Friday, April 07, 2006

Consumer Privacy and Information Security

The afternoon session today, "Consumer Privacy and Information Security: Does the Risk of Security Breaches Justify the Burden of Additional Safeguards," expressed the view that "who owns the data" is irrelevant. The salient issue is whether entities are using consumer information in ways that harm consumers (e.g., FTC case against Choicepoint). For a decade privacy issues have been about choice -- opt/in and opt/out -- but in terms of security there is movement away from innundating the public with notices that people do not read. Now if a party takes to store and use personal data it has a range of obligations, but knowing those is difficult, because of the sectoral approach in the United States. The FTC has used "fairness" power to go after companies whose errors included the storage of personal data that was not justified by any business or operating reason.

The IRS has proposed a rule that allows tax preparers to sell the information you give them provided the consumer consents. This has created an uproad during the past two weeks. Why should the tax preparers be allowed to use under any circumstances such information gather in that activity? Just because a firm prepares your taxes should not mean that by getting some kind of consent it should be allowed to sell your personal data to a Kleenex maker who wants to sell tissues to you. But consumers who put such freeze on their accounts often find they lack the key needed to lift the freeze within 15 minutes as needed to obtain, for example, of a car loan. Few consumers have taken advantage of this tool. There is federal legislation pending on this at this time.

Personal information, of course, covers a spectrum of increasingly sensitive information. The panel took the view that when you are developing safeguards for information you need to determine at the outset the sensitivity of the information. Social security numbers are among the most sensitive information collected by firms on US persons.

As a result, security and privacy cannot be cut in half or segregated, and their linkage is the underlying assumption of the Fair Credit Reporting Act. And yet, federal law protects personal information linked to a credit card than personal information linked to a debit card.

Another aspect of the kind of information issue is that a small amount of personal data gathered on many people can result in substantial harm to a large number of them, particularly when credit cards numbers are stolen and misused. One man in the last year took in $37 million by such identity theft -- and this occurred through a series of comparatively small charges $20 - $40 per transaction, repeated numerous times, that led to a small-fraud activity and large-fraud theft of funds by use of stolen identities. Such activity tends to escape the neural networks that the credit card companies created in order to detect abberant activity in card usage that would alert them to a misuse of the credit card.

Theft of debit card numbers is a growing problem that the banks do not like to disclose or discuss. Consumers who are victim of such activity often do not know that their funds are being stolen until the theives have vacumed out all of their funds.

One panelist argued that the best solution to Identity Theft is the tool known as a "security freeze," namely a freeze on a consumer's account for the creation of any new credit unless the consumer issues a temporary unfreeze order (requiring a string of security procedures).

(Unfortunately, the written materials which detail many of the state data breach reporting laws seem to have little, if any, relevance to this panel's discussion.)

CIPerati Newsletter on the Google Library Project

CIPerati Newsletter
Vince Polley reminded me that our CIPerati newsletter had recently had a discussion of Google Library Project -- James Nguyen's discussion is a good accompaniment to Prof. Sharon Sandeen's presentation on the same topic at the CLC Hot Topics. Check it out!

Open Source

Yesterday's session on Open Source in Mergers & Acquisitions took a seemingly highly technical topic and revealed it to be one that transactional counsel need to learn about, because their clients deals already involve hidden risks from the undisclosed presence of Open Source software. Panel was excellent, and endeavored to pack into two hours what it needed three hours to address. For those who have been nodding off when Open Source was mentioned as if it were some fringe geeky activity, the Panelists made clear that all software engineers now graduating are trained to use Open Source code and that almost all companies (particularly those with Web sites) are making substantial use of such code, which carries with it license compliance obligations that few senior executives are aware of, pointing up a new task for counsel to bridge a gap between management and the IT personnel.

Thursday, April 06, 2006

Connectivity, Storage and Computing Infrastructure

David Satola and Richard Keck, co-chairs of the Connectivity, Storage and Computing Infrastructure subcommittee, offer the following:
Following is a description of progress the CSCI sub-committee has made since WWM '06 and our future work plan.

At the WWM in Wilmington, the CSCI sub-committee was joined by Mike Jerbic of the Security Forum of Open Group to explore possibilities for collaboration between CSCI and the Security Forum on a white paper on network security. Since the WWM, we have been working on a draft outline of the paper, which has gone through 3 iterations. We have also had a number of conference calls with the Security Forum on the subject, with our next one scheduled for April 6.

Although the co-chairs are unable to attend the Spring Meeting in Tampa, the subcommittee has scheduled an all day working session on April 28 in Washington, DC that is contemporaneous with a meeting of the Open Group also scheduled in Washington earlier that week. We intend to progress the draft outline to a pre-beta draft of the white paper. We intend to discuss a more advanced draft of the white paper with the subcommittee in Honolulu. We will also be planning a program either for the Spring or annual meeting in '07.

Any subcommittee members who wish to have a copy of the draft outline, or who would like more information regarding the April 28 meeting in DC, should get in touch with Richard or David. The draft outline was prepared by Mike Jerbic, in consultation with Richard and David.

Another Wrinkle in Due Diligisms



The Committee's first Program of the 2006 Spring Meeting discussed Another Technology Wrinkle in M&A. Of course, the cyberspace law angle is the ongoing struggles that business lawyers have with analyzing free and open source software issues -- particularly when looking at a target company which may or may not have software that may or may not be at risk of 'infecting' or being put in a non-proprietary mode of ownership.

Of course, a great deal of the problem is just teaching folks how to recognize the problem and the legal risks -- our illustrious panelists took the experienced and the inexperienced down that road. For the rest of the story, be sure to connect to the materials posted by the Section for its members (as well as Vince Polley's observations posted here).

Why Open-Source software?

The 6 April 2006 program presentation on open source ("Another Technology Wrinkle in M&A Practice: Open Source and Free Software") was very interesting and timely. Almost every acquisition these days somehow involves software, and increasingly "open-source" software has inflitrated business operations. Steve Gold talked about the viral effect of much open-source code (when it's integrated with other proprietary code, it can taint the entire corpus with an "open-source" character, and make the larger program also subject to the original code license terms. Karen Copenhaver makes the important point that there's so much open-source code for a very simple reason: it's very well written.

The Free Software Foundation has useful resources: e.g., pointers to the various flavors of open-source licenses, together with their (current) language and commentary. Karen Covenhaver's program materials provide a good first-checklist for preparing (and executing) necessary open-source due-diligence activities. (Business Law Section members can find copies of all Spring Meeting programs at http://www.abanet.org/buslaw/home.shtml -- click on the "Tampa" icon under "Program Library" (top-left), and then click to page number "4").

E-Commerce Subcommittee

The E-Commerce Subcommittee held its meeting on Thursday afternoon, and previewed a great new tool for generating discussion. More on that below.

Elaine Ziff opened the meeting by thanking the Subcommittee for allowing her to be the Chair, as her term is soon to come to an end. Prof. Ben Beard will be taking over Elaine's chair this August.

Elaine took a few minutes to go over recent cases of interest, particularly focusing on the recent advertising keyword cases -- Pointing out that we seem to have a split between various courts that feel a keyword either is or is not a 'use' under trademark law. This promises to remain a hot topic.

Prof. Chris Kunz then opened up the new roundtabling method -- rather than picking a single topic to brownbag, she invited a handful of members to 'prime' discussions by raising some (sometimes provacative) points in the hope that other members in attendance would pick up on a point and run with it. Hank Judy spoke of his growing sense that the Cyberspace world was better explained through a property law analysis than the long-standing presumption that there is such a thing as a 'virtual' world. A cynical fellow sitting next to Hank opined to the opposite. Roland Trope, Candace Jones and Steve Middlebrook also joined in with their different topics. With that -- the discussion was off, and it was clear that this room could have kept going for yet another hour. Too bad -- We had to vacate at 2 PM.

Chris suggested that we had not seen the last of that format for roundtabling -- Look for it again in Hawaii!

Welcome to Tampa



The beautiful Marriott Westside in Tampa is hosting the meetings for our Committee. For those of you who aren't here, I won't tell you anything about the nice weather, such as found in the above picture (taken just moments ago).

Many of us have already begun our networking, greeting and talking -- The best part of any CLC gathering. The first official meetings begin at 1 PM EDT -- I will try to update you from time to time.

Saturday, April 01, 2006

Spring Meeting Program Materials are Posted

Members should be able to review the materials from the Cyberspace Committee's programs that will be presented in Tampa this coming week. Read them now, because there may be a quiz!

(Only Business Section members will be able to download the materials.)

Two Edged Swords, Part 743

One of Hank Judy's London partners shared this, and we both agreed that it needed to be shared further (for educational purposes only of course). (Click on the picture to enlarge.)