Monday, January 15, 2007
Business Blogging Article Published
Given this and the Kahana/Bowles article published in the same issue of BLT, the Cyberspace Law Committee continues its run as one of the most-published entities within the Section of Business Law (if not the whole ABA!).
Congratulations, and a big thanks, to all of our newly published authors.
And, if you are in the committee and want to be the next one to gather kudos about this, be sure to get in touch with our committee's Publications Chair Prof. Juliet Moringiello -- She has all of the details, including word on the new short-format articles (600 or so words) that the magazine is constantly looking to receive.
Friday, January 12, 2007
Arrivals and Departures
In deference to Roland, all times are given military style. Of course, all times here are local time in Little Rock (Central Standard Time).
ARRIVALS
Thursday
1200-1400
1400-1600
- Michael Fleming
- Michael McGuire (Yes, Believe it or not, I'm coming)
- Chris Kunz
- Eran Kahana
- Lisa Lifshitz
- John Ottaviani
- Bill Denny
- David Satola
- Steve Middlebrook
- Vince Polley
2000-2200
- Kristine Dorrain
- Candace Jones
- Mattias Hallendorff
- John Gregory
0600-0800
0800-1000
DEPARTURES
Saturday
1200-1400
1400-1600
- Lisa Lifshitz
- John Ottaviani
- David Satola
1600-1800
- Candace Jones
- Bill Denny
- Steve Middlebrook
1800-2000
- Chris Kunz
- Vince Polley
Sunday
0600-0800
- Kristine Dorrain
- Eran Kahana
1000-1200
1200-1500
- Michael Fleming
- John Gregory
Wednesday, January 10, 2007
Little Rock -- Transportation Concerns
The Doubletree Inn is about 7 miles from the airport. The hotel's web site suggests you can get a cab for $14, but the hotel also has a courtesy shuttle between the airport and the hotel (and presumably back again!). If interested in the shuttle bus, call the hotel at 501-372-4371.
If you do choose to rent a car, the hotel has free parking for registered guests.
(Click on the map for a larger version.)
If your plans were to do any serious touring outside of the downtown area, a rental car is definitely called for.
Thursday, January 04, 2007
Creative Commons Tool to Terminate Transfers of Copyright
Here's the introduction to the Blog posting:
Creative Commons is excited to launch a beta version of its “Returning Authors Rights: Termination of Transfer” tool. The tool has been included in ccLabs — CC’s platform for demoing new tech tools. It’s a beta demo so it doesn’t produce any useable results at this stage. We have launched it to get your feedback.
Briefly, the U.S. Copyright Act gives creators a mechanism by which they can reclaim rights that they sold or licensed away many years ago. Often artists sign away their rights at the start of their careers when they lack sophisticated negotiating experience, access to good legal advice or any knowledge of the true value of their work so they face an unequal bargaining situation. The “termination of transfer” provisions are intended to give artists a way to rebalance the bargain, giving them a “second bite of the apple.” By allowing artists to reclaim their rights, the U.S. Congress hoped that authors could renegotiate old deals or negotiate new deals on stronger footing (and hopefully with greater remuneration too!!). A longer explanation of the purpose of the “termination of transfer” provisions is set out in this FAQ.
And here's the link to a very well organized FAQ on the provision of the Copyright Act and the tool: http://labs.creativecommons.org/termination/faq.php
Wednesday, January 03, 2007
Sony Settles DRM Class Action in 40 States & DC
But, what about the 'rest of the story' for Sony?
On December 21, 2006, forty states and the District of Columbia settled with Sony BMG Music Entertainment ("Sony") regarding the anti-copying software which was installed allegedly without consumer knowledge or agreement via music compact discs distributed in 2005. On December 21, Sony entered into an Assurance of Voluntary Compliance or Discontinuance and agreed to pay $4.25 million to the states, and also to pay up to $175 per consumer who incurred damage while trying to uninstall the software.
Sony has also agreed that it will not distribute music CDs with DRM software without first going through a series of corporate reforms, and that it will replace all of the affected CDs at no charge. I note that Sony has gone to great lengths to publish a 3rd party's audit report, which states the auditor's opinion that Sony never took advantage of any access it might have had to individual's personal information by way of the DRM software. (Personal identity information might have been the lurking issue underneath all of the discussions about people's computers getting trashed by the software that was getting the major press.)
Maybe this will mean a great deal for those of us who were ultimately concerned about the sanctity of our own computers, as well as the use of electronic contracting techniques to 'sneak' unexpected terms by unsuspecting consumers. In the end, those are the issues that should have mattered through this whole discussion.
But, one sitting above the fray might suspect that the public outcry was really less about computer sanctity and the majesty of knowing-contract, and really just another public protest against the whole concept of DRM. In that regard, the victory here is short-lived and rather meaningless. As I stare right now at my own iPod, of which about 25% is filled with tunes I downloaded off of Apple's store, I realize that the battle over copy protection is being waged (and likely won) through less obnoxious means than secretive software that takes over my computer's root functions. (And, before you ask—The other 75% are copies from my own purchased CDs—What do you take me for?)
(Fleming's aside: If you still believe regular folks were really up in arms over the 'sanctity of the computer' instead of just protesting copy-protection, I'd suggest that all of us tech-savvy readers, of which I suspect most of you reading this might be, go back and look carefully at your Uncle Alfred's vintage 1999 Windows ME machine, which he's just happy with using every day for e-mail and the occasional Web surf, particularly since he found all of those nice smiley-faced icons for his mouse that that one Web site was offering for free one day last year... Same goes for your 15 year old niece's machine that you get called about every few months because her home page keeps changing to some oddball search engine without warning instead of her boyfriend's mySpace page. You guys with me now? OK.)
Information on the Sony settlement is available here. For the time being I have posted a copy of the Assurance document here. (Given very limited space, I won't leave that document up for more than a couple of weeks, so get your copy soon!).
(Irony time: One of the 10 states that had not settled with Sony as of December 21 was my own home state of Minnesota—The company that is processing the consumer claims for the settlement is located in (you guessed it) Minnesota. What does that say about us? Anyway, I can't find any resource to find out which other states might have opted in since December 21.)
(UPDATE: I should have noted that California and Texas also entered into their own settlement with Sony apart from this 40 state thing. I have not had time to peruse whether the $175 to consumer part will apply to Californians and Texans as well. New York is apparently part of the 40 state thing, even though it had an earlier settlement with Sony from December, 2005.)
(Another aside: Is there any doubt that keyword advertising has come of age? Sony was obligated to publicize this settlement as follows:
SONY BMG shall continue, for at least 12 months from the date of this Assurance, its program of using “keyword buys” ” and “bannering” on capable CDs to give consumers notice of the known forms of security vulnerabilities to their computers and of information consumers can obtain regarding the protection of their property. The “keyword buys” and “bannering” shall also disclose to consumers any known loss of functionality that can occur following use of XCP or Media Max CDs, including, but not limited to, the disabling of a CD-ROM drive. SONY BMG shall consider in good faith any suggestions the States may offer concerning possible adjustments to the specific terms of the keyword buys program and the language displayed to consumers in connection with the relevant links and landing pages. SONY BMG shall adopt procedures to monitor and ensure that such keyword buys result in consumers receiving a Clear and Conspicuous link on the first page of returned results. The return result shall provide a warning of the security vulnerabilities and direct consumers to additional information on XCP and MediaMax patching and removal. SONY BMG shall adopt procedures to monitor and ensure that banner ads function properly and provide consumers with a Clear and Conspicuous warning of known forms of security vulnerabilities and the website address to obtain additional information on XCP and MediaMax patching and removal.
So, that means you now get this when you search for SONY DRM on Google (click to see a bit bigger):
Surely this is the coming of age for keyword advertising, no?
Saturday, December 30, 2006
Last Chance for Hotel in Little Rock!
(Note that I say "officially" -- Our members have a long history of sweet-talking hotels into extending the official time windows. However, your mileage may vary, no warranties express or implied, use at your own risk, and we'll leave the lights on (in case you get stuck at the Motel 6).)
(NOTE FROM THE OTHER SIDE OF TIME: It's now January 3. Anybody who gets a favorable response from the hotel regarding 'late' reservations, could you please file a comment below for all of us to see? Thanks!)
If you have not yet registered for the meeting, but sure to head now to the meeting's home page.
Access to Source Code Denied
If I find a copy of the judge's actual opinion, I'll post it as a follow up.
Consider whether this type of thinking will prevail in a contract dispute where one party seeks access to "black box" components of a system that underlie a disputed online transaction.
Friday, December 22, 2006
Even Criminals Should be Careful about Authentication
Well, it seems you can't even solicit somebody to do a crime without running into potential authentication problems. On an e-mail exchange posted on the site http://attrition.org/, a couple of guys apparently answered a widely disseminated request from somebody who was allegedly soliciting for someone to engage in potentially criminal enterprises (i.e., entering without authority into the systems of the solicitor's alma mater to change his Grade Point Average). The guys who took up the call were spoofing the solicitor -- let's just say that hilarity ensued. (It almost reminded me of the elaborate e-mail chains the infamous Nigerian spammers would start once they might have started to reel in a victim...)
To put it mildly, when you get to the part where the spoofers ask the solicitor for pictures of the pigeons on his college campus to prove that he's not an FBI agent, you will probably be spitting your lunch all over the table. (Aim away from the computer screen when you do that. Trust me on that one.)
Notes --
- All people are innocent before the law until found guilty -- Even on this blog.
- There is a background story on this that involves U.S. politics -- Many of you might have already gotten wind of this story because of that aspect. This blog has no dog in that hunt... We're all about the cyberspace part.
- If you do go to the actual e-mail exchange posted at http://www.attrition.org/postal/z/033/0871.html, it contains a few choice words that most of us would not want to say out loud in front of our grandmothers. Press the link at your own risk. There's a less naughty-word laden report on the story here if you wish. And, props to Talking Point Memo for originally pointing out the story to me.
ANYWAY -- I hope each of you has a happy holiday season, and we look forward to seeing many of our readers at upcoming Cyberspace Law Committee events during 2007!
Thursday, December 14, 2006
Ken Adams on Web Searching for Contracts
My only other thing to add is that in my particular practice, involving a great deal of day-to-day contracting for technology licensing and purchasing, the times I've been able to find useful work on EDGAR is almost too small to count. The EDGAR system is potentially useful if one is interested in contracts that publicly-held companies might do that rise to a certain level of materiality--Software licenses rarely fall into that bucket for either the licensor or the licensee. I've no doubt that there are exceptions to that, but combined with the fact that I think any of us who read this blog are more than capable of running rings around what we might find on EDGAR, my suggestion is to stick to our own form libraries and use our own inherent skills rather than relying on some other person's randomly-selected work.
ASIDE: The other Cyberspace angle -- Ken Adams will be joining a panel of lawyers from this Committee at the ABA Business Section's Spring Meeting this March in Washington DC. The pre-meeting CLE programs put on for the Section's Young Lawyer Forum are fantastic, and that's not just because I will be speaking for one of them! We hope to see you there.
Tuesday, December 05, 2006
Remotely Eavesdropping on Cell Phone Microphones
read more | digg story
FOLLOWUP THOUGHTS (Jan 4, 2007):
I can’t get paranoid about this one. It seems to me that if the bug is obtained through the auspices of a proper (4th Amendment compliant, probable cause, yadda yadda yadda) court order, it’s not all that different than any other form of bug. We can be paranoid about the cops and courts as a general rule (and should be…), but the means they use to exercise their court orders is not all that much more scary.
I couldn’t tell (and CNET obviously can’t from what I read) if the bug is one that directly transmits a signal to a receiver operated by the police, or if it transmits something via the cell network. Legally it should not be all that much different if there's been a proper court order, although you’d have to rope in the cell provider if the latter.
Technically it is interesting in that the only radio that should be in your typical cell phone is the radio that transmits to the cell network. (Blue tooth, found in an increasing number of handsets is, of course, a wild card in all of this – Let’s set that one aside for the moment though.) If we’ve got the bug set up as a purely software bug that infects the phone and has it transmitting what’s passing through the microphone over some sort of ‘radio’ then it must be going over the cell-transmission radio – And, that seems difficult to conceive other than something that would require the cooperation of the cell phone provider, since operating that radio without interacting with the cell network would be something I cannot believe would be an ‘off-the-shelf’ capability of the phone handset. If that’s the case then I’m less concerned again about non-legal hackers because it seems hard to believe that the cell networks would volunteer to allow a hacker to use the network! (It also suggests that this technique shouldn’t work against somebody sitting on an airplane, unless the FBI is suggesting that the FAA’s prohibition on cell phone use is not really a safety concern for all on the plane...)
If, as the BBC article mentioned in the CNET article linked above suggests, the cell network radio is hacked, via some kind of Malware that is sent electronically to the victim’s phone, to stay in transmit mode even where the phone seems to be turned off (or the radio has been turned off, as I can supposedly do with my BlackBerry), and even if ‘intelligence agencies’ can find ways of intercepting that signal and decode it, that would still require the spy to have physical proximity to the victim at all times (presuming the cell network isn't being used), and I find that all rather implausible as a useful source of data unless the spy is investing a LOT of money in this victim (and, if they have that much money to invest, they’d find some other way than this exploit to get what they want). We’re not going to see hackers using this tactic for random crap they might want to listen to while your talking to your best friend at the local coffee shop. (And, the cell providers would quickly come up with anti-spyware tactics for their phones if the exploit got out beyond this nefarious ‘intelligence community,’ so any win by a hacker would be short-lived at best.)
Apart from the radio that is used for purposes of the cell network, the only other ‘radio’ in a typical cell phone (off the shelf) is the Bluetooth. That might be an interesting hack (and the subject of multiple discussions already). Still, it seems hard to believe that there would be a hack that might alter the phone to NOT turn off the Bluetooth (and/or the phone itself) when I thought I’d turned it off – There would be a hell of a lot of software necessary to do that, and it would be so handset specific that, again, the investment for any one particular victim would prevent the odd private citizen hacker from taking advantage of it – We don’t have the single-source problem for cell phone operating software that we have for PCs. (I do work for that industry, and actually work on licenses for cell phone operating system software, so I speak from knowledge in that regard.) Also, since the off-the-shelf Bluetooth system in my phone does not use the microphone on the phone handset itself, but rather the microphone in my earset, it would require an even more incredible hack to get the handset to use the Bluetooth transmitter for such a non-standard function as to transmit the sounds on the microphone to a surreptitious Bluetooth listener, and to do so while also allowing the spy to circumvent whatever encryption is on the Bluetooth transmitter, and probably to do so as well while still allowing the Bluetooth transmitter to be used simultaneously for its intended purposes since otherwise one would tip off the victim of the bug. Finally, Bluetooth is even more susceptible to the need to be proximate to the victim -- That radio will reliably transmit only a few hundred feed through clean space. Again, it might be plausible for the 'intelligence community' to invest in human resources to follow somebody around who is a high-value target, but that target would be gotten one way or the other if somebody was really interested, that target would probably know well enough to take out the battery of his phone, and the rest of us are perfectly safe from the pimple-faced script kiddie.
Finally, if all that’s involved in the above is a physical bug snuck into the cell phone itself, then those paranoid executives who remove their batteries are missing the boat. And, pimple-faced kids sitting in coffee shops are still at a loss when it comes to physical invasions of people’s personal property (or I’m not all that worried about the few who would try such a thing). Regardless, the addition of using a cell phone (as opposed to slipping a bug into the back of my jacket collar) to the mix doesn’t change anything where you’ve got somebody who’s willing to commit a criminal breach of my personal effects in order to plant his bug.
In other words – I’m kind of skeptical about all of this.
But, it all leads to finding stuff on the BBC article cited by CNET, such as this actual living example of a Cone of Silence. Where’s Maxwell Smart when you need him? (If you read the BBC article, it really seems poorly thought out – For example, they find ‘experts’ who claim that a physical bug wouldn’t work since the battery would wear out, but who’s to say the bug wouldn’t be set up to use the cell phone’s own battery (duh…). And, I did check the dateline of the article – It’s not April 1, but maybe it should have been.)