Thursday, April 19, 2007
News Flash: The Internet Is Still Part of the Real World
More to the point -- Why do we always feel a need to create special rules for what happens on the Internet? Where there are distinct differences there might be good cause for special carveouts, but more often than not the "Internet rules" are simply a restatement of what the rules are already in the real world, with the implicit thought that the real world rules didn't apply to the Internet unless we say so. The rules already apply -- The Internet is still a function of the real world, it still applies to how human beings communicate with each other just as pamphleteering, newspapering and broadcasting applied before it. We can apply the same rules to the 'Net in most cases just as well as we can to the other media. Let's get past the fallacy that just because it's the Internet all the rules are off the table, so that we can start to talk about real differences rather than perceived ones.
Wednesday, April 18, 2007
Authentication? We Don't Need No Stinking Authentication!
On a more mundane footing, when we as attorneys find these wonderful nuggets stored by the Wayback machine, and eagerly seek to get them admitted into a courtroom proceeding for the benefits of our clients, might we take a second to pause and consider the good old rules of evidence? That was the issue in [XXX[, where the plaintiff sought to admit pages printed from the Wayback Machine as part of his prima facie argument. The existence of the older Web pages was not the issue, but rather the admissibility of the information posted therein.
"Where postings from internet websites are not statements made by declarants testifying at trial and are offered to prove the truth of the matter asserted, such postings generally constitute hearsay under Fed. R. Evid. 801."
We all of course remember that there may be exceptions to the hearsay rule, but absent a showing of one of those exceptions hearsay gets kicked. In today's case, the court noted that the plaintiff
lacks the personal knowledge required to set forth with any certainty that the documents obtained via third-party websites are, in fact, what he proclaims them to be. This problem is even more acute in the case of documents procured through the Wayback Machine. Plaintiff states that the web pages archived within the Wayback Machine are based upon "data from third parties who compile the data by using software programs known as crawlers," who then "donate" such data to the Internet Archive, which "preserves and provides access to it." (Novak Decl. ¶4.) Based upon Novak's assertions, it is clear that the information posted on the Wayback Machine is only as valid as the third-party donating the page decides to make it—the authorized owners and managers of the archived websites play no role in ensuring that the material posted in the Wayback Machine accurately represents what was posted on their official websites at the relevant time. As Novak proffers neither testimony nor sworn statements attesting to the authenticity of the contested web page exhibits by any employee of the companies hosting the sites from which plaintiff printed the pages, such exhibits cannot be authenticated as required under the Rules of Evidence.
(emphasis added)
Without the necessary authentication, the evidence that Mr. Novak was seeking to admit was kicked.
Novak d/b/a Petswarehouse.com v. Tucows, Inc., 2007 WL 922306 (USDC EDNY No. 06-CV-1909 (JFB) (ARL), Mar. 26, 2007).
The lesson for us? Simply this -- Don't skip steps just because you got it from the Internet! All of the same rules continue to apply. And, in some cases, those rules may mean that your golden nugget will remain outside the courtroom unless and until you can find a way to authenticate it.
There was a second part of the same opinion which I found equally interesting on a totally different topic, but to maintain thread integrity (!) I shall hold that for another posting...
Wednesday, March 28, 2007
Open Source News
The Free Software Foundation has announced publication of the third discussion draft of the GNU General Public License Version 3. Because quite a few changes have been made since the previous draft and important new issues have surfaced, the drafting process has been extended and revised to encourage more feedback. The most significant changes in this draft include refinements in the "tivoization" provisions to eliminate unwanted side effects, revision of the patent provisions to prevent end-runs around the license, and further steps toward compatibility with other free software licenses.
Get your copy here.
I guess it's not surprising how long this new version of the GPL is taking to work its way through their system. This third discussion draft is only being issued today -- The second discussion draft came out July a year ago. (Offhand I can't find when the first discussion draft came out, but I'm sure it was some months before the second.) The good folks at FSF are certainly finding out what happens when many folks with varied interests all get to participate in the crafting of a document that will have universal impact on almost all users of software -- Maybe we should get them to connect with the folks over at NCCUSL who were working on UCITA? Think of how much they all have in common now!
Monday, March 26, 2007
Payment Cards and Money Laundering -- Evidence of Reality?
Well...
Just recently Florida law enforcement is reporting that they have discovered that a number of the credit card accounts that were the subject of the recent T.J. Maxx hacking incident, where many thousands of credit card numbers were likely revealed, were eventually used to buy gift cards from Wal-Mart stores -- $18,000 and $24,000 worth in two different Florida stores. In turn the bad guys then used those cards at Sams Club locations to buy electronics. (Recall, of course, that Sams Clubs are part of the Wal-Mart empire, and therefore this seems to have been a scheme entirely within a retailer's own private card system, rather than one involving the credit-card branded cards processed through Visa, Mastercard and the like. Maybe the bad guys thought that the private card issuers would be less diligent than the card association issuers? Who knows...)
- UPDATE: I've been reminded that the industry terms for those two kinds of cards are 'open loop' (the kind that is branded with VISA or MASTERCARD and is usable pretty much anyplace that can accept credit cards) versus 'closed loop' (the kind that is branded by one particular retailer, for example, and is usable only in that retailer's own stores).
Apparently somebody at Wal-Mart eventually took note of the large card purchases, and ultimately they were able to connect the cards to the T.J. Maxx hacking incident.
This isn't the cross-the-border sort of money laundering that we were discussing in Washington. Nonetheless, these guys certainly viewed the gift cards as another way to 'wash' their stolen credit cards, since the only time the stolen cards would have been used was when the gift cards were purchased rather than at the time the electronics were being purchased.
The good news is that the systems that might catch this seem to have worked (of course, we can say that only for the attempts we know about). The bad news is that maybe the 'hype' isn't quite as 'hypey' as we might have thought.
Saturday, March 17, 2007
Electronic Commerce Subcommittee
Beyond that, the subcommittee continues to be interested in developing a body of law surrounding virtual reality gaming -- Both in terms of legal issues here in 'real space' as well as the burgeoning law within the virtual spaces. One thought is to publish an outline of legal issues that Christina Kunz has been developing since our Little Rock meeting -- Just in taking notes she has gathered over six pages of nothing but issues (no answers!). This looks like it has legs for a while...
CAIT Meeting

Bill Denny, Co-Chair of the Subcommittee on Corporate Aspects of Information Technology, passed along his notes from their meeting on Thursday:
The CAIT subcommittee had a highly dynamic and well-attended meeting. Don Cohn and Bill Denny, the co-chairs, gave brief presentations on IT issues in M&A Transactions. Don focused on the challenges of addressing electronic records in the Purchase Agreement and then implementing the transfer of such records. CAIT is building a checklist and commentary of IT issues in M&A transactions, which it intends to publish as a supplement to the M&A checklist published by the Negotiated Acquisitions Committee and to present at a Program in Spring 2008. A number of people volunteered to help develop parts of this checklist.
Steve Hollman and Dino Tsibouris gave a fast-paced overview of their exciting project on blogs, wikis and social networking in business communications. This Project has proposed a program for the ABA 2007 Annual Meeting as well as possible podcasts, and will package the materials for use by a speakers bureau. It also intends to develop sample business blogging policies to supplement previous publications covering employer internet policies. There was lots of interaction by the participants about the record retention challenges of these new methods of electronic communication.
Ariane Siegel explained her CAIT project of developing short form and long form data transfer agreements for cross-border transactions. These agreements will cover the collection, use and disclosure of personal information. The participants discussed the challenge of facilitating the transfer of data and keeping focus on the process. Don Cohn addressed another CAIT project relating to cybersecurity. It focuses on security holes associated with software, as economics drive the software market to push products out to customers and deal with problems later. Customers can deal with this through warranties, specifications, acceptance testing or indemnities, and the project will come up with sample contract provisions and discussion of ways the clauses do and do not address risk.
CAIT participants came up with several exciting ideas for new projects. Liz Blumenfeld suggested dealing with how corporations are dealing with virtual worlds such as Second Life. There seemed to be significant energy around developing corporate-related issues in this context. Another interesting new project would be to examine mass market licenses and ask what standards should be placed on vendors regarding the terms in these adhesion contracts. Questionable clauses include audit clauses, confidentiality clauses and indemnity clauses requiring licensees to indemnify for licensor's negligence. The project ties in with work being done by the subcommittee on Electronic Contracting Practices. Chris Kunz said this topic related closely to a Loyola LA symposium on contracting out of mandatory rules in the UCC. She is writing a paper for that symposium on the ethics of invalid and iffy contract clauses.
Data Integrity: The Emerging Risk to SOX Reporting, E-Discovery and Information Protection
The Privacy Subcommittee coordinated a broad expert panel of speakers who taught us something of the potential threats to businesses who depend on data and how reliable it is. A few photographs were used to demonstrate some visible data integrity concerns -- The manipulation of photographs. We took a quick glance at some famous photo manipulations found on the Wired News site. Then Ted Claypool showed us a few examples of his own manipulations, including the photo at top which shows him as a member of a recent space shuttle team. (He's the Canadian team member on the top right by the way. Not.)
Our moderator was Ted Claypoole of Womble Carlyle's Charlotte office. Panelists were Mary Ann Davidson, Chief Security Officer of Oracle Corporation; Francoise Gilbert of IT Law Group in Palo Alto; Paul Doyle of ProofSpace, Inc.; and John Tomaszewski, the Vice President of Policy and Compliance at TRUSTe, the online privacy advocacy and certification organization.
Skipping past the fun stuff, we moved on to discussing how these issues may impact real data. As we have learned in past discussions about data security, data integrity is often more a matter of tracking what has happened than it is preventing that which probably cannot be prevented.
Of course, the panel first tried to define what it was talking about when it spoke of data integrity, something we all want but don't necessarily know what it is. The panel did agree that access/security is not the same thing as integrity, and that helping integrity does not mean the data is any more useful (or not) as Garbage In/Garbage Out still applies. Consensus seems to be that integrity is more of a question of consistency and the ability to link the data's state to a particular point in time.
The lawyers on the panel were more in line with the idea that showing that access had not happened would subsequently be evidence of integrity (the thought being that if nobody was in the room nobody could have changed it). The technologists felt that proof of access (or lack thereof) would not be the point, since we need to focus on somehow comparing the facts at one point to the facts on hand today that we purport are the same as the ones put in the room.
The number of questions from the audience spoke well to the interest in the topic.
Hot Topics in Cyberspace Law
The committee's always popular Hot Topics forum was held on Saturday morning (the first meeting day that finally broke without storm clouds overhead...).
The speakers (left to right in this picture) this Spring were David Satola from the World Bank, Marc Martin from K&L Gates, Holly Towle from K&L Gates, Juliet Moringiello from Widener University and Ben Beard from the University of Idaho.
Marc opened with a primer on the ongoing controversy known as Net Neutrality. He reminded us that this is both a new battle but also one that has a historical element going back over many years. The telecommunications industry has long had elements of 'how do we categorize' this form of communication, the reason often being that once we categorize the form of communication we have pre-determined the type of regulation. Marc ultimately left us with the idea that this is a battle with many goliaths on both sides of the concern, one that may be very politicized, and that it may take a while for any of us to have any answers about this.
David, who along with member and IP Subcommittee Chair Kristine Dorrain visited the recent Internet Governance Forum in Athens, Greece, presented a short discussion of what happened at that meeting and what may happen next. His presentation contained a summary of the presentation he moderated on legal issues, and you can see the slides in the linked document.
Holly reviewed the recent re-birth of claims by advocates for disabled persons that the Americans with Disabilities Act covered a retailer's web site as a 'place of accommodation' which needed to be set up with proper tools (such as text tags that are used by persons who need to use vocalizers because they cannot see). The case against Target Corporation, which alleges that Target's website did not allow blind people to use their text readers to navigate the site, has recently survived an early round of summary judgment. Holly concluded that the case was not so earth-shaking as first thought, since the plaintiffs' case only survived to the degree they could allege a strong connection between the defendant's physical stores and the site, and particularly how the ability to use the physical stores could be negatively impacted by an ability to use the website. The judge has clearly not allowed claims to go forward that allege only that the website is itself a 'place' for ADA purposes. While the outcome of this case is not certain, it does seem that the more narrow category of sites that have a close interaction with a physical place that is unquestionably covered by ADA should be paying attention to their sites' own usability.
Finally, Ben and Juliet discussed for those of us who are completely absorbed in the law the new phenomenon of virtual worlds and the legal issues arising from them. Ben noted that within the world itself we have a burgeoning economy, with the potential for intra-virtual-world disputes, as well as the odd twist of (in at least one instance) being able to move 'money' from the real-world to the virtual-world and back again. There are already people clamoring to note that these sorts of systems have the legal effect of turning the operators of these systems into banks (or at least one of their cousins in the financial services regulatory world). Juliet reviewed a recently file action by a Second Life member against the service operator. The member alleges that he more or less received property rights from Linden Labs, and that Linden has improperly 'converted' his property (he'd purchased 'land' in the Second Life world) when it chose to terminate his account.
We give our thanks to those who dragged themselves out at 8 AM on a Saturday, and especially to our great crew of speakers.
Kennedy Overlooks Jones Overlooking Nuara
UPDATE: Above entry fixed to reflect the correction to Fleming's faulty history, given that he thought it was Gerry Ford in the photograph and originally posted it that way. Thanks to Lenny for the assist -- You must have looked up at least once last night.
A Snowy Night at the Capital
The weather was beautiful here in D.C. -- The night before we all arrived. Pretty much from that point forward, it rained almost continuously. This writer ultimately ventured into Chinatown to see if he could find the usually ubiquitous $5 umbrella, but none were left. The rain lasted all day on Friday, with no letup.
Actually, that's not true. At about 8 o'clock in the evening, walking home from dinner, there was something familiar to those of us from the North falling from the sky.
The snow really was quite pretty, and hopefully this photo will let you see a bit of that.