According to Manhattan’s District Attorney, smartphone data encryption hinders criminal investigations in state courts. Cyrus R. Vance, Jr. testified to the Senate Judiciary Committee on July 8, 2015 in an effort to advocate legislation allowing law enforcement officials to access private phone data with judicial authorization.

Vance, Jr. cites that 71% of phone evidence in his office comes from Apple or Android devices. As a result, Apple and Google’s move to fully integrate data encryption in their next devices will significantly affect prosecution processes in state courts.

State courts adjudicate over 90% of all criminal cases annually, which means over 100,000 cases for Vance’s office alone.

“To investigate these 100,000 cases without smartphone data is to fight crime with one hand tied behind our backs,” he asserts.

Vance does not support bulk data collection or surveillance without authorization. Civil liberty and privacy advocates are still wary, however, and endorse data encryption overall. This sentiment is in relative accordance with statements from Deputy Attorney General Sally Yates and FBI Director James Comey. They say that the Obama administration has no current plans to mandate companies to provide federal agents encryption keys for their products, but they also recognize that companies should not make their devices “warrant-free zones” that impede law enforcement’s authorized access to criminal evidence.

Article via Legaltech NewsAugust 10, 2015

Photo: IPhone via Jorge Quinteros [Creative Commons Attribution-NonCommercial-NoDerivs]

The National Institute of Standards and Technology (NIST) released a practice guide on how health care providers can share patient information securely through mobile devices. The guide is the first in a series dedicated to the development of advanced cybersecurity for all organizations.

Tablets and smartphones are already integrated in the health professions, as 87% of physicians report using a tablet or smartphone in the workplace. Physicians can exchange patient information, submit medical claims, access electronic records, and e-prescribe through mobile devices. In general, the use of mobile devices for these tasks is efficient and less susceptible to error.

However, the use of tablets and smart phones for secure health information carries significant risk. Vital patient information could be leaked if the device were lost or stolen, or if a patient sent data through insecure cellular networks. Without developed authentication or data encryption, patients face the threat of “medical identity theft,” disastrous for both their own health and the success of their provider.

NIST guide seeks to mitigate risks through explicit instructions and hypothetical scenarios. The guide will take comments from the public until Sept. 25, 2015.

Article via Ice Miller Strategies LLC, August 6, 2015

Photo: Man at work–physician assistant via yooperann [Creative Commons Attribution-NonCommercial-NoDerivs]

Legislation was passed last spring that allows police in North Dakota to utilize drones not only for surveillance but also as non-lethal weapons. The bill, which was originally introduced by Representative Rick Becker, did not permit the use of any kind of weaponry to be used, but lobbyists advocated for the bill to be amended to allow non-lethal weapons in order to win the support of law enforcement. There are restrictions incorporated into the law that limit the scenarios in which drones can be used by police, though. For example, a drone may only be used for surveillance if the data will be used in investigating a felony, and law enforcement must obtain a warrant to use the drone which includes very specific details on how, when and where it will be used. There are also limits on how personal information that the drone uncovers may be dealt with. Even with some restrictions within the legislature limiting the use of drones, some say that the drones are providing law enforcement with too much power.

Jay Stanley from the American Civil Liberties Union states that even non-lethal weapons can still have lethal results. Tasers, though non-lethal, still lead to approximately fifty deaths a year. Additionally, using drones may lead to detachment between the person operating the drone and the suspect on the other side, which could lead to regrettable choices. Jim McGregor disagrees, explaining that police officers out in the field may have a harder time making the right call than someone operating a drone in an offsite location with less to distract them. He likens drones to other methods, including SWAT teams and snipers, to show that drones are not so different from well-known choices for dealing with dangerous situations.

Whether non-lethal drones are a positive or negative development in law enforcement technology, Representative Becker intends to propose a  new law that will make non-lethal as well as lethal weaponry on drones illegal.

Article via TechNewsWorld, August 28, 2015

Photo: Drone via ninfaj [Creative Commons Attribution-NonCommercial-NoDerivs]

In a ruling by the US Court of Appeals on Aug. 24, the Federal Trade Commission (FTC) has the authority to prosecute corporations that have insufficient cybersecurity to protect customers against hackers.

The Third Circuit ruled in favor of the FTC, which litigated the international hotel company Wyndham Worldwide Corporation for failing to prevent the theft of 619,000 customer’s personal and financial information by hackers. The hacking resulted in over $10.6 million in counterfeit charges.

Wyndham attempted to counter the Commission’s lawsuit in the US Court of Appeals, but the recent ruling declared the FTC’s actions legal.

The FTC will be expected “to increase its regulatory activity in this area now that its authority has been upheld,” says Michael Hindelang, head of the data security/privacy litigation and e-discovery/information management practice groups at Honigman Miller Schwartz and Cohn.

 

Article via Legaltech News, August 26, 2015

Photo: statue at Federal Trade Commission via sha in LA [Creative Commons Attribution-NonCommercial-NoDerivs]

As more and more content ranging from emails to personal information is being stored virtually in the cloud, questions about who should be able to access this content and how they must obtain the information are starting to arise. Currently, Microsoft has challenged the ability of the US government to obtain information stored in one of their data centers located abroad. If the information was stored in a physical form, the United States would have to work in cooperation with the government of the country in which the information is stored. However, the law is not as black and white concerning digital files. Executive Vice President and General Counsel of Microsoft Brad Smith states that is the responsibility of not only tech companies but also Congress to start setting precedents for laws regarding internet privacy so citizens can trust and understand digitally-storing files.

Smith also states that views on who has ownership of digital files may need to be altered. He explains that companies providing online storage have no more ownership of the files than the post office has of the content of a letter that is being mailed. Congress will also have to decide whether physical borders between countries continue to exist in the virtual world. Though the technicalities and concerns about internet privacy may seem confusing, Smith reassures tech users that measures are already being implemented that relieve citizens of having to worry about their privacy being violated even if they don’t understand all the ins and outs of cloud storage.

Article via Above the LawAugust 18, 2015

Photo DSC_6005 via Judson Weinsheimer [Creative Commons Attribution-NonCommercial-NoDerivs]

Police are using facial recognition software to identify suspects, but the rules on how they should be using the technology are not transparent.

Some San Diego citizens say their pictures had been taken even though they had not been arrested, and without permission. Spokesman Lt. Scott Wahl, when asked about department policy for this practice, said it doesn’t exist. Officers are not required to document the use of facial recognition technology and do not receive training on its use.

Eric Hanson, a retired firefighter with a non existent criminal record, says his picture was taken after being stopped by police due to a dispute with a prowler.

Article via ABA Journal, 13 August 2015

Photo: [59- 365] Behind the camera via Gemma Bou [Creative Commons Attribution-NonCommercial-NoDerivs]