Showing posts with label courts. Show all posts
Showing posts with label courts. Show all posts

Wednesday, August 15, 2012

Parking Ticket Privacy

Imagine getting a $20 parking ticket and then filing suit against the issuing municipality for exposing too much personal information on that ticket.  That’s exactly what Jason Senne did after receiving a $20 parking ticket in 2010 for illegally parking his car overnight in the Chicago ‘burb of Palatine, Ill.  His name, address, driver's license number, date of birth, height and weight all appeared on the ticket, which was placed on his windshield in full public view.  Senne's complaint alleged that disclosure of his identity was in violation of the Driver’s Privacy Protection Act of 1994 (DPPA).  DPPA requires that all states protect a driver's name, address, phone number, Social Security number, driver identification number, photograph, height, weight, gender, age, and specific medical or disability information.  Congress passed the privacy legislation in response to the death of actress Rebecca Schaeffer.  She was killed by a stalker who had gotten her unlisted home address through the California DMV.  In Senne’s case, initially a federal judge found that an exception for law enforcement protected the village's actions, and a 3-judge panel of the 7th Circuit affirmed that last year.  Senne pushed and the full federal appeals court agreed to rehear the case.  Last week, the full federal appeals court decided Monday that ‘the parking ticket at issue here did constitute a disclosure regulated by the DPPA.’

In a 7-4 ruling, the appeals court said that it didn’t matter if someone walking by happened to notice the personal info – just the fact that it was exposed in such a public manner was enough.  The earlier district court decision, in favor of Palatine Village, was based on the notion that a ‘disclosure’ was when an entity turned over information to someone else without consent and was not considered disclosure.  In this case, there was no direct handoff, just the ticket flapping on the windshield/wiper blade in plain sight.  In the overturned ruling, the divided court  felt that there was real risk, safety and security concerns at stake.  A stalker looking for a target could just hang out where overnight parking is banned and collect a bunch of potential victim’s info for future harassment.  The recent court’s interpretation of the law might also expose Palatine to a hefty $80 million fine.  Since there is a 4 year statute of limitations on private lawsuits and each privacy violation carries a $2500 penalty, all those tickets issued during that time frame with the protected info could be in play.

It’s an interesting case about privacy and how others, without malicious intent, may expose personal, sensitive details about an individual.  While identity theft due to electronic means, like data breaches, is on the rise, stolen wallets or physical documents (dumpster diving) still account for a good percentage of ID theft crimes.  Back in 2009, a Javelin study indicated that stolen wallets and physical documents accounts for 43% of all identity theft (pdf) which means we still need to shred our printed materials. 

ps

References:

Technorati Tags: F5, smartphone, integration, byod, Pete Silva, security, business, education, technology, application delivery,ipad,mobile device, context-aware,android, iPhone, web, internet, security

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, November 28, 2011

Cloud Copyright, Capital and The Courts

In 2006, Cablevision was developing a service which allowed customers to record, pause and replay their television content on/from servers located at Cablevision’s data center rather than on the customer’s Digital Video Recorder itself – in the cloud rather than on a local hard drive.  A consortium of U.S. television and copyright holders challenged Cablevision in court arguing that Cablevision’s Remote Storage Digital Video Recorder (RS-DVR) infringed on copyrighted content laws in that, they were making copies of protected works and infringing on exclusive right of reproduction; briefly buffering/storing that content also infringes on exclusive reproduction rights; and by transmitting the data back to the customer, they were infringing on exclusive rights to public performance.  In 2007, a district court found in favor of the copyright owner but in 2008, the decision was reversed by the Second Court of Appeals.  The court clarified that Cablevision was not directly infringing copyright by offering a remote DVR service outside the customer’s home.  Viewers could now record and save authorized TV content on a device within Cablevision’s infrastructure.

This ruling, according to Josh Lerner, Harvard Business School’s Professor of Investment Banking, had a huge impact on U.S. venture capital moving to cloud computing.  A risk was removed.  In Europe, where the ruling had no authority, the venture investments in the cloud were much less.  This is an important economic topic and ruling due to the relationship between venture, innovation and job growth.  The ruling might also be relevant in Australia where Optus is facing the same legal challenge today.  They started a service in July called Optus TV Now that does essentially the same thing as Cablevision’s.  Allowing customers to record and watch the 15 free-to-air stations that are available.  Customers can watch the content directly or over their smartphone or computer via the internet.  In their July announcement they even included, ‘it is a breach of copyright to make a copy of a broadcast other than to record it for your private and domestic use. Optus accepts no responsibility for copyright infringement.’  Well, the owners of the copyright material being stored and retrieved are saying breach, especially the AFL and NRL, the football and rugby leagues.  Optus is saying it’s no different than people recording on a personal DVR at home.  It’ll be interesting to follow this.

Back to the ‘funding the cloud’ story.  Lerner’s study, 'The Impact of Copyright Policy Changes on Venture Capital Investment in Cloud Computing Companies,' he examines the impact and effect of the US Second Circuit Court of Appeals decision.  The authors found that the decision led to additional incremental investment in U.S. cloud computing companies compared to Europe.  Figure 1 of their paper:
vc emea cloud

The same growth did not occur in Europe and in some cases, these types of services have been blocked from even getting to market.  Imagine how much different services from Amazon, Apple and Google would be if the court did not reverse the 2007 ruling.  

ps

Related:
Technorati Tags: F5, costs, integration, cloud computing, Pete Silva, security, business, venture capital, technology, application delivery, cloud, emea, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, December 2, 2010

Got a SSN I can Borrow?

Apparently, I can use my own name and your Social Security Number to get a job or buy a car and it is not an identity theft crime.  Really.  This is according to a recent Colorado Supreme Court ruling.  They ruled that, ‘that using someone else’s Social Security number is not identity theft as long as you use your own name with it.’  Seriously.  The case in question involved a man who used his real name but someone else’s Social Security number to obtain a car loan.  The court said that since he used his real name, along with other identifiable pieces of information, he wasn’t trying to impersonate someone else.  The SSN info was just the ‘lender’s’ requirement and not a ‘legal’ requirement.  The defendant said that he fully intended to pay the loan back and wasn’t trying to avoid the bills.  There was another case where a man used a fake SSN to get a job at a steel plant in Illinois.  He presented a Social Security card with his name but a fake SSN.  Since he didn’t know that the number was fake and belonged to another person, the US Supreme Court ruled that he also didn’t break any federal ID theft laws since he did not ‘knowingly’ use another person’s number.  He just ‘borrowed’ it.  He could have just written 9 random numbers that may or may not have been tied to someone’s identity or he could have bought it from a broker, not knowing it was either fake or stolen.

These decisions contradicted previous rulings in Missouri, California, the Midwest, the Southeast and many other regions.  It also left folks scratching their heads wondering just what were the courts thinking.  Their logic is that, ‘(The suspect) claimed that the government could not prove that he knew that the numbers on the counterfeit documents were numbers assigned to other people….The question is whether the statute requires the government to show that the defendant knew that the ‘means of identification’ he or she unlawfully transferred, possessed, or used, in fact, belonged to ‘another person.’ We conclude that it does.’  I understand that there is a fine legal line between malicious intent and an uninformed accident but if you make up a number or obtain it by improper means, it’s still fake, false and fraudulent.  I also understand that there are criminal organizations that prey on immigrants who might not fully understand the ramifications and are told that it is legitimate.  We’ve all, at some point, been lured, duped or convinced that something we were obtaining was the real thing.  We’re told with great conviction that it is authentic and because we want to believe, we do.  When the truth is exposed, the ‘I didn’t know’ defense is obviously the most common and very well might be the honest answer.  Maybe because I focus on Information Security and a bit skeptical myself, I also gotta believe that there’s that little nudge, intuition or feeling in your belly telling you that something isn’t right.  I know because I’ve ignored that gut-check and got burned.  Just because something is ‘not-illegal’ does not make it the right thing to do. 

I’m not claiming to be a Mr. Goody-Two-Shoes and have certainly made my fair share of mistakes along with doing things I know to be wrong, legal or not.  I also know that always acting in the ‘proper’ way or doing the ‘right’ thing is difficult sometimes.  That’s what makes us human.  We might seek the easiest, least complicated and sometimes slightly unethical way of accomplishing something.  Sometimes we have to break the law to ensure the safety of others – like speeding to the Emergency Room if your wife is giving birth or a person is bleeding to death – but those are extenuating circumstances and doesn’t necessarily cause harm to others; unless, of course, you run somebody over on the way to the hospital.  There are victims with this SSN borrowing since the real person may not ever know that their information was used since it won’t show up on a credit report.  The trouble starts when a loan or tax payment is missed and by then, it’s too late.  The courts have had difficulty over the years trying to interpret certain laws as technology whizzes by but, at least in the States, our Social Security Number is one of our unique, primary identifiers and should be protected.  Incidentally, BIG-IP ASM does have a cool feature called Data Guard that can mask sensitive data from being leaked from the web application.  Data Guard helps protect against information leakage like the leakage of credit card or Social Security numbers.  Instead of sending the actual data to the client, ASM can respond by replacing the sensitive data with asterisks, or block the response and sending out an alert.  You can also decide what ASM should consider as sensitive: credit card numbers, Social Security numbers, or responses that contain a specific pattern.

ps

Related:

twitter: @psilvas

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach