Monday, June 30, 2008
New Guidelines To Deal With SPAM
This article discusses new guidelines released by The Messaging Anti-Abuse Working Group (MAAWG) intended to reduce spam. According to the article, the new guidelines (which do not appear to be available online) recommend that ISPs use separate servers for received and forwarded e-mails, and that they block port 25, through which spam travels. Even if the guidelines were successfully adopted, though, there's no indication that they would be successful. Still, this might be a start.
Tuesday, June 24, 2008
Texas AG Settles With EZCORP Over Identity Theft
The Texas Attorney General's Office announced a settlement yesterday with EZCORP over the company's failure to adequately safeguard customer's personal information. Apparently, the company had simply dumped 483 customer records laden with social security numbers and other highly sensitive information in the trash. The AG's office filed suit under Texas Business & Comm. Code Section 48-102, claiming the company had failed to implement "reasonable procedures" to safeguard customers personal information. The AG's website includes a picture of a credit application that was found in the trash.
Monday, June 16, 2008
Web Site Liability For Third Party Content
The question of when a website owner becomes liable for content posted by third parties has been around for some time. As far back as 1997, the Courts were already dealing with this issue (See Zeran v. AOL). In the past several months a number of new opinions on this issue have appeared. In May of this year, the 9th Circuit case Fair Housing Council v. Roommates.com tackled the issue of whether an online roommate matching website should be held liable for violation of the federal housing discrimination laws, since certain postings discriminated against particular groups. The Court held that the website could be held liable because it used drop-down menus to limit users' choice as to the content of their listing. As a result, the safeharbor provisions of the Communications Deceny Act (CDA) did not apply. On the other hand, in March of this year, the 7th Circuit in Chicago Lawyer's Committee v. Craigslist found Craigslist immune under the CDA for user posted listings which likewise discriminated against certain groups. The distinction between the two rulings appears to be that once a website operator takes an active involvement in the generation of content (as was the case in the Fair Housing decision), the safeharbor provisions of the CDA no longer apply.
Suing For Identity Theft Using RICO
Check out this National Law Journal article, "RICO And Data Thieves" (subscription). Historically, data theft has been largely prosecuted using the Computer Fraud and Abuse Act (CFAA). The author, Nick Akerman, suggests that filing suit under the Racketeer Influenced and Currupt Organizations (RICO) statute might have some advantages. As the author points out, RICO, unlike the CFAA, provides for treble damages and attorney fees.
Friday, June 13, 2008
The Ethics of Viewing Metadata
The controversy over whether an attorney is permitted to view the metadata of documents they receive from opposing counsel has been ongoing for some time. A number of jurisdictions--including Florida (Ethics Opinion 06-2) and New York (Ethics Opinion 749)--prohibit an attorney from making use of the metadata. The ABA (Ethics Opinion 06-442), on the other hand, permits it. Boris Reznikov recently published this excellent article on the current state of the legal ethics debate on metadata.
Do Data Breach Laws Reduce Identity Theft?
A new working paper entitled "Do Data Breach Laws Reduce Identity Theft?" (Carnegie Mellon University) analyzes the effect of data breach laws on the presence of identity theft. Although the authors acknowlege limitations to their study, they conclude that they found no statistically significant effect that data breach laws reduce identity theft. This is one more indication that an effective approach to tackling the problem of identity theft requires more than enacting legislation alone.
Friday, June 06, 2008
New York Internet Sales Tax Setting A Trend?
A highly controversial New York law recently went into effect. Under the new law (Chapter 57, Laws 2008, Part KK-1), New York becomes the first state to require internet sales companies to collect sales tax. Will this new law set a trend for other states? According to this National Law Journal article (subscription), legislators in Colorado, Florida, Illinois, Kansas and Minnesota are also considering passing similar laws. For a fuller explanation of the law, see this technical bulletin. A number of retailers--Amazon.com and Overstock.com--have already filed suit. See Overstock's Complaint here.
Tuesday, June 03, 2008
Vulnerabilities of Printers and Copiers
This AP article, quoting the European Network and Information Security Agency, warns that printers and copiers could be the weak link in a company's cyber defense program. For more on this, see this post by Bruce Schneier responding to a presentation by Brendan O'Connor.
Tuesday, May 27, 2008
Law Firm Suit For The Outsourcing of Litigation Support
The Annapolis, MD law firm of Newman McIntosh & Hennessey recently filed suit against a legal process outsourcer located in India. The case, filed in US District Court for DC, seeks a ruling from the court on the following question: “Given the pervasive nature of the signals intercept by the United StatesGovernment and UKUSA Allies, will the electronic transmission of data to foreign nationals residing overseas waive Fourth Amendment protections with respect to the data transmitted?” It appears that the law firm also submitted this question to the Ethics Committee of the DC Bar. See here for more info.
Wednesday, May 21, 2008
Maryland Identity Theft Statute Held Not To Apply To Fictitious Identities
Maryland's highest court recently published a surprising ruling: to be prosecuted under the Maryland identity theft statute (Criminal Law Article 8-301), one must have stolen the identity of an actual person. The statute does not apply, the court reasoned, in cases where an individual commits identity theft using a fictitious identity. The majority of the case centers on an analysis of the term "another" in the statute. After delving into the statute's legislative history, the court determined that "another" must refer to an actual person for the statute to apply.
New CAN-SPAM Rules
The FTC recently (May 12) recently published a new final rule implementing the CAN-SPAM Act (15 U.S.C. 7701-7713). For a brief overview of the new rules, see here. For the Press Release announcing the new rules, see here. For a more detailed overview of the rules, see this article from B2B.
Monday, May 12, 2008
New Net Neutrality Bill
Representative John Conyers (D-Mich) recently introduced (May 8th) a new bill (HR 5994) on net neutrality dubbed the ‘‘Internet Freedom and Nondiscrimination Act of 2008." This is the the most recent of a series of bills on this issue. Other notable bills dealing with net neutrality include HR 5353, S 215, HR 5417, and S.2917. For a list of net neutrality bills which have been introduced, see this Wikipedia article.
EDiscovery Vendor Suits
For those of you that missed the news a few months back, the law firm of Sullivan & Cromwell agreed to settle with ediscovery vendor Electronic Data Discovery. Sullivan & Cromwell had sued the vendor for alledly providing sub-par work. See this article for more info. The case is important because it could be the first of many similar suits.
Friday, May 02, 2008
Rambus Wins On Appeal
As this Law.com article reports, the ongoing litigation between Samsung and Rambus seems to have come to a close. The Rambus case had caught the attention of the legal community because of allegations that Rambus had shredded millions of documents prior to initiating a slew of litigation. The opinion published April 30 overturns previous decisions on the grounds that they did not have the requisit jurisdiction. For more on the history of the case, see the Rambus.org website.
Friday, April 25, 2008
The Future Of The Internet
The US Senate Committee on Commerce, Science and Transportation met recently to discuss a rather timely topic: "the future of the internet." You can see either a webcast of the hearing or read some of the prepared testimony (see FCC Chairman Kevin Martin's testimony, in particular).
Monday, April 14, 2008
New Suits Target Information On Store Receipts
This National Law Journal article discusses a recent increase in suits against companies who are alledgely failing to comply with the Fair Credit Reporting Act (FACTA). One of the provisions of FACTA prohibits a company from printing more than the last 5 digits of a credit card number on the customer's receipt. According to the article, more than 300 class actions have been filed against a number of companies, including Toys "R" Us Inc. and AMC Entertainment Holdings.
Life Sentence For Identity Theft?
According to this Baltimore Sun article, a Maryland woman indicted on identity theft charges could face life in prison. Belinda Marie Glock, 33, was indicted on counts of aggravated identity theft (18 USC 1028A(a)(1)) and fraud in connection with access devices (18 USC 1029(a)(2)).
Tuesday, April 08, 2008
2007 Internet Crime Report
The 2007 Internet Crime Report, published by the Internet Crime Complaint Center (a partnership among the FBI, the National White Collar Crime Center, and Bureau of Justice Assistance), includes some interesting findings. The report demonstrates (not suprisingly) that internet fraud is on the rise. Reported losses were $240 million compared to $200 million in 2006. Other notable findings include that the most common crime occurred through the use of email and that those affected were more likely to be males rather than females. For IC3's previous reports see here.
Wednesday, April 02, 2008
Country Cybercrime Reports
The Council of Europe has a great page on Cybercrime legislation for a number of countries. Each country report contains a listing of citations to cybercrime statutes for that country as well as english language excerpts of the actual statutes.
Friday, March 28, 2008
FTC Announces Settlement With TJX, Lexis
The FTC agreed to settle charges with discount retailer TJX and data broker Reed Elsevier. The FTC had sued each of the companies for failing to adequately protect the security of consumer data. Both of the FTC's suits were brought under the unfair trade practices theory under Section 5(a) of the Federal Trade Commission Act, 15 U.S.C § 45(a). The TJX Complaint is available here; the Reed Elsevier Complaint is available here.
Subscribe to:
Posts (Atom)