<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A0YAQX04eip7ImA9WhRUFko.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698</id><updated>2012-01-27T07:45:40.332-08:00</updated><category term="TJX" /><category term="chain of custody" /><category term="data security" /><category term="contract" /><category term="robot ethics" /><category term="technology legislation" /><category term="electronic records law" /><category term="cell phone text" /><category term="3D printing" /><category term="end user license agreement (EULA)" /><category term="privacy" /><category term="Revenue authority" /><category term="employee computers" /><category term="data investigation" /><category term="IP address" /><category term="web terms" /><category term="police" /><category term="automated law enforcement" /><category term="tax notice" /><category term="privacy disclaimer" /><category term="state government" /><category term="industrial espionage" /><category term="payment cards" /><category term="pornography" /><category term="PCI-DSS" /><category term="payment card law" /><category term="audio records" /><category term="electronic records" /><category term="computer forensics" /><category term="acceptable use policy" /><category term="agreement" /><category term="HF 1758" /><category term="credit card law" /><category term="record destruction" /><category term="management investigation" /><category term="video" /><category term="cyber investigation" /><category term="data breach notification" /><category term="lawsuit" /><category term="healthcare privacy" /><category term="electronic evidence" /><category term="e-signature" /><category term="phone call history" /><category term="fraud" /><category term="activist" /><category term="voicemail" /><category term="security incident" /><category term="legal compliance" /><category term="Hannaford" /><category term="privacy contract" /><category term="public key infrastructure" /><category term="mobile phone record" /><category term="cloud computing" /><category term="divorce evidence" /><category term="law enforcement" /><category term="hostile workplace" /><category term="SMS records" /><category term="data privacy" /><category term="instant message law" /><category term="digital photo" /><category term="whistleblower" /><category term="privacy terms of service" /><category term="AB 779" /><category term="hacker crime" /><category term="employment" /><category term="Facebook/Myspace legal record" /><category term="subpoena" /><category term="PKI" /><category term="electronic signature" /><category term="record retention policy" /><category term="e-mail filters" /><category term="litigation hold" /><category term="intellectual property" /><category term="misallocation of funds" /><category term="payment card data breach" /><category term="data authentication" /><category term="e-discovery" /><category term="data break-in" /><category term="robot law" /><category term="social networking law" /><category term="IT security" /><category term="enterprise information security" /><category term="digital signature" /><category term="private investigator law" /><title>Spies, Snoops, Snitches &amp; Privacy Law</title><subtitle type="html">Crime | Video | Camera | Record | Forensic | Whistleblower | Surveillance  &lt;img height="36" src="http://www.sans.org/images/badges/sans-security.jpg" width="155" align="bottom"&gt; &lt;p&gt;           See important notices and disclaimers on right side of full web version of this blog.&lt;/p&gt;</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://hack-igations.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>119</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/SpiesSnoopsSnitchesPrivacyLaw" /><feedburner:info uri="spiessnoopssnitchesprivacylaw" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;A0cCRngycSp7ImA9WhRUE0g.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-3369623533594837698</id><published>2012-01-23T11:07:00.001-08:00</published><updated>2012-01-23T14:51:07.699-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-23T14:51:07.699-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="cloud computing" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Megaupload Users | Get Legal Files Back?</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FdfL3fuwJc_4Xr_FtfP_3kaCOik/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FdfL3fuwJc_4Xr_FtfP_3kaCOik/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FdfL3fuwJc_4Xr_FtfP_3kaCOik/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FdfL3fuwJc_4Xr_FtfP_3kaCOik/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: left;"&gt;
&lt;/div&gt;
When the US Department of Justice and its allies &lt;a href="https://plus.google.com/113714308152841400614/posts/hg6kxYTsbrC" target="_blank" title="cloud computing"&gt;shut down&lt;/a&gt; Megaupload, they affected many kinds of users and many kinds of files. &amp;nbsp;Many of those files are legal. &amp;nbsp;Artists, writers and other content creators used Megaupload for storing, managing, distributing and publishing their original work.&lt;br /&gt;
&lt;br /&gt;
It is unknown precisely what law enforcement has done with the legal files stored in the Megaupload platform.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Privacy Protection Act&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
US law enforcement must be mindful of Privacy Protection Act ("PPA"), 42 U.S.C. § 2000aa:&lt;br /&gt;
&lt;br /&gt;
“[I]t shall be unlawful for a government officer or employee, in connection with the investigation or prosecution of a criminal offense, to search for or seize any work product materials possessed by a person reasonably believed to have a purpose to disseminate to the public a newspaper, book, broadcast, or other similar form of public communication...”&lt;br /&gt;
&lt;br /&gt;
Essentially, the purpose of the law is protect First Amendment free speech, free press materials.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Uh30_mbnjtU/Tx3kGBwm49I/AAAAAAAAAik/y0NGO_qRsy4/s1600/Dept+of+Justice.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-Uh30_mbnjtU/Tx3kGBwm49I/AAAAAAAAAik/y0NGO_qRsy4/s1600/Dept+of+Justice.JPG" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Law Enforcement&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
Courts &lt;a href="http://www.cybertelecom.org/privacy/ppa.htm" target="_blank"&gt;interpret&lt;/a&gt; PPA to allow police to seize a computer containing PPA-protected material, if there is good reason to believe they are commingled with illegal data. &lt;br /&gt;
&lt;br /&gt;
What is less clear is what police may or must do with PPA-related material after they have lawfully seized it. &amp;nbsp;In &lt;i&gt;Steve Jackson Games, Inc. v. Secret Service&lt;/i&gt;, a district court penalized the government for not returning &amp;nbsp;PPA-protected materials promptly after learning they were protected. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Asset Forfeiture Law&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Another relevant law is the &lt;a href="http://www.fear.org/publicdocs/Cassella_CAFRA2000.pdf" target="_blank"&gt;2000 Civil Asset Forfeiture Reform Act&lt;/a&gt;, which is intended to make it easier for innocent parties to recover their property when seized by the US government. &amp;nbsp;A public-interest expert in holding government to this law is the &lt;a href="http://www.ij.org/" target="_blank"&gt;Institute for Justice&lt;/a&gt;. &amp;nbsp;The Institute for Justice should consider taking up the case for innocent Megaupload users.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Related: &lt;a href="http://hack-igations.blogspot.com/2012/01/megaupload-takedown.html" target="_blank" title="Liquid Motors"&gt;Megaupload Raid: The Legitimate Users&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-3369623533594837698?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/tNUB89mT5WQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/3369623533594837698/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2012/01/kim-dotcom.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3369623533594837698?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3369623533594837698?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/tNUB89mT5WQ/kim-dotcom.html" title="Megaupload Users | Get Legal Files Back?" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Uh30_mbnjtU/Tx3kGBwm49I/AAAAAAAAAik/y0NGO_qRsy4/s72-c/Dept+of+Justice.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2012/01/kim-dotcom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkMCSXk9fip7ImA9WhRUE0g.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-608535897836416703</id><published>2012-01-22T09:51:00.000-08:00</published><updated>2012-01-23T13:34:28.766-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-23T13:34:28.766-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="cyber investigation" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud computing" /><category scheme="http://www.blogger.com/atom/ns#" term="police" /><title>Cloud Provider FBI Raid</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/H1Iyn7cNh-XIT_cwvEiLjB7ZmjU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H1Iyn7cNh-XIT_cwvEiLjB7ZmjU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/H1Iyn7cNh-XIT_cwvEiLjB7ZmjU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/H1Iyn7cNh-XIT_cwvEiLjB7ZmjU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
As it becomes more common for law enforcement to raid online facilities like Megaupload, it is incumbent&lt;br /&gt;
on law enforcement to respond to the needs of innocent users.&lt;br /&gt;
&lt;br /&gt;
A few days ago law enforcement, led by the US Dept of Justice, seized the domain for Megaupload.com,&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-xVQCp53prlw/TxxUmdDyy9I/AAAAAAAAAiU/-aGtl7-xTRI/s1600/Department+of+Justice.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="149" src="http://4.bp.blogspot.com/-xVQCp53prlw/TxxUmdDyy9I/AAAAAAAAAiU/-aGtl7-xTRI/s200/Department+of+Justice.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Domain Redirect&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
causing traffic to that site to be redirected to a government notice saying the domain had been seized under court order.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Economic Hardship to Bystanders&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Megaupload is a very popular service, with many millions of customers worldwide. &amp;nbsp;It is a cyberlocker&amp;nbsp;that allows users to store and share files. &amp;nbsp;Some of those files, perhaps many of them, may violate&amp;nbsp;copyright and other laws. &amp;nbsp;But a great many of those files are not illegal. &amp;nbsp;Users rely on those files for&amp;nbsp;many purposes, including running their law-abiding businesses and lawfully earning a living.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
By shutting down the site, law enforcement has caused substantial economic hardship.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/3gIsSJO4x7c/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/3gIsSJO4x7c?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;




&lt;param name="bgcolor" value="#FFFFFF" /&gt;




&lt;embed width="320" height="266"  src="http://www.youtube.com/v/3gIsSJO4x7c?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;Precedence: &amp;nbsp;Liquid Motors Case&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
US law has previously provided relief to an online service provider's users who are not under investigation. &lt;br /&gt;
&lt;br /&gt;
In Spring 2009, FBI seized servers run by Core IP Networks. &amp;nbsp;Some of the data processed on those servers belonged&amp;nbsp;to Liquid Motors, an innocent company that helps large auto dealerships manage their inventory and Internet marketing.&amp;nbsp;The raid had severely degraded Liquid Motor’s service to its law-abiding customers.&lt;br /&gt;
&lt;br /&gt;
Liquid Motors promptly petitioned a federal court for relief. &amp;nbsp;Although the court believed FBI’s raid was justified,&amp;nbsp;it acknowledged the economic impact on innocent parties. &amp;nbsp;Significantly, the &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/08/cloud-computing-police-raid.html" target="_blank" title="property rights"&gt;court compelled FBI&lt;/a&gt; to work &lt;i&gt;over&amp;nbsp;the weekend&lt;/i&gt; to provide Liquid Motors copies of its data and to return a server to Liquid Motors as soon as possible.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Over-Zealous Police Undermine Public Trust&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Yes, law enforcement needs to shut down cyber criminals and collect evidence so they can be prosecuted. &amp;nbsp;But law&amp;nbsp;enforcement undermines the community’s trust when it damages innocent bystanders.&lt;br /&gt;
&lt;br /&gt;
Moreover, principles of due process, human rights and property rights call for law enforcement to take proactive&amp;nbsp;measures to minimize collateral damage.&lt;br /&gt;
&lt;br /&gt;
Before executing a raid, law enforcement should evaluate whether its mission truly requires it to take services offline. &amp;nbsp;It should develop techniques for surgically getting what it needs, while avoiding disruption of anything else.&lt;br /&gt;
&lt;br /&gt;
What’s more, law enforcement should develop and execute a plan for returning disrupted services, or returning&amp;nbsp;confiscated data, as soon as possible.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Police Should Strive for Transparency&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Law enforcement further should strive for transparency and accountability. &amp;nbsp;It should engage intensively with the community,&amp;nbsp;disclosing as much as it can, as soon as it can. &amp;nbsp;In the case of Megaupload, the vacuum created by law enforcement’s relative&amp;nbsp;silence has lent credence of malicious phishing sites that appear to enable worried users to retrieve their files.&lt;br /&gt;
&lt;br /&gt;
The Department of Justice and its colleagues should be commended undertaking the hard work to responsibly police&amp;nbsp;the Internet. &amp;nbsp;And, I grant you that, for law enforcement to heed the needs of bystanders requires much time and&amp;nbsp;effort. But this is what democracy and rule of law expect of 21st Century law enforcement.&lt;br /&gt;
&lt;br /&gt;
--&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;
Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of data security and investigations at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
Related: &amp;nbsp;&lt;a href="http://hack-igations.blogspot.com/2012/01/kim-dotcom.html" target="_blank" title="seized assets"&gt;Theories for Relief to Blameless Megaupload Customers&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-608535897836416703?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/574_KUe0x5M" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/608535897836416703/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2012/01/megaupload-takedown.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/608535897836416703?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/608535897836416703?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/574_KUe0x5M/megaupload-takedown.html" title="Cloud Provider FBI Raid" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-xVQCp53prlw/TxxUmdDyy9I/AAAAAAAAAiU/-aGtl7-xTRI/s72-c/Department+of+Justice.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2012/01/megaupload-takedown.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YFRXw7cSp7ImA9WhRVEE4.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-4098170005666050962</id><published>2011-11-09T15:52:00.001-08:00</published><updated>2012-01-08T08:11:54.209-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-08T08:11:54.209-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="lawsuit" /><category scheme="http://www.blogger.com/atom/ns#" term="tax notice" /><title>Service of Process via Social Media</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ppYSyHBhN4OYYfI02aNDtTZsRrg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ppYSyHBhN4OYYfI02aNDtTZsRrg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ppYSyHBhN4OYYfI02aNDtTZsRrg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ppYSyHBhN4OYYfI02aNDtTZsRrg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Claims, Orders and Notices&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Service of Process is the formal means by which notices of legal action -- such as the initiation of a lawsuit or the issuance of a subpoena -- are given to people who are subject to the notices. &amp;nbsp; Service can relate to matters in court, i.e., judicial proceedings, or it can involve extrajudicial matters, such as notice of action by a government agency.&lt;br /&gt;
&lt;br /&gt;
Traditionally, formal service of legal notice is performed by hand. &lt;br /&gt;
&lt;br /&gt;
Sometimes when the person’s location is unknown, alternative service is permitted. &amp;nbsp;Alternative service can include publishing the notice in the newspaper. &amp;nbsp;In reality, publication of small notices in the newspaper is not very reliable as a way to put most people on notice of something.&lt;br /&gt;
&lt;br /&gt;
Some courts have allowed service via email. &amp;nbsp;A problem with email is that spammers commonly send official-looking emails trying to trick the recipient into clicking on something that will infect the recipient’s computer with malware.&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0byWwWpoCdo/TrsTAtvTZuI/AAAAAAAAAfU/_KnRezwLlgM/s1600/spam.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="8" src="http://1.bp.blogspot.com/-0byWwWpoCdo/TrsTAtvTZuI/AAAAAAAAAfU/_KnRezwLlgM/s320/spam.JPG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Malware&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
Therefore, recipients have reason to ignore emails from unknown senders.&lt;br /&gt;
&lt;br /&gt;
Social media like -- Flickr, Yelp, Twitter, Facebook, Youtube and many others -- open new potential avenues for alternative service. &amp;nbsp;The intended recipient might be reachable in many online places.&lt;br /&gt;
&lt;br /&gt;
In Federal US courts, the method used for service of process must be &lt;a href="http://www.deadiversion.usdoj.gov/fed_regs/actions/2011/fr0809_4.htm" target="_blank"&gt;reasonably calculated&lt;/a&gt; to notify the recipient of the matter. &lt;br /&gt;
&lt;br /&gt;
Here are factors that can help to establish that service over the Internet was indeed reasonably calculated to put the recipient on notice.&lt;br /&gt;
&lt;br /&gt;
1. &amp;nbsp;&lt;b&gt;Multiple Attempts&lt;/b&gt;. &amp;nbsp;Make multiple attempts through multiple channels, including Facebook Wall and chat, relies to Twitter tweets, comments under photos and comments under blog posts or status updates. &amp;nbsp;Social media are opening so many avenues for reaching a person that liberal use of them increases the likelihood of successful delivery.&lt;br /&gt;
&lt;br /&gt;
2. &amp;nbsp;&lt;b&gt;Video Response&lt;/b&gt;. &amp;nbsp;If the recipient has posted videos on Youtube, send the notice as “Video Response” to one of the videos. &amp;nbsp;Put the text of the notice directly into the video. &amp;nbsp;This approach holds two advantages:&lt;br /&gt;
&lt;br /&gt;
(a) It normally causes an email to go from Youtube to the recipient seeking approval of video as a response that would appear under the recipient’s video. &amp;nbsp;It does not seem like a spam ploy to send malware.&lt;br /&gt;
&lt;br /&gt;
(b) Video Responses are relatively rare on Youtube, so the Video Response is more likely to attract the curiosity and interest of the recipient.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-37bcd8ee53439bcd" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;
&lt;param name="bgcolor" value="#FFFFFF"&gt;
&lt;param name="allowfullscreen" value="true"&gt;
&lt;param name="flashvars" value="flvurl=http://v18.nonxt2.googlevideo.com/videoplayback?id%3D37bcd8ee53439bcd%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329826625%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D127B16BBCF7A3A961AD799D48602AEEF50B46DF2.8192D85DA0C80B2A43305F7C833534A6551A79EA%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D37bcd8ee53439bcd%26offsetms%3D5000%26itag%3Dw160%26sigh%3Dr2wfBOeMx70HASpYHvWA07WPmDM&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;
&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"
width="320" height="266" bgcolor="#FFFFFF"
flashvars="flvurl=http://v18.nonxt2.googlevideo.com/videoplayback?id%3D37bcd8ee53439bcd%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329826625%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D127B16BBCF7A3A961AD799D48602AEEF50B46DF2.8192D85DA0C80B2A43305F7C833534A6551A79EA%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D37bcd8ee53439bcd%26offsetms%3D5000%26itag%3Dw160%26sigh%3Dr2wfBOeMx70HASpYHvWA07WPmDM&amp;autoplay=0&amp;ps=blogger"
allowFullScreen="true" /&gt;&lt;/object&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
3. &amp;nbsp;&lt;b&gt;Use Verified Identity&lt;/b&gt;. &amp;nbsp;When posting notices, use a verified identity, such as is available through Google Plus. (As the photo shows, Google shows my name has been verified when the viewer places the cursor on the check next to my name.)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-qWgkXsVrZmk/TrsVRrOOTxI/AAAAAAAAAfk/wnt-Y5Bm6Ug/s1600/verified.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="73" src="http://2.bp.blogspot.com/-qWgkXsVrZmk/TrsVRrOOTxI/AAAAAAAAAfk/wnt-Y5Bm6Ug/s320/verified.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Authenticity&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
4. &lt;b&gt;Use simple text&lt;/b&gt;. &amp;nbsp;Put as much information as possible in simple text rather than a link. &amp;nbsp;If the recipient has to click on a link, he may have reason to believe the notice is a hoax trying to trick him into clicking on malware. &amp;nbsp;If necessary, break the full text of the message into multiple postings. &amp;nbsp;Start the notice with a plain statement like, “Benjamin Wright: You have been sued in connection with property located in Carson County, Texas.”&lt;br /&gt;
&lt;br /&gt;
5. &amp;nbsp;&lt;b&gt;Name in subject line&lt;/b&gt;. &amp;nbsp;If using email, put the recipient’s name in the &amp;nbsp;subject line. &amp;nbsp;Bulk spammers don’t do that.&lt;br /&gt;
&lt;br /&gt;
6. &amp;nbsp;&lt;b&gt;Expose the notice to search engines&lt;/b&gt;. &amp;nbsp;Publish the notice on a web page so it comes up in a general search of the person’s name. &amp;nbsp;People commonly search their own name.&lt;br /&gt;
&lt;br /&gt;
7. &amp;nbsp;&lt;b&gt;Toll Free Number&lt;/b&gt;. &amp;nbsp;Give the recipient a toll-free number to get more documents or information. &amp;nbsp;A toll-free number conveys seriousness (less likely a hoax) because the person owning the number pays the toll on calls coming into the number.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;8. &amp;nbsp;Monitor Subsequent Activity&lt;/b&gt;. &amp;nbsp;After service/notice is attempted through a particular social media account, public activity in the account can be monitored. &amp;nbsp;Commonly people have entwined their lives so tightly with their accounts that they cannot stop using them. &amp;nbsp;Subsequent activity is evidence that the account is being used. Specific activity (photos, videos, comments, &lt;a href="http://hack-igations.blogspot.com/2011/08/geolocation-data-for-tax-collection.html" target="_blank"&gt;geolocation data&lt;/a&gt;) can be so unique to the account holder that it can be established that the account was not being used by an impostor and that it was likely the account holder saw the service/notice.&lt;br /&gt;
&lt;br /&gt;
The expansion and diversity of social media open many new opportunities to be creative.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
P.S. In a couple of &lt;a href="http://computerfraud.us/articles/how-do-you-sue-an-unknown-hacker-who-steals-data-through-the-company-web-site" target="_blank"&gt;cases&lt;/a&gt; involving unknown hackers, courts have allowed discovery to start before an attempt to serve process. &amp;nbsp;The discovery might include subpoenas to ISPs to discover the identity and location of the hackers.&lt;br /&gt;
&lt;br /&gt;
See: ideas on how to &lt;a href="https://plus.google.com/113714308152841400614/posts/amp9cLevta6" target="_blank"&gt;document details of a person’s web presence&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-4098170005666050962?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/NgzM9d4Suak" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/4098170005666050962/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/11/reasonably-calculated.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4098170005666050962?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4098170005666050962?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/NgzM9d4Suak/reasonably-calculated.html" title="Service of Process via Social Media" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-0byWwWpoCdo/TrsTAtvTZuI/AAAAAAAAAfU/_KnRezwLlgM/s72-c/spam.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/11/reasonably-calculated.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIDQ3c7fSp7ImA9WhRSE00.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-6219950097381827897</id><published>2011-11-05T13:35:00.000-07:00</published><updated>2011-11-14T14:09:32.905-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-14T14:09:32.905-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="electronic records law" /><category scheme="http://www.blogger.com/atom/ns#" term="Revenue authority" /><category scheme="http://www.blogger.com/atom/ns#" term="agreement" /><title>How to Record Nonstandard Online Financial Trades</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/d4IvUF-0sXZqOijFPcDYcd1wE7U/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/d4IvUF-0sXZqOijFPcDYcd1wE7U/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/d4IvUF-0sXZqOijFPcDYcd1wE7U/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/d4IvUF-0sXZqOijFPcDYcd1wE7U/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Audit Evidence &amp;amp; Documentation&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Making records of non-standard financial transactions is not easy.&lt;br /&gt;
&lt;br /&gt;
Electronic trading platforms for nonstandard transactions are numerous and diverse. &amp;nbsp;They change constantly. &amp;nbsp;They facilitate trades and auctions in myriad nonstandard financial assets, such as OTC derivatives, bankruptcy claims, privately-held equity, esoteric asset-based securities and so on. &amp;nbsp;An example of such a platform is &lt;a href="http://www.secondmarket.com/" target="_blank"&gt;SecondMarket&lt;/a&gt;, which specializes in bringing together buyers and sellers of illiquid assets.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Multiple Media and Services&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-G12c1pE55EI/TrWky4xmEQI/AAAAAAAAAfM/hDu91j575TM/s1600/commodities+trading.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;" target="_blank"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-G12c1pE55EI/TrWky4xmEQI/AAAAAAAAAfM/hDu91j575TM/s200/commodities+trading.JPG" width="198" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Capital Markets&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
The platforms provide information in multiple media, including audio, video, formatted documents, instant messages, structured data and augmented reality. &amp;nbsp;These platforms can present a professional trader a welter of financial disclosures, trade confirmations, legal representations, and contract terms and conditions.&lt;br /&gt;
&lt;br /&gt;
The relevant contract data for a trade may not arrive all through a single platform. &amp;nbsp;A trade executed on one platform may be supported by emails or text messages sent through different services.&lt;br /&gt;
&lt;br /&gt;
Are All Records Linked Together So Someone Can Understand Them Five Years From Now?&lt;br /&gt;
&lt;br /&gt;
After a trade has been executed, how can the terms be documented? &amp;nbsp;If there were a &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/09/cds-litigation.html" target="_blank" title="structured finance"&gt;dispute&lt;/a&gt; about the trade, will reliable and complete records exist? &lt;br /&gt;
&lt;br /&gt;
Lawyers ask these questions, thinking about legal &lt;a href="http://legal-beagle.typepad.com/security/2011/06/e-banking.html" target="_blank" title="accountant"&gt;evidence&lt;/a&gt;. &amp;nbsp;Auditors ask these questions, thinking about proof to support financial claims and statements. &amp;nbsp; Tax advisors ask these questions as they analyze tax obligations and prepare for audit.&lt;br /&gt;
&lt;br /&gt;
Although a platform provider like SecondaryMarket may keep some records, the provider cannot be relied upon as the long-term, comprehensive, record repository for investors. &amp;nbsp;The provider might go out of business, and it might not keep all of the records the investor needs for the number of years the investor needs them.&lt;br /&gt;
&lt;br /&gt;
Further, the provider may not keep records to show the precise organization of information, or the order in which communications were exchanged, or the interconnection of messages communicated via different media and services – all of which could be relevant to determining the legal import of a transaction.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Narrated Screencast Video&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Here is a method for recording the data a professional sees at a certain point in time, such as half-an-hour after a trade is executed.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/QScvCb4tFzo/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/QScvCb4tFzo?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;






&lt;param name="bgcolor" value="#FFFFFF" /&gt;






&lt;embed width="320" height="266"  src="http://www.youtube.com/v/QScvCb4tFzo?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
It is a screencast video that memorializes what the professional claims he sees, with realtime narration from him explaining how he moves from one item of information to the next. &lt;br /&gt;
&lt;br /&gt;
The screencast is made with screencast-o-matic, a free, Java-based, open-source tool for recording what you see on your screen,&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Interactivity and Inter-Connections&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The resulting video is a unified package of evidence that captures the interaction and interconnectedness of the web better than a bunch of sceenshots. &amp;nbsp;The video illustrates what happens as each link is clicked.&lt;br /&gt;
&lt;br /&gt;
The final, comprehensive record of the transaction might include this video, together with copies of emails, the disclosure documents that were exchanged and so on. &amp;nbsp;The video is the twine that binds all of these records together into a unit that is comprehensible to someone who may review the transaction in the future.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Cloud Time Stamp&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Fixing the time of evidence like this video adds to its credibility. &amp;nbsp;The auditor states the time directly into the video.&lt;br /&gt;
&lt;br /&gt;
To corroborate the vocalized date, the auditor could store the video, soon after he creates it, in a file-management resource that applies a timestamp to it and to any modifications of it.&lt;br /&gt;
&lt;br /&gt;
Thus, if the video, dated by the auditor’s voice as November 5, were uploaded on November 5, but then replaced November 10, there would be a mismatch of dates, suggesting that the video in the resource is not the one originally created by the auditor.&lt;br /&gt;
&lt;br /&gt;
What enterprise-class resources might reliably attach a timestamp to a video? &amp;nbsp;Autonomy is an example of &amp;nbsp;a third-party archive service providing such a timestamp, and Microsoft Sharepoint is an example of in-house resource. &amp;nbsp;Sharepoint maintains rich, detailed metadata (such as time of file upload and time of file modification) that is hard for anyone, even IT staff, to manipulate inconspicuously.*&lt;br /&gt;
&lt;br /&gt;
–&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Attorney Wright teaches the law of data &lt;a href="http://www.sans.org/security-training/law-data-security-investigations-122-mid" target="_blank" title="hackers and botnets"&gt;security and investigations&lt;/a&gt; at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
* Manipulation of all relevant metadata (including metadata in backups) in a complex enterprise resource like Sharepoint is extremely challenging, if not utterly impractical. &amp;nbsp;Thus, the timestamp in that resource corroborates the time stated in the video. &amp;nbsp;A tool like &lt;a href="http://www.avepoint.com/sharepoint-auditing-docave/" target="_blank"&gt;DocAve Auditor&lt;/a&gt; accesses and analyzes the trove of metadata in Sharepoint.&lt;br /&gt;
&lt;br /&gt;
Related Articles: &lt;br /&gt;
&lt;br /&gt;
* &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/04/credible.html" target="_blank" title="Internet crime"&gt;Online Investigation&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
* &lt;a href="http://hack-igations.blogspot.com/2011/10/how-to-record-debt-collector-web-page.html" target="_blank" title="web lawsuit"&gt;Recording Cyber Adversary&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-6219950097381827897?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/O57YwUoOBfA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/6219950097381827897/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/11/electronic-contracts.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6219950097381827897?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6219950097381827897?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/O57YwUoOBfA/electronic-contracts.html" title="How to Record Nonstandard Online Financial Trades" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-G12c1pE55EI/TrWky4xmEQI/AAAAAAAAAfM/hDu91j575TM/s72-c/commodities+trading.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/11/electronic-contracts.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEEQnY7eip7ImA9WhRXFEU.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-8705925415491657590</id><published>2011-10-24T13:20:00.000-07:00</published><updated>2011-12-21T07:50:03.802-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-21T07:50:03.802-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="electronic records law" /><category scheme="http://www.blogger.com/atom/ns#" term="credit card law" /><title>How to Record Debt Collector Web Page</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NhapxUou8Kce8TEBLsfh3gC8dM0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NhapxUou8Kce8TEBLsfh3gC8dM0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NhapxUou8Kce8TEBLsfh3gC8dM0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NhapxUou8Kce8TEBLsfh3gC8dM0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Coping with Bill Collection&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Suppose you want to record your online interaction with an adversary . . . such as a collection agency. &amp;nbsp;Your goal is to capture reliable legal evidence of what you encountered when trying to access or provide information to the adversary’s web site or online app. &lt;br /&gt;
&lt;br /&gt;
In effect, the video you create will record your eyewitness testimony of what you see online at a particular point in time.&lt;br /&gt;
&lt;br /&gt;
You might want to do this, for example, to show that you tried to access a debt collector’s web site, but it was not available, did not work right or gave you misinformation.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Ten Steps&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
For making your record, here are 10 steps:&lt;br /&gt;
&lt;br /&gt;
1. &amp;nbsp;Write out a step-by-step script of what you going to do and say as you make the recording.&lt;br /&gt;
&lt;br /&gt;
2. &amp;nbsp;Launch your webcam so you can see yourself live on your monitor.&lt;br /&gt;
&lt;br /&gt;
3. &amp;nbsp;Launch your browser or app so you can see that on your monitor at the same time you see the webcam image.&lt;br /&gt;
&lt;br /&gt;
4. &amp;nbsp;Start a screencast recording program, such as &lt;a href="http://www.screencast-o-matic.com/"&gt;screencast-o-matic&lt;/a&gt; (free, open-source service), to record what appears on your monitor.&lt;br /&gt;
&lt;br /&gt;
5. &amp;nbsp;As the recording starts, identify yourself and explain the reason for your recording. &amp;nbsp;Explain the technical methods you are using to make the recording. &amp;nbsp;Don’t be afraid to read directly from your script. &amp;nbsp;Your purpose is to record legal evidence, not to make a television news cast.&lt;br /&gt;
&lt;br /&gt;
6. &amp;nbsp;Use your browser or app and carefully explain each step you take.&lt;br /&gt;
&lt;br /&gt;
7. &amp;nbsp;Describe what you see and what it means.&lt;br /&gt;
&lt;br /&gt;
8. &amp;nbsp;Conclude the recording by signing and dating it with your voice. &amp;nbsp;Say words like, “I Ben Wright hereby sign and affirm this screencast as an accurate reflection of my work.”&lt;br /&gt;
&lt;br /&gt;
9. &amp;nbsp;Review the video to ensure it is accurate.&lt;br /&gt;
&lt;br /&gt;
10. &amp;nbsp;Soon after you create the video, store it in an online service such as Microsoft’s Skydrive, which &lt;a href="http://legal-beagle.typepad.com/security/2011/10/cops.html" title="police investigation"&gt;records the date a file like the video&lt;/a&gt; was uploaded and last modified.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Example&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Here is a hypothetical example.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/8S1wetjCt0o/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/8S1wetjCt0o?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;











&lt;param name="bgcolor" value="#FFFFFF" /&gt;











&lt;embed width="320" height="266"  src="http://www.youtube.com/v/8S1wetjCt0o?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
This demonstration is not the only way to make records of online events. &amp;nbsp;And it does not cover all of the legal and technical issues that might apply to your particular situation.&lt;br /&gt;
&lt;br /&gt;
If you need legal advice for your particular situation, you need to consult a lawyer rather than to rely on this educational blog and video.&lt;br /&gt;
&lt;br /&gt;
This blog post and video intend to spark public discussion about ways to record online activities. &amp;nbsp;What do you think?&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/jlWXNCHBnDg/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/jlWXNCHBnDg?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;












&lt;param name="bgcolor" value="#FFFFFF" /&gt;












&lt;embed width="320" height="266"  src="http://www.youtube.com/v/jlWXNCHBnDg?version=3&amp;f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
–Benjamin Wright&lt;br /&gt;
&lt;br /&gt;
Attorney Wright teaches the law of data security and investigations at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
Related articles: &lt;br /&gt;
&lt;br /&gt;
* &amp;nbsp;&lt;a href="http://hack-igations.blogspot.com/2011/10/how-to-make-gotcha-video.html" title="clandestine infidelity"&gt;How to Make a Gotcha! Video&lt;/a&gt;&lt;br /&gt;
* &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/04/credible.html" title="cyber criminal"&gt;How to video record online chat with legal adversary&lt;/a&gt;
&lt;br /&gt;
* &lt;a href="http://i-sight.com/investigation/finding-treasure-in-updates-photos-tweets-and-comments/" title="screencast proof"&gt;Recording Social Media Legal Evidence&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="https://plus.google.com/u/0/113714308152841400614?rel=author"&gt;Google+&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-8705925415491657590?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/ixlCC3SkmuY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/8705925415491657590/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/10/how-to-record-debt-collector-web-page.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/8705925415491657590?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/8705925415491657590?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/ixlCC3SkmuY/how-to-record-debt-collector-web-page.html" title="How to Record Debt Collector Web Page" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/10/how-to-record-debt-collector-web-page.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08NRHc-fip7ImA9WhRUEkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-5447131829157133933</id><published>2011-10-20T18:58:00.000-07:00</published><updated>2012-01-22T10:11:35.956-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-22T10:11:35.956-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="whistleblower" /><category scheme="http://www.blogger.com/atom/ns#" term="audio records" /><category scheme="http://www.blogger.com/atom/ns#" term="police" /><title>Exploiting Scandalous Evidence</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qdZzI68sqte-W7ObU4F8TbQ5ccg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qdZzI68sqte-W7ObU4F8TbQ5ccg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qdZzI68sqte-W7ObU4F8TbQ5ccg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qdZzI68sqte-W7ObU4F8TbQ5ccg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Political Exposé&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Let’s say you possess incriminating or embarrassing evidence about someone. &amp;nbsp;Maybe it’s video catching a public official in an act of corruption or audio in which an executive admits her corporation violates the law. &amp;nbsp;You know this evidence is sensitive and it serves a public interest. &amp;nbsp;How do you handle it?&lt;br /&gt;
&lt;br /&gt;
Here are options and issues:&lt;br /&gt;
&lt;br /&gt;
1. &amp;nbsp;&lt;b&gt;Ethics&lt;/b&gt;. Ask an independent party like an attorney to evaluate the evidence for credibility and to provide input on the ethical use of the evidence.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-BEmb6lC7SoY/TqDRjqJAqGI/AAAAAAAAAeg/uuOxtMn5LCY/s1600/Capture.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" src="http://4.bp.blogspot.com/-BEmb6lC7SoY/TqDRjqJAqGI/AAAAAAAAAeg/uuOxtMn5LCY/s200/Capture.JPG" width="135" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Surprise Camera&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
2. &amp;nbsp;&lt;b&gt;Money&lt;/b&gt;. &amp;nbsp;Inquire whether you are entitled to protection and compensation under whistleblower law. &amp;nbsp;Invocation of whistleblower law may require turning the evidence over to law enforcement or filing a lawsuit. &amp;nbsp;Federal tax law provides compensation to whistleblowers who provide the IRS reliable evidence about cheating by a particular taxpayer. &amp;nbsp;The False Claims Act provides a bounty to whistleblowers who sue lawbreakers and successfully recover money on behalf of the federal government.&lt;br /&gt;
&lt;br /&gt;
3. &amp;nbsp;&lt;b&gt;Editing&lt;/b&gt;. &amp;nbsp;Should you hide or redact information from the evidence before publishing it? &amp;nbsp;Blurring faces or removing other personally identifiable information may be the prudent, responsible thing to do. &amp;nbsp;Masking of graphic details can help portray you as a conscientious citizen, not a gossip monger.&lt;br /&gt;
&lt;br /&gt;
4. &amp;nbsp;&lt;b&gt;Investigate&lt;/b&gt;. &amp;nbsp;Should a careful investigation of the facts be undertaken to determine how the evidence was gathered, what the evidence actually depicts or whether the compilation of the evidence violated any laws? &amp;nbsp;When an investigation is led by an attorney, often the methods and the outcome can often be kept confidential under something known as the &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2010/03/confidential.html" title="legal banner"&gt;attorney work-product doctrine&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
5. &amp;nbsp;&lt;b&gt;Third Party&lt;/b&gt;. &amp;nbsp;Should you use an intermediary to publish the evidence or present it to authorities, while protecting your identity? &amp;nbsp;Both attorneys and police agencies have legal power to maintain confidentiality.&lt;br /&gt;
&lt;br /&gt;
6. &amp;nbsp;&lt;b&gt;News Media&lt;/b&gt;. &amp;nbsp;Should you sell the evidence to the news media? &amp;nbsp;Sometimes they do pay for good material.&lt;br /&gt;
&lt;br /&gt;
7. &amp;nbsp;&lt;b&gt;Disclaimers&lt;/b&gt;. &amp;nbsp;Consider how to present the evidence to authorities or the public. &amp;nbsp;Does it need explanation and background? &amp;nbsp;Does it need disclaimers?&lt;br /&gt;
&lt;br /&gt;
8. &amp;nbsp;&lt;b&gt;Exoneration&lt;/b&gt;. &amp;nbsp;Should you file a lawsuit to cause a court to declare that the evidence was not stolen or created in a way that violates privacy, property or other rights?&lt;br /&gt;
&lt;br /&gt;
Are you an amateur gumshoe? What is your experience dealing with evidence of a scam or hipocrisy?&lt;br /&gt;
&lt;br /&gt;
–Benjamin Wright&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of data security and investigations at the SANS Institute, where he teaches professionals how to use Internet media to deliver legal messages.
&lt;br /&gt;
&lt;a href="https://plus.google.com/113714308152841400614?rel=author"&gt;Google+&lt;/a&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-5447131829157133933?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/ggJ6iOCbMCc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/5447131829157133933/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/10/exploiting-scandalous-evidence.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5447131829157133933?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5447131829157133933?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/ggJ6iOCbMCc/exploiting-scandalous-evidence.html" title="Exploiting Scandalous Evidence" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-BEmb6lC7SoY/TqDRjqJAqGI/AAAAAAAAAeg/uuOxtMn5LCY/s72-c/Capture.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/10/exploiting-scandalous-evidence.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUIDQXc6eyp7ImA9WhdaEEo.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-6422040070494295984</id><published>2011-10-19T19:23:00.000-07:00</published><updated>2011-10-19T19:26:10.913-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-19T19:26:10.913-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="digital photo" /><category scheme="http://www.blogger.com/atom/ns#" term="divorce evidence" /><category scheme="http://www.blogger.com/atom/ns#" term="SMS records" /><category scheme="http://www.blogger.com/atom/ns#" term="mobile phone record" /><title>How to Recover Deleted Phone Text and Photos</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/z9d8sgMw5-lxdy2GEBMIplGGzTo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/z9d8sgMw5-lxdy2GEBMIplGGzTo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/z9d8sgMw5-lxdy2GEBMIplGGzTo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/z9d8sgMw5-lxdy2GEBMIplGGzTo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Forensics&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
In a legal dispute, text, photos and other data on a smart phone or tablet can be relevant. &amp;nbsp;Can they be recovered if they have been deleted? &lt;br /&gt;
&lt;br /&gt;
Cellular service carriers (Verizon, AT&amp;amp;T, Sprint, TMobile) keep records of text, photos and transmitted data for periods of time that vary from one provider to the next. &amp;nbsp;However, legally forcing them to turn over user data in a non-criminal case is difficult. &amp;nbsp;The carriers tend to resist subpoenas from civil lawsuits such as divorces, on the grounds that the content of user data is protected by the Electronic Communications Privacy Act.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Customer Cooperation&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
To a limited degree, recovery from a service provider may be possible if the customer is cooperative. &amp;nbsp;For example, Sprint records transmitted photographs on a web page protected by a customer password. &amp;nbsp;Mobile App providers may similarly keep records of messages, photos or videos on a web page protected by a customer password. &amp;nbsp;In a lawsuit, the customer may be required to cooperate in the recovery of those records under a subpoena or ediscovery demand. &lt;br /&gt;
&lt;br /&gt;
(Cellular carriers have a reputation for not helping customers recover messages unless the customer has a web page for storing those messages as Sprint does for photos.)&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Data Forensics&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
An alternative approach to recovering data is forensics. &amp;nbsp;An adversary in a civil law proceeding (divorce, child custody, bankruptcy or other lawsuit) may be able to demand through the rules of court procedure that the owner of a mobile device take two steps:&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-C6eBdlF4-qg/Tp-F4V9hnQI/AAAAAAAAAeU/g90-C2XfJz4/s1600/Photos+and+Video.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-C6eBdlF4-qg/Tp-F4V9hnQI/AAAAAAAAAeU/g90-C2XfJz4/s200/Photos+and+Video.JPG" width="153" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Text, Photos, Video&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
Step 1: Protect data on the device from erasure or further damage. &amp;nbsp;This demand for protection might come in the form of a data preservation letter sent by the adversary’s lawyer.&lt;br /&gt;
&lt;br /&gt;
Step 2: Deliver the device to a forensics expert so he can recover data.&lt;br /&gt;
&lt;br /&gt;
Forensic recovery of data from a mobile device is tricky. &amp;nbsp;Sometimes deleted data can be recovered and sometimes it can’t. &amp;nbsp;Sometimes fragments of a message can be recovered. &amp;nbsp;Recovery capabilities vary from one device to the next.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Documented Authority&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
When a forensics expert is engaged to recover data from a device, he needs to ensure he has authority from the proper person. &amp;nbsp;He is wise to get the authority in writing. &lt;br /&gt;
&lt;br /&gt;
If someone who is not the owner of the device asks him to recover data, he might be violating an anti-hacking law like the &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/09/cfaa.html" title="forensics legality"&gt;Digital Millennium Copyright Act&lt;/a&gt;. &amp;nbsp;When a nonowner asks for data recovery, the expert is wise to ask for a court order.&lt;br /&gt;
&lt;br /&gt;
–Benjamin Wright&lt;br /&gt;
&lt;br /&gt;
Attorney Wright teaches the law of data security and investigations at the SANS Institute.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-6422040070494295984?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/L2qTbBQV1kc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/6422040070494295984/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/10/how-to-recover-deleted-phone-text-and.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6422040070494295984?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6422040070494295984?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/L2qTbBQV1kc/how-to-recover-deleted-phone-text-and.html" title="How to Recover Deleted Phone Text and Photos" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-C6eBdlF4-qg/Tp-F4V9hnQI/AAAAAAAAAeU/g90-C2XfJz4/s72-c/Photos+and+Video.JPG" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/10/how-to-recover-deleted-phone-text-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04DQXY8eyp7ImA9WhRUEkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-7373370070592617355</id><published>2011-10-16T18:11:00.000-07:00</published><updated>2012-01-22T10:12:50.873-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-22T10:12:50.873-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="electronic evidence" /><category scheme="http://www.blogger.com/atom/ns#" term="whistleblower" /><category scheme="http://www.blogger.com/atom/ns#" term="activist" /><category scheme="http://www.blogger.com/atom/ns#" term="e-signature" /><category scheme="http://www.blogger.com/atom/ns#" term="cloud computing" /><title>How to Make a Gotcha! Video</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FsTVe3Y7xVzFeMVBG3cRMGxuBA4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FsTVe3Y7xVzFeMVBG3cRMGxuBA4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FsTVe3Y7xVzFeMVBG3cRMGxuBA4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FsTVe3Y7xVzFeMVBG3cRMGxuBA4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Phone Evidence&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
How should a vigilante or a political activist make a video record of illegal activity?&lt;br /&gt;
&lt;br /&gt;
Let’s say you catch the mayor parking her motorcycle in a no-parking zone, arrogantly thinking she won't get a ticket because she is mayor. &amp;nbsp;You pull out your smart phone and record by video. &amp;nbsp;You intend to present the video as evidence to a legal body like the city council. &amp;nbsp;Or you intend to give the video to the local TV news team. &amp;nbsp;Or, you intend to publish the video on youtube.&lt;br /&gt;
&lt;br /&gt;
Here are steps to make the video more credible and worthy of attention:&lt;br /&gt;
&lt;br /&gt;
1. &amp;nbsp;Narrate what you see as you record it, so that the viewer understands what is being displayed. &amp;nbsp;Narration makes video more compelling than a still photograph.&lt;br /&gt;
&lt;br /&gt;
2. &amp;nbsp;Formally sign the video at the end. &amp;nbsp;Point the camera at your face and recite words like, “I Ben Wright hereby sign and affirm this video as an authentic record of what I witnessed.” &amp;nbsp;A video is more believable when an accountable witness takes full responsibility for it. &amp;nbsp;Also, the signature bolster's the video's value in case you are not available in the future to vouch for it, such as in a legal hearing.&lt;br /&gt;
&lt;br /&gt;
3. &amp;nbsp;State the location, the date and the time.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/laTx9AlJd4E/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/laTx9AlJd4E&amp;fs=1&amp;source=uds" /&gt;














&lt;param name="bgcolor" value="#FFFFFF" /&gt;














&lt;embed width="320" height="266"  src="http://www.youtube.com/v/laTx9AlJd4E&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
4. &amp;nbsp;Promptly after creating the video upload it to an Internet service that memorializes the date of the video (including the date of any modifications). &amp;nbsp;If the date vocalized by the witness in the video matches with the date on the Internet service, then the two corroborate each other.&lt;br /&gt;
&lt;br /&gt;
As a demonstration, I uploaded the video above to Microsoft’s Skydrive service. &amp;nbsp;I uploaded within minutes after I created the video. &amp;nbsp;This screenshot shows the details that Skydrive records about the video, including time of upload and identity of the user who uploaded.&lt;br /&gt;
&lt;br /&gt;
&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1E6khhIbemE/Tpt-GkFVJ_I/AAAAAAAAAdk/_TN8otgJpBE/s1600/Skydrive+screenshot.JPG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="153" src="http://3.bp.blogspot.com/-1E6khhIbemE/Tpt-GkFVJ_I/AAAAAAAAAdk/_TN8otgJpBE/s320/Skydrive+screenshot.JPG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Cloud Service Metadata&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
5. &amp;nbsp;Give the video to some friends and ask them to load it to a service like Skydrive that records date and time.&lt;br /&gt;
&lt;br /&gt;
6. &amp;nbsp;Capture GPS information. &amp;nbsp;A geotag on the video corroborates the location stated by the witness in the video.&lt;br /&gt;
&lt;br /&gt;
P.S. &amp;nbsp;&lt;a href="http://legal-beagle.typepad.com/security/2011/10/cops.html"&gt;Two witnesses&lt;/a&gt; are better than one.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Attorney Wright teaches the law of data security and investigations at the SANS Institute. &amp;nbsp;One topic he covers in that course is whistleblower law.&lt;br /&gt;
&lt;br /&gt;
Related article: &amp;nbsp;&lt;a href="http://hack-igations.blogspot.com/2011/10/exploiting-scandalous-evidence.html" title="documented corruption"&gt;How to Exploit a Gotcha Video&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-7373370070592617355?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/zr01ZRikj50" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/7373370070592617355/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/10/how-to-make-gotcha-video.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7373370070592617355?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7373370070592617355?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/zr01ZRikj50/how-to-make-gotcha-video.html" title="How to Make a Gotcha! Video" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-1E6khhIbemE/Tpt-GkFVJ_I/AAAAAAAAAdk/_TN8otgJpBE/s72-c/Skydrive+screenshot.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/10/how-to-make-gotcha-video.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEEQ3s_fyp7ImA9WhdbFk8.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-155141372072017644</id><published>2011-10-14T13:01:00.000-07:00</published><updated>2011-10-14T13:03:22.547-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-14T13:03:22.547-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="hacker crime" /><title>Cyber Defense Law | Botnet | Computer Crime Lawsuit</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mYH9w-r3WI_hxxciH1D88qrnwdI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mYH9w-r3WI_hxxciH1D88qrnwdI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mYH9w-r3WI_hxxciH1D88qrnwdI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mYH9w-r3WI_hxxciH1D88qrnwdI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;Microsoft breaks new legal ground. From a US Federal court, Microsoft has obtained a temporary restraining order (ex parte TRO) that allows Microsoft and its white hat affiliates to take (apparently) aggressive technical measures against the Waledac botnet.&lt;a class="ot-anchor" href="http://blogs.technet.com/microsoft_blog/archive/2010/02/25/cracking-down-on-botnets.aspx" style="color: #3366cc; cursor: pointer; text-decoration: none;"&gt;http://blogs.technet.com/microsoft_blog/archive/20&lt;wbr&gt;&lt;/wbr&gt;10/02/25/cracking-down-on-botnets.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The TRO is available for download at&amp;nbsp;&lt;a class="ot-anchor" href="http://blog.seattlepi.com/microsoft/archives/195793.asp" style="color: #3366cc; cursor: pointer; text-decoration: none;"&gt;http://blog.seattlepi.com/microsoft/archives/19579&lt;wbr&gt;&lt;/wbr&gt;3.asp&lt;/a&gt;. The TRO explicitly orders Verisign to lock domains at the registry level and to hold the domains in escrow.&lt;br /&gt;&lt;br /&gt;Query whether any of these steps by Verisign would arguably qualify as "hacking" in the absence of the TRO. For discussion purposes, we can define "hacking" as entering a computer without authority -- or exceeding authority within a computer -- and causing damage. Maybe one could say Verisign is "hacking" because, as it locks domains, it:&lt;br /&gt;&lt;br /&gt;1. enters computers that it owns or duly controls;&lt;br /&gt;&lt;br /&gt;2. exceeds its authority in those computers because it is locks domains that putatively belong to another person; and&lt;br /&gt;&lt;br /&gt;3. damages that other person.&lt;br /&gt;&lt;br /&gt;Stephen Paluck of Beaverton, Oregon, complains that actions taken under the TRO interrupted service for his domain,&lt;a class="ot-anchor" href="http://debtbgonesite.com/" style="color: #3366cc; cursor: pointer; text-decoration: none;"&gt;debtbgonesite.com&lt;/a&gt;, and he's done nothing wrong. Wingfield &amp;amp; Worthen, "Microsoft Battles Cyber Criminals," Wall Street Journal, 26 Feb. 2010.&lt;br /&gt;&lt;br /&gt;Microsoft further says, "Microsoft has since been taking additional technical countermeasures to downgrade much of the remaining peer-to-peer command and control communication within the botnet . . ." The company does not reveal what these additional countermeasures are. Query whether any of these measures would arguably qualify as "hacking" in the absence of the TRO or other legal justification.&lt;br /&gt;&lt;br /&gt;PCWorld sheds some light on those additional countermeasures: "Waledac distributes instructions through command-and-control servers that work with a peer-to-peer system. [According to a researcher who worked with Microsoft,] 'We disrupted the peer-to-peer layer to redirect traffic not to botmaster servers but to our servers.'"&amp;nbsp;&lt;a class="ot-anchor" href="http://www.pcworld.com/businesscenter/article/190234/microsoft_recruited_top_notch_guns_for_waledac_takedown.html" style="color: #3366cc; cursor: pointer; text-decoration: none;"&gt;http://www.pcworld.com/businesscenter/article/1902&lt;wbr&gt;&lt;/wbr&gt;34/microsoft_recruited_top_notch_guns_for_waledac_&lt;wbr&gt;&lt;/wbr&gt;takedown.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In my research, I have only found one case [Cartier Int'l, B.V. v. Dipadova, CV 00-06717 (C.D. Cal.) (entered Nov. 7, 2000)] where a judge authorized technical measures -- the disabling of a web page (a legal hack) -- to combat an online threat or menace. Has anyone found any other such case?&lt;br /&gt;&lt;br /&gt;On the issue whether any of the technical steps in this Waledac botnet case are causing "damage": Microsoft posted a $54,600 bond so that money would be available to compensate the defendants (presumably these people are mainly botnet herders) if the TRO causes damage to them without justification.&lt;br /&gt;&lt;br /&gt;Microsoft is teaching us how to use civil law enforcement measures -- as distinguished from criminal law enforcement -- to respond to malicious Internet behavior like phishing, hacking, cybertheft and identity theft.&lt;br /&gt;&lt;br /&gt;Notice that Microsoft is not doing this in the dark. It is working through our open public court system, so that Microsoft is transparent and accountable and all can see what is happening and evaluate it.&lt;br /&gt;&lt;br /&gt;–Benjamin Wright - Legal Issues Instructor at the SANS Institute, where he teaches professionals on the law of malware, e-discovery, data security, internal investigations and the Computer Fraud and Abuse Act.&amp;nbsp;&lt;a class="ot-anchor" href="http://www.sans.org/ondemand/description.php?tid=3897" style="color: #3366cc; cursor: pointer; text-decoration: none;"&gt;http://www.sans.org/ondemand/description.php?tid=3&lt;wbr&gt;&lt;/wbr&gt;897&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;
[This post was originally published 2010 on Mr. Wright's Google Buzz page.]&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-155141372072017644?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/3WBo2AcLNmA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/155141372072017644/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/10/cyber-defense-law-botnet-computer-crime.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/155141372072017644?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/155141372072017644?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/3WBo2AcLNmA/cyber-defense-law-botnet-computer-crime.html" title="Cyber Defense Law | Botnet | Computer Crime Lawsuit" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/10/cyber-defense-law-botnet-computer-crime.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0AFR349eCp7ImA9WhRTEUg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-1236009568926773420</id><published>2011-09-26T15:37:00.000-07:00</published><updated>2011-11-01T06:55:16.060-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-01T06:55:16.060-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="3D printing" /><category scheme="http://www.blogger.com/atom/ns#" term="intellectual property" /><title>3D Printing | Inducing to Violate Intellectual Property</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/sITV0uPS30urxN7JytEaph0T2QQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sITV0uPS30urxN7JytEaph0T2QQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/sITV0uPS30urxN7JytEaph0T2QQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/sITV0uPS30urxN7JytEaph0T2QQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
The vendors of 3D printing software and services must be careful to avoid encouraging users to violate the patent, copyright or trademark of others.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Manipulate an Image&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Imagine a software vendor tells kids to:&lt;br /&gt;
&lt;br /&gt;
1. scan a &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/07/notices.html"&gt;3D image&lt;/a&gt; of their favorite toy vehicle;&lt;br /&gt;
2. use the software to manipulate the image to add cool new features, like wings or monster tires; and&lt;br /&gt;
3. print a model of the manipulated image.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ujm842m5UnE/ToD-WLZl9XI/AAAAAAAAAac/zqU8SgDDadM/s1600/3D+printer.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="191" src="http://2.bp.blogspot.com/-ujm842m5UnE/ToD-WLZl9XI/AAAAAAAAAac/zqU8SgDDadM/s200/3D+printer.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Printing 3D Objects&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
The maker of the original toy might have a claim against the software vendor for inducing the kids to violate intellectual property. &lt;br /&gt;
&lt;br /&gt;
Toymakers often claim copyright and trademark protection for their toys. &amp;nbsp; But when kids make reproductions of the toys, they may be violating that protection.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Tort&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Widespread encouragement for kids to violate IP may constitute illegal inducement.&lt;br /&gt;
&lt;br /&gt;
Courts have recognized a tort for inducing others to violate intellectual property. &amp;nbsp;Music companies, for example, won a &lt;a href="http://www.mediapost.com/publications/?fa=Articles.showArticle&amp;amp;art_aid=128088"&gt;judgment&lt;/a&gt; against peer-to-peer network Limewire for inducing users to make unauthorized copies of music. &amp;nbsp;Evidence in the case showed that Limewire intentionally targeted music pirates for membership and use of its service.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Many New Manufacturing Technologies&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
This tort issue applies not just to 3D printing. &amp;nbsp;It applies to all of the many new technologies that enable localized, custom, computer-driven manufacturing. &amp;nbsp;One such technology is the &lt;a href="https://plus.google.com/104228952724423394368/posts/JWZyqG2wotH"&gt;stonemaker&lt;/a&gt;, which makes unique, precision stones on-location at a construction site. &amp;nbsp;The shape and other features of each stone are dictated by software. &amp;nbsp;Imagine a home owner using the stonemaker, and software templates from an "intellectual property pirate" to make stones depicting copyrighted figures, like Disney characters.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of data &lt;a href="http://www.sans.org/security-training/law-data-security-investigations-122-mid"&gt;security and investigations&lt;/a&gt; at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
Related Article: &lt;a href="http://hack-igations.blogspot.com/2011/07/copyright-3d-printing-object.html" title="cease desist"&gt;3D printing fair use&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-1236009568926773420?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/YlT7ahKqiFE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/1236009568926773420/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/09/3d-printing-inducing-to-violate.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1236009568926773420?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1236009568926773420?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/YlT7ahKqiFE/3d-printing-inducing-to-violate.html" title="3D Printing | Inducing to Violate Intellectual Property" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-ujm842m5UnE/ToD-WLZl9XI/AAAAAAAAAac/zqU8SgDDadM/s72-c/3D+printer.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/09/3d-printing-inducing-to-violate.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QBQns_fip7ImA9WhdWGUs.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-5871375466937175798</id><published>2011-09-06T08:10:00.000-07:00</published><updated>2011-09-13T18:55:53.546-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-13T18:55:53.546-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="data privacy" /><category scheme="http://www.blogger.com/atom/ns#" term="data break-in" /><category scheme="http://www.blogger.com/atom/ns#" term="healthcare privacy" /><title>Telemedicine Meets Privacy &amp; Free Speech</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/AxElpCtATfv08PuGeg5P9sau2Dk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AxElpCtATfv08PuGeg5P9sau2Dk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/AxElpCtATfv08PuGeg5P9sau2Dk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/AxElpCtATfv08PuGeg5P9sau2Dk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Anonymous, Asynchronous Patients?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Local laws such as state physician licensing rules have &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/06/transparency-meets-it-compliance.html" title="healthcare"&gt;limited&lt;/a&gt; the adoption of telemedicine. &amp;nbsp; &amp;nbsp;But the practical effect of some limitations is eroding under new technology and patient civil rights (privacy and free speech). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;New Telemedicine Technologies&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
An online patient can retain increasingly sophisticated services from a physician outside the patient’s state, even outside the country.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-WoaEmaCx6cw/TmY1Xv5MgLI/AAAAAAAAAZw/GmhIWGqJgTE/s1600/Capture.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="131" src="http://1.bp.blogspot.com/-WoaEmaCx6cw/TmY1Xv5MgLI/AAAAAAAAAZw/GmhIWGqJgTE/s200/Capture.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Online Healthcare&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
The modern patient has a growing array of channels for interacting with a remote physician (or a team of physicians knit together via social media). &amp;nbsp;Webcams, mobile apps and monitoring devices that work with smartphones are collecting diagnostic data that can be transmitted to a physician anywhere in the world. &amp;nbsp;The patient can easily provide laboratory results to an online physician.&lt;br /&gt;
&lt;br /&gt;
Patient and physician can engage a rich, extended relationship with little or no direct physical contact.&lt;br /&gt;
&lt;br /&gt;
New technologies are coming. &amp;nbsp;&lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/07/notices.html" title="manufacturing"&gt;3D printers&lt;/a&gt;, for example, will make the creation of custom medical appliances easier for the patient at home. &lt;br /&gt;
&lt;br /&gt;
Telemedicine will marry up with medical tourism, the growing practice of traveling to another country to access medicine or health service that is either forbidden or more expensive in the home country.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Patient Privacy&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Does a physician in Japan need to be licensed in Oklahoma to treat an online patient located in Oklahoma? &amp;nbsp;The answer is very possibly yes. &amp;nbsp;However, if the physician – out of respect for privacy – never inquires as to the patient’s location, how can the physician know he needs a license in Oklahoma? &lt;br /&gt;
&lt;br /&gt;
Depending on the services being rendered, the physician need not (for purposes of care) know the identity or location of the patient. &amp;nbsp;The patient can be anonymous, or identified without location. &lt;br /&gt;
&lt;br /&gt;
Patient privacy does matter. &amp;nbsp;Privacy is more than just an excuse to skirt local physician licensing laws.&amp;nbsp;&lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/03/eu-privacy.html" title="right to be forgotten"&gt;Privacy&lt;/a&gt; is a legal and ethical imperative, which is accorded growing importance today. &amp;nbsp;In the case described here the patient and the physician use technology in a way that promotes the socially-desirable goal of patient privacy. &amp;nbsp;The patient is getting treatment in a way that prevents outsiders from knowing about it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Patient Data Security&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://i.ytimg.com/vi/gPvhhc9jIlk/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/gPvhhc9jIlk?f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" /&gt;
















&lt;param name="bgcolor" value="#FFFFFF" /&gt;
















&lt;embed width="320" height="266"  src="http://www.youtube.com/v/gPvhhc9jIlk?f=user_uploads&amp;c=google-webdrive-0&amp;app=youtube_gdata" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
Reducing the amount of patient identifying information also promotes data security. &amp;nbsp;Like patient privacy, data security is more than just an excuse for the physician to avoid being licensed in the patient's home location.&lt;br /&gt;
&lt;br /&gt;
Like patient privacy, data security is a legal and ethical imperative, which is rising in priority in this age of computers. &amp;nbsp; Data security is very difficult and expensive for health care providers. &amp;nbsp;Chilling stories about data breaches at health care providers are abundant.&lt;br /&gt;
&lt;br /&gt;
Demanding new laws require healthcare providers to &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2008/09/legal-liability-for-data-security-breach.html" title="legislation"&gt;protect patient data&lt;/a&gt;. The goals of those laws are achieved when a physician knows the patient only by a pseudonym or user ID and the physician is ignorant of the patient's location. &amp;nbsp;A data breach would not expose information that could identify the patient to the outside world.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Small Target for Local Authorities&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
If the online physician, licensed and operating from Japan, truly treats patients from around the world, he is probably not much of a target for investigation and enforcement by authorities in Oklahoma.* &amp;nbsp; He is likely not to have many patients in Oklahoma.&lt;br /&gt;
&lt;br /&gt;
That’s not to say Oklahoma law does not apply. &amp;nbsp;It probably does. &amp;nbsp;Also, a Japanese physician who commits malpractice can probably be sued in Oklahoma courts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Mitigation of Risk&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The physician may be able to mitigate his risk with explicit&amp;nbsp;&lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/06/does-world-wide-web-publication-constitute-legal-notice-to-the-world.html"&gt;terms of service&lt;/a&gt; accepted by the patient: &amp;nbsp; The physician is providing only information, like a second opinion, and assumes the patient will get direct care from a local physician. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Asynchronous Interaction&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The physician might further mitigate his risk by interacting with the patient only through recordings, not real-time. &amp;nbsp;By making the interaction non-real-time (asynchronous), the physician emphasizes that his input is merely information, merely a second opinion. &amp;nbsp;And the physician de-emphasizes his responsibility for any emergency (e.g. the patient faints) that could arise if the physician were treating the patient in real-time.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span id="Anonymity"&gt;Anonymity&lt;/span&gt; and Asynchronicity Influence&lt;/b&gt;&lt;b&gt;&amp;nbsp;Regulation&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Physician interaction with an anonymous, asynchronous patient is different from traditional medical care. &lt;br /&gt;
&lt;br /&gt;
When physician interacts with anonymous patient only through recordings, the physician-patient relationship becomes less emotional and more abstract, more intellectual. &amp;nbsp;It places more control into the hands of the patient, allowing the patient to shop around for input and opinions. &amp;nbsp;It allows the patient to shop among multiple physicians, or even non-physicians and artificial intelligence systems like IBM's Watson. &lt;br /&gt;
&lt;br /&gt;
The justification for regulation of such interaction is different compared to that for traditional face-to-face medical care. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;First Amendment Right to Freedom of Speech&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Over regulation of anonymous, recorded interaction will bump against free speech, First Amendment rights. &amp;nbsp;Recorded interaction seems like patient telling a story and listening for a reply. &amp;nbsp;Telling a story and listening for a reply is the essence of free speech. &amp;nbsp;Our society reveres free speech and is reluctant to let government restrain it by regulation.&lt;br /&gt;
&lt;br /&gt;
In other words, when an anonymous patient in Oklahoma is interacting through asynchronous recordings with a physician in Japan, the State of Oklahoma must clear a high burden to prove that it needs to regulate and restrain that interaction. &amp;nbsp;If the State cannot clear that burden, then its physician licensing regulation will violate the First Amendment and be unconstitutional.&lt;br /&gt;
&lt;br /&gt;
What do you think?&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of &lt;a href="http://www.sans.org/security-training/law-data-security-investigations-122-mid"&gt;data security and investigations&lt;/a&gt; at the SANS Institute. &amp;nbsp;(As with all of Mr. Wright's public statements, the purpose of this post is public discussion and not legal advice. &amp;nbsp;If you need legal advice, you should consult your lawyer.)&lt;br /&gt;
&lt;br /&gt;
*The exception is a case like that of Christian Hageseth. &amp;nbsp;He was a physician in Colorado who in association with an online pharmacy prescribed psychiatric medication for a California patient. &amp;nbsp;The physician’s contact with the patient was only an online questionnaire, filled out by the patient. &amp;nbsp;The patient committed suicide. &amp;nbsp;The physician was not licensed to write the prescription even in Colorado. &amp;nbsp;California &lt;a href="http://articles.sfgate.com/2009-04-18/bay-area/17193803_1_john-mckay-medical-license-telemedicine"&gt;prosecuted&lt;/a&gt; him for practicing in California without a license.&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-5871375466937175798?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/xWyrfn2PZZM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/5871375466937175798/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/09/telemedicine-meets-privacy.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5871375466937175798?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5871375466937175798?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/xWyrfn2PZZM/telemedicine-meets-privacy.html" title="Telemedicine Meets Privacy &amp; Free Speech" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-WoaEmaCx6cw/TmY1Xv5MgLI/AAAAAAAAAZw/GmhIWGqJgTE/s72-c/Capture.JPG" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/09/telemedicine-meets-privacy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEHQXc6eyp7ImA9WhdREkQ.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-1535728467051904695</id><published>2011-08-01T08:47:00.000-07:00</published><updated>2011-08-02T07:00:30.913-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-02T07:00:30.913-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="state government" /><category scheme="http://www.blogger.com/atom/ns#" term="Revenue authority" /><category scheme="http://www.blogger.com/atom/ns#" term="social networking law" /><title>Geolocation Data for Tax Collection</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0onX20UvQw5CBpA4Kf1YYRosjkQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0onX20UvQw5CBpA4Kf1YYRosjkQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0onX20UvQw5CBpA4Kf1YYRosjkQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0onX20UvQw5CBpA4Kf1YYRosjkQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Smartphones Snitch on Fugitives, Deadbeats, Tax Evaders&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Social media like Yfrog, Flickr, Twitter, Instapaper, Foursquare and innumerable others broadcast an astonishing trove of publicly-accessible geolocation data about users. &lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-XvGJ4NseApQ/TjbItM3xZII/AAAAAAAAAZY/wycgtrTtVP4/s1600/State+Tax+Audit.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-XvGJ4NseApQ/TjbItM3xZII/AAAAAAAAAZY/wycgtrTtVP4/s1600/State+Tax+Audit.JPG" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;State Tax Audit&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
This data can be aggregated so an observer can track people who are, for example, using mobile devices to tweet, “check-in” and publish photo albums of their minute-to-minute lives. &amp;nbsp;Some mobile apps broadcast geolocation data constantly, automatically. A program aptly named “&lt;a href="http://www.thinq.co.uk/2011/3/30/creepy-app-warns-end-privacy/"&gt;Creepy&lt;/a&gt;” demonstrates how to aggregate geolocation data from multiple public sources. &amp;nbsp;It can plot a social media enthusiast’s up-to-the minute movement on a Google map!&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Arrest Warrants Executed&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Publicly-accessible geolocation data will be a bonanza to law enforcement agents, such as police and tax collectors.&lt;br /&gt;
&lt;br /&gt;
Law enforcement is limited by geographic jurisdiction. &amp;nbsp;It is easier for a government officer to enforce his state’s laws on a subject when the subject is standing within the borders of the state. &amp;nbsp;When the subject is physically located in the state, the local officer can verifiably deliver official papers to the subject, or even detain or arrest her.&lt;br /&gt;
&lt;br /&gt;
Suppose a subject lives in Nevada, but Oregon has a warrant out for her arrest (perhaps for child support or a speeding ticket). &amp;nbsp;It is much easier for the State of Oregon to execute that warrant when the subject visits Oregon.&lt;br /&gt;
&lt;br /&gt;
It is not news that police and &lt;a href="http://legal-beagle.typepad.com/security/2010/03/internet-probe.html" title="social network surveillance"&gt;tax collectors monitor&lt;/a&gt; suspects on social media. &amp;nbsp; But what &lt;i&gt;is&lt;/i&gt; news is that social media are now publishing precise, real-time location data about those suspects.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Checking-in to an Airport&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Fugitives and tax scofflaws beware! &amp;nbsp;You would be foolish to broadcast your location when you temporarily visit a state that wants you. &lt;br /&gt;
&lt;br /&gt;
If there is a warrant for your arrest in the State of Illinois,* don’t use your iPhone to “check-in” as you transfer through Chicago's O’Hare Airport. &amp;nbsp;Local police may race to Gate B30 to greet you.&lt;br /&gt;
&lt;br /&gt;
If you owe taxes in California, don’t post a geo-tagged photo on Picasa when you arrive at LAX airport in Los Angeles. &lt;br /&gt;
&lt;br /&gt;
I envision tax administrators in hungry states setting up enforcement operations at major airports.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Short-term Income Tax Earnings&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Here’s another prediction: &amp;nbsp;State revenue authorities will use geolocation data to support claims that people working temporarily (such as a day or a week) within their borders owe &lt;a href="http://www.nytimes.com/2010/03/22/business/22tax.html"&gt;tax on the income&lt;/a&gt; they earn during that time. &amp;nbsp;States already look at public sources like newspaper sports pages to assert taxes on high-income earners, like professional athletes, who work temporarily within their borders. &amp;nbsp;But public geolocation data will enable states to expand their enforcement to taxpayers of lower profiles.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Attorney Wright teaches law of data security and investigations at &lt;a href="http://www.sans.org/"&gt;SANS&lt;/a&gt; Institute.&lt;br /&gt;
&lt;br /&gt;
* State of Illinois arrested tax evader, Jacob Sabu, when he arrived at&amp;nbsp;&lt;a href="http://www.nbcchicago.com/news/local/Perps-Busted-by-Food-Stamps-92690634.html"&gt;O’Hare&lt;/a&gt; Airport.&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-1535728467051904695?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/-CHeiwN6sLo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/1535728467051904695/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/08/geolocation-data-for-tax-collection.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1535728467051904695?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1535728467051904695?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/-CHeiwN6sLo/geolocation-data-for-tax-collection.html" title="Geolocation Data for Tax Collection" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-XvGJ4NseApQ/TjbItM3xZII/AAAAAAAAAZY/wycgtrTtVP4/s72-c/State+Tax+Audit.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/08/geolocation-data-for-tax-collection.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEDQ3wyfCp7ImA9WhRVFEU.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-7166130096602773271</id><published>2011-07-27T09:02:00.000-07:00</published><updated>2012-01-13T10:51:12.294-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-13T10:51:12.294-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="data break-in" /><category scheme="http://www.blogger.com/atom/ns#" term="legal compliance" /><category scheme="http://www.blogger.com/atom/ns#" term="IT security" /><title>Who is at Fault for Credit Card Insecurity?</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FqF2Rpb1PrrBj9t7RGRfqMb3SUg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FqF2Rpb1PrrBj9t7RGRfqMb3SUg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FqF2Rpb1PrrBj9t7RGRfqMb3SUg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FqF2Rpb1PrrBj9t7RGRfqMb3SUg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;b&gt;Investigate the Payment Card Issuers&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The Massachusetts Attorney General &lt;a href="http://www.boston.com/business/ticker/2011/03/restaurant_grou.html"&gt;forced&lt;/a&gt; the owner of some local restaurants to pay $110,000 to settle charges that the company maintained inadequate security over credit card data. &amp;nbsp;Malware had infected the company’s computers. &amp;nbsp;The company (Briar Group LLC) had failed to change the default passwords on point of sale devices, and its wireless security was inadequate. &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Even Sophisticated Systems are Breached&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-rStz7ZEra-A/TjA1js7EluI/AAAAAAAAAZQ/dW_eqXwDLbM/s1600/SME+computer+security.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;" title="data privacy"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-rStz7ZEra-A/TjA1js7EluI/AAAAAAAAAZQ/dW_eqXwDLbM/s1600/SME+computer+security.JPG" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;SME Computer Security&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
Data security is a difficult, sophisticated job. &amp;nbsp;Briar Group was not well-suited to the job. A company like this relatively small restauranteur is an expert at serving food, not an expert at data security. &lt;br /&gt;
&lt;br /&gt;
The reality is that most any commercial computer system can be &lt;a href="http://legal-beagle.typepad.com/security/2010/05/breach-notice.html" title="vulnerability"&gt;breached&lt;/a&gt;. &amp;nbsp;Even sophisticated technology companies like Sony and RSA suffer data breaches. &amp;nbsp;RSA is one of the most trusted data security firms in the world! &amp;nbsp;If RSA can get hacked, it is no surprise that Briar Group was hacked.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Investigate Credit Card Issuers Themselves&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
I am sure that in punishing the Briar Group restaurants the Attorney General had the best intentions. &amp;nbsp;Yet why is it that the Attorney General focuses attention on a modest restaurant company? &amp;nbsp;If that company needs to be investigated and fined, why does the Attorney General not investigate companies that have real influence on credit card security – the &lt;i&gt;issuers&lt;/i&gt; of credit cards themselves? &amp;nbsp;Credit cards are abused regularly on account of their weak security. &amp;nbsp;Why should the Attorney General not punish the issuers for using faulty, out-of-date technology?&lt;br /&gt;
&lt;br /&gt;
Why, for example, should the Attorney General not force the issuers to require a text message confirmation for each credit card transaction? &amp;nbsp;(Example: I swipe my card at a point-of-sale device; I promptly get a text message on my phone asking for approval; the transaction does not complete until I text approval to the issuer.)&lt;br /&gt;
&lt;br /&gt;
Alternatively, why should the Attorney General not require card issuers to embed dynamic authentication &lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=3419"&gt;EMV chips&lt;/a&gt; in cards, as is done outside the US? &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Continuing to Operate after Breach Discovered?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The Attorney General said that one the justifications for punishing the Briar Group restaurants is that they continued to accept credit cards after they knew their computers were compromised.&lt;br /&gt;
&lt;br /&gt;
But do not card issuers do the same thing? &amp;nbsp;They know that their system is compromised routinely, but they continue to use their old system.&lt;br /&gt;
&lt;br /&gt;
Maybe the argument for issuers to continue to use the flawed credit card system is that even though it is imperfect, it has redeeming qualities. &amp;nbsp; It has many redundant controls, such as the rule that consumers are normally not liable for false transactions on their cards. &amp;nbsp;Further, if issuers immediately stopped using their flawed system, the economy would be harmed. &amp;nbsp;Jobs would be lost.&lt;br /&gt;
&lt;br /&gt;
Could not similar arguments be made in favor of Briar Group? &amp;nbsp;The theft of card data from a restaurant does not automatically mean fraud will occur. &amp;nbsp;Redundant controls (such as transaction monitoring by card issuers) help to protect card holders. &amp;nbsp;Further, if Brian Group had immediately ceased processing cards after it learned it had been breached, it would have been forced to shut down and lay off employees. &amp;nbsp;For Briar Group to have shut down would have caused &amp;nbsp;greater harm than the harm caused by some false credit card transactions (for which individual card holders will not be held liable).&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of data security and investigations at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
Update: &amp;nbsp;Why law enforcement should focus attention not on merchants, but on the &lt;a href="https://plus.google.com/113714308152841400614/posts/7GqgXCpRwqa" title="PCIDSS") target="_blank"&gt;insecurity that is inherent in credit cards as they are presently designed&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-7166130096602773271?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/mEkUI-Zwb5o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/7166130096602773271/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/07/who-is-at-fault-for-credit-card.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7166130096602773271?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7166130096602773271?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/mEkUI-Zwb5o/who-is-at-fault-for-credit-card.html" title="Who is at Fault for Credit Card Insecurity?" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-rStz7ZEra-A/TjA1js7EluI/AAAAAAAAAZQ/dW_eqXwDLbM/s72-c/SME+computer+security.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/07/who-is-at-fault-for-credit-card.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAGRX4ycSp7ImA9WhdaEEo.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-5920067428281174641</id><published>2011-07-12T07:03:00.000-07:00</published><updated>2011-10-19T18:38:44.099-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-19T18:38:44.099-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SMS records" /><category scheme="http://www.blogger.com/atom/ns#" term="instant message law" /><title>SMS Text Messages | Recovery from Carriers</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Z6k7AVEr3vHuYDAgiOywmdJs7ZQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Z6k7AVEr3vHuYDAgiOywmdJs7ZQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Z6k7AVEr3vHuYDAgiOywmdJs7ZQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Z6k7AVEr3vHuYDAgiOywmdJs7ZQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;br /&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;div style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;
&lt;i&gt;Over on the social networking site reddit a topic came up that you may find interesting- the technical ability of telephone carriers to restore txt sms messages.&lt;/i&gt;&lt;/div&gt;
&lt;div style="font-family: Calibri, sans-serif; font-size: 11pt;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;span class="Apple-style-span" style="font-family: Calibri, sans-serif;"&gt;&lt;span class="Apple-style-span" style="font-size: 15px;"&gt;&lt;a href="http://www.reddit.com/r/netsec/comments/iifg8/can_txt_messages_be_subpoenaed_from_carriers/"&gt;&lt;i&gt;http://www.reddit.com/r/netsec/comments/iifg8/can_txt_messages_be_subpoenaed_from_carriers/&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;The default stance of the carriers seems to be “no we can not recovery txt messages” however that seems to be at odds with reality:&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;Kobe Bryant case.&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;i&gt;In Flagg v. City of Detroit, 2008 WL 787061 (E.D. Mich. Mar. 20, 2008) (text messages were subpoenaed from SkyTel, a cell phone provider) although I don’t know the time period on that one.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;i&gt;In a more recent case Verizon restored nearly 5 months of text messages: &lt;a href="http://www.zdnet.com/news/police-blotter-verizon-forced-to-turn-over-text-messages/178942"&gt;ZDNet&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;i&gt;Do you have any experience or tips in successfully compelling a carrier (AT&amp;amp;T in this instance) to restore messages when subpoenaed?&amp;nbsp; Does it take an order from a judge?&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;i&gt;Thanks,&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;i&gt;Liam&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="MsoNormal" style="font-family: Calibri, sans-serif; font-size: 11pt; margin-bottom: 0.0001pt; margin-left: 0in; margin-right: 0in; margin-top: 0in;"&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;[The foregoing is the content of a message sent to me by Liam Randall. &amp;nbsp;Liam gave me permission to repost the message . &amp;nbsp; My comment: &amp;nbsp;The rules of procedure for a civil lawsuit provide for "discovery" of relevant records, which can include &lt;a href="http://hack-igations.blogspot.com/2008/04/text-message-investigations.html"&gt;text messages&lt;/a&gt;. &amp;nbsp;In a lawsuit involving a telecom subscriber, the opposing party might invoke the rules of discovery to demand that the subscriber request that the telecom produce whatever records it may possess. &amp;nbsp;If the subscriber does not cooperate with the demand, then the opponent might ask the court to impose sanctions on the subscriber. &amp;nbsp; However, cooperation of the subscriber may not persuade the telcom to do much. &amp;nbsp;--Ben]&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span class="apple-style-span"&gt;&lt;span style="color: black;"&gt;[&lt;u&gt;Update&lt;/u&gt;. &amp;nbsp;The document posted &lt;a href="http://www.techdirt.com/blog/wireless/articles/20110929/13165516137/doj-document-shows-how-long-telcos-hold-onto-your-data.shtml"&gt;here&lt;/a&gt; apparently shows how long telcos keep different classes of subscriber data. &amp;nbsp; And a discussion &lt;a href="http://ridethelightning.senseient.com/2011/10/how-do-you-get-data-from-cell-phone-companies-in-e-discovery.html"&gt;here&lt;/a&gt;&amp;nbsp;describes the likely result of a subpoena for &amp;nbsp;text messages from a cell phone provider.]&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-5920067428281174641?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/I-DWZsIa1JY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/5920067428281174641/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/07/sms-text-messages-recovery-from.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5920067428281174641?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/5920067428281174641?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/I-DWZsIa1JY/sms-text-messages-recovery-from.html" title="SMS Text Messages | Recovery from Carriers" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/07/sms-text-messages-recovery-from.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUMR3c4fCp7ImA9WhdaFE0.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-4789789448538064289</id><published>2011-07-06T10:17:00.000-07:00</published><updated>2011-10-23T14:44:46.934-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-23T14:44:46.934-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="electronic evidence" /><category scheme="http://www.blogger.com/atom/ns#" term="3D printing" /><category scheme="http://www.blogger.com/atom/ns#" term="intellectual property" /><title>Copyright | 3D Printing Object</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/55arC0EAOLFCdmK8gmf2Vgfn-k8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/55arC0EAOLFCdmK8gmf2Vgfn-k8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/55arC0EAOLFCdmK8gmf2Vgfn-k8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/55arC0EAOLFCdmK8gmf2Vgfn-k8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Fair Use | Super 8 Movie Prop&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Intellectual property enforcement needs a sense of scale.  &lt;br /&gt;
&lt;br /&gt;
An engineer named Todd Blatt created a 3D digital model of a distinctive cube object from the movie &lt;i&gt;Super 8&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
Then he made the model available on the 3D printing site &lt;a href="http://shapeways.com/"&gt;Shapeways&lt;/a&gt; so that fans could purchase copies of the cube, manufactured on a one-off basis.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Cease and Desist Letter?&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Lawyers from the movie studio, Paramount Pictures, issued a &lt;a href="http://torrentfreak.com/paramount-cease-and-desist-targets-3d-printer-pirate-110628/"&gt;cease and desist letter&lt;/a&gt; to Mr. Blatt, and he complied.  The lawyers believed this odd-ball, one-by-one, relatively expensive method for reproducing the cube violated the studio’s copyright.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-IkVjf1rZT6g/TjcFoHueajI/AAAAAAAAAZc/cmfqd-7ipF4/s1600/Additive+Manufacturing+Technology.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="119" id=":current_picnik_image" src="http://4.bp.blogspot.com/-IkVjf1rZT6g/TjcFoHueajI/AAAAAAAAAZc/cmfqd-7ipF4/s320/Additive+Manufacturing+Technology.JPG" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Additive Manufacturing Technology&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
This was over-lawyering.  The cease and desist letter did not serve the studio’s best interest. 3D printing is today a novelty.  &lt;a href="http://hack-igations.blogspot.com/2011/09/3d-printing-inducing-to-violate.html"&gt;3D printing&lt;/a&gt; is unlikely to reduce the studio’s ability to sell its own reproductions of the cube.  &lt;br /&gt;
&lt;br /&gt;
Mr. Blatt’s 3D reproduction comfortably fits within the "fair use" doctrine of copyright law, which allows small-scale copying.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Advice to the Studio&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The studio comes off looking like an ogre when it sends this cease and desist letter.  &lt;br /&gt;
&lt;br /&gt;
The studio should be flattered that Mr. Blatt would go to the trouble to enable this unusual,&lt;br /&gt;
intriguing form of acclamation for the movie.   The studio needs enthusiasts like Mr. Blatt.  Instead of hitting him with a lawyer’s letter, the studio would be better advised to blog about him, tweet about him on Twitter and publish a video about his inspiring work.&lt;br /&gt;
&lt;br /&gt;
In years to come, as 3D printing drops in cost, 3D reproduction of a movie prop could shrink the market for officially-licensed copies of a prop.  But &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2011/07/notices.html"&gt;3D printing&lt;/a&gt; is not there today.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Mr. Wright teaches the law of data security and investigations at the SANS Institute.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Update&lt;/b&gt;: &amp;nbsp;Mr. Blatt asked me to elaborate on why I think his 3D reproduction is fair use. &amp;nbsp;(Obviously, none of my public statements are legal advice to Mr. Blatt or anyone else. &amp;nbsp;I'm just stating ideas for public discussion.)&lt;br /&gt;
&lt;br /&gt;
Let's look at the law. &amp;nbsp;17 USC Section 107:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;"the fair use of a copyrighted work, including such use by reproduction in copies or phonorecords or by any other means specified by that section, for purposes such as criticism, comment, news reporting, teaching (including multiple copies for classroom use), scholarship, or research, is not an infringement of copyright. In determining whether the use made of a work in any particular case is a fair use the factors to be considered shall include:&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;1. the purpose and character of the use, including whether such use is of a commercial nature or is for nonprofit educational purposes;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;2. the nature of the copyrighted work;&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;3. the amount and substantiality of the portion used in relation to the copyrighted work as a whole; and&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;4. the effect of the use upon the potential market for or value of the copyrighted work."&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
My feeling is that Mr. Blatt's work is so limited and restrained that its impact and purpose are more like commentary, education or research than commerce. &amp;nbsp;His work is a wondrous novelty that praises the movie makers. &amp;nbsp;Due to the expense and awkwardness of 3D technology today, the movie makers themselves are very unlikely to try to make a 3D version of the cube in the way that Mr. Blatt did.&lt;br /&gt;
&lt;br /&gt;
The purpose of the fair use doctrine is to enable the kind of cool, provocative exchange of ideas that Mr. Blatt's work exemplifies.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-4789789448538064289?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/i6b5K_5y4-A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/4789789448538064289/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/07/copyright-3d-printing-object.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4789789448538064289?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4789789448538064289?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/i6b5K_5y4-A/copyright-3d-printing-object.html" title="Copyright | 3D Printing Object" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-IkVjf1rZT6g/TjcFoHueajI/AAAAAAAAAZc/cmfqd-7ipF4/s72-c/Additive+Manufacturing+Technology.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/07/copyright-3d-printing-object.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEANQ3sycSp7ImA9WhdREkQ.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-2913508859175860536</id><published>2011-01-15T16:17:00.000-08:00</published><updated>2011-08-02T07:53:12.599-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-02T07:53:12.599-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="mobile phone record" /><category scheme="http://www.blogger.com/atom/ns#" term="cyber investigation" /><category scheme="http://www.blogger.com/atom/ns#" term="instant message law" /><title>Recording Telephone Calls and Instant Messages</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/urRunx2648IRSynKe7Yl4MgoTkE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/urRunx2648IRSynKe7Yl4MgoTkE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/urRunx2648IRSynKe7Yl4MgoTkE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/urRunx2648IRSynKe7Yl4MgoTkE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Recorded Video Calls&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Why does &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/08/retain-documents.html" title="email deletion"&gt;spoliation law&lt;/a&gt; punish pre-mature destruction of email records, while not also requiring that telephone conversations be recorded and preserved? &amp;nbsp;That question came to me from a student taking the 5-day SANS course I teach (The Law of Data Security and Investigations). &amp;nbsp;Following was my reply to him . . . &lt;br /&gt;
&lt;br /&gt;
My reply ties into the philosophy I express in day 2 of the course, on records management. &amp;nbsp;My answer speaks in broad generalities.&lt;br /&gt;
&lt;br /&gt;
US and Canadian law has evolved in a way that is not necessarily optimal, given recent developments in technology.  &lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-6zJsNydIc0w/TjgPMTp0M3I/AAAAAAAAAZg/lmKlzm7nZRM/s1600/Audio+recording.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-6zJsNydIc0w/TjgPMTp0M3I/AAAAAAAAAZg/lmKlzm7nZRM/s1600/Audio+recording.JPG" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Audio Recording&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
Our law takes the attitude that a "record" is really something important. &amp;nbsp; After a record exists, our law tilts toward wanting the record to stay around, especially if the record holder has reason to believe the record might be needed in a future lawsuit or official investigation. &amp;nbsp;Thus, our law punishes unwarranted destruction of records.&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;The same holds true in politics. &amp;nbsp;When politicians investigate a scandal, they (and the media) howl if "records were destroyed."  &lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/09/investigate.html" title="government scandal"&gt;Here is a Canadian example&lt;/a&gt;. &amp;nbsp;The destruction of records sounds like a "cover up."&lt;br /&gt;
&lt;br /&gt;
Email always creates a written record automatically. &amp;nbsp;Once that written record exists, the law and the politicians tend to think it is like a written letter, a "precious record" that deserves some measure of preservation.&lt;br /&gt;
&lt;br /&gt;
Contrast traditional voice conversations (telephone or face-to-face). &amp;nbsp;They do not automatically create a record of the content of what people say. &amp;nbsp;So there is no "precious record" to retain and to protect from loss.  &lt;br /&gt;
&lt;br /&gt;
Furthermore, we have a history of believing that if a record is in fact created of a voice conversation (e.g. tape recording), then privacy is implicated. &amp;nbsp;So we believe that if you are going to record a phone call, you must first get the &lt;i&gt;consent&lt;/i&gt; of the other party.  &lt;br /&gt;
&lt;br /&gt;
Notice we don't ask for consent to record email, because it is naturally assumed that email will be recorded.&lt;br /&gt;
&lt;br /&gt;
Today, technology is changing. &amp;nbsp; The difference between email and a voice telephone call is blurring. &amp;nbsp;Some instant message systems now automatically record voice and video the same way that they record text. &amp;nbsp;The law has not fully considered this new development. &amp;nbsp; As things like IM become more common, I think we will see confusion in the law about whether instant voice and video records should be retained like email.&lt;br /&gt;
&lt;br /&gt;
--&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-2913508859175860536?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/NEfRdouVcHk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/2913508859175860536/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/01/recording-telephone-calls-and-instant.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/2913508859175860536?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/2913508859175860536?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/NEfRdouVcHk/recording-telephone-calls-and-instant.html" title="Recording Telephone Calls and Instant Messages" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-6zJsNydIc0w/TjgPMTp0M3I/AAAAAAAAAZg/lmKlzm7nZRM/s72-c/Audio+recording.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/01/recording-telephone-calls-and-instant.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMFRXk9eCp7ImA9WhdUFEQ.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-9141557943235527735</id><published>2011-01-04T09:43:00.000-08:00</published><updated>2011-10-01T11:06:54.760-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-01T11:06:54.760-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="data privacy" /><category scheme="http://www.blogger.com/atom/ns#" term="legal compliance" /><title>How to Comply with Internet Regulations</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/kg_A81LhvWWfgtsDMjpmlarTrqU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kg_A81LhvWWfgtsDMjpmlarTrqU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/kg_A81LhvWWfgtsDMjpmlarTrqU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/kg_A81LhvWWfgtsDMjpmlarTrqU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;b&gt;Privacy and Computer Crime Cases | Spirit of the Law&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
How is a citizen of the Internet to comply with the data laws of the world?  &amp;nbsp;By citizen I especially have in mind a reputable enterprise or professional.&lt;br /&gt;
&lt;br /&gt;
A welter of laws from around the globe purport to regulate the citizen's use of computers, collection of data, publishing of information and so on.  &amp;nbsp;The laws are often confusing because they conflict, they overlap, they use vague terminology that can be interpreted in ways that make little sense, and they apply to technology that changes faster than lawmakers can assimilate.&lt;br /&gt;
&lt;br /&gt;
&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-UHWwafKcc08/TodWeNHxCCI/AAAAAAAAAag/-OgWXRWXT5A/s1600/Capture.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="181" src="http://4.bp.blogspot.com/-UHWwafKcc08/TodWeNHxCCI/AAAAAAAAAag/-OgWXRWXT5A/s200/Capture.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Responsible Global Citizen&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
The laws of multiple countries can apply simultaneously to any given activity on the Internet.&lt;br /&gt;
&lt;br /&gt;
Compounding the problem, new laws on privacy, hacker crimes, data processing and intellectual property are enacted every day.&lt;br /&gt;
&lt;br /&gt;
The laws often speak in strong declaratory statements, which give the impression that they set  bright-line rules and boundaries that can be objectively tested.  &amp;nbsp;Yet the rules and boundaries become less distinct when they meet practical application.&lt;br /&gt;
&lt;br /&gt;
In all the history of law, nothing is so novel as the Internet. &amp;nbsp;When applying law to particular Internet situations, the authorities struggle.  &amp;nbsp;In the pursuit of justice, thoughtful courts and government officials are forced to eschew mechanical readings of data law.  They try instead to divine what the spirit of the law says about the situation at hand.  &amp;nbsp;They inevitably weigh all the factors in case – even when law does not explicitly call for such an “all the facts and circumstances” analysis.&amp;nbsp;  Their analysis adopts surprisingly subjective tone. &lt;br /&gt;
&lt;br /&gt;
Two examples:&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Purpose and Context of an Action Relevant to Computer Crime Law&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
White hat hacker cases are rare, but &lt;a href="http://www.internetlibrary.com/cases/lib_case37.cfm"&gt;Moulton v. VC&lt;/a&gt;3 is one of them. &amp;nbsp;A business, VC3, sued an IT professional, Scott Moulton, after he did a port scan and a throughput test of VC3’s servers.  VC3 and Moulton were contractors for government agencies that were establishing a network connection between themselves. VC3 claimed that Moulton’s port scan and throughput test violated the Computer Fraud and Abuse Act.  The CFAA forbids the "intentional[] access[ing] [of] a protected computer without authorization, [that] as a result of such conduct, recklessly causes damage." 18 U.S.C. Section 1030(a)(5)(B).    &lt;br /&gt;
&lt;br /&gt;
Moulton alleged he had a justification for doing the port scan and throughput test, within the scope of his work protecting the system of his client, the 911 center at Cherokee County.  Moulton was not trying to steal or compromise sensitive data. When VC3 asked him about his scanning, he declared in an email that “he worked for Cherokee County 911 Center and was testing security.”&lt;br /&gt;
&lt;br /&gt;
In construing the words of the CFAA for this particular case, the court took into account more than just the mechanics of Moulton’s conduct.  It weighed Moulton’s &lt;bold&gt;purpose&lt;bold&gt; when he conducted the scan and test.  The court said, “The public data stored on Defendant's network was never in jeopardy.  Plaintiff Moulton’s actions never threatened the public health and safety.”   The court concluded that Moulton did not violate the CFAA.  The implication is that if Moulton’s scan and test were intended to advance a larger scheme to steal or damage data, then the court would view them differently and possibly find a violation of the CFAA.  &lt;br /&gt;
&lt;br /&gt;
In other words, the purpose and context of an action, which are discerned from all the facts and circumstances, are relevant to whether the CFAA has been violated.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt; Proportionality in EU Data Protection Law&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The European Directive on Data Protection calls for strict limits on the collection and processing of personal data.  A wooden reading of the Directive might lead to bizarre results.  For example, in my SANS course, I asked this hypothetical question: A magazine subscription marketing company holds data showing the names and postal addresses of subscribers.  But this data grows out of date. The “integrity” principle under the EU Directive suggests that the company must keep its data up to date, but to do that the company would have to pester people by contacting them asking them to update their information.  Does EU data law require the company to pester people? I asked.  A German lawyer (privacy law expert) who was attending the course answered that such a tasteless outcome would not be required because the pestering would be “disproportionate” to the need for integrity.  &lt;br /&gt;
&lt;br /&gt;
In other words, I learned from my German friend, a balancing test of proportionality modulates the literal words of European data protection law.&lt;br /&gt;
&lt;br /&gt;
Another European lawyer, Christopher Kuner, argues that proportionality is a central concept in EU data protection law, even though explicit reference in the law to proportionality is limited. “Proportionality in European Data Protection Law And Its Importance for Data Processing by Companies,”&lt;a href="http://www.hunton.com/files/tbl_s47Details/FileUpload265/2379/Kuner_Proportionality_in_EU_DataProtectionLaw.pdf"&gt; Privacy &amp;amp; Security Law Report, Vol. 07, No. 44&lt;/a&gt;, 11/10/2008, pp. 1615. &amp;nbsp;Mr. Kuner observes that even though “companies are often used to thinking of data protection compliance in terms of satisfying a well-defined set of statutory requirements,” the principle of proportionality blurs the requirements.  &lt;br /&gt;
&lt;br /&gt;
Proportionality calls for analysis of whether the results of a data activity are excessive or necessary.  A review of proportionality calls for an analysis of all the facts and circumstances of a case to determine what is a socially-good outcome.&lt;br /&gt;
&amp;nbsp;&lt;/bold&gt;&lt;/bold&gt;&lt;br /&gt;
&lt;bold&gt;&lt;bold&gt;&lt;br /&gt;
&lt;/bold&gt;&lt;/bold&gt;&lt;br /&gt;
&lt;bold&gt;&lt;bold&gt;&lt;b&gt;Conclusion: How to Comply&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;Examples like these show the good Internet citizen that “&lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2009/06/transparency-meets-it-compliance.html" title="transparency accountability"&gt;compliance with law&lt;/a&gt;” is often not a cut and dried affair.  &amp;nbsp;Compliance involves appeal to subjective notions like good purpose, socially-redeeming motives, or culturally-desirable outcome.&lt;br /&gt;
&lt;br /&gt;
What does this understanding of compliance mean for the Internet citizen in practice?  It means compliance often requires more than satisfying a technical IT checklist.  It means the citizen is wise to deliberate on the social implications of its activities and strive to document how the activities seek laudable ends.&lt;br /&gt;
&lt;br /&gt;
–&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/bold&gt;&lt;/bold&gt;&lt;br /&gt;
A practicing attorney, Mr. Wright teaches &lt;br /&gt;
&lt;div itemscope="" itemtype="http://schema.org/EducationEvent"&gt;
the &lt;a href="http://www.sans.org/security-training/law-data-security-investigations-122-mid" title="professional training"&gt;law of data security and investigations at the SANS Institute&lt;/a&gt;.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-9141557943235527735?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/X_ZrlIkPjaE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/9141557943235527735/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2011/01/how-to-comply-with-internet-regulations.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/9141557943235527735?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/9141557943235527735?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/X_ZrlIkPjaE/how-to-comply-with-internet-regulations.html" title="How to Comply with Internet Regulations" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-UHWwafKcc08/TodWeNHxCCI/AAAAAAAAAag/-OgWXRWXT5A/s72-c/Capture.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2011/01/how-to-comply-with-internet-regulations.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAMQHwyeyp7ImA9WhRVEk4.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-3338238526775486475</id><published>2010-12-29T06:43:00.001-08:00</published><updated>2012-01-10T15:06:21.293-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-10T15:06:21.293-08:00</app:edited><title>Web Contract (EULA) Published to World</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/35OrbFiKrWIUW1yWMN51dYqerAI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/35OrbFiKrWIUW1yWMN51dYqerAI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/35OrbFiKrWIUW1yWMN51dYqerAI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/35OrbFiKrWIUW1yWMN51dYqerAI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;
Can I publish &lt;a href="https://plus.google.com/113714308152841400614/posts/492mMQxVr22" title="online agreement"&gt;legal terms on the web&lt;/a&gt; and declare them a contract that is binding on spammers who send me spam?  Based in part on such contracts, Attorney Dan Balsam of California earns a living by suing spammers and collecting money from them.&lt;br /&gt;
&lt;a href="http://legal-beagle.typepad.com/wrights_legal_beagle/2010/09/no-trespassing.html"&gt;http://legal-beagle.typepad.&lt;wbr&gt;&lt;/wbr&gt;com/wrights_legal_beagle/2010/&lt;wbr&gt;&lt;/wbr&gt;09/no-trespassing.html&lt;/a&gt;&lt;br /&gt;
in reference to: &lt;br /&gt;
&lt;blockquote&gt;
"bound by the terms of the contract"&lt;br /&gt;
- &lt;a href="http://www.danbalsam.com/"&gt;Welcome&amp;nbsp; to&amp;nbsp; DanHatesSpam&lt;/a&gt;&amp;nbsp;&lt;/blockquote&gt;
--&lt;a href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html" rel="author"&gt;Benjamin Wright&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-3338238526775486475?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/h4jhRNe7gPk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/3338238526775486475/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/12/web-contract-eula-published-to-world.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3338238526775486475?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3338238526775486475?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/h4jhRNe7gPk/web-contract-eula-published-to-world.html" title="Web Contract (EULA) Published to World" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/12/web-contract-eula-published-to-world.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUAMSXk6eyp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-3930160194838994773</id><published>2010-12-17T17:17:00.001-08:00</published><updated>2011-06-09T14:09:48.713-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:09:48.713-07:00</app:edited><title>Legal Definition of Compromise</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/K0uVF69eGYPdzG4MTtOTJ9K5nWw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K0uVF69eGYPdzG4MTtOTJ9K5nWw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/K0uVF69eGYPdzG4MTtOTJ9K5nWw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K0uVF69eGYPdzG4MTtOTJ9K5nWw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;We have many laws requiring organizations to issue notices when data security has been breached.  But system compromise is so common that we run the risk of seeing a "data breach" everywhere we look in IT systems.  If we see too many breaches, then we flood constituents with confusing, unhelpful notices. &lt;a href='http://hack-igations.blogspot.com/2007/09/definition-of-data-security-breach.html'&gt;http://hack-igations.blogspot.&lt;wbr/&gt;com/2007/09/definition-of-&lt;wbr/&gt;data-security-breach.html&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;"adversaries are going to go unnoticed on our networks"&lt;br /&gt;
- &lt;a href='http://www.eweek.com/c/a/Security/NSA-Assume-Attackers-Will-Compromise-Networks-395027/'&gt;NSA: Assume Attackers Will Compromise Networks - Security - News &amp;amp; Reviews - eWeek.com&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/TGBIzZn8fcd_CiTsgobAD4gc6f0'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-3930160194838994773?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/yefqL-QyjZo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/3930160194838994773/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/12/legal-definition-of-compromise.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3930160194838994773?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/3930160194838994773?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/yefqL-QyjZo/legal-definition-of-compromise.html" title="Legal Definition of Compromise" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/12/legal-definition-of-compromise.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU4CQ3w6fSp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-6729972280649168557</id><published>2010-12-08T18:24:00.001-08:00</published><updated>2011-06-09T14:12:42.215-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:12:42.215-07:00</app:edited><title>Obstruction of Justice or Harbinger of Transparency?</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rOQaLrSPSMYzmvl01mnZWZaXwDU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rOQaLrSPSMYzmvl01mnZWZaXwDU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rOQaLrSPSMYzmvl01mnZWZaXwDU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rOQaLrSPSMYzmvl01mnZWZaXwDU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Could a mobile phone app be illegal if it warned users of police activity like a speed trap or a drug bust?  "Obstruction of Justice" is the crime of intentionally doing something to impede or hamper a law enforcement activity or an official investigation.&lt;br /&gt;
&lt;br /&gt;
South African legal authorities are taking legal action against a Twitter tweeter who warns motorists about speed traps: &lt;a href="http://tech.slashdot.org/story/10/09/19/0110246/Criminal-Charges-Against-Speed-Trap-Tweeter"&gt;http://tech.slashdot.org/&lt;wbr&gt;&lt;/wbr&gt;story/10/09/19/0110246/&lt;wbr&gt;&lt;/wbr&gt;Criminal-Charges-Against-&lt;wbr&gt;&lt;/wbr&gt;Speed-Trap-Tweeter&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Swiss authorities have outlawed certain GPS devices that alert drivers of speed traps. &lt;a href="http://www.techdirt.com/articles/20070212/075138.shtml"&gt;http://www.techdirt.com/&lt;wbr&gt;&lt;/wbr&gt;articles/20070212/075138.shtml&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
The trend is for technology to shed more light and scrutiny on all police activities.  Police must learn how to operate in a transparent world. &lt;a href="http://hack-igations.blogspot.com/2007/12/people-in-authority-sometimes-abuse.html"&gt;http://hack-igations.blogspot.&lt;wbr&gt;&lt;/wbr&gt;com/2007/12/people-in-&lt;wbr&gt;&lt;/wbr&gt;authority-sometimes-abuse.html&lt;/a&gt;&lt;br /&gt;
in reference to: &lt;br /&gt;
&lt;blockquote&gt;"traffic information based on the wisdom of the crowd"&lt;br /&gt;
- &lt;a href="http://www.waze.com/homepage/"&gt;Free GPS Navigation with Turn by Turn - Waze |&lt;/a&gt; (&lt;a href="http://www.google.com/sidewiki/entry/benwright214/id/xHU1MyccskN7-gjavOCJoHG4zek"&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;Update: &amp;nbsp;&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif; font-size: 13px; line-height: 17px;"&gt;For more on mobile apps that might contribute to the crime of "obstruction of justice," see&lt;a href="http://www.google.com/url?q=http%3A%2F%2Ftechnolog.msnbc.msn.com%2F_news%2F2011%2F05%2F25%2F6704362-police-on-radio-scanner-apps-thats-not-a-10-4&amp;amp;usd=1&amp;amp;usg=AFQjCNHsnkB5ByxoUThSun2Zjt4LTOkqBg" rel="nofollow" style="color: #0000cc; cursor: pointer; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-decoration: underline;" target="_blank"&gt;http://technolog.msnbc.msn.com/_news/2011/05/25/6704362-police-on-radio-scanner-apps-thats-not-a-10-4&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-6729972280649168557?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/pTDYZNWenVs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/6729972280649168557/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/12/obstruction-of-justice-or-harbinger-of.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6729972280649168557?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/6729972280649168557?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/pTDYZNWenVs/obstruction-of-justice-or-harbinger-of.html" title="Obstruction of Justice or Harbinger of Transparency?" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/12/obstruction-of-justice-or-harbinger-of.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkcHQ3g6cSp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-2988865103971980156</id><published>2010-12-07T15:58:00.001-08:00</published><updated>2011-06-09T14:13:52.619-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:13:52.619-07:00</app:edited><title>Privacy in Business Litigation</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/MLZ7HIIvUfpkSKh90lrs2xmV3o4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MLZ7HIIvUfpkSKh90lrs2xmV3o4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/MLZ7HIIvUfpkSKh90lrs2xmV3o4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MLZ7HIIvUfpkSKh90lrs2xmV3o4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;If executives can cleanly separate business use of a smart phone from personal use, they can better avoid subpoenas that demand access to their home and personal systems. &lt;a href='http://legal-beagle.typepad.com/wrights_legal_beagle/2009/05/e-mail-records-on-home-computers-and-personal-blackberries.html'&gt;http://legal-beagle.typepad.&lt;wbr/&gt;com/wrights_legal_beagle/2009/&lt;wbr/&gt;05/e-mail-records-on-home-&lt;wbr/&gt;computers-and-personal-&lt;wbr/&gt;blackberries.html&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;"a single phone to run two operating systems"&lt;br /&gt;
- &lt;a href='http://www.networkworld.com/news/2010/120710-vmware-virtualizes-lg-android.html'&gt;VMware to virtualize Android smartphones for business users&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/8j-4Hf8-Kx11vuVdRiBaadpWT6w'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-2988865103971980156?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/gQwGm-7LOG4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/2988865103971980156/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/12/privacy-in-business-litigation.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/2988865103971980156?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/2988865103971980156?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/gQwGm-7LOG4/privacy-in-business-litigation.html" title="Privacy in Business Litigation" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/12/privacy-in-business-litigation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0IBRHg9fSp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-1890498328303773417</id><published>2010-11-23T06:43:00.001-08:00</published><updated>2011-06-09T14:39:15.665-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:39:15.665-07:00</app:edited><title>Electronic Record Retention: Global Law</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/pCflCZ-A1sc7vuDApEYliDB_YuI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pCflCZ-A1sc7vuDApEYliDB_YuI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/pCflCZ-A1sc7vuDApEYliDB_YuI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/pCflCZ-A1sc7vuDApEYliDB_YuI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;As Anglo-American notions of anti-corruption and anti-money laundering law spread around the world, enterprises like banks in emerging economies (e.g. Russia) sense greater need to archive and review electronic records like email.  &lt;a href='http://www.google.com/buzz/benwright214/hgPHAguLJqP/The-process-known-as-e-discovery-in-US-litigation'&gt;http://www.google.com/buzz/&lt;wbr/&gt;benwright214/hgPHAguLJqP/The-&lt;wbr/&gt;process-known-as-e-discovery-&lt;wbr/&gt;in-US-litigation&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;"Russian authorities should endeavour to increase the number of investigations"&lt;br /&gt;
- &lt;a href='http://www.fatf-gafi.org/document/1/0,3343,en_32250379_32236963_40945665_1_1_1_1,00.html'&gt;Mutual Evaluation of the Russian Federation&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/pFD8XZs8g9BWxCiuYFSejFs-KEc'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-1890498328303773417?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/SAuUQpzSHgM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/1890498328303773417/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/11/electronic-record-retention-global-law.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1890498328303773417?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/1890498328303773417?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/SAuUQpzSHgM/electronic-record-retention-global-law.html" title="Electronic Record Retention: Global Law" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/11/electronic-record-retention-global-law.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ADQHc8fyp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-988974266880572616</id><published>2010-11-09T06:58:00.001-08:00</published><updated>2011-06-09T14:42:51.977-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:42:51.977-07:00</app:edited><title>Webcam Android Apps</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/xLYHOx0R_gbfrGDRT6BAgjtZMVk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xLYHOx0R_gbfrGDRT6BAgjtZMVk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/xLYHOx0R_gbfrGDRT6BAgjtZMVk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/xLYHOx0R_gbfrGDRT6BAgjtZMVk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;As more mobile devices like the Streak come to have user-facing cameras, we need apps that allow business users to sign/authenticate their email with video signatures.  &lt;a href='https://groups.google.com/group/appinventor/browse_thread/thread/5a31c9073a0cdf0f'&gt;https://groups.google.com/&lt;wbr/&gt;group/appinventor/browse_&lt;wbr/&gt;thread/thread/5a31c9073a0cdf0f&lt;/a&gt;&lt;br /&gt;
&lt;a href='http://legal-beagle.typepad.com/wrights_legal_beagle/2010/10/video-authentication.html'&gt;http://legal-beagle.typepad.&lt;wbr/&gt;com/wrights_legal_beagle/2010/&lt;wbr/&gt;10/video-authentication.html&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;"front and rear-facing camera enabled for video conferencing and to capture photos"&lt;br /&gt;
- &lt;a href='http://www.dell.com/content/topics/topic.aspx/us/segments/bsd/mobile-streak'&gt;Discover the Dell Streak | Dell&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/64_UHWmzDrRVaUwJL8C2RBimSRI'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-988974266880572616?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/QYVaMHzpzTc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/988974266880572616/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/11/webcam-android-apps.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/988974266880572616?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/988974266880572616?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/QYVaMHzpzTc/webcam-android-apps.html" title="Webcam Android Apps" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/11/webcam-android-apps.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08DR38_fyp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-7469018710365298155</id><published>2010-11-05T06:41:00.001-07:00</published><updated>2011-06-09T14:44:36.147-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:44:36.147-07:00</app:edited><title>Litigation Hold on Private Data</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zadzh4Uw16EYGpDxHdsYkHkHLcQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zadzh4Uw16EYGpDxHdsYkHkHLcQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zadzh4Uw16EYGpDxHdsYkHkHLcQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zadzh4Uw16EYGpDxHdsYkHkHLcQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;The "right to be forgotten" may conflict with laws requiring that evidence be preserved for lawsuits or investigations.  Query whether the holders of private data will be able to delete data about consumers when they have some knowledge that the data might be needed for other legal purposes. &lt;a href='http://legal-beagle.typepad.com/wrights_legal_beagle/2010/03/plaintiff-policy.html'&gt;http://legal-beagle.typepad.&lt;wbr/&gt;com/wrights_legal_beagle/2010/&lt;wbr/&gt;03/plaintiff-policy.html&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;""right to be forgotten" when their data is no longer needed or they want their data to be deleted"&lt;br /&gt;
- &lt;a href='http://yro.slashdot.org/story/10/11/05/0411231/EU-Commission-Says-People-Have-a-Right-To-Be-Forgotten-Online?from=rss'&gt;Slashdot Your Rights Online Story | EU Commission Says People Have a 'Right To Be Forgotten' Online&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/6YssMU4t8GXD3Dxn9bp8mz1w27E'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-7469018710365298155?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/KsIugIM1ckE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/7469018710365298155/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/11/litigation-hold-on-private-data.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7469018710365298155?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/7469018710365298155?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/KsIugIM1ckE/litigation-hold-on-private-data.html" title="Litigation Hold on Private Data" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/11/litigation-hold-on-private-data.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04EQ3Y6eSp7ImA9WhZUFkg.&quot;"><id>tag:blogger.com,1999:blog-2938493123269026698.post-4284599489156802896</id><published>2010-10-16T10:54:00.001-07:00</published><updated>2011-06-09T14:45:02.811-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-09T14:45:02.811-07:00</app:edited><title>Traditional Investigations Under Pressure</title><content type="html">
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/v6TaO_Dd_jPEhLWv-NnQxHMxQJ4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/v6TaO_Dd_jPEhLWv-NnQxHMxQJ4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/v6TaO_Dd_jPEhLWv-NnQxHMxQJ4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/v6TaO_Dd_jPEhLWv-NnQxHMxQJ4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;&lt;p&gt;In the Internet Age, official investigators, like prosecutors in Japan, must change.  They must embrace more transparency, and make themselves more accountable to the public.  &lt;a href='http://legal-beagle.typepad.com/wrights_legal_beagle/2009/11/transparency.html'&gt;http://legal-beagle.typepad.&lt;wbr/&gt;com/wrights_legal_beagle/2009/&lt;wbr/&gt;11/transparency.html&lt;/a&gt;  Technology promotes accountability by, for example, enabling witness interviews to be recorded.  &lt;a href='http://legal-beagle.typepad.com/wrights_legal_beagle/2009/09/exposure.html'&gt;http://legal-beagle.typepad.&lt;wbr/&gt;com/wrights_legal_beagle/2009/&lt;wbr/&gt;09/exposure.html&lt;/a&gt;&lt;/p&gt;in reference to: &lt;p&gt;&lt;blockquote&gt;"they are sure to face further calls for limits to their power, including demands for interrogations to be recorded to prevent abuse."&lt;br /&gt;
- &lt;a href='http://www.ft.com/cms/s/0/67f62b24-d875-11df-8e05-00144feabdc0.html'&gt;FT.com / Japan - Calls for curbs on Japanese prosecutors&lt;/a&gt; (&lt;a href='http://www.google.com/sidewiki/entry/benwright214/id/eZSSPaTXpMHCJ90cnlylECfFwos'&gt;view on Google Sidewiki&lt;/a&gt;)&lt;/blockquote&gt;&lt;/p&gt;&lt;p&gt;--&lt;a rel="author" href="http://hack-igations.blogspot.com/p/about-benjamin-wright.html"&gt;Benjamin Wright&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2938493123269026698-4284599489156802896?l=hack-igations.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~4/lqXA6HUFQCA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://hack-igations.blogspot.com/feeds/4284599489156802896/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://hack-igations.blogspot.com/2010/10/traditional-investigations-under.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4284599489156802896?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/2938493123269026698/posts/default/4284599489156802896?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SpiesSnoopsSnitchesPrivacyLaw/~3/lqXA6HUFQCA/traditional-investigations-under.html" title="Traditional Investigations Under Pressure" /><author><name>Benjamin Wright</name><uri>https://profiles.google.com/113714308152841400614</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="32" src="//lh3.googleusercontent.com/-KYaQQ5DfHBM/AAAAAAAAAAI/AAAAAAAAAYM/It1RMv4maEM/s512-c/photo.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://hack-igations.blogspot.com/2010/10/traditional-investigations-under.html</feedburner:origLink></entry></feed>

