Pages

Showing posts with label law. Show all posts
Showing posts with label law. Show all posts

Tuesday, July 31, 2012

Irish watchdog aborts talks with Europe vs. Facebook, via text

Ireland's Office of the Data Protection Commissioner says it will determine, by October, whether Facebook will face legal action under European privacy laws.

The Austrian group Europe versus Facebook, which has been a thorn in the social-networking giant's European side ever since it brought various privacy issues to light and spurred an investigation by Ireland Data Protection Commissioner Billy Hawkes, just got a rather unpleasant text message. The Office of the Data Protection Commissioner (ODPC) has made it quite clear it does not have the time to talk to the watchdog group, even though the duo has been working together for months with the goal of getting Facebook to care about privacy.
You might think all of this isn't a big deal, but it's has has potential impacts for all Facebook users. Just because you don't live in Ireland, or Europe, doesn't mean you're not affected. You already have been, and you will once again be depending on what happens in the next few months.
Europe versus Facebook has been sending letters back and forth with the ODPC in order to get more information about why the laws against Facebook are not being enforced. When the group didn't get an answer, it tried calling the office. The discussion with the secretary led nowhere, and instead of a call back, the response came in the form of a text message on Friday:
Max, I know you have contacted the office. Neither the commissioner nor myself are available to speak to you. Regards Gary
Max Schrems is the founder of Europe versus Facebook. Gary Davis is the deputy commissioner. Below is a video showing Schrem's reaction to Davis' SMS:
"In a letter we finally wanted to clarify problems we experienced in the proceeding before the ODPC," Schrems said in a statement. "There is no written procedural law for the ODPC, which resulted in the ODPC 'inventing' its own rules. These 'inventions' massively weaken our position in the proceeding against Facebook: For about a year we have been denied access to all files, evidence and even the legal counterarguments by Facebook. A fair proceeding against Facebook is practically impossible under these conditions."
"At the same time this makes it impossible to asses if the ODPC has made a proper decision," Schrems continued. "The same is true for 'deals' between the ODPC and Facebook. We cannot accept this situation before an authority within the EU. Unfortunately this very likely means that there are no more chances for a fair proceeding for us in Ireland. We can currently not believe that the responsible officer can decide in an unbiased way after we have made our criticism public. It is unclear how this proceeding will go on. We will fly to Ireland next week and talk to lawyers... This means the situation will stay interesting!"
Schrems outlined the following problems his group faces while trying to communicate with the legal teams for ODPC and Facebook:
  • Facebook does not give us their counterarguments, since they said they were afraid that their arguments might be used against them at court.
  • The ODPC does not give us their legal counterarguments either. Some selected arguments will be included in the "draft decision." What will be included is based on the sole discretion of the ODPC. Facebook received our arguments from the very beginning.
  • Until now, the "raw data" we received from Facebook after we exercised our right to access was the most important piece of evidence.
  • Facebook stopped delivering such data after we published our findings, despite an obligation under the Irish and EU law to disclose such data within 40 days.
  • The ODPC is referring us to a "Download Tool" which holds some, but by far not all data, after waiting for this tool for about a year.
  • The tool does not provide the raw data (the way it is stored on the servers), but processed data which is displayed as a normal webpage. Only Facebook can decide what information is available and in what format. External control is impossible.
  • The ODPC does not see any reason enforce this right to access, despite more than 1,000 users having made complaints and 100 complaining to the EU.
  • The entire procedure is run as a "secret trail". We are generally denied to access any of the files or evidence in our own procedure.
  • We do not know about the different "deals" between the ODPC and Facebook.
  • We are not treated as a party of a legal proceeding, but like the general public.
It's understandable for Schrems to be "stunned" at the message he received. After all, the Data Protection Commissioner (DPC) is planning to publish its next Facebook privacy review in early October, when it will determine if the social networking giant will face legal action under European privacy laws. If Schrems can't properly argue his side of the case, Facebook will be able to get its way without much conflict.
For its part, the ODPC says its text message was not meant to add insult to injury:
"Europe-v-facebook performed a useful public service in highlighting the specific issues raised in its complaints," the Irish watch dog said in a statement. "We informed the organization last week that we had nothing to add to the answers we had already provided both orally and in writing and that therefore senior staff members were not available to discuss such procedural matters any further."
That doesn't cut it for Schrems. "Bad service? According to different media, the ODPC feels sorry that we did not like the "service' we experienced," he said in a statement. "The ODPC is missing the point that we are asking to basic procedural rights and not 'better service.' The ODPC does not react to the criticism that we have outlined. There is not a single word on a fair proceeding. It seems like the ODPC hopes to overcome this situation by ignoring it. On top of that the ODPC has said that it go on with the proceeding just like before. Engaged extensively? The ODPC is even claiming that it has engaged continuously and extensively with europe-v-facebook.org. This is simply wrong: Since we have filed our complaints we were in fact locked out of our own proceeding. We can only wonder about the statements by the ODPC. At the same time we are still inviting the ODPC to start engaging 'extensively' from now on. It just seems that the chances for this are not too good..."

Last month, Europe versus Facebook forced Facebook to put its new privacy policy (or rather Data Use Policy) up for a vote, by taking advantage of a loophole in the social network's own rules. The plan didn't get very far.
Facebook requires 30 percent of all users to vote for a change to be binding. Unfortunately, only 0.038 percent participated in the poll, meaning that even though most of the votes were against the change, Facebook did not have to do anything. That's despite the fact that the Data Use Policy affects everyone, not just those in Europe.
Facebook has more than 955 million monthly active users, but its U.S. headquarters is not responsible for the majority of them. Facebook's international headquarters is in Dublin, meaning all users outside of the U.S. and Canada are subject to Irish and European data protection laws. Facebook chose Dublin for the tax incentives: businesses are charged approximately 2 percent tax in Dublin compared to 35 percent tax in the U.S.
Europe versus Facebook originally made 22 formal complaints regarding the social network's practices. The group even managed to accidentally get Reddit involved, whose users overwhelmed Facebook with data requests back in September 2011. Eventually, the ODPC took notice.
This past December, the DPC completed his three-month privacy audit of Facebook's activities. Facebook promised to make a slew of changes, and agreed to a more formal follow-up review in July 2012.
The second audit will test whether Facebook has improved its privacy stance as promised, and will ensure the company is complying with European laws. "It's still all systems go, on getting this work with Facebook to an end, and from our perspective producing an output which ensures that Facebook is compliant with European data protection," Davis told Reuters. As you know, it's already the end of July, so it looks like October 2012 is the next timeframe deadline

Monday, July 30, 2012

Critics assail 1980s-era hacking law as out of step


A 1984 U.S. anti-hacking law passed when computer crime was in its infancy is under fire for potentially going too far in criminalizing the actions of employees who violate workplace policies.
Judges across the country are divided on how the 28-year-old law, the U.S. Computer Fraud and Abuse Act, can be applied. At the same time, the Justice Department has signaled it wants to ramp up prosecutions under the law, even as it has lost some cases.
Civil liberties advocates and some lawyers and judges are questioning whether the CFAA, intended to punish hackers and other trespassers who damage computer systems or steal customer information, can be used to prosecute people inside a company who download sensitive data without their employers' approval.
The debate is centered around a key phrase in the law: that it is illegal to "intentionally access a computer without authorization or exceed authorized access." Critics argue this language is too broad and vague and could turn ordinary people into criminals for things many do routinely, such as dabble in online shopping or scan an online matchmaking site at work.
"This statute has the potential to affect millions of Americans in the workplace who work at or use a computer to do their job," said Brent Cossrow, a partner at law firm Fisher & Phillips in Radnor, Pennsylvania, which specializes in computer breach cases. "Hopefully, it gets cleared up soon."
BOUND FOR SUPREME COURT?
A split decision in April by the 9th U.S. Circuit Court of Appeals in San Francisco could be the case that forces the U.S. Supreme Court to examine the law's reach.
In a 9-2 ruling, the appeals court threw out criminal charges brought under the law against David Nosal, a former managing director at executive search firm Korn/Ferry International. Nosal was indicted in 2008 for allegedly persuading colleagues to download confidential source lists and contact information from the firm to use at his new business.
Three co-defendants pleaded guilty to CFAA violations. But Nosal fought the charges, arguing that he and his colleagues had been authorized to access the company's database. The appeals court supported Nosal's argument, and threw out the CFAA charges against him, though he still faces separate charges of trade secrets theft in U.S. District Court in San Francisco.
The 9th Circuit ruling was suspended to give the Justice Department time to consider petitioning the Supreme Court to review the case. If the Supreme Court were to hear the matter, it could potentially be on the docket for the upcoming term.
The Justice Department, which declined to comment on the case, has until August 8 to decide whether to seek Supreme Court review.
Nosal's lawyer, Steven Gruel, said his client wants to exonerate himself. "He's always said he did nothing wrong."
NEW SCENARIOS
If the high court does not take the Nosal case, legal experts say, little is likely to get settled in the near future over how and when the law can be applied.
The CFAA was crafted before the Internet was omnipresent in the workplace. Employees today have vastly more sensitive company information accessible on their computers, leading to scenarios that the writers of the law may never have envisioned.
Some companies, such as Oracle Corp, which filed a brief supporting the Justice Department against Nosal, say such criminal prosecutions are justified.
Oracle said Congress rooted the statute in common-law trespass doctrines.
"Among them is the concept of restricted authorization: a person commits trespass not only when he or she enters property or a portion of it when told not to; a person commits trespass also when he or she has authorization to enter for some purposes but enters for different ones," the brief said.
Critics say the statute, which carries civil and criminal penalties, could be abused by employers.
The precedent that develops largely in the context of a private, workplace dispute "becomes something that people can go to jail for, and that's really dangerous," said Marcia Hoffman, senior staff attorney with the Electronic Frontier Foundation, a non-profit civil liberties organization.
Potential criminal penalties under the law range from one year to 10 years in prison, if the offense involves information relating to U.S. national security.
Prosecutors have brought about 550 federal criminal cases under the CFAA and related computer fraud laws in the past 5-1/2 years, according to court filings reviewed in Westlaw, a legal data division of Thomson Reuters. Over the same period, nearly 500 civil lawsuits were brought in private disputes citing the CFAA and related laws, the filings show.
The Justice Department wants to expand the penalties and prosecutions under the act, an Obama administration official told a hearing on Capitol Hill in November. Richard Downing, deputy section chief for computer crime and intellectual property, said it was important to retain the provisions of the law that apply to employee-use agreements.
Removing that section of the law "could make it difficult or impossible to deter and punish serious threats from malicious insiders," he told the Crime, Terrorism and Homeland Security Subcommittee of the House Judiciary Committee.
If the Justice Department were to go to the Supreme Court and lose over the CFAA, it would remove an arrow in its quiver for prosecuting those "insider" computer abuse cases.
Congress has partially addressed the issue while crafting new cyber security legislation. One possible amendment to a bill pending in the U.S. Senate would narrow criminal cases to exclude relatively innocuous violations of agreements governing the use of private computers, such as a social-network user signing up under a pseudonym.
MIXED RULINGS
In February, the U.S. government lost another case involving an employee who had accessed company data, a case that also raised questions about use of the hacking statute.
That case involved a former Goldman Sachs Group Inc programmer, Sergey Aleynikov, who was accused of stealing code used in the bank's high-frequency trading system before leaving for a new company in Chicago.
Before Aleynikov went on trial, U.S. District Judge Denise Cote dismissed the charges brought under the CFAA, saying the government's interpretation "could convert an ordinary violation of the duty of loyalty or of a confidential agreement into a federal offense." But she let trade-secrets charges against him stand, and in December 2010 Aleynikov was found guilty.
That conviction was thrown out earlier this year by the 2nd U.S. Circuit Court of Appeals, and Aleynikov was freed after serving one year of an eight-year prison term.
The Nosal and Aleynikov cases conflict with an earlier appeals court ruling. That case was a civil dispute between a real estate developer, Jacob Citrin, and his former employer, International Airport Centers LLC. The 7th U.S. Circuit Court of Appeals in Chicago ruled in 2006 that Citrin violated the CFAA by installing a program that deleted files on a company laptop as he was departing for another job.
Citrin was not criminally charged and his case was settled on undisclosed terms, but a Justice Department guide for prosecutors on the CFAA points to the 7th Circuit ruling as "the leading authority" for the position that when an employee is doing something disloyal to an employer, authorized access to the computer ends under the law.
Citrin's lawyers, Ronald Marmer and John Koch, of Jenner & Block in Chicago, had no comment. Citrin is now CEO of Cargo Ventures in Doral, Florida, according to his company's web site.
Unless the Supreme Court ultimately weighs in, the inconsistent decisions will continue, said lawyer John Dozier, of Dozier Internet Law, a Glen Allen, Virginia law firm.
Without clarity, he said, "what is going to be illegal in one part of the country is not illegal in the other."
The cases are USA v David Nosal in the 9th U.S. Circuit Court of Appeals 10-10038 and International Airport Centers LLC v Jacob Citrin in the 7th U.S. Circuit Court of Appeals No. 05-1522 and USA v Aleynikov, U.S. District Court for the Southern District of New York 10-00096.