Wednesday, June 20, 2007

Is Your Virus Checker Going to Get You Sanctioned?

BNA's e-commerce reporter tells the tale this week of a defendant in a federal tax case, who found himself severely sanctioned for spoliation of evidence.

His crime? The court found that after he'd received a subpoena for "e-mail, computer print-outs, and any file, data, or information on a computer disk or hard drive," he nonetheless installed an anti-virus program which also included a feature that routinely 'wiped' the hard-drive of the computer.

The court rejected the defendant's contention that his activity fell within the purview of the e-discovery safe harbor for "good faith routine operations," as provided at Fed. R. Civ. P. 37(f). Wiping a hard drive is not a routine computer maintenance task, the court said, and here it was carefully calculated to deprive the government evidence.


I believe that in most cases the 'wiping' function only serves to completely clean a hard-drive of remanants of a file that has been "deleted" (very much in quotes) by Windows. As most of us know, "deleting" under native Windows does little more than removing the file from the hard drive's file system's directory records. There is no actual deletion of the file until the operating system happens to re-use the space the file had been previously stored in. Since that might take months or years to completely finish, a true deletion of the file requires extraordinary efforts -- Usually with the use of a non-native program known as a wiper. The wiper's principle is to do a true erasure of the former file, done by looking for the space that the files were stored in and over-writing random 1's and 0's over the now 'un-used' spaces on the hard drive to make sure the trash has really been sent out to the trash.

(There are even more obnoxious nooks and crannies within a Windows NTFS hard-drive, including the so-called 'slack' -- If we had to get into that depth I'd bore you to tears. Suffice it to say that "deleting" and Windows are not terribly compatible concepts.)

Wiping actually has little to do with virus-protection, and more to do with the idea that many of us would like to think that when we 'delete' something it actually gets deleted. Since many virus checking programs have since become more generalized suites of security programs, virus checking being just one part, it is entirely likely that many of our computers (and our clients computers) have these wipers installed today, and in many cases the wipers are set to automatically go out on the hard drive and do their jobs.

Therein lies the problem this gentleman had. Once he'd received the subpoena, he had an obligation to maintain the integrity of all of the evidence on his hard drives, which would include the retention of the bits on the hard drive that might have been evidence of files he'd "deleted" prior to the date of the subpoena.

If we give him the benefit of the doubt for a moment, and presume that he never deleted a single (relevant) file (prior to the subpoena or after), what the "wiper" did is wipe out the evidence that he could have used to his advantage to show that he never attempted to delete anything. If the wipe had not been done, a forensics person could have examined the drive and opined that there was no evidence that relevant files had been deleted. By taking away the primary piece of evidence that the forensics person could have used to show the defendant's lack of bad acting, the defendant suffered the sanction of a finding that he had deleted files, that the files would have been evidence of his underlying tax fraud, and the worst flowed from there.

On the other hand, if he had been deleting files that contained incriminating evidence, the sanctions led to the right result. The problem, of course, is that we'll never know. Was this an innocent person who killed his own defense, or was this a person who tried to hide evidence of a fraud and who got his just desserts? The evidence to prove which is forever lost to the wiper.

(That said -- The court did cite evidence of some files that had not been lost to the wiper, indicating a likely pattern of behavior that would not be consistent with the seemingly benign content that remained after the wiper had done its job. In other words, there was at least a significant amount of smoke there, and the court probably felt it was enough to conclude that there must have been a fire there before the wiper had done its job.)

(In this case, the wiper was not actually part of a virus program or suite, but was a separate program called GhostSurf that is designed to delete trails of what one might have visited on the Internet, so I'm not sure why the defendant even tried the argument that this was all part of his 'virus' regime. Likely, it has to do with how much of the public subsumes all 'bad stuff' on computers with the word 'virus.' Again, we should explore what our clients actually mean when they use buzz words like that, since often they are not accurate descriptions.)

The court's harsh assessment of wipers may be a bit over-stated, since wiping a hard drive is very much a routine computer maintenance task for those who are tasked to ensure that data security rules like GLBA, HIPAA and the EU Data Directive (which include obligations to ensure proper destruction of data that the holder is no longer entitled to hold). But, just like everything else, once the subpoena has arrived the rules immediately change. (And, if we find ourselves between the competing obligations of the subpoena and the data privacy rules, we must approach the court and seek relief, and not engage in our own rationalization of how to resolve that dilemma.)

All of which is to say that next time your client receives such a subpoena, particularly one where desktop PC hard drives are in play, be sure to add yet another question to your checklist -- Have you any automated 'wiper' programs in place on any of those systems, and if so have you turned off any automated functions of those programs?

The case is United States v. Krause, Bankr. D. Kan., No. 05-5775, 6/4/07.

(Sidebar: The court made note of how it came to its own understanding of this issue. "The Trustee’s experts presented to the Court a virtual 'live' tour of the imaged hard drives from Krause’s computers. This vastly simplified the Court's understanding of the technical aspects of the spoliation issues. Many of the exhibits referenced in this Order are computer screen shots from that virtual tour." Of course, one might argue that this sort of presentation could be so over-simplified that it could be overly leading regarding the conclusions that should be drawn. While it doesn't appear that this happened to this judge, I would always be very concerned about what an adversary might do in the guise of "helping" a judge understand arcane matters of computer operating systems.)

Saturday, June 09, 2007

Gateway Having Trouble Proving Agreement to Arbitrate

An interesting story surfaced on Slashdot today. A California man has sued Gateway in small claims court alleging he got a lemon. Gateway is trying to have the case kicked to private arbitration, per the arbitration agreement they claim he agreed to.

The customer claims that because the monitor on his Gateway computer was malfunctioning so badly right out of the box, he couldn't read the arbitration agreement, let alone "click" the I Agree button. He claims that during tech support calls, a technician had him bypass the screen altogether. He also claims there was no written documentation with the PC that set forth the arbitration agreement.

The original judge agreed with the customer, but Gateway has asked the court to reconsider its ruling.

This case demonstrates one of the weaknesses of what I call the "gatekeeper theory" of proving assent.

Read the story from the Sacramento Bee.

Monday, May 14, 2007

MINNESOTA LAWYER Blog: Who's your legal tech geek?

MINNESOTA LAWYER Blog: Who's your legal tech geek? A local legal blog has posted a comment on how both businesses as well as law firms have not reached any kind of consensus on how to address the "intersection of law and technology."

The money quote for those of us who actually do understand that intersection: "Is it time for firms and corporations to develop positions that specialize full-time in legal technology? By assigning that beat on a catch-as-catch-can basis, it seems more likely that new developments in this area could be missed or misunderstood."

Maybe a few of us should visit that blog and post some thoughts, eh?

Wednesday, May 09, 2007

Metadata Disclosure - Alabama Follows New York, Not ABA

The Alabama bar has issued a formal ethics opinion, in which it essentially adopts the New York position on a receiving attorney's use of inadvertently disclosed meta-data received from opposing counsel or party (i.e., Don't Do It).

This is in contrast to some of the recent trends. The ABA recently issued an opinion, Formal Opinion 06-442 (August 5, 2006)
Review and Use of Metadata. The abstract for that opinion states, "The Model Rules of Professional Conduct do not contain any specific prohibition against a lawyer’s reviewing and using embedded information in electronic documents, whether received from opposing counsel, an adverse party, or an agent of an adverse party." (Order a full copy of the opinion here.) This is not a specific endorsement of the use of an opponent's metadata, since it merely says the (new) rules are silent on this point. But, remember that this new opinion withdrew a former opinion that specifically condemned the activity. Remember as well that the new ABA opinion arose from a logical result of the ABA's issuance of its new Model Rules, which had removed the specific rule cited in the withdrawn opinion to justify the old position. (I'm not up to speed on whether Alabama or New York have implemented the new Model Rules.)

Regardless, Alabama and New York both hold that the lawyer who has inadvertently received metadata has a duty to avoid use of the inadvertently disclosed information. Under Alabama's rule, "Absent express authorization from a court, it is ethically impermissible for an attorney to mine metadata from an electronic document he or she inadvertently or improperly receives from another party."

They do note that the SENDING lawyer who sent the inadvertently disclosed metadata has independently violated the duty to maintain a client's confidences. On that point both the ABA and Alabama are in full agreement. So, again, if you have not yet installed good meta-data scrubbers on your own systems, do give consideration to that.

(And, of course, remember that meta-data that is embedded in a document that is itself evidence should not be scrubbed when transmitted to the other side in discovery, since the metadata is part of the evidence and to scrub the evidence would be tantamount to spoliation. This rule only applies to documents that are not themselves evidence.)

Zippo Zinged Without Reazon

I don't know why this keeps happening, but yet another court has misstated the holding of the famous Zippo sliding-scale of interactivity case (Zippo Manufacturing Co. v. Zippo Dot Com, Inc., 952 F Supp 1119 (USDC WDPA 1997). (It isn't entirely clear to me if the confusion arose from the litigants, so I'll reserve my right to re-aim my ire.)

Once again, just so we can get this straight: Zippo is a SPECIFIC JURISDICTION holding. Its author went out of his way to say that the sliding-scale test had no application to GENERAL JURISDICTION.

In Howard v. Missouri Bone and Joint Center, Inc. 2007 ILRWeb (P&F) 1675 [Ill App Ct, 2007], the court went out of its way to reject the Zippo test, saying it had no application to the matter at bar (and that web sites, interactive or not, should be viewed as nothing different than advertising, essentially stating that interactivity is irrelevant to the question of jurisdiction). However, all of the parties were in agreement that the web site in question could only apply for jurisdictional purposes as a matter of GENERAL JURISDICTION. The Zippo rule has no application to claims of general jurisdiction.

There was no need for the court to reject Zippo. It need merely have pointed out to counsel that their cite to Zippo in support of their argument for general jurisdiction was clearly misplaced. Having said that, it does make sense to this author, when doing a general jurisdiction analysis, to view web sites as nothing more than another form of advertising. But, there is plenty to commend the interactivity sliding-scale test when looking for specific jurisdiction -- Jurisdiction arising out of a litigated matter that occurred via that particular interactive web site. (I'm not saying it's necessarily perfect... But, it's certainly better, when used in the right circumstances, than this court seems to allow it.)

Another Judge Questions Admissability of Electronic Evidence

As further evidence that the judiciary is no longer willing to simply trust computers and everything they say to us, yet another court has undertaken to teach us what will be needed to have electronic evidence admitted. And, it looks to me like the skills that our cyberspace lawyers can bring to the table are well suited to that task.

In Lorraine v. Markel Am. Ins. Co. (USDC D. Md., No.06-1893, 5/4/07), Chief Magistrate Judge Paul W. Grimm laid out a near treatise-length standard on how he would analyze what he calls electronically stored information, or "ESI". And, he reserves his primary critiques not on the parties, or on the technologists, but rather on the lawyers seeking to have the ESI admitted.

Although he ended up discussing nearly every type of ESI that might come up as possible evidence in litigation, much of the opinion focused on e-mail. As noted in the opening paragraphs of the exposition:

[U]nauthenticated e-mails are a form of computer generated evidence that pose evidentiary issues that are highlighted by their electronic medium. Given the pervasiveness today of electronically prepared and stored records, as opposed to the manually prepared records of the past, counsel must be prepared to recognize and appropriately deal with the evidentiary issues associated with the admissibility of electronically generated and stored evidence.
...
Indeed, the inability to get evidence admitted because of a failure to authenticate it almost always is a self inflicted injury which can be avoided by thoughtful advance preparation.


Lawyers -- Just because it came from a computer does not excuse your forgetting the basic rules of evidence.

I could not possibly even begin to summarize the teachings of the opinion in a short blog entry. Go now and download your own copy here.

Lawyers, the days of simply printing out e-mails and hoping to get them into the court are soon to be behind us. And, cyberspace lawyers: Is this yet another opportunity for you to pose your own knowledge in these areas to the benefit of your litigation colleagues?

Friday, May 04, 2007

Dvorak's Stinging Indictment of the Profession

Computer industry columnist John C. Dvorak has just published his take on the DVD decryption key case -- And he zooms his focus right on the lawyers who wrote the demand letters.

Because of the lawyers and the nasty letters, now everyone online knows how important this number must be. Boom! Now users get to work on it.

Heck of a job, lawyers.

Investors should be aware of the overall dangers the legal profession present to companies, and how its current and generalized naiveté can sink fortunes overnight. While I know of no corporation that has been bankrupted by this sort of fiasco, it will happen eventually if lawyers doesn't catch up with the times.

Or perhaps some executives should think for themselves.

Who knew that your law degree could be a weapon of mass destruction?

So, what do you think? Is Dvorak right to suggest that if not for naive but fee-hungry lawyers wielding their C&Ds with impunity that the executives never would have gone down this path? Or, would this have reached a head regardless of whether the legal profession was there to assist it? What alternative paths might have the attorneys taken? How do we factor in the role of Congress, which created the rules that the lawyers operate under?

It's your profession under fire folks. The Comment link is functional.

Wednesday, May 02, 2007

ADA Claims Against Web Site Operator -- Certified Class is Narrowly Defined

One of our recent Hot Topics presentations at the Spring Business Law Section Meeting in D.C. concerned the question of whether, and to what extent, a Web site operator is subject to the rules of the Americans with Disabilities Act. A suit against Target Corporation alleged that its target.com Web site did not meet the ADA's requirements to make it accessible to blind persons, and sought class action status for all blind persons in the USA.

A few months back, the judge had already cut back on the breadth of the suit, saying that there was no ADA protection available where the claims were purely related to the Web site. She did allow that claims which could be construed as how the inaccessible Web site impeded a blind person from accessing a physical retail outlet might go forward.

In her most recent action on April 25, the judge noted that the class that would be certified for this suit would be "All legally blind individuals in the United States who have attempted to access Target.com and as a result have been denied access to the enjoyment of goods and services offered in Target stores."

She then followed up with the real kicker -- Apparently the judge was quite concerned that none of the original declarants (the named plaintiffs who represent the class) would be eligible to join the class under this new narrower definition.

Judge Patel allowed that the plaintiffs might still be able to provide declarations to meet the test, or a different named representative, so the suit goes forward with the condition that the plaintiffs' lawyers must come up with at least one named plaintiff who can actually be a part of the class. Nat'l Fed'n of the Blind v. Target Corp., N.D.Cal., No. C 06-01802, 4/25/07)

For the moment, the ADA-specific concerns for Web operators are still rather remote. How site operators might operate in practice is of course a different topic, but for now one better left for those trained in ethics, mores and cost-benefit ratios. (Which is not to say that lawyers should be avoiding those topics in forming their advice.)

Thursday, April 19, 2007

News Flash: The Internet Is Still Part of the Real World

Vince Polley's MIRLN newsletter alerts us to a story out of Florida, where the Florida state bar authorities are on the verge of implementing new rules regarding lawyer advertising that are specifically concerned with advertising on the Internet. That's not so interesting as was a quote from the Orlando Sentinel story about this development. "If the Supreme Court approves the proposed rule, it would make Florida the first state to address lawyer advertisements via the Internet." That's just plain wrong, for one simple reason. Every state authority that regulates lawyers already addresses lawyer advertising -- And internet advertising is, in the end, just advertising. The laws and rules that already exist regarding lawyer advertising should be applicable to the Internet just as they are to newspapers, TV and the back cover of the Yellow Pages. (My guess is that the quote is the newspaper reporter's own characterization rather than by the bar authorities -- So, please forgive my using that as an opportunity for a rant, and no ill will is wished upon those same authorities.)

More to the point -- Why do we always feel a need to create special rules for what happens on the Internet? Where there are distinct differences there might be good cause for special carveouts, but more often than not the "Internet rules" are simply a restatement of what the rules are already in the real world, with the implicit thought that the real world rules didn't apply to the Internet unless we say so. The rules already apply -- The Internet is still a function of the real world, it still applies to how human beings communicate with each other just as pamphleteering, newspapering and broadcasting applied before it. We can apply the same rules to the 'Net in most cases just as well as we can to the other media. Let's get past the fallacy that just because it's the Internet all the rules are off the table, so that we can start to talk about real differences rather than perceived ones.

Wednesday, April 18, 2007

Authentication? We Don't Need No Stinking Authentication!

Many lawyers in internet-related practices have become acquainted with some of the research tools out there for investigations. One of the more popular options is the Wayback Machine maintained by the Internet Archive organization. For the 3 persons left on the planet who haven't seen this tool in action yet, these folks have been crawling the Web for years and maintaining html copies of the pages they find -- More or less every site that hasn't made a request to be excluded from the crawl. (Whether the archive has a right to do that, and how all of this intersects with copyright, contract law and the like, is the subject of other threads of discussion.)

On a more mundane footing, when we as attorneys find these wonderful nuggets stored by the Wayback machine, and eagerly seek to get them admitted into a courtroom proceeding for the benefits of our clients, might we take a second to pause and consider the good old rules of evidence? That was the issue in [XXX[, where the plaintiff sought to admit pages printed from the Wayback Machine as part of his prima facie argument. The existence of the older Web pages was not the issue, but rather the admissibility of the information posted therein.

"Where postings from internet websites are not statements made by declarants testifying at trial and are offered to prove the truth of the matter asserted, such postings generally constitute hearsay under Fed. R. Evid. 801."

We all of course remember that there may be exceptions to the hearsay rule, but absent a showing of one of those exceptions hearsay gets kicked. In today's case, the court noted that the plaintiff

lacks the personal knowledge required to set forth with any certainty that the documents obtained via third-party websites are, in fact, what he proclaims them to be. This problem is even more acute in the case of documents procured through the Wayback Machine. Plaintiff states that the web pages archived within the Wayback Machine are based upon "data from third parties who compile the data by using software programs known as crawlers," who then "donate" such data to the Internet Archive, which "preserves and provides access to it." (Novak Decl. ¶4.) Based upon Novak's assertions, it is clear that the information posted on the Wayback Machine is only as valid as the third-party donating the page decides to make it—the authorized owners and managers of the archived websites play no role in ensuring that the material posted in the Wayback Machine accurately represents what was posted on their official websites at the relevant time. As Novak proffers neither testimony nor sworn statements attesting to the authenticity of the contested web page exhibits by any employee of the companies hosting the sites from which plaintiff printed the pages, such exhibits cannot be authenticated as required under the Rules of Evidence.

(emphasis added)

Without the necessary authentication, the evidence that Mr. Novak was seeking to admit was kicked.

Novak d/b/a Petswarehouse.com v. Tucows, Inc., 2007 WL 922306 (USDC EDNY No. 06-CV-1909 (JFB) (ARL), Mar. 26, 2007).

The lesson for us? Simply this -- Don't skip steps just because you got it from the Internet! All of the same rules continue to apply. And, in some cases, those rules may mean that your golden nugget will remain outside the courtroom unless and until you can find a way to authenticate it.

There was a second part of the same opinion which I found equally interesting on a totally different topic, but to maintain thread integrity (!) I shall hold that for another posting...