Monday, August 27, 2007

Innovation without Permission

This article today in the New York Times about Serena Software's effort to create a Web 2.0 platform for company employees to create their own mashups caught my eye.

The company claims that in the current environment of severe cut-backs, company IT departments probably won't be able to satisfy a company's application development needs. The frustrated employees will need to turn elsewhere.
“The generation that is sitting in their dorm rooms building Facebook applications is going into the workplace in the next few years,” Mr. Burton said. “The whole mindset is innovation without permission.”

How should in-house lawyers respond to this trend and these tools? Sounds like a project for CAIT (Committe on Corporate Aspects of IT). What do you think Don?

Sunday, August 12, 2007

Boing Boing claims Google Video robs customers of the videos they "own"

Boing Boing has an interesting post this morning about a Google user who received a letter telling him that the video's he paid for on Google's Video service were no longer going to be available to him. In exchange, they're giving him a credit on the Google Checkout service that will last for only 60 days. Kind of takes the "own" out of Download to "Own" doesn't it.

Why not kick this one around at the meeting.

Saturday, August 11, 2007

Committee Forum: Website Agreements -- I Didn't Agree to Those Terms, Did I?


The Committee continued its long-standing leadership in the electronic contracting arena. After our groundbreaking articles on Click-Through Agreements and Browse-Wrap Agreements, it was time to revisit some new topics that we've seen bouncing around in recent years.

After spending some time in reviewing the prior scholarship, Chris Kunz, Kathy Porter and Juliet Moringiello went over recent cases involving modifications and amendments to contracts done via electronic means. The cases are still in flux, but we see trends that tell us that principals of 'notice' and basic fairness still apply. The biggest sit-up-and-take-notice moment was discussions of a growing trend in a number of states that find that terms in a contract that allow amendment by unilateral postings on a web site may not only be unenforceable on their own, but might even go so far as to cause the original underlying contract itself to be voided!

Eran Kahana and John Ottaviani spoke on the recent discussions (and very thin case law) regarding 'bots' and their abilities to enter into contracts. While it is pretty clear that 'bots' are recognizable players in a contracting situation, we still wait to see how far the courts are willing to let those things play out.

Putting the Winter Back into Winter Working Meeting!

The Minnesota contingent of our committee is proud to invite all members to the 2008 Winter Working Meeting of the Committee to be held in the Twin Cities on January 25 and 26, 2008.

The event will be held at the Executive Conference Center at the Mall of America in Bloomington.


The world-famous mall is very near to the Minneapolis-St Paul Airport. We will have a block of rooms at a very reasonable price at the Embassy Suites Minneapolis Airport. Free shuttles from the airport and to the mall will be available. And, the MSP International Airport is a very easy airport to reach.

Along with the mall itself, those with families might consider the nearby Waterpark of America as a reason to bring some kids along.

We do promise to keep everybody warm!

More details to follow -- But, we want you all to hold the dates and plan to be with us for Winter Working Meeting 2008!

Friday, August 10, 2007

Program: Net Neutrality--The Great US and Global Debate--What it is About and Why Your Clients Should Care


Hank Judy and Tom Laudise, co-chairs of the Internet Law Subcommittee, gathered a first-class panel of speakers for the Net Neutrality program held on Friday morning at the 2007 Annual Meeting. The program was sponsored by the Business Section Technology Committee, and co-sponsored by the Cyberspace Committee and the Section of Science and Technology.

Greg Luib from the FTC first gave a helpful overview of the debate, which does require some technological background to follow and he gave it the yeoman's effort to teach a bunch of lawyers how routers work. My own common sense suggests that trying to summarize that description is unwise, particularly since one of Greg's points was that

Then, the debate began. Examples on one side -- Imagine you placed a phone call to reach your local pizza joint, and the phone company suggests that instead of your choice of pizza it might be nicer if you tried their chosen pizza provider, but if you really want to talk to your original joint please hold for three minutes (while others are already placing their orders for hot juicy pizzas from the preferred pizza provider, or PPP). The stronger statements were along the lines of "Don't break the Internet." The argument is that by ensuring that even the smallest of new content provider can get access to the Internet consumer, we can have a chance to allow a garage company of today to become an important player, be it by financial success to become the next Google, or be it by having an ability to reach people it couldn't otherwise reach through traditional media or means of communication.

On the other side of the debate, it was suggested that it is over-reacting to enter into regulation prior to knowing if there is a harm to be resolved, as well as questioning if consumers are being harmed in any of the discussed scenarios. "Balancing the risks is a complex empirical question." Another primary argument is that the ability to add new networks, and create further competition, is a better way to resolve the problem rather than to regulate those networks that already exist. The economic arguments often followed a line that regulating today may lead to results we cannot anticipate. Quoting panelist Michael Katz from an article he recently published, "Public policy should intervene where anti-competitive actions can be identified and the cure will not be worse than the disease. Policymakers must tread carefully, however, because it can be difficult, if not impossible, to determine in advance whether a particular practice promotes or harms competition."

Many speakers cited to a recent report issued through the Federal Trade Commission, a copy of which is found here. In the end, the executive summary of the FTC's report followed the 'caution' model: "In evaluating whether new proscriptions are necessary, we advise proceeding with caution before enacting broad, ex ante restrictions in an unsettled, dynamic environment."

The committee thanks participants on the panel -- Michael Katz, professor of economics at the University of California at Berkeley, David Sohn from the Center for Democracy and Technology, Gail Levine from Verizon, and Markham Erickson representing a group of content providers through his firm Holch & Erickson.

Thursday, August 02, 2007

Minneapolis Disaster

Many of you in our committee have been calling around looking for news about fellow members and friends who live here in Minneapolis in light of the bridge disaster.

I've already heard from a number of members based here in the Twin Cities. I've heard nothing to this moment that suggests any of our members have been directly impacted by this event. Give me a ring or send an e-mail if you've got any particular questions or concerns.

--
Fleming

Tuesday, July 31, 2007

Lessig to Move On

I missed this announcement that Lessig made last month. He's decided to shift his energy to battling "Corruption" in public policy. As many of you know, Lessig was the first recipient of the Cyberspace Law Excellence Award given out by the Cyberspace Law Committee. I'm personally sad to see him move on to other issues, but his reasons (as usual) are unassailable.

You can read his announcement, entitled "The Next Ten Years" is here.

Wednesday, June 20, 2007

Is Your Virus Checker Going to Get You Sanctioned?

BNA's e-commerce reporter tells the tale this week of a defendant in a federal tax case, who found himself severely sanctioned for spoliation of evidence.

His crime? The court found that after he'd received a subpoena for "e-mail, computer print-outs, and any file, data, or information on a computer disk or hard drive," he nonetheless installed an anti-virus program which also included a feature that routinely 'wiped' the hard-drive of the computer.

The court rejected the defendant's contention that his activity fell within the purview of the e-discovery safe harbor for "good faith routine operations," as provided at Fed. R. Civ. P. 37(f). Wiping a hard drive is not a routine computer maintenance task, the court said, and here it was carefully calculated to deprive the government evidence.


I believe that in most cases the 'wiping' function only serves to completely clean a hard-drive of remanants of a file that has been "deleted" (very much in quotes) by Windows. As most of us know, "deleting" under native Windows does little more than removing the file from the hard drive's file system's directory records. There is no actual deletion of the file until the operating system happens to re-use the space the file had been previously stored in. Since that might take months or years to completely finish, a true deletion of the file requires extraordinary efforts -- Usually with the use of a non-native program known as a wiper. The wiper's principle is to do a true erasure of the former file, done by looking for the space that the files were stored in and over-writing random 1's and 0's over the now 'un-used' spaces on the hard drive to make sure the trash has really been sent out to the trash.

(There are even more obnoxious nooks and crannies within a Windows NTFS hard-drive, including the so-called 'slack' -- If we had to get into that depth I'd bore you to tears. Suffice it to say that "deleting" and Windows are not terribly compatible concepts.)

Wiping actually has little to do with virus-protection, and more to do with the idea that many of us would like to think that when we 'delete' something it actually gets deleted. Since many virus checking programs have since become more generalized suites of security programs, virus checking being just one part, it is entirely likely that many of our computers (and our clients computers) have these wipers installed today, and in many cases the wipers are set to automatically go out on the hard drive and do their jobs.

Therein lies the problem this gentleman had. Once he'd received the subpoena, he had an obligation to maintain the integrity of all of the evidence on his hard drives, which would include the retention of the bits on the hard drive that might have been evidence of files he'd "deleted" prior to the date of the subpoena.

If we give him the benefit of the doubt for a moment, and presume that he never deleted a single (relevant) file (prior to the subpoena or after), what the "wiper" did is wipe out the evidence that he could have used to his advantage to show that he never attempted to delete anything. If the wipe had not been done, a forensics person could have examined the drive and opined that there was no evidence that relevant files had been deleted. By taking away the primary piece of evidence that the forensics person could have used to show the defendant's lack of bad acting, the defendant suffered the sanction of a finding that he had deleted files, that the files would have been evidence of his underlying tax fraud, and the worst flowed from there.

On the other hand, if he had been deleting files that contained incriminating evidence, the sanctions led to the right result. The problem, of course, is that we'll never know. Was this an innocent person who killed his own defense, or was this a person who tried to hide evidence of a fraud and who got his just desserts? The evidence to prove which is forever lost to the wiper.

(That said -- The court did cite evidence of some files that had not been lost to the wiper, indicating a likely pattern of behavior that would not be consistent with the seemingly benign content that remained after the wiper had done its job. In other words, there was at least a significant amount of smoke there, and the court probably felt it was enough to conclude that there must have been a fire there before the wiper had done its job.)

(In this case, the wiper was not actually part of a virus program or suite, but was a separate program called GhostSurf that is designed to delete trails of what one might have visited on the Internet, so I'm not sure why the defendant even tried the argument that this was all part of his 'virus' regime. Likely, it has to do with how much of the public subsumes all 'bad stuff' on computers with the word 'virus.' Again, we should explore what our clients actually mean when they use buzz words like that, since often they are not accurate descriptions.)

The court's harsh assessment of wipers may be a bit over-stated, since wiping a hard drive is very much a routine computer maintenance task for those who are tasked to ensure that data security rules like GLBA, HIPAA and the EU Data Directive (which include obligations to ensure proper destruction of data that the holder is no longer entitled to hold). But, just like everything else, once the subpoena has arrived the rules immediately change. (And, if we find ourselves between the competing obligations of the subpoena and the data privacy rules, we must approach the court and seek relief, and not engage in our own rationalization of how to resolve that dilemma.)

All of which is to say that next time your client receives such a subpoena, particularly one where desktop PC hard drives are in play, be sure to add yet another question to your checklist -- Have you any automated 'wiper' programs in place on any of those systems, and if so have you turned off any automated functions of those programs?

The case is United States v. Krause, Bankr. D. Kan., No. 05-5775, 6/4/07.

(Sidebar: The court made note of how it came to its own understanding of this issue. "The Trustee’s experts presented to the Court a virtual 'live' tour of the imaged hard drives from Krause’s computers. This vastly simplified the Court's understanding of the technical aspects of the spoliation issues. Many of the exhibits referenced in this Order are computer screen shots from that virtual tour." Of course, one might argue that this sort of presentation could be so over-simplified that it could be overly leading regarding the conclusions that should be drawn. While it doesn't appear that this happened to this judge, I would always be very concerned about what an adversary might do in the guise of "helping" a judge understand arcane matters of computer operating systems.)

Saturday, June 09, 2007

Gateway Having Trouble Proving Agreement to Arbitrate

An interesting story surfaced on Slashdot today. A California man has sued Gateway in small claims court alleging he got a lemon. Gateway is trying to have the case kicked to private arbitration, per the arbitration agreement they claim he agreed to.

The customer claims that because the monitor on his Gateway computer was malfunctioning so badly right out of the box, he couldn't read the arbitration agreement, let alone "click" the I Agree button. He claims that during tech support calls, a technician had him bypass the screen altogether. He also claims there was no written documentation with the PC that set forth the arbitration agreement.

The original judge agreed with the customer, but Gateway has asked the court to reconsider its ruling.

This case demonstrates one of the weaknesses of what I call the "gatekeeper theory" of proving assent.

Read the story from the Sacramento Bee.

Monday, May 14, 2007

MINNESOTA LAWYER Blog: Who's your legal tech geek?

MINNESOTA LAWYER Blog: Who's your legal tech geek? A local legal blog has posted a comment on how both businesses as well as law firms have not reached any kind of consensus on how to address the "intersection of law and technology."

The money quote for those of us who actually do understand that intersection: "Is it time for firms and corporations to develop positions that specialize full-time in legal technology? By assigning that beat on a catch-as-catch-can basis, it seems more likely that new developments in this area could be missed or misunderstood."

Maybe a few of us should visit that blog and post some thoughts, eh?