Showing posts with label internet law and policy. Show all posts
Showing posts with label internet law and policy. Show all posts

Monday, September 14, 2009

Nilekani acknowledges security and privacy concerns over the UID [India - Data Protection/Privacy]

Nandan Nilekani conceded that there are “legitimate” apprehensions over the proposed Unique Identification Number database’s being vulnerable to hacking and misuse. He said that given the inclusivity, enormous opportunity and developmental benefits it will provide, Unique Identification Database (UID) project is worth the risks.
Mr. Nilekani, the chairman of Unique Identification Authority of India told Karan Thapar on CNN-IBN’s Devil’s Advocate program that the project had so many significant benefits for the poor in making it inclusive and in giving them a chance to participate in the country’s progress.To question on the possibility of the database being hacked, he said that they would have to design it as foolproof as possible by incorporating checks and balances. After saying “in every system, there will be people who will try to hack on it,” he asked if the security risks it involves are enough to do away with the project.
Responding to a question about the worthiness of spending an amount as huge as Rs 1.5 lakh crore in a country where 80 per cent of the population live under Rs 20 a day, Mr Nilkani rejected the estimation although he couldn’t spell out the exact amount. “Whatever the cost be, the social, economic and efficiency benefits of it would make it well worth it,” he said. The investment in this project would actually make all those other money be spent on education, health for women and children and sanitation programmes more efficiently. When asked whether the project will be helpful in solving the irregularities relating to the allotment of BPL cards as it can’t identify those who should have BPL cards and do not, replied that UID is not a panacea for all the problems but an enabler of more effective public delivery.

Friday, August 28, 2009

Tata Sons wins case against travel portal

Tata Sons, the holding company of the Tata Group firms, has won a case at the World Intellectual Property Organisation against the travel portal, MakeMyTrip, which has been using the term 'tata' in one of its website, 'oktatabyebye.com'. Gurgaon-based mmt admin (commonly known as MakeMyTrip) has been using the domain name 'oktatabyebye.com'.
Tata Sons has contended that it is confusingly similar to its 'Tata' brand and the travel portal runner has no rights or legitimate interests to use it. In May, Tata Sons had moved the Geneva-based WIPO Arbitration and Mediation Center demanding transfer of disputed domain name. The company had argued that the site infringed the right of its registered trademark/service mark 'Tata'. The WIPO has now ordered the transfer of domain name to Tata Sons. "The impugned website incorporates the Tata's orporate name and registered trademark in full and it proves that it is identical in part and confusingly similar to its well-known brand in which the company has a statutory right," Tata Sons had said in its complaint. Replying to the charges, MakeMyTrip had said the usage of the word 'tata' as a gesture finds its mention in the origin of a place called Ta Ta Creek as far back as in the year 1860 and denied that the domain in question is confusingly similar to the trade mark 'Tata' of the complainant. The Gurgaon-based firm stated that "the impugned domain name is derived from the common parlance 'OK Ta Ta Bye Bye' since it signifies travel, journey and related activities. But in its argument at the WIPO, Tata Sons said, 'it is apparent that the sole purpose of registering the disputed domain name is to misappropriate the reputation associated with the complainant's well-known and famous trademark Tata.'
The Internet site owner has registered a separate domain name (makemytrip.com). According to Tata Sons, both the sites offer similar services. However, MakeMyTrip says both cater to separate class of persons. While makemytrip.com offers discounts and easy access to travel plans, oktatabyebye.com lets these travelers make an online records about their journey. The WIPO is a specialised agency of the United Nations for developing a balanced and accessible international system in the field of intellectual property rights. As per details available with the WIPO, Tata Sons during the case had made an effort to settle the issue with the MakeMyTrip, which refused to accept the just demands on the grounds on 'vague reasons.'
This story was sent to us by Shri Siddharth Kumar, Press Trust of India.

Thursday, August 27, 2009

Expansion of Top-Level Domain Names opposed by INTA

The International Trademark Association (INTA) announced in its August 1, 2009 Bulletin that INTA passed a resolution to oppose the current proposal by the Internet Corporation for Assigned Domain Names and Numbers (ICANN) for an unlimited expansion of new generic Top-Level Domain Names (gTLDs).

ICANN sets and manages global policies for Internet gTLDs and has proposed expanding from the 21 existing gTLDs, e.g., .com, .org, and .net, to an unlimited number of gTLDs. A number of organizations in addition to INTA have expressed opposition to ICANN’s proposed expansion of gTLDs. Some view the new policy as a money grab. Others focus on the concerns regarding increased potential for trademark infringement and dilution and complaints that ICANN’s existing system has not been effective at protecting trademarks against cybersquatters already trading among the current gTLDs.
According to the INTA Bulletin, INTA will be issuing a revised Draft Applicant Guidebook for new gTLDs in September 2009. Text of INTA’s resolution opposing the proposed unlimited expansion of gTLDs can be found at www.inta.org.
Expansion of new gTLDs has been a hot topic among domain name and trademark professionals, including business and legal professionals and cyber entrepreneurs. If this topic interests you, consider attending Cyber Symposium 2009 in Lehi, Utah on September 25, 2009. Cyber Symposium 2009 is a full day seminar for business and legal professionals interested in strengthening their presence in the high tech industry. David Kelly, partner and chair of the trademark and copyright practice group at Finnegan, Henderson, Farabow, Garrett & Dunner, LLP, will be lecturing at the Cyber Symposium on the new gTLDs and on monetizing domain names. For more info see: www.utahcyberlaw.org.

Tuesday, August 25, 2009

Cyber Regulation Appellate Tribunal Court inaugurated [India]

The new Office and the Court Room of the Cyber Regulation Appellate Tribunal was inaugurated on July 27 [2009]. Speaking on the occasion, Mr. Justice K.G. Balakrishnan, Chief Justice of India said while administrating the regulations Tribunal will face a challenge to strike a balance between the interests of the Government and end users of internet. Highlighting the need for Tribunal, Shri A. Raja said that it will help prevent all possible cyber contraventions. Congratulating Tribunal for getting prime place to house it, Shri Sachin Pilot, Minister of State for C&IT said Tribunal is destined to a path breaking work to check cyber fraud, cyber crime and even cyber terrorism.
Speaking on the role of Department of Information Technology (DIT),Secretary, DIT said that it will facilitate and support the functioning of the Tribunal. He said in view of intermixing of legal and technical issues a multimember Tribunal has been constituted to look into the cyber contraventions. The tribunal has been established under Section 48 of the Information Technology Act. The Information Technology Act 2000 came into force on 17th October, 2000. The definition of the Information Technology Act provides as under: “Computer” means any electronic, magnetic, optical or other high speed data processing device or system which performs logical, arithmetic, and memory functions by manipulations of electronic, magnetic or optical impulses, and includes all input, output, processing, storage, computer software, or communication facilities which are connected or related to the computer in a computer system or computer network; Section 3 of the Act provides with regard to Digital signature and the Authentication of electronic records. Section 4 provides the legal recognition of electronic governance in short known as E. governance.
For adjudicating of the dispute under the Information Technology Act, Section 46 was enacted which has given the power for adjudication of the crimes. The power has been give to the Secretary, Information Technology and he has power to adjudge the quantum of compensation under Sections 46 and 47 of the Act. Section 46 provides for appointment of an adjudicating officer not below the rank of a Director to the Government of India. Every adjudicating officer shall have the powers of a civil court, which are conferred on the Cyber Appellate Tribunal under Section 48. The Act provides for penalty for damage to computer, computer system etc: penalty for failure to furnish information return; residuary penalty and publishing information which is obscene in electronic form etc.

Monday, April 06, 2009

New York District Court Rules That State Common Law Copyright Claims Are Not Barred by the Communications Decency Act [United States]

The Southern District of New York issued a ruling in Atlantic Recording Corp. v. Project Playlist, No. 1:08-cv-03922-DC, denying Defendant Playlist’s motion to dismiss Plaintiffs’ state law copyright infringement and unfair competition claims. In its ruling, the Court found that the Communications Decency Act ("CDA") does not apply to state or common law copyright claims (such as those that protect sound recordings fixed prior to 1972). The recent decision diverges from the Ninth Circuit’s 2007 ruling in Perfect 10, Inc. v. CCBill, LLC., 488 F.3d 1102 (9th Cir. 2007), which suggested that the exception to the statutory immunities of the Communications Decency Act for claims "pertaining to intellectual property" might not reach (and thus the CDA would bar) state or common law claims that involve or relate to intellectual property or related rights.


Project Playlist involved claims brought by six record labels (affiliated with the Warner Music Group and the Universal Music Group), against the owner and operator of a website that enables and allows users to search, play, share, and download music available on the Internet. In addition to claims for direct and secondary liability under federal copyright law, Plaintiffs asserted claims for common law copyright infringement and unfair competition under New York state law with respect to Defendant’s infringement of Plaintiffs’ pre-1972 sound recordings. (There is no federal copyright protection for sound recordings produced before February 15, 1972. 17 U.S. C. 301(c).) In response to the Complaint, Defendant moved to transfer venue to the Northern District of California. In the alternative, Defendant moved to dismiss Plaintiffs’ state law claims for common law copyright infringement and unfair competition as barred by the CDA, 47 U.S.C. § 230.

Congress passed the CDA in 1996 with the goal of protecting minors from obscene online content. In order to avoid stunting the Internet’s growth, the Court also immunized Internet service providers from liability based on certain communications by users of the services. That immunity was codified in Section 230(c)(1), which provides that "[n]o provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider." The CDA defines "information content providers" as companies that play a role in the creation or development of content. In other words, persons or entities that create or develop content to be disseminated on the Internet may be subject to liability for that content, while those who merely transmit or publish that content ("interactive computer services") cannot be held liable.

The relationship between the immunities of the CDA and claims for infringement or violation of state or common law intellectual property rights has been a matter of some controversy.

Under Section 230(e)(2), the CDA shall have "[n]o effect on intellectual property law. Nothing in this section shall be construed to limit or expand any law pertaining to intellectual property." In CCBill, the Ninth Circuit held that the Section 230(e)(2) carve-out was limited to federal intellectual property law, and thus would not apply to state law right of publicity claims, even though such claims arguably involved "intellectual property" rights. By contrast, in Universal Communication Systems, Inc. v. Lycos, Inc., the First Circuit, considering a state law trademark dilution claim, reasoned that "[c]laims based on intellectual property laws are not subject to Section 230 immunity." 478 F.3d 413 (1st Cir. 2007). In an effort to avoid liability for its role in copying and disseminating pre-1972 sound recordings, Project Playlist argued that it was an "interactive computer service" and thus immune from liability under the CDA. Noting that this was an issue of first impression in the Second Circuit, the Court relied on First and Third Circuit precedent to find that "an interactive computer service is not liable where it posts or links to a third-party’s content." The Court concluded that Playlist is an "interactive computer service" and thus (as a threshold matter) fell within the broad scope of the CDA because it "merely creates an interface for users of Playlist’s Website to listen to third-party content, and also provides links to download third-party content."

The Court then turned to the second issue: Whether the CDA’s exception or carve-out for "any law pertaining to intellectual property" would apply to state law or common law copyright claims. Citing CCBill, Playlist argued that the carve-out only applies to federal intellectual property law, and thus the CDA necessarily would bar the Plaintiffs’ state law claims for the pre-1972 sound recordings. The Court disagreed, finding that to limit the Section 230(e)(2) carve-out solely to federal claims was contrary to the plain language of the statute, as well as the intent of Congress:

The problem with Playlist’s argument is that it lacks any support in the plain language of the CDA. In four different points in Section 230(e), Congress specified whether it intended a subsection to apply to local, state, and federal law.... It is therefore clear from the statute that if Congress wanted the phrase "any law pertaining to intellectual property" to actually mean "any federal law pertaining to intellectual property," it knew how to make that clear, but chose not to.
As a result, the Court concluded, unambiguously, that "as a matter of law... Section 230(c)(1) [of the CDA] does not provide immunity for either federal or state intellectual property claims." This conclusion, if adopted by other courts, could give a boost to the viability of a range of state law claims related to intellectual property - such as common law misappropriation, right of publicity, and state or common-law trademark law claims - brought against the operators of various online services.

Google Must Face Trademark Suit Involving Keyword Ads [2nd Circuit; United States]

In a long-awaited opinion, the 2nd U.S. Circuit Court of Appeals ruled that Google must face a trademark infringement lawsuit for selling keywords that trigger ads.

The three-judge panel reversed a lower court's dismissal of Rescuecom v. Google, 06-4881, in which computer-repair company Rescuecom had claimed that users could be confused by links to competitors' ads that appear alongside Google search results for the company's trademarked name.

Google had persuaded the lower court to toss the case, arguing that its use of Rescuecom's trademark was internal and not a "use in commerce," which constitutes trademark infringement. The dismissal was hailed as a big victory for Google and other search engines, for which keyword advertising is a lucrative business.

The appeals court ruled Friday that "Google's recommendation and sale of Rescuecom's mark to its advertising customers are not internal uses," sending the case back to the trial court. IP lawyers had been anticipating the decision because of mixed rulings on keyword cases.

In dismissing the case, the lower court had relied on 2nd Circuit precedent in the watershed case of 1-800 Contacts v. WhenU.com., which found that 1-800-Contacts didn't have its trademark infringed by keyword advertising sales. In Friday's ruling, the 2nd Circuit expended considerable effort explaining how the Rescuecom case is different. The 2nd Circuit decision doesn't offer that many answers about the legality of keyword advertising. Rescuecom and others will still have to prove their trademarks were infringed in the end.

Wednesday, April 01, 2009

India ranks fifth in reporting cyber crime cases

India ranks fifth among countries reporting the maximum number of cyber crimes, the latest report released by Internet Crime Complaint Centre of the United States has said.

The US report analysing internet crime in 2008 compiled by experts from FBI, Internet Crime Complaint Centre (IC3) and other agencies shows the number of complaints from victims shot up by almost a third since 2007 with the total touching 275,284 cases in which about USD 265 million were lost globally.

The United States led the tally of victims' complaints, while India remained at fifth by reporting 0.36 per cent of the global complaints received at IC3 which was about 1,000 complaints, the data said.


Majority of the fraudsters on the information highway, this year, resorted to the trick of selling products online but not delivering it to buyers who had already made payments.
It remained the most adopted method to cheat during the year with 33 per cent of internet crimes of this nature being reported, according to the report.

Cyber crimes record 50 percent rise in India

With India being home to the fourth highest number of internet users in the world, cyber crimes under the the Information Technology (IT) Act recorded a whopping 50 percent jump in 2007 over the previous year. What's more, the majority of offenders were under 30 years of age.


Cyber crimes have emerged as a new class of crimes, rapidly increasing due to extensive use of the internet and IT enabled services. The maximum cyber crime cases, about 46 percent, were related to incidents of cyber pornography, followed by hacking. In over 60 percent of these cases, offenders were between 18 and 30, according to the "Crime in 2007" report of the National Crime Record Bureau (NCRB).

Cyber crimes are punishable under two categories - the IT Act 2000 and the Indian Penal Code (IPC). The report says that 217 cases of cyber crime were registered under the IT Act in 2007 compared to 142 in 2006 - an increase of 50 percent. Under the IPC too, 339 cases were recorded in 2007 compared to 311 cases in 2006.

"Seventeen out of 35 mega cities have reported nearly 300 cases of cyber crimes under both categories, thereby recording an increase of 32.6 percent in a year," the report says. The report indicates that cyber crimes are no longer limited to metro cities. "Bhopal in Madhya Pradesh has reported the highest incidence of cyber crimes under IPC sections, thus accounting for 87.8 percent of the total crimes in the country," the report says.

Thursday, October 30, 2008

ICANN to allow new top-level domains – warning to brand owners

The Internet Corporation for Assigned Names and Numbers (ICANN) is responsible for the allocation of all top-level domain names. There are presently only a limited number of top-level domains (e.g. .com, .net, .org etc) but ICANN has announced it intends to open the market for any person to create new top-level domains of their choosing.
ICANN has issued a draft "Applicant Guidebook" on which it is inviting comments. The draft guidebook may be seen here. ICANN is inviting comments from the public on the draft guidebook, and states that it will receive comments for 45 days (from 24 October 2008). The draft guidebook states that, during the (as yet undetermined) application period, any "established entity" from any country may apply to operate a top-level domain. The top-level domain proposed may either be an "open" domain, which is available to any type of applicant, or a "community based" domain, which must relate to an identifiable and pre-established community that has endorsed the registration of the domain. The application must show that the applicant will have a dedicated registration and use policy, and that the applicant has the operational, technical, financial and organisational capability to maintain the top-level domain proposed. The draft guidebook states that the proposed registration fee for the new top-level domain will be $185,000. Of particular interest to brand owners, the draft guidebook contains details of the proposed objection mechanism which will allow interested parties to challenge the registration of a new top-level domain. The proposed grounds of objection are:String Confusion Objection – existing operators of top-level domains can complain that a domain applied for is confusingly similar to an existing top-level domain; Legal Rights Objection – a "rightsholder" (which is not defined, but this is likely to mean a trade mark owner or someone with unregistered trade mark rights/reputation) may complain that a domain applied for infringes their rights; Morality and Public Order Objection – the parties who may complain about a domain applied for which is contrary to morality and public order are yet to be determined by ICANN, but they may be limited to Government bodies; and Community Objection – an "established institution" within a defined community may complain about a domain applied for which may be targeted at such community if a significant part of that community substantially objects to the application. The draft guidebook contains a long description of the proposed procedure to be followed if objections are raised to top-level domain applications. The procedure will involve arbitration with set rules similar to a UDRP arbitration that is operated by one of a number of providers (e.g. WIPO). The cost of the procedure is not outlined in the draft guidebook, but it is proposed that String Confusion and Legal Rights Objections should be dealt with by the arbitration provider for payment of a fixed fee, and other Objections should be dealt with for payment of an hourly rate. There is no procedure proposed to notify brand owners if a top-level domain is applied for which features a registered trade mark. As a result, brand owners will need proactively to monitor ICANN's website to see the applications that have been made. There is only a limited time period proposed in the guidebook during which objections may be made to applications. It is therefore very important that brand owners wishing to object to applications do so within the required time period. Otherwise, costly court action might be the only remedy available to brand owners after the new top-level domain is approved. Further information about the proposals may be seen on ICANN's website.

Monday, July 21, 2008

Cybersquatting: Don’t let your IP slip through the net

Cybersquatting is the practice of registering domain names incorporating trade marks of third party companies and then trying to sell the domain name back (for a handsome profit) to the trade mark proprietor. It's not going away - it's growing and it's a huge problem for trade mark proprietors.

The number of domain name disputes lodged in terms of the Uniform Domain Name Dispute Resolution Procedure (UDRP) that applies to .com, .net and .org domain names increased by 18% in 2007 compared to the number filed in 2006 and by 48% versus the number lodged in 2005.
The increase can be attributed to:
The rise of "pay-per-click" advertising, whereby cybersquatters associate the domain name they have registered with a website containing adverts promoting a variety of competing brands. Every time Internet users access this website and click on one of the adverts, the cybersquatter receives money.
Domain tasting, whereby cybersquatters register a number of domain names and then wait several days before paying for the domain names. They then count the domain names that attract the most Internet users and then pay for only for those. The remaining domain names are then deleted. Problem is, in the period between the cybersquatter registering and paying (or does not pay) for the domain name, it is reflected as being registered.
The use of privacy services by cybersquatters, who are thereby able to register domain names without revealing their identity to the general public. Cybersquatters can thus remain anonymous while trade mark proprietors must go to great lengths to establish the cybersquatter's identity.
There are a number of steps that companies can take to combat cybersquatting, the most important of which is to develop a domain name registration and conflict policy.
Such a policy would clearly identify relevant criteria to determine which domain names should be registered, whose responsibility it is to administer them and in which countries they should be registered.
As a general rule, companies should ensure that companies register their trade marks and trading names in the countries in which they trade, thereby preventing third parties from launching a website to sell competing goods and services under a domain name identical to a company's trade marks and trading names.
Not only should a company continually ensure that its most important trade marks and trading names are registered as domain names, but it should continually monitor what domain names have been registered that incorporate its trade marks and trading names.
In short, companies must monitor the domain name space to check what domain names have been registered that might incorporate their trade marks and domain names.

Thursday, May 29, 2008

Staff of Deutsche Telekom suspected of privacy breaches [Germany]

Security staff at the German phones giant Deutsche Telekom are suspected of breaching German data privacy laws during a secret attempt to identify the sources of high-level leaks to the media, the company said Saturday. Using the company's own records of millions of numbers dialled, the dates and the durations, the internal-security unit had hunted for possible matches between news reporters and Telekom directors.


Both public prosecutors and a German law firm have been assigned to investigate the suspected breach three years ago of German data- retention laws. Bonn-based Telekom said it had purged the security department last year to ensure it operated within the law.

The scandal was first reported Saturday morning by the German news weekly Der Spiegel in advance of its Monday issue. Telekom, one of the biggest companies on the German stock market, remains one third in federal ownership. Its affairs are closely followed by the German news media, which have often reported leaks from authoritative sources. Spiegel said the corporate security division had suspected senior executives or supervisory board members might be to blame.


Telekom said calls were not actually tapped, but the billing data had been illegally accessed in 2005 and "according to new claims" in 2006 too. Chief executive Rene Obermann said, "We're taking this very seriously. We have reported it to the public prosecutor."


In recent years German companies whose shares are traded in the United States have adopted the US practice of investigating and publicizing criminal actions within their own bureaucracies.

Monday, May 19, 2008

Chewing Gum Trademark Suit Sent Back to District Court [United States]

A nearly decade-long dispute over the use of formulas for Bazooka bubble gum and other products made by Topps Co. is headed back to a district court following a decision by a federal appeals court.


The 2nd U.S. Circuit Court of Appeals reversed Southern District of New York Judge Charles Haight, finding that he erred in granting summary judgment to Cadbury Stani S.A.I.C. over rights to the formulas in parts of South America.

The decision in The Topps Co. Inc. v. Cadbury Stani, 06-5316-cv. was made by 2nd Circuit Judges Richard Cardamone and Rosemary Pooler and, sitting by designation, Southern District Judge John Keenan. Cardamone wrote for the panel in finding that the case was not ripe for summary judgment.

Topps began licensing the rights to make, sell and distribute Bazooka and other Topps brands in Argentina, Bolivia, Chile, Paraguay and Uruguay to Cadbury Stani in 1957. In exchange for royalties on Stani's sales, the company promised to share "the know-how, formulae, processes and techniques used by Topps."

In 1976, Topps and Stani reached a new agreement that called for the continued sharing of "manufacturing technology, marketing concepts and techniques, administrative and consultive assistance and trademark use" in exchange for license fees. Under this agreement, Stani would be able to sell "licensed products utilizing Topps technology."

The companies reached an amended license agreement with nearly identical language in 1980, at the same time signing an escrow agreement that called for the holding in escrow of stock certificates in an entity called Verco Holding Corp. until 1996, when they would be transferred to Stani's owner.

Stani agreed to pay $100,000 to Topps in exchange for the transfer under the agreement, which stated in the preamble that "Topps has transferred legal title to the registration in Argentina of the trademarks 'Bazooka', 'Topps' and other trademarks to the Verco Holding Corp."

The license agreement expired in 1996. Topps filed suit in 1999, claiming Stani continued to use its chewing gum formulas and that it had transferred those formulas and other Topps technology to its parent company, Cadbury. Topps claimed this was a violation of the 1980 licensing agreement.

Haight found that Stani retained the right to use the formulas after the expiration of the agreement in 1996. He granted Cadbury Stani summary judgment after finding Stani had not misappropriated trade secrets and had not breached the contract.

Tuesday, April 01, 2008

EU Debates Cybercrime Law Enforcement [International]




One of the beauties, if you can call it that, of organized crime is that while the criminal organizations of the world respect none of the boundaries that we call jurisdictions and countries, and by definition, the rule of law must respect those boundaries. These criminals, whether they are the traditional mob that we all know and love or the terrorist organizations bent on the destruction of civilization as we know it, have for more than a decade or two have known about and exploited this fact.

Two groups working separately to boost Europe's defenses against online crime will present proposals this week, almost a year after most of the nation of Estonia's links to the Internet were disrupted for days or weeks. At a two-day conference starting today in Strasbourg, France, the Council of Europe will to review implementation of the international Convention on Cybercrime and discuss ways to improve international cooperation.

Cyber defense also will be on the agenda when heads of state from NATO's 26 member nations gather in Bucharest Wednesday for three days. The leaders are expected to debate new guidelines for coordinating cyber defense.

The Convention on Cybercrime, a binding treaty ratified by most members of the 47-nation Council of Europe, provides guidelines to protect computer users against hackers and Internet fraud.

The controversial agreement also covers electronic evidence used in prosecution of such offenses as child sexual exploitation, organized crime and terrorism. At this week's conference, the council will discuss guidelines to bolster the convention to improve cooperation between investigators and Internet providers, according to the council's Web site.

Participants and speakers at the conference — including police officials and representatives of technology companies such as Microsoft Corp., eBay Inc., McAfee Inc. and Symantec Inc. — also will address training.

NATO's three-day summit, which is to focus on enlarging the treaty organization and on its operations in Kosovo and Afghanistan, will include a special briefing on cyber defense, according to the treaty organization's Web site.

Some cybercrime experts are casting current Internet security challenges in terms of terrorism, while others remain focused on data loss, identity theft and fraud.

Privacy advocates, the American Civil Liberties Union and others are concerned that the Cybercrime Convention presses businesses and individuals to aid law enforcement in new ways and subjects them to surveillance that violates the U.S. Constitution.

President Bush signed the treaty in 2003 and the U.S. Senate ratified it in 2006. The convention has been ratified by 21 other nations.


Useful Links:
http://www.google.com/url?q=http://www.coe.int/cybercrime&usg=AFQjCNFRIQBFwSOvy5Gpd8lfTfoYxSix-g
http://www.google.com/url?q=http://www.nato.int/docu/update/2008/04-april/e0402b.html&usg=AFQjCNEsZbPAK5f7EORqcFz-SlqBBAKqbw

Crime, CyberSpace and the Singapore Model [International - Internet Law]

The Government of Singapore has devoted significant effort to combating computer crime. It passed legislation in 1993 and periodically amends this legislation as needed. It has created new agencies and given its law enforcement personnel greater powers in its fight against these crimes.
This has lead to both a proliferation of computer-based crime in Singapore and to efforts by the Singaporean government to combat such crime. The primary tool for law enforcement officials in Singapore is the Computer Misuse Act which was passed in 1993 and has been amended four times, as recently as 2005.Singapore has chosen to follow the model of the United Kingdom by enacting legislation that addresses computer crime and utilizing the existing Penal Code for cyber crime. Computer crime is dealt with in Singapore’s Computer Misuse Act. This law prohibits the obtaining of unauthorized access to computer material, modifying the contents of a computer, obtaining or intercepting any computer service or function, interfering with or obstructing the lawful use of a computer, impeding or preventing access to or impairing the usefulness or effectiveness of any computer program or data, or disclosing a password, access code, or other means of gaining access to a program or data.
Professor Warren Chik, a Singaporean law professor states, in a 2006 paper comparing cyber crime laws in the United States, the United Kingdom and Singapore, that Singapore adopted four approaches in combating computer crime.
These are:1) Passing new legislation that creates crimes where activity warrants it;2) Imposing severe penalties as punishment and as deterrents;3) Providing law enforcement agencies with additional powers, granting them extra-territorial jurisdiction, and creating new agencies with specially trained experts to deal with this technological crimes;4) Making it a crime to abet or even to attempt to perpetrate computer crimes.The agencies created to fight computer crime in Singapore include the Computer Crimes Branch of the Criminal Investigation Department, the Computer Forensics Branch of the Singapore Police, and the Singapore Computer Emergency Response Team. The creation of these specialized units was deemed necessary as a result of the ever more sophisticated nature of the technology involved in such crimes.What is “computer crime” and what is “cyber crime”?
Computer crime involves acts that attack the functions of a computer, access to a computer or the Internet, and similar items. They might be called “cyber-trespass”. They are viewed as crimes against a computer. Examples of these crimes are hacking, denying another access to Internet usage, and sending unsolicited or virus-causing electronic mail. Cyber crime, on the other hand, is traditional crime such as fraud, theft, extortion, and the like in which the computer is used as an instrument of the crime. These acts are traditional crimes that are facilitated through the use of a computer.
How has Singapore addressed these two types of crime?In 1993, Singapore passed the Computer Misuse Act (Chapter 50A of the Singapore Statutes), which it has amended four times, as recently as 2005. This Act addresses computer crimes and provides for stiff penalties for the violation of the law. It has applied its existing Penal Code provisions for activities that are deemed cyber crime. For example, the release of a virus would fall under the jurisdiction of the Computer Misuse Act, whereas an economic crime (e.g. extortion or securities fraud) would fall under the aegis of the Penal Code.What are the penalties for conviction of computer crime in Singapore?
Most of the provisions of the Computer Misuse Act carry a maximum fine up to $10,000 Singaporean dollars and/or imprisonment up to three years for a first offense. For the second and subsequent offenses, the penalty is a fine up to $20,000 Singaporean dollars and/or imprisonment up to five years. If there was damage caused as a result of the crime, the penalty is a fine up to $50,000 and/or imprisonment up to seven years. If the crime involved a threat to Singapore’s security, or to the banking or other financial, communications, or transportation industries, or to public services including utilities, safety, police, civil defense, or medicine, the penalty is a fine up to $100,000 Singaporean dollars and/or imprisonment up to 20 years.In what other manner is Singapore fighting computer crime?Singapore has created new law enforcement agencies with specially trained personnel to keep pace with the rapid advances in technology and the resulting proliferation of computer-based crimes. It has given its police force additional powers, including extra-territorial jurisdiction to aid in their efforts at apprehending computer-based criminals.

Monday, March 31, 2008

Yahoo! Supports OpenSocial; Yahoo!, MySpace and Google to Form Non-Profit OpenSocial Foundation [International]

Yahoo!, MySpace, and Google today announced they have agreed to form the OpenSocial Foundation to ensure the neutrality and longevity of OpenSocial as an open, community-governed specification for building social applications across the web. Yahoo!'s support of OpenSocial and role as a founding member of the new foundation are landmarks for the rapidly growing specification which will now offer developers the potential to connect with more than 500 million people worldwide.

The OpenSocial Foundation will be an independent non-profit entity with a formal intellectual property and governance framework; related assets will be assigned to the new organization by July 1, 2008. The foundation will provide transparency and operational guidelines around technology, documentation, intellectual property, and other issues related to the evolution of the OpenSocial platform, while also ensuring all stakeholders share influence over its future direction.

The OpenSocial Foundation website at www.opensocial.org will serve as the portal for the community to find all information about OpenSocial and the foundation as they evolve. Developers and website owners can now visit www.opensocial.org for the latest specifications, links to other resources, and the opportunity to get involved.

Engineers from Yahoo!, MySpace, and Google will continue to work together and with the OpenSocial community to further advance the specification through the new foundation, continuing several core elements of OpenSocial since its announcement by Google, MySpace, and many others in November 2007:
· all specifications are available under a Creative Commons copyright license
· public community involvement shapes the specification's direction
· an open source reference implementation called Shindig is being created and developed as a project in the Apache Software Foundation incubator, available at http://incubator.apache.org/shindig/

About OpenSocial
OpenSocial addresses an emerging problem for developers who are eagerly building applications people can enjoy with their friends: before OpenSocial, if a developer built a "favorite photos" application to work on one social network, it would have to be built all over again to work on another site. OpenSocial tackles this problem at its technology ro, providing common "plumbing" that lets social applications run on many different websites without requiring duplicate work from either developers or the websites.
The result is a vast distribution platform for social applications, whether they are for sharing photos or playing games or arranging real-world meetings or any number of other activities ' everything is more fun, interesting, and useful when users can involve their friends and contacts.

Steady Evolution, Important Milestones
Millions of people around the world are beginning to see the benefits of the OpenSocial platform as new features appear on their favorite social networks. MySpace launched the MySpace Developer Platform, which uses the OpenSocial APIs, and began rolling out applications to its users. orkut has also started making OpenSocial applications available to its users, and hi5 will do so at the end of March.

Thanks to the Shindig reference implementation, most websites can have a proof of concept of OpenSocial applications up and running in days. That means websites need only to make this small time investment in order to make thousands of new social features available to their users.

Global members of the OpenSocial community include Engage.com, Friendster, hi5, Hyves, imeem, LinkedIn, Ning, Oracle, Orkut, Plaxo, Salesforce.com, Six Apart, Tianji, Viadeo, XING, and others. In time, OpenSocial will unlock more powerful and pervasive social capabilities across the entire web, as developers' applications can easily reach users across any of the websites, web applications, or social networks they use.

Thursday, March 27, 2008

German court tightens up ISP, phone data retention rules

Germany's highest court apparently had memories of Nazi and Stasi abuses in mind when it ruled on a series of surveillance and data privacy cases this year. In the most recent ruling, made in Karlsruhe, the Constitutional Court found that Germany's recent data retention directive targeting ISPs and telephone companies was problematic; going forward, the data retention will still be mandatory, but the information can only be accessed with a warrant and only for serious crimes.

Germany's law went into effect last December, and it ordered telecommunications companies to keep various kinds of data (e-mail addresses, numbers dialed, etc.) for at least six months and to turn this information over to investigators who requested it.

30,000 Germans promptly filed a class-action suit over the law, concerned about the implications of data retention. Could the data be used in any investigation, for instance, such as copyright infringement cases or file-sharing? Would it make personal information too easy for law enforcement to obtain?

The court found that parts of the law were unconstitutional. In its ruling, it upheld the retention requirement but instituted much stricter safeguards around who might get access to the information.

The ruling follows other, similar rulings this year. Last week, the court also struck down indiscriminate license plate monitoring in the states of Schleswig-Holstein and Hesse, saying that authorities needed to have a reason for running people's plates. The court hoped to prevent the creation of automated systems that track movement around the country.

In late February, the court also ruled on the matter of police spyware. German authorities and intelligence agencies had developed spyware (much like the FBI in the US has done) that can monitor suspects' computers and remotely glean information from their hard drives. The court said that judicial oversight of this process was required, and it also carved out areas that cannot be examined. Police are not allowed to include unrelated personal information in their investigations of suspects. This is similar to restrictions faced by traditional surveillance, where authorities have to cut a phone tap if suspected terrorists start talking religion.

Keeping up appearances?
While the decisions have all favored privacy rights, the court did not altogether eliminate remote computer snooping or data retention. They can continue under certain conditions, but the fact that the court does keep whacking away bits of legislation on these issues leads some German observers to wonder why such boundary-pushing legislation continues to get passed. One might ask the same question about video game violence laws in the US, which have been repeatedly struck down by courts but continue to pass legislatures around the country.

The answer in both cases seems to be that it's politically more expedient to look "tough" on crime, violence, and terrorism and then leave the courts to sort out what's actually constitutional. Such votes rarely have negative political consequences; though can end up costing governments plenty of money when the rules end up in court.

Sunday, March 02, 2008

Free Speech, Privacy and Wikileaks [International]

Free speech advocates immediately hailed as a victory the decision on Friday of a federal judge to withdraw a prior order turning off the Web address of the site Wikileaks.org. But the reasoning of United States District Judge Jeffrey S. White also means that the court may dodge having to grapple with some of the meaty First Amendment questions posed by the case and touched on repeatedly at a lengthy hearing in San Francisco.

The lawsuit, brought by a Swiss bank and its Cayman Islands subsidiary against Wikileaks and Dynadot, the San Mateo, Calif., company that is the registrar for the domain name Wikileaks.org, became a cause célèbre for organizations like the American Civil Liberties Union, Public Citizen and the Electronic Frontier Foundation. Such organizations responded with a barrage of court filings in the wake of an order signed by Judge White last month that required Dynadot to disable the Wikileaks.org address, making it more difficult – but far from impossible – for Internet users to get to materials published by Wikileaks.
The bank, Bank Julius Baer & Co., claimed that Wikileaks had displayed confidential, personally identifiable account information of its customers, as a result of possibly criminal actions by a former employee. Lawyers for the bank on Friday repeatedly told Judge White that Julius Baer clients had a right to keep their account information private and that there was no compelling interest to justify their disclosure. In this way lawyers for the bank set up a conflict between freedom of speech and the right to personal privacy.
After hours of discussion that suggested the judge’s level of concern with reaching the correct outcome, Judge White looked unhappy that he could not think of a way to help the bank customers affected by the release of the documents. But he said that he feared the initial order suspending Wikileaks.org raised serious questions of unjustified prior restraint on free speech, and that in any event, once the documents were online, the court might well be powerless. “Maybe that’s just the reality of the world that we live in,” Judge White said. “When this genie gets out of the bottle, that’s it.”