Friday, April 01, 2005

Wildhorse Saloon

LinedancersStart thinking now about Saturday's Committee dinner at the Wildhorse Saloon! If you have not already gotten a ticket, look up Jackie Scheib as soon as possible to see if you can get on the list for a mere $45. Bring your cowboy boots kids...

News of the World

(from Mike McGuire, reporting remotely from Minnesota, these stories in Steptoe & Johnson's E-Commerce Law Week, March 26, 2005)

Dear Feds, Send Money or the IT Infrastructure Could Get It

They say money makes the world go 'round . . . And now a group of experts are warning that without a serious cash infusion, the nation's information technology (IT) infrastructure world is at grave risk of being knocked off its axis by a terrorist or criminal attack. In a report entitled, "Cyber Security: A Crisis of Prioritization," the President’s Information Technology Advisory Committee (PITAC) -- an advisory body of IT leaders in academia and industry -- argues that the IT infrastructure of the US is "highly vulnerable to terrorist and criminal attacks." The report, made public on March 18, calls for a drastically increased federal role in supporting the development of new cybersecurity technologies. PITAC warns that short-term solutions to infrastructure vulnerability, like patching or retrofitting software, are inadequate and that only a massive deployment of money and manpower can successfully address the "large structural insecurities" of the nation's IT infrastructure. We've heard such dire warnings before, however, to little discernable effect. But perhaps the current spotlight on identity theft and data security breaches will lend some heft to the argument that the security of the nation's cyber infrastructure deserves at least as much attention as the data it carries.

Bank Regulators Beat Congress to the Punch on Security Breach Notifications

With all the Congressional activity on data security and identity theft these days, it's easy to forget that threats of new legislation are only half the story. In some industries, federal regulators are already setting guidelines for when companies should disclose security breaches. For example, the four federal financial industry regulators have issued "Interagency Guidance on Response Programs for Unauthorized Access to Customer Information and Customer Notice" to instruct financial institutions on when they will be expected to report security breaches of "sensitive customer information" -- whether that information is stored electronically or in paper form. The federal regulators will view a financial institution's failure to comply with the guidance as an unsafe and unsound information security practice.

Cyberspace CLE Program: Strategies for Modifying Electronic Agreements and Policies

Program: Strategies for Modifying Electronic Agreements and Policies Posted by Hello



(Please forgive the lousy photography...)

Kathy Porter, Chris Kunz, Jason Epstein (A new daddy as of about 36 hours ago! Twice Over!), Kristie Prinz, and Andrew Serwin presented the results of their research (ABA membership required) on how electronic contracts have been (purportedly) modified by various Web site providers.

Transferability of Electronic Assets

The Working Group on Transferability of Electronic Assets meeting on Friday morning. Posted by Hello


Mattias Hallendorff and Prof. Linda Rusch (both here from the Twin Cities, continuing the tradition of making sure that any law that actually makes a difference in Cyberspace actually comes out of Minnesota or passes through it...), are continuing the group's thoughts discussed in Palo Alto -- How can we actually create a working and functional system of Electronic Chattel Paper (ECP) that is contemplated under New Article 9 at Section 9-105?

Continuing a collaboration that initiated in Palo Alto with the technology experts at The Open Group, the WG has worked together with the technologists to try to work towards some recommendations. In particular, Mike Jerbic, Chair of The Open Group's Security Forum, has undertaken to work closely with the Working Group. His beat -- data security -- has particular relevance to ECP and its need for (relatively?) unassailable records.

Mike gave an early version of a slide presentation, where he began the effort to get the two worlds talking together. He noted that the tech world has largely concentrated on a concept they term as "command" -- which is fundamentally at odds with the UCC's requirement of "control." Command presumes that if we tell the system to do something, it's actually going to go ahead and do it. Control is not going to be happy with just assuming -- it needs to know that the machine did what it was ordered to do, a concept that is surprisingly foreign to current technology systems. Today, most technology systems rely more on redundancy and other similar concepts of just throwing the kitchen sink at everything to make sure the 'command' gets followed, which makes good sense where bandwidth and storage are cheap. But, for 'control' in the ECP world, the thought is that it needs to be done only once, and that one shot needs to be on target.

There was a lively debate over how to move the lawyers, the bankers, and the technologists to getting off the ball -- or if they should be moved. Prof. Ken Kettering raised a general theme of how the statute is unwilling to take a stand on HOW to get control. While he noted that there may be any number of technology answers that seemingly meet the requirements of the statute, the thousand bishops who might be willing to swear to its leading to control will not necessarily lead to an unassailable legal conclusion of control. He thinks we are being somewhat over-optimistic that any one of our systems will make the jump from good tech to good law.

Others still feel that the issue is not one of black and white, but trying to decide where the financial markets are going to be comfortable with the final system's degree of greyness. There are clear pressures to move this idea forward coming from the finance industries -- and this might push us to the point where we need to do it anyway. The 'pro' group's opinion could be summarized by John Gregory's thought that we need to compare this to the systems we've used in the past, and how we ultimately need to reach some degree of 'comfort' in whether that paper signature means something. The electronic world needs to figure out when the industry will get comfortable -- either for an agency to rate a deal, or for a law firm to offer an opinion.

Dina Moskowitz, Assistant General Counsel at Standard & Poor's (who will be lecturing -- guess where? -- Minnesota this coming month!), noted that law firms offering these opinions will be expected to have SOME degree of ability to do technical due dilligence. The opinion cannot rely on the raw assurances of the vendors. However, there is not going to be an expectation that law firms will become System Analysts -- the use of a good technology framework of analysis, combined with a level of technology understanding, should probably be an adequate basis for a meaningful opinion of counsel.

And, it is that framework that the Working Group is working to create.

BlogMaster?

I suppose I could accept the title BlogMaster? Or is Blogiapher Blographer better?

Life of a Prepaid Card presentation

The Committee Forum, this Spring on speaking on Prepaid Card issues. Posted by Hello


Too much great material for me to blog, but I can link you to the materials here. (ABA membership required)

CLCC Hot Topics

The Committee continues our new tradition of melding together a couple of then-current hot (or hotter...) topics for presentation to the crowds.

Brad Joslove spoke at the Committee Forum, detailing some of the recent case law in France as it relates to e-contracting, particularly in the consumer arena. Posted by Hello


E. Michael Power and Roland Trope spoke about their upcoming new book on data security issues, with a focus on director and officer liability, Sailing in Dangerous Waters: A Director's Guide to Data Governance. The book grew out of a project that originated and was supported by the Cyberspace Law Committee's Privacy and Security Subcommittee, chaired by Marc Pearl and Ray Gustini. There are plenty of good reasons as to why our clients continue to be subject to danger while they stick their heads in the sand. Posted by Hello

Working Group on Spam and Unsolicited Electronic Marketing

Elizabeth Bowles, chair of the Working Group on Spam and Unsolicited Electronic Marketing, leading the morning meeting of the WG on Friday morning. Posted by Hello


The group briefly discussed the coming program for Saturday morning (8 AM!!) concerning technology controls. The bulk of the hour was spent discussing future projects -- an initial consensus was to develop materials concerning Spyware and Phishing for a future program. There is pending federal legislation concerning Spyware in both houses, Senate Bill 687 and House of Rep Bill Bill 29. The thought is that this legislation, and general interest on the topic, as well as a smattering of pre-existing law that might apply, so the WG believes there will be plenty of material to work with.

Publication Opportunities

The cyberspace committee has a long history as a prolific source of material for the book publishing arm of the ABA. Suzy Bibko (ABA staff; head of the Section's publications group), told the committee this morning that the ABA already has published two works by committee members this calendar year; at least four other books are in the "approved for publication" pipeline, and a few more are under concept development.

If you, or your subcommittee, are working on a project or presentation that could yield a book, please see Vince or Candace Jones.

Blogging The CLCC Plenary Session

Vince, Candace and John (of Jones, Polley and Lunseth, LLP) opened the Spring Meeting plenary session for the Cyberspace Committee. We learned of the programs that are occurring here in Nashville, discussed the dinner coming up on Saturday night, and plugged the continuing need for publication materials.

Candace, Vince and John Posted by Hello


The Annual Meeting in Chicago, this coming August, will feature at least 3 main programs from CLCC and one hour-long forum. We have one of the main programs set already -- a very timely discussion of outsourcing concerns that will feature a star panel of lawyers including an attorney from India who will speak to the issues from his own perspective. There are other slots that are officially 'open' still -- but time is coming short on making final decisions, so those who are interested in getting a slot should get proposals to John Lunseth post haste.

Vince announced a couple of leadership issues. Mike McGuire has relinquished his role as the publication head, and the committee is soliciting volunteers for taking over the position (finishing the current term and presumably as well as picking up with the new 3 year cycle this coming August.) The committee thanks Mike for his hard work, so long as he continues to promise his efforts towards this blog going forward.

Finally, speaking of the new 3 year cycle coming up, Vince's term as The Boss is coming to a close as of August. The incoming chair of the Business Section appoints the Committee chair, and Vince was pleased to announce the appointment of Candace to take over the chair as of August. Applause. All of us should be sure to congratulate Candace on her new appointment -- and volunteer your respective behinds into assisting her with this huge task!

And with that -- We cut the Plenary short to allow enough time for the Committee Forum that followed.