How one small American VPN company is trying to stand up for privacy (ArsTechnica, 27 Oct 2013) – In recent months, I’ve started to take my own digital security much more seriously. I encrypt my e-mail when possible, I’ve moved away from Gmail , and I’ve become much more vigilant about using a VPN nearly all the time. Just as cryptographers and security researchers are auditing tools like TrueCrypt , I’ve started to kick the tires of the products that I rely upon on a daily basis. When I lived in Germany between 2010 and 2012, my wife and I paid $40 a year for a commercial VPN so we could continue to watch Hulu. But upon our return stateside, I kept paying for it anyway, for privacy-minded reasons. There are lots of VPNs out there, but the one I use isPrivate Internet Access (PIA). Why PIA? No particular reason, really. I don’t remember exactly how I came to choose it, but I remember seeing it in a roundup of VPNs listed on TorrentFreak . I now use PIA nearly every day, almost all the time, and that got me wondering: how does the company respond to real-world legal requests? Has it ever been compelled to hand over user data? Were those users ever notified? Unfortunately, Private Internet Access’ website doesn’t really make clear who is behind its site. The site’s footer points to London Trust Media , which also provides nothing more than an e-mail address. A little searching led me to find, and then get in touch with, the CEO of London Trust Media, Andrew Lee-one of the firm’s two owners. Lee has a background in the world of Bitcoin (he was one of the original founders of Mt. Gox), but he has had an interest in online privacy for years. PIA has been around since August 2009. Today, it has around 100,000 users. One of PIA’s biggest selling points (like other VPN providers) is that it does not log anything, and thus has little data to actually hand over to law enforcement. “We’ve never been asked for keys, nor [have we] handed over user data,” Lee told Ars. “What happens is that if anybody asks us for information, first and foremost, we confirm that they are a legit agency or government body that has any jurisdiction to even attempt to ask for that data. Then we go through and see that that complies with the letter and the spirit of the law. We don’t have any logs whatsoever. We don’t log metadata [or] session data either. We will comply with anything, but we can’t comply because we do not provide any logs. We don’t log, period.” Of course, one of the biggest problems is that there’s essentially no way for me to verify PIA’s (or anyone else’s) practices. Lots of VPN firms claim not to log, and I’d like to believe them, but there’s really no way for me to know for sure that Lee can’t see that I’m loading Ars about 100 times a day. Lee also told me that his firm has spoken with the Electronic Frontier Foundation (EFF) and other related groups to try to come up with a third-party audit system that would attempt to alleviate this exact problem. That way, ordinary consumers like me would at least have a little bit more of a reason to trust that no logs are being kept. “You have to trust the VPN-they have access to your data,” Dan Auerbach of the EFF told Ars. “Even if they’re really good, the government can come in and say we have a warrant… You have to take it on faith that there will be no CALEA -type orders, [where] the government will come in and say you have to come in and do logging. This is the reason that Tor was developed, was that people realized that we want some sort of anonymity service that doesn’t require you to trust just one party. That’s the basic problem with VPNs.” * * *

Vince Polley : This continues, with interesting discussion about legal issues, including possible use of a “ warrant canary ”. For many of the reasons stated in this story, I’ve decided to cancel my VPN account with GetCloak.com; it comes down to my inability to trust any third-party service provider that might log, or steal, my traffic. I’d suggested to GetCloak that they make public security promises that might be enforceable by the FTC, but even those might not be sufficient to enable me to use my financial log-in credentials over their network. So, I’m back to using AT&T, via my iPhone tethering, to secure my sensitive traffic, notwithstanding NSA interception. Better the NSA than somebody I don’t know and really cannot trust.]

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/ddpavumba.

 

 

Dubious news hook lets me confirm and blog my pre-existing views (Stewart Baker, 20 Oct 2013) – I’m a much bigger fan of Girl Talk, whom I’ve blogged about before, than of current copyright law, so it’s hard to resist a chance to talk about both. Girl Talk (actually a fellow named Greg Gillis) produces delightful mashups of hip-hop and classic rock that shed new light on both. Since Girl Talk relies on a claim of fair use for his sampling and doesn’t seek the original label’s authorization, he has trouble selling his albums through the usual channels. Now Michael Schuster, another Girl Talk lawyer-fan, has produced a law-review study of All Day, Girl Talk’s latest album , arguing that the songs it samples actually had higher sales in the year after the sampling than in the year before. For those of us who think copyright law is too protective of plaintiffs, the article is comforting. It suggests that current law may actually be hurting the authors it purports to help by discouraging musicians from introducing their fans to our pop-cultural heritage. Actually, though, I think the article is a little too comforting. I am always skeptical of scholarly research that reinforces academic prejudices, since scholars tend adjust their standards of proof to fit their prejudices. Hostility to copyright is pretty much the norm in academic circles, and if you read the article skeptically, it loses much of its persuasiveness. Schuster achieves his results by playing with the sample, dropping nine songs from a sample of about 200 because they completely wreck his argument. His reason for dropping the songs is that they were hits in the 30 months prior to the release of Girl Talk’s album, and hits by definition suffer declining sales after topping out. If he didn’t drop those songs, Schuster’s data would show a 50% drop in sales of the songs that Girl Talk samples. Schuster says he’s just correcting for noise in the data, and it isn’t appropriate to charge Girl Talk with the natural rhythm of pop music sales. Maybe so, but once you start making big after-the-fact adjustments to a sample of 200, you can prove pretty much anything. At best, Schuster has developed an interesting hypothesis that ought to be tested by a new experiment untainted by data cherry-picking.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/tungphoto.

Mississippi the latest state to claim copyright over official compilation of its laws (TechDirt, 14 Oct 2013) – We’ve written about Carl Malamud and his ongoing crusade to make sure that the law is actually publicly accessible and not locked up by copyright. Just recently, we noted that he’d run into some troubles with Georgia, and it appears now he’s facing a similar challenge from Mississippi. The basic story was actually posted as an update to Malamud’s ongoing Kickstarter project, which we’ve already told you about. The issue? Malamud had purchased, formatted and posted Mississippi’s Code of Law, Annotated . As with Georgia, the real issue seems to be in the question of whether or not the annotations themselves are covered by copyright, as they’re often produced and sold by a private company (usually LexisNexis), but in coordination with the government. That’s the case here, as the letter Malamud received from Mississippi’s intellectual property counsel , Larry Schemmel, suggests. Schemmel goes to great lengths to point out that the unannotated code is “freely available,” but that the “creative work” behind the annotations is covered by copyright, and thus should be taken off of Malamud’s site. However, as Malamud notes in his response letter (complete with a bunch of “exhibits”), the State of Mississippi makes it fairly clear that the annotated code is part of the law , and thus he argues it, too, should be freely accessible.

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/krishnana.

Is Florida too tough on lawyers using LinkedIn and Twitter? Endorsements and short skirts targeted(ABA Journal, 30 Sept 2013) – Orlando lawyer Luis Gonzalez has no plans to block endorsements on LinkedIn, no matter what the new Florida ethics rules require. “I’m not changing a damn thing,” he tells the Daily Business Review . “I want the bar to come after me. I’m 61 years old, and I’m not going to tolerate garbage like that.” Gonzalez is one of several lawyers criticizing the state bar’s new social media rules, enacted as part of new rules on lawyer advertising approved in May by the Florida Supreme Court. Many law firms consider the rules regarding Facebook, Twitter and LinkedIn to be the toughest in the country, the story says. According to this summary(PDF), the guidelines require advertising lawyers to list their names and office addresses, bar misrepresentative testimonials and restrict the use of the words “specialist” and “expert,” as well as their variations. Lawyers on Twitter are concerned about the need to state an office location on each tweet, the story says. Lawyers on LinkedIn also are concerned about the need to ban third-party endorsements and to refrain from using the word “expertise.” For lawyers on Facebook there is another potential problem-the need to refrain from posting inappropriate or unprofessional photos and videos. Kathy Bible, advertising counsel for The Florida Bar, told the Daily Business Review that the bar is involved in two disciplinary probes regarding LinkedIn, but there are no probes of Twitter violations. She added she has privately talked to some lawyers about inappropriate Facebook photos. “One lawyer had pictures of his staff with skirts too short,” she told the Daily Business Review. “He kindly removed them when we asked.”

Provided by MIRLN.

Image courtesy of FreeDigitalPhotos.net/KROMKRATHOG.

 

Presentation about the problems of online trespass to chattels (Eric Goldman, 8 Oct 2013) – You may recall my prior post where I outlined my conceptual objections to online trespass to chattels doctrines, including the common law, the Computer Fraud & Abuse Act and state computer crime laws like California Penal Code Sec. 502. As I outline in that post, I don’t think nibbling around the edges with CFAA reform is very helpful. Instead, I challenge the basic premise that sending electronic signals to a remote computer is a chattel “use.” If we follow the logic of that revised premise, most of the online trespass to chattels doctrines simply go away. I think this issue is so important that I put together a “stump speech,” replete with my signature use of Microsoft clipart. Last month, I gave this talk for the first time at the Utah State Bar Cyberlaw Section’s “i-Symposium” in Lehi, Utah. The talk recording ( download ) and accompanying PowerPoint slides ( download ) are available in the HTLI iTunesU page 

Courtesy of MIRLN.

Photo provided by Chris Sharp/FreeDigitalPhotos.net

Scientists used Facebook for the largest ever study of language and personality – and the results are groundbreaking (Business Insider, 2 Oct 2013) – A group of University of Pennsylvania researchers who analyzed Facebook status updates of 75,000 volunteers have found an entirely different way to analyze human personality, according to a new study published in PLOS One. The volunteers completed a common personality questionnaire through a Facebook application and made their Facebook status updates available so that researchers could find linguistic patterns in their posts. Drawing from more than 700 million words, phrases, and topics, the researchers built computer models that predicted the individuals’ age, gender, and their responses on the personality questionnaires with surprising accuracy. The “open-vocabulary approach” of analyzing all words was shown to be equally predictive (and in some cases more so) than traditional methods used by psychologists, such as self-reported surveys and questionnaires, that use a predetermined set of words to analyze. Basically, it’s big data meets psychology. The Penn researchers also created word clouds that “provide an unprecedented window into the psychological world of people with a given trait,” graduate student Johannes Eichstaedt, who worked on the project, said in a press release. “Many things seem obvious after the fact and each item makes sense, but would you have thought of them all, or even most of them?” [ Polley : story includes some pretty fascinating word-clouds; this looks like quite an interesting study.]

Provided by MIRLN.

Photo courtesy of Renjith Krishnan/FreeDigitalPhotos.net