although this is an ACPA case, the logic would seem to apply equally to a UDRP analysis, and one might at least cite this as persuasive evidence on point.
[If anybody with more time than I have wants to find public links to any of those opinions, please let me know and I shall post them. The ones I have are through a password-protected site, so they are not of much use to the rest of the world. UPDATE: I found a free link to the Wachter Mgmt case out of Kansas. Still looking for the other two...]
I had a small start when reading a squib in the BNA eCommerce Reporter this morning, which discussed a New York federal trial court decision which proclaimed that a Web site is not interactive for personal jurisdiction purposes if the interactivity is merely through password-protected activity. Whoa! I thought, since that would be a major change to the Zippo standards if it were followed. However, careful reading of the squib (as opposed to just the headline...) reveals that the New York case was one regarding general jurisdiction. As any of us who walk these cyberlaw halls knows, Zippo was a specific jurisdiction case. The law as we knew it has not changed. Cite is to C.B.C. Wood Products Inc. v. LMD Integrated Logistics Serv. Inc., E.D.N.Y., No. 06-2673, 10/7/06. {Note: For those of you who aren't lawyers and have no idea what the difference is between specific versus general jurisdiction -- Well, not to be elitist on you, but that's one of those ones I couldn't begin to explain in a sentence, particularly since you need a good grounding on the concept of 'personal jurisdiction' in the first place. You can try this outline from a law school professor on the concept if you want, or this Wikipedia article. And, if you want a cyberspace law angle, read this article by another law professor.}
The Supreme Court of Kansas has taken a look at shrink-wrap licenses, and has dealt a blow against them. In Wachter Mgmt. Co. v. Dexter & Chaney Inc., Kan., No. 95,102, 10/27/06, the court looked at a software transaction that was initially done through a paper purchase order between the parties, and then was followed by the unwrapping of a shrink-wrap license by the software user. When the user ultimately decided to claim a problem, and brought a claim in his local court in Kansas, the software developer pointed to its shrink-wrap license and the venue clause therein. Most of us might have presumed that this would ultimately have favored the developer -- But, the Kansas court revived the thinking of Step-Saver Data Sys. v. Wyse Tech. Inc., 939 F. 2d 91 (3d Cir. 1991). In Step-Saver, the shrink-wrap was ignored on the basis of its being 'a proposal for additional terms' under the UCC, and hence rejectable by the other party. The court in Kansas felt that this was the case here, and refused to enforce the shrink-wrap license. (One should note that the case was a 4-3 decision, and the dissent was clearly bothered with the revival of Step-Saver.) All that said, and whether you agree with one side or the other, this leads to a PRACTICE NOTE: When counseling clients who are using the paper followed by shrink-wrap process, advise them to have an unequivocal statement in the paper that the transaction is subject to the shrink-wrap (or click-wrap, or whatever...) terms that will follow. The Kansas court seems to suggest that this would have avoided the problem, and there is no harm in adding such statements to one's paper contracts, particularly since most of our clients will still like to hold out the possibility of doing business in Kansas!
Finally, an idea that many have bounced around has been endorsed in a U.S. District Court -- Is the transfer of a domain name from one party to another an event that should be treated as a new 'registration' by the recipient? Recall that both the Anti-Cybersquatting Protection Act and the ICANN Uniform Domain Name Dispute Resolution Policy provide that the defendant's actions in registering the domain are important to the case. In many cases, the original registration of the domain was years in the past, and may have actually been done by somebody in good faith or the facts are hard to prove from that ancient time. But, one might have easy facts to show that the subsequent registrant took and uses the domain in bad faith. Some of us wondered if we could simply look to the most recent registrant for our analysis.
In Christensen Firm v. Chameleon Data Corp., W.D. Wash., No. C06-337Z, 11/1/06, the court agreed under the ACPA that each act of transfer was a new 'registration' for the purposes of ACPA analysis. Thus, one need not trace the progeny of a domain back through to the first party that registered it, but only to the most recent (i.e., the one the complaint is all about). Although this is an ACPA case, the logic would seem to apply equally to a UDRP analysis, and one might at least cite this as persuasive evidence on point.
[If anybody with more time than I have wants to find public links to any of those opinions, please let me know and I shall post them. The ones I have are through a password-protected site, so they are not of much use to the rest of the world. UPDATE: I found a free link to the Wachter Mgmt case out of Kansas. Still looking for the other two...]
Wednesday, November 01, 2006
Internet Governance Forum -- Our session


David Satola reports that the session at the IGF entitled 'Legal Aspects' was a big success and well attended. Kristine Dorrain suggested that interest was high amongst the panel as well as the audience and felt it could have gone on easily for another hour. Theoretically the session was recorded (audio) and will be posted on-line, but I have not found a link to such yet.
David sent over a couple of photographs from the session -- Kristine also has some and will send them along when she can.
Monday, October 30, 2006
Live Feeds from the Internet Governance Forum
Although time zone issues will probably impede many of us on this side of the world from participating live, this site:
http://igf2006.intgovforum.org/
is open for business and allows one to monitor the Internet Governance Forum taking place in Greece right now. If you register, you can monitor live feeds, read and participate in chats, and all that other good Web 2.0 stuff.
The Internet Governance Forum is the continuing discussion that arose out of the meeting in Tunisia last year, which itself was part of the World Summit on the Information Society (WSIS) set up by the UN and the ITU. Many of our members have worked to understand the original mandate of the WSIS and its ongoing efforts through IGF.
Remember, our own members David Satola and Kristine Dorrain are live and on the ground at the Athens meeting, and will be presenting to the crowd on legal issues this coming Wednesday at 9:30 AM Athens time (which is, unfortunately, about 1:30 in the morning my own time, so I regret that I'll have to read about it in the papers the next day).
UPDATE: Dave Satola reports to me that all is going well at the Summit. Still, there are some troubles to be had apparently... United Nations "Internet" Summit held sans internet
http://igf2006.intgovforum.org/
is open for business and allows one to monitor the Internet Governance Forum taking place in Greece right now. If you register, you can monitor live feeds, read and participate in chats, and all that other good Web 2.0 stuff.
The Internet Governance Forum is the continuing discussion that arose out of the meeting in Tunisia last year, which itself was part of the World Summit on the Information Society (WSIS) set up by the UN and the ITU. Many of our members have worked to understand the original mandate of the WSIS and its ongoing efforts through IGF.
Remember, our own members David Satola and Kristine Dorrain are live and on the ground at the Athens meeting, and will be presenting to the crowd on legal issues this coming Wednesday at 9:30 AM Athens time (which is, unfortunately, about 1:30 in the morning my own time, so I regret that I'll have to read about it in the papers the next day).
UPDATE: Dave Satola reports to me that all is going well at the Summit. Still, there are some troubles to be had apparently... United Nations "Internet" Summit held sans internet
Wednesday, October 18, 2006
Open Source Continues to Come of Age
cNet notes that "OpenLogic, a provider of open-source software for enterprises, is offering indemnification against legal action for companies using its code." The company does note that its indemnity no longer applies if the indemnitee has modified the code in the OpenLogic code. And, the operating system used (e.g., Linux) is not covered by the OpenLogic indemnity (although there may be policies available from insurers, such as Lloyds, to cover that). So, the end user still has some degree of patching together risk-allocation tools in order to create a reasonably protected system.
Still, the days when lawyers in the know should just instantly panic when they hear about OS in their clients' houses should be deemed as officially over. Our own committee's members recently presented a very well-received program on how to assess open source as a risk during a corporate merger transaction -- materials available here (ABA Business Law Section members only).
Like everything else we do, there is still plenty of work to do to make sure the hatches are battened down. However, the coming of age of the OS industry means that the lawyers can start to add value by pointing out the risk management tools their clients can use, and help them to negotiate or assess actual risk versus falling into abject panic.
Still, the days when lawyers in the know should just instantly panic when they hear about OS in their clients' houses should be deemed as officially over. Our own committee's members recently presented a very well-received program on how to assess open source as a risk during a corporate merger transaction -- materials available here (ABA Business Law Section members only).
Like everything else we do, there is still plenty of work to do to make sure the hatches are battened down. However, the coming of age of the OS industry means that the lawyers can start to add value by pointing out the risk management tools their clients can use, and help them to negotiate or assess actual risk versus falling into abject panic.
Saturday, October 07, 2006
Wendy's Blog: Legal Tags: Coming Soon: Kitten with a EULA?
The title of Wendy's blog post (quoted above in this posting's own title) gets it slightly wrong. They don't require you to sign a "license agreement," but they do require that you agree to a rather lengthy contract before they'll allow you to purchase their specially bred hypoallergenic cat. The contract contains a rather broad indemnity clause, a restriction that you not let the cat wander outside or suffer a waiver of any warranties, restrictions on further sale, etc. They also claim patent rights in the cats. Whew.
Thursday, September 14, 2006
Software Doesn't Need to be Perfect?
The company that makes the self-balancing Segway scooters (the two-wheeler for people) announced on September 14 that it is recalling all 23,500 of the units it has shipped to date "because of a software glitch that can make its wheels unexpectedly reverse direction, causing riders to fall off."
As discussed in prior posts, we have come to expect a lesser standard of care in the provision of software -- The sort of thing that we would never find acceptable in other areas such as how our airplanes work. Maybe this story reminds us that those two concepts are more or less impossible to sever in practice, since there are all too many physical products that may potentially injure us that are dependent themselves on software.
That much was probably obvious already to anybody who can reach this blog. What it should also suggest to those of us practicing in cyberspace is that our willingness to let our deals go forward where the software providers to a larger project are held to a lower standard than the provider of the project as a whole. If the software provider for a car's computer suggests that it cannot take liability for what might go wrong with the car, then what is the car manufacturer to do that needs that software? Should it decide that it cannot afford the cost of the vendor's sure-thing software guaranty? Should it decide that it must ultimately bring the project in-house because it can't afford to allow quality control to lie in a third-party who is not willing to be on the hook? Should it calculate the risk of a problem and insure against it rather than try to avoid fixing the problem?
These are often seemingly irresolveable problems for buyers and sellers, although that may be a reflection of the consumer willingness to pay for safety versus whether or not it can be done. That said, understanding these issues and now to describe and negotiate them are what our subset of the profession can offer to the move the debate beyond what today is often simply a battle of wills.
As discussed in prior posts, we have come to expect a lesser standard of care in the provision of software -- The sort of thing that we would never find acceptable in other areas such as how our airplanes work. Maybe this story reminds us that those two concepts are more or less impossible to sever in practice, since there are all too many physical products that may potentially injure us that are dependent themselves on software.
That much was probably obvious already to anybody who can reach this blog. What it should also suggest to those of us practicing in cyberspace is that our willingness to let our deals go forward where the software providers to a larger project are held to a lower standard than the provider of the project as a whole. If the software provider for a car's computer suggests that it cannot take liability for what might go wrong with the car, then what is the car manufacturer to do that needs that software? Should it decide that it cannot afford the cost of the vendor's sure-thing software guaranty? Should it decide that it must ultimately bring the project in-house because it can't afford to allow quality control to lie in a third-party who is not willing to be on the hook? Should it calculate the risk of a problem and insure against it rather than try to avoid fixing the problem?
These are often seemingly irresolveable problems for buyers and sellers, although that may be a reflection of the consumer willingness to pay for safety versus whether or not it can be done. That said, understanding these issues and now to describe and negotiate them are what our subset of the profession can offer to the move the debate beyond what today is often simply a battle of wills.
Wednesday, September 06, 2006
You Might Want to Look it up Before You Go to Court
In an interesting little case at the 8th Circuit involving the intersection between 'computer program' and 'data' and the application of the Computer Software Rental Amendments Act of 1990, the court took pains to suggest that the lawyer arguing the case at District Court for the (alleged...) copyright holder did not even understand a fundamental concept in the world of copyright registration:
Oops. I would not want to presume anything about whomever was arguing the case, since it may have been a last minute substitution. But, there was obviously a mishandling of the registration of the copyright (and, maybe I need to reconsider my rule-of-thumb that lawyers are rarely needed in actual registration practice for copyright). It clearly is a lesson for the rest of us -- These technicalities are important but oft-times relegated to the last minute if at all.
Although the case ended up turning on a technicality (failure to register the copyright prior to litigation), the court did offer some thoughts on the underlying theories suggesting that it would have likely decided the case against the copyright holder in any event. The case involved a company that made programs that controlled sewing machines making patterns. The program uses memory cards that contained the instructions for the pattern that was being sewed. A retailer made a habit of lending out memory cards to her customers (although unstated in the opinion, I presume that the computer program itself was not lent out, just the memory cards with the instructions).
The copyright holder sued, claiming that the lending out of the memory cards was an infringement based on the Rental Act's prohibition on lending out copies of 'computer programs' (a specific statutory exemption from the first sale doctrine). The defendant argued that the memory cards did not comprise a 'computer program,' and therefore were still subject to the plain old First Sale Doctrine rules (which allow one to lend, rent or otherwise dispose of a particular authorized copy of a work once it has first been sold under the authority of the copyright holder). The District Court agreed and granted summary judgment on that basis. The 8th Circuit did not reach the question since it noted that the registration used by the plaintiff was not properly done for a 'computer program,' which, among other things, requires that the source code for the program be filed with the registration (which had not been done) -- Thus, deciding the case on the ground that the plaintiff had no case because it "failed to prove it applied for registration of the computer program copyrights before commencing this infringement suit." The plaintiff tried to duck the problem by noting that it still held a valid copyright in the visual design, and again the court noted that even if that were true the exemption from the first sale doctrine only applies to computer programs and not to visual designs.
Although our group focuses on our 'cyberspace' commonality, many of us are frequently brought in for intellectual property concerns, and particularly where computer programs or the like are involved. Or, rather -- We should be brought in. Yet another reason to seek out attorneys who have the knowledge and background to know what Source Code might be...
Indeed, the term source code is nowhere to be found in Action Tapes’ pleadings and motion papers, and at the summary judgment motion argument counsel did not know the meaning of that term.
Oops. I would not want to presume anything about whomever was arguing the case, since it may have been a last minute substitution. But, there was obviously a mishandling of the registration of the copyright (and, maybe I need to reconsider my rule-of-thumb that lawyers are rarely needed in actual registration practice for copyright). It clearly is a lesson for the rest of us -- These technicalities are important but oft-times relegated to the last minute if at all.
Although the case ended up turning on a technicality (failure to register the copyright prior to litigation), the court did offer some thoughts on the underlying theories suggesting that it would have likely decided the case against the copyright holder in any event. The case involved a company that made programs that controlled sewing machines making patterns. The program uses memory cards that contained the instructions for the pattern that was being sewed. A retailer made a habit of lending out memory cards to her customers (although unstated in the opinion, I presume that the computer program itself was not lent out, just the memory cards with the instructions).
The copyright holder sued, claiming that the lending out of the memory cards was an infringement based on the Rental Act's prohibition on lending out copies of 'computer programs' (a specific statutory exemption from the first sale doctrine). The defendant argued that the memory cards did not comprise a 'computer program,' and therefore were still subject to the plain old First Sale Doctrine rules (which allow one to lend, rent or otherwise dispose of a particular authorized copy of a work once it has first been sold under the authority of the copyright holder). The District Court agreed and granted summary judgment on that basis. The 8th Circuit did not reach the question since it noted that the registration used by the plaintiff was not properly done for a 'computer program,' which, among other things, requires that the source code for the program be filed with the registration (which had not been done) -- Thus, deciding the case on the ground that the plaintiff had no case because it "failed to prove it applied for registration of the computer program copyrights before commencing this infringement suit." The plaintiff tried to duck the problem by noting that it still held a valid copyright in the visual design, and again the court noted that even if that were true the exemption from the first sale doctrine only applies to computer programs and not to visual designs.
Although our group focuses on our 'cyberspace' commonality, many of us are frequently brought in for intellectual property concerns, and particularly where computer programs or the like are involved. Or, rather -- We should be brought in. Yet another reason to seek out attorneys who have the knowledge and background to know what Source Code might be...
Subscribe to:
Posts (Atom)