Can we have both privacy and security? That is a question that has been popular since 9/11/2001. I believe we can have both. As someone who personally witnessed the terrorist attacks on The World Trade Center from a couple of blocks away (and became homeless because of them and eventually moved), I am fully well versed on these issues from the security side. As an attorney who focuses on technology and privacy issues and who has advocated for stronger personal privacy laws on the state and federal level, I also understand the inherent privacy issues.
To recap the latest privacy vs. security debate: the U.S. Justice Department is demanding that Apple help unlock an iPhone that was utilized by the San Bernardino terrorists who killed 14 people and injured 22 in 2015. Without getting too technical, the FBI has requested (there has been multiple requests/back and forth between the parties) that Apple create software or disable some security protections on an iPhone that would weaken its encryption to allow the FBI to ensure that it may access the contents on the device. According to The New York Times, the FBI has also requested that Apple assist it with unlocking at least 9 other iPhones.
Weakening encryption or creating back doors into our technology may sound like a good idea for this one case; however, there are and will be other cases where similar requests will be made to access information stored on electronic devices. If the FBI is provided a back door for this one case, security services from others countries will also demand one for their cases (there could be demands for access to phones belonging to government political opponents or to whistle blowers) as well. In addition, hackers may also utilize back doors which would harm the privacy and personal security of all of us.
I am in favor of law enforcement being able to access digital content when a valid warrant has been obtained. However, the legal process needs to be followed before content requested is turned over. In general, a major problem with our current legal process is that our digital laws are outdated. For example, the 1986 Electronic Communications Privacy Act which governs email access was created before we had smart phones and the Internet as we know it. The judiciary is stuck trying to interpret laws that are woefully out of date.
Congress must step up to fix this process. Bills such as the Email Privacy Act, and the Law Enforcement Access To Data Stored Abroad Act-LEADS need to be enacted because these bills demonstrate that government is willing to update our laws to better reflect how we utilize technology. Absent a legislative fix, private industry has a challenge when law enforcement makes certain demands which are more than just data requests. Should they comply absent trying to block these demands through the courts or should they fight law enforcement demands via a flawed legal process?
This case and others like it demonstrate the need for more dialogue on these issues and the enactment of legislation that provides clearer guidance on how to handle these issues. Technology is moving too fast to leave it solely up to the judiciary to try to interpret how laws enacted decades ago for a different time should apply in the Digital Age. Our personal privacy and national security demand that Congress and the White House work on a long term solution to these important privacy and security issues.
Copyright 2016 by The Law Office of Bradley S. Shear, LLC All rights reserved.
To inform about the legal, business, privacy, cyber security, and public policy issues that confront those who utilize digital platforms.
Showing posts with label Social Media Privacy Law Expert. Show all posts
Showing posts with label Social Media Privacy Law Expert. Show all posts
Wednesday, February 24, 2016
Monday, November 30, 2015
Email Privacy Act: Much Needed Reform
In general, the government should be required to obtain a warrant in order to access the private password protected digital accounts of its citizens. Unfortunately, due to an outdated law, the Electronic Communications Privacy Act of 1986 (ECPA) this is not the case.
The ubiquitous nature of online communications has made updating the law to account for how technology has changed over the past 30 years a necessity to ensure that our 4th amendment rights in the virtual world equal our 4th amendment rights in the physical world. A Congressional hearing on the Email Privacy Act will be held this week to try to update the woefully out of date ECPA statute. Multiple efforts over the years have failed so I am cautiously optimistic that this effort and others such as the LEADS Act which complement this bill will be passed this term.
The Email Privacy Act has more than 300 cosponsors in the House of Representatives and it would close a glaring loophole in ECPA which enables the government to utilize a subpoena instead of a warrant to require digital service providers to provide their customer's digital communications if they are greater than 180 days old. When ECPA was enacted in 1986, this loophole wasn't concerning because our technology wasn't such that we could hold years of personal communications in an email account stored in the cloud around the world.
According to a recent poll by Vox Populi, 77% of 1000 registered voters said "a warrant should be required to access emails, photos and other private communications stored online." This super majority demonstrates the importance of this issue and that Congress should listen to the voters to rectify this glaring hole in our 4th amendment protections.
In order for the Email Privacy Act to became law, it is imperative to contact your local members of Congress to tell them about the importance of this issue. Absent public support, Congress doesn't act. Therefore, if you believe that our 4th amendment protections should extend to our digital activities please take a stand and urge your representatives and senators to support the much needed Email Privacy Act.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
The ubiquitous nature of online communications has made updating the law to account for how technology has changed over the past 30 years a necessity to ensure that our 4th amendment rights in the virtual world equal our 4th amendment rights in the physical world. A Congressional hearing on the Email Privacy Act will be held this week to try to update the woefully out of date ECPA statute. Multiple efforts over the years have failed so I am cautiously optimistic that this effort and others such as the LEADS Act which complement this bill will be passed this term.
The Email Privacy Act has more than 300 cosponsors in the House of Representatives and it would close a glaring loophole in ECPA which enables the government to utilize a subpoena instead of a warrant to require digital service providers to provide their customer's digital communications if they are greater than 180 days old. When ECPA was enacted in 1986, this loophole wasn't concerning because our technology wasn't such that we could hold years of personal communications in an email account stored in the cloud around the world.
According to a recent poll by Vox Populi, 77% of 1000 registered voters said "a warrant should be required to access emails, photos and other private communications stored online." This super majority demonstrates the importance of this issue and that Congress should listen to the voters to rectify this glaring hole in our 4th amendment protections.
In order for the Email Privacy Act to became law, it is imperative to contact your local members of Congress to tell them about the importance of this issue. Absent public support, Congress doesn't act. Therefore, if you believe that our 4th amendment protections should extend to our digital activities please take a stand and urge your representatives and senators to support the much needed Email Privacy Act.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Tuesday, November 10, 2015
Belgian Court Says Facebook Must Stop Tracking Non-Users
In a very promising development, a Belgian court has ruled that Facebook may no longer collect information about non-users. According to The New York Times, the court ruled that Facebook may no longer collect and store digital information from Belgians who do not have a Facebook account due to a lack of consent.
Facebook will appeal the ruling because it wants the right to track everyone on the Internet for monetary purposes. However, if Facebook loses and fails to abide by the court's decision it may be fined up to $270,000 per day.
I do not trust Facebook with my personal information. Even though I have a personal Facebook account, my profile photo shows my "favorite social media titan," and I have intentionally included incorrect personal information about myself. I do not utilize the platform to share my personal thoughts or activities because the data is sent to data brokers. Furthermore, Facebook is not transparent regarding how personal user information is utilized by its business partners.
Its too early to speculate on whether Facebook will ultimately win the case; however, my hope is that other countries around the world including the U.S. require Facebook, Google, etc... to become more transparent about their data collection and utilization practices. Those who do not use Facebook have an expectation that it will not destroy non-users' privacy. We may soon find out if the Belgian judiciary agrees.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Facebook will appeal the ruling because it wants the right to track everyone on the Internet for monetary purposes. However, if Facebook loses and fails to abide by the court's decision it may be fined up to $270,000 per day.
I do not trust Facebook with my personal information. Even though I have a personal Facebook account, my profile photo shows my "favorite social media titan," and I have intentionally included incorrect personal information about myself. I do not utilize the platform to share my personal thoughts or activities because the data is sent to data brokers. Furthermore, Facebook is not transparent regarding how personal user information is utilized by its business partners.
Its too early to speculate on whether Facebook will ultimately win the case; however, my hope is that other countries around the world including the U.S. require Facebook, Google, etc... to become more transparent about their data collection and utilization practices. Those who do not use Facebook have an expectation that it will not destroy non-users' privacy. We may soon find out if the Belgian judiciary agrees.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Monday, November 9, 2015
Supreme Court Declines Cell Phone Privacy Case
Earlier today, the Supreme Court declined to hear a case regarding whether law enforcement needs a warrant to access the location information of cell phone users. While the decision to turn down the case may disappoint some privacy advocates it is not surprising.
Earlier this year in Davis v. U.S., the 11th Circuit Court of Appeals determined that it was not necessary for the police to obtain a warrant before accessing cell phone location records. The defendant was convicted of armed robbery based in part by his cell phone location data. The appeals court opinion compared cell phone location data to security camera surveillance images (page 27 of the opinion) which is an interesting analogy.
In general, absent exigent circumstances (legal jargon for an emergency), a warrant should be required to access the content and meta data associated with one's digital devices. In the physical world, law enforcement is generally required to obtain a warrant to search one's home or car. A home or car may contain physical information (i.e. clothing, hard copy paper records, etc...) that may indicate an investigatory target's location history or other relevant data.
Since a warrant is generally required for physical world evidence, a warrant should generally be required for digital world evidence including location information, meta data, etc...I am hoping that the court declined this matter because it is waiting for a test case that will more easily enable them to strengthen our privacy laws.
This denial of cert demonstrates that it is imperative for the privacy community to increase its efforts to better educate the judiciary, state and federal lawmakers, and other stakeholders about digital privacy issues.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Earlier this year in Davis v. U.S., the 11th Circuit Court of Appeals determined that it was not necessary for the police to obtain a warrant before accessing cell phone location records. The defendant was convicted of armed robbery based in part by his cell phone location data. The appeals court opinion compared cell phone location data to security camera surveillance images (page 27 of the opinion) which is an interesting analogy.
In general, absent exigent circumstances (legal jargon for an emergency), a warrant should be required to access the content and meta data associated with one's digital devices. In the physical world, law enforcement is generally required to obtain a warrant to search one's home or car. A home or car may contain physical information (i.e. clothing, hard copy paper records, etc...) that may indicate an investigatory target's location history or other relevant data.
Since a warrant is generally required for physical world evidence, a warrant should generally be required for digital world evidence including location information, meta data, etc...I am hoping that the court declined this matter because it is waiting for a test case that will more easily enable them to strengthen our privacy laws.
This denial of cert demonstrates that it is imperative for the privacy community to increase its efforts to better educate the judiciary, state and federal lawmakers, and other stakeholders about digital privacy issues.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Friday, October 30, 2015
UK Police May Soon Have Power To View All Users Web History
Privacy is something you don't know you have until you lose it. Unfortunately, the Internet has gone from the world's greatest communication and knowledge spreading platform to the best surveillance tool ever invented.
According to The Independent, UK police may soon be granted the power to view the web browsing history of everyone in the country. The alleged bill would require communication companies to retain all web browsing history of its customers for 12 months in case the police or spy agencies want access. The article claims that the police will still need to go through some type of judicial process to obtain the data.
A user's Internet search history may be very useful for law enforcement. For example, in the United States, it appears that in the infamous disappearance of Caylee Anthony the police may have forgotten to check all of the Internet browsing history of a computer that was searched. If all of the browsing history of the computer that was checked was readily accessible in one dashboard would it have changed the outcome of the case?
This potential new UK law is very troubling. Will phone companies soon be required to tape record every phone call that is made? Will people soon be required to tape record every personal voice conversation and keep a physical copy of every pen and paper interaction they have? Will librarians soon be required to track every request by every user and keep it on file for 12 months?
The potential for abuse is tremendous. Will one be prosecuted for just doing an Internet search about a topic? Who will have access to it? Will the proper cyber security and privacy safeguards be implemented to protect the data? What happens when multiple people utilize a device? Will everyone eventually be forced to have their own Internet ID # to track everything they do online? How much compensation will one be able to obtain after their browsing history is illegally leaked to the media? These are just some of the many questions that need to be answered.
Unfortunately, it sounds as though George Orwell's Nineteen Eighty-Four surveillance society is coming true in the U.K. Which country will be next?
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
According to The Independent, UK police may soon be granted the power to view the web browsing history of everyone in the country. The alleged bill would require communication companies to retain all web browsing history of its customers for 12 months in case the police or spy agencies want access. The article claims that the police will still need to go through some type of judicial process to obtain the data.
A user's Internet search history may be very useful for law enforcement. For example, in the United States, it appears that in the infamous disappearance of Caylee Anthony the police may have forgotten to check all of the Internet browsing history of a computer that was searched. If all of the browsing history of the computer that was checked was readily accessible in one dashboard would it have changed the outcome of the case?
This potential new UK law is very troubling. Will phone companies soon be required to tape record every phone call that is made? Will people soon be required to tape record every personal voice conversation and keep a physical copy of every pen and paper interaction they have? Will librarians soon be required to track every request by every user and keep it on file for 12 months?
The potential for abuse is tremendous. Will one be prosecuted for just doing an Internet search about a topic? Who will have access to it? Will the proper cyber security and privacy safeguards be implemented to protect the data? What happens when multiple people utilize a device? Will everyone eventually be forced to have their own Internet ID # to track everything they do online? How much compensation will one be able to obtain after their browsing history is illegally leaked to the media? These are just some of the many questions that need to be answered.
Unfortunately, it sounds as though George Orwell's Nineteen Eighty-Four surveillance society is coming true in the U.K. Which country will be next?
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Thursday, October 29, 2015
Snapchat's Troubling New Terms Destroy User Privacy and Safety
Snapchat is an ephemeral messaging app that has become popular with millions of people due to its claim that the content users send using its platform is permanently erased after a certain period of time. This sounds great; however, federal regulators have found otherwise.
According to the FTC, in 2014 Snapchat was caught making false promises to consumers about the amount of content it was collecting and saving about them. This deception led to an FTC settlement that was announced in December of 2014 that prohibits Snapchat from misrepresenting the extent to which it maintains the privacy, security, or confidentiality of users' information.
Unfortunately, this settlement has not yet encouraged Snapchat to become a company that actually cares about user privacy and personal safety. For example, Marketwatch.com has reported that Snapchat recently changed its terms of service and the update appears to be very similar to Facebook's terms. Snapchat's new policy states,
"But you grant Snapchat a worldwide, perpetual, royalty-free, sublicensable, and transferable license to host, store, use, display, reproduce, modify, adapt, edit, publish, create derivative works from, publicly perform, broadcast, distribute, syndicate, promote, exhibit, and publicly display that content in any form and in any and all media or distribution methods (now known or later developed)."
and
"To the extent it’s necessary, you also grant Snapchat and our business partners the unrestricted, worldwide, perpetual right and license to use your name, likeness, and voice in any and all media and distribution channels (now known or later developed) in connection with any Live Story or other crowd-sourced content you create, upload, post, send, or appear in. This means, among other things, that you will not be entitled to any compensation from Snapchat or our business partners if your name, likeness, or voice is conveyed through the Services."
In other words, these terms allow Snapchat to publicly display user content and utilize personal data in ways many users most likely do not understand nor would they knowingly agree to. Will Snapchat soon include a clear warning message in front of its app stating that its new terms harm user privacy and safety? I highly doubt it....:)
I do not trust services that contain the above or similar terms. Whether its words, photos, or videos, your content is not private nor safe when the above terms govern. If you don't trust Facebook because of its privacy killing agreements with data brokers you shouldn't trust Snapchat. It appears not to be a question of if, but when Snapchat enters into similar privacy killing agreements with data brokers. Will the FTC soon open an investigation into these new terms?
The bottom line is that if you care about your personal privacy and safety you should avoid utilizing Snapchat.
I do not trust services that contain the above or similar terms. Whether its words, photos, or videos, your content is not private nor safe when the above terms govern. If you don't trust Facebook because of its privacy killing agreements with data brokers you shouldn't trust Snapchat. It appears not to be a question of if, but when Snapchat enters into similar privacy killing agreements with data brokers. Will the FTC soon open an investigation into these new terms?
The bottom line is that if you care about your personal privacy and safety you should avoid utilizing Snapchat.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Wednesday, September 9, 2015
Cybersecurity Alert: Porn App Blackmails Users
As a former New Yorker, I loved the Broadway musical "Avenue Q". There are some Broadway shows that have widespread appeal because they are a microcosm of our society. The production had many memorable musical numbers; however, one that is timeless is "The Internet is for Porn."
In 2013, more people visited porn websites than Twitter, Amazon, and Netflix combined. In other words, Avenue Q's "The Internet is For Porn" still resonates with audiences more than 12 years after it was introduced. Not only have Broadway writers taken note of society's love affair with porn so have hackers and criminals.
According to CNN, a porn app called, "Adult Player", "secretly takes your photo and locks you out of your digital device and demands $500 to unlock it. This activity is known as ransomware and it is becoming a growing challenge. Criminals have even successfully targeted police departments and law firms with these schemes.
To avoid becoming a victim of this type of crime, it is imperative to be careful what you download. Even if something appears to be legitimate it may be a phishing expedition by a criminal enterprise. Therefore, if an email attachment or link looks suspicious delete it. If someone really wants to get in touch with you they will figure out a way to do so.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
In 2013, more people visited porn websites than Twitter, Amazon, and Netflix combined. In other words, Avenue Q's "The Internet is For Porn" still resonates with audiences more than 12 years after it was introduced. Not only have Broadway writers taken note of society's love affair with porn so have hackers and criminals.
According to CNN, a porn app called, "Adult Player", "secretly takes your photo and locks you out of your digital device and demands $500 to unlock it. This activity is known as ransomware and it is becoming a growing challenge. Criminals have even successfully targeted police departments and law firms with these schemes.
To avoid becoming a victim of this type of crime, it is imperative to be careful what you download. Even if something appears to be legitimate it may be a phishing expedition by a criminal enterprise. Therefore, if an email attachment or link looks suspicious delete it. If someone really wants to get in touch with you they will figure out a way to do so.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Friday, August 28, 2015
FTC Announces PrivacyCon Symposium
Earlier today, I received notification from the FTC announcing that on January 14, 2016 it will hold an event called PrivacyCon. According the FTC's website, the conference is designed "to bring together a diverse group of stakeholders, including whitehat researchers, academics, industry representatives, consumer advocates, academics, and a range of government regulators, to discuss the latest research and trends related to consumer privacy and data security."
The FTC has done some great work in privacy and cybersecurity and just like previous events, this event will bring together some of the world's most knowledgeable experts in the field. FTC Chairwoman Ramirez published an excellent op-ed earlier today about the need for this symposium. In her piece, she stated, "[p]olicymakers need to ensure that privacy is respected while innovation flourishes, and technology academics and researchers are crucial to hitting that sweet spot."
Previous FTC symposiums I have attended were well worth my time so if you are interested in learning about some of the most cutting edge regulatory issues in privacy and cybersecurity this event is a must.
Copyright 2015 by the Law Office of Bradley S. Shear, LLC. All rights reserved.
The FTC has done some great work in privacy and cybersecurity and just like previous events, this event will bring together some of the world's most knowledgeable experts in the field. FTC Chairwoman Ramirez published an excellent op-ed earlier today about the need for this symposium. In her piece, she stated, "[p]olicymakers need to ensure that privacy is respected while innovation flourishes, and technology academics and researchers are crucial to hitting that sweet spot."
Previous FTC symposiums I have attended were well worth my time so if you are interested in learning about some of the most cutting edge regulatory issues in privacy and cybersecurity this event is a must.
Copyright 2015 by the Law Office of Bradley S. Shear, LLC. All rights reserved.
Thursday, July 23, 2015
NY Court: Facebook has no standing to challenge search warrants
Earlier this week, a New York state appeals court ruled that Facebook had no legal standing to challenge search warrants on behalf of its
customers. The court stated that only the defendant may challenge the search warrant and not Facebook.
The court's unanimous opinion stated that, “[f]here is no constitutional or statutory right to challenge an allegedly defective warrant before it is executed.” This ruling was not surprising because the law usually takes years to catch up to the technology. Will other courts around the country follow this ruling?
As more of these types of cases (and similar ones) pop up, it will be interesting to see how the law addresses new technologies. There is no one size fits all in determining public policy and I hope there is a robust conversation on these important issues.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
The court's unanimous opinion stated that, “[f]here is no constitutional or statutory right to challenge an allegedly defective warrant before it is executed.” This ruling was not surprising because the law usually takes years to catch up to the technology. Will other courts around the country follow this ruling?
As more of these types of cases (and similar ones) pop up, it will be interesting to see how the law addresses new technologies. There is no one size fits all in determining public policy and I hope there is a robust conversation on these important issues.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Tuesday, June 16, 2015
FBI Investigating St. Louis Cardinals For Allegedly Hacking Houston Astros
According to The New York Times, the FBI is investigating the St. Louis Cardinals for allegedly hacking into the Houston Astros' internal network. The Cardinals are the most successful National League franchise and 2nd most successful organization in Major League Baseball after the New York Yankees. While this investigation is ongoing, it would not surprise me if in addition to serious state and federal charges, Major League Baseball imposes a harsh penalty on the Cardinals and those employees responsible if it is found that they hacked into the Astros computer networks.
This is a breaking story so more updates may be provided later.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
This is a breaking story so more updates may be provided later.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Saturday, May 23, 2015
Instagram Photos Show Slip and Fall Lawsuit Against NYC Is Frivolous
Taking photos and sharing them digitally is so easy. However, just because it is, that doesn't mean you should do so. In Silicon Valley, the term "frictionless sharing" was coined to describe the ability to make it as simple as possible to share your personal content with others via the Internet and apps.
Technology companies make billions of dollars per year in advertising revenue due to frictionless sharing. This capability is so important to the monetary viability of many digital companies that some of them recently spent millions of dollars lobbying Congress to weaken the Video Privacy Protection Act to make it easier for consumers to share their video viewing habits with others. While Silicon Valley may promote this change as providing more "consumer choice", others may believe this revision has diminished important privacy protections.
Just because you have the ability to take a photo or a video doesn't mean you should do so and share it digitally. Having the skills to understand when not to share is very important in the Social Media Age. In general, I advise many clients not share their personal content digitally unless it is in furtherance of their professional career.
The latest person who has not mastered the skill of when not to share appears to be Rev. Al Sharpton's daughter Dominique Sharpton. According to The New York Post's analysis of Ms. Sharpton's personal Instagram account she has "a lot of explaining to do." Ms. Sharpton is suing the City of New York for $5 million dollars because she allegedly injured her angle on a Soho sidewalk. I am highly skeptical of this claim because it appears that on her personal Instagram account she has posted photos of herself climbing mountains in the U.S. and overseas.
Ms. Sharpton's Instagram account photos do not appear to demonstrate that she has a $5 million dollar claim against the New York City. According to The New York Post, New York City has ordered Ms. Sharpton to preserve her photos because they appear to contradict the claims in her complaint against the City. If the photos on Ms. Sharpton's Instagram account are authenticated, the City of New York may take legal action against her because it appears that her legal complaint is deficient due to a "failure to state a claim."
The bottom line is be careful what you post because it may create tremendous legal liability for you and/or others.
UPDATE: According to The New York Post, Ms. Sharpton has made her social media accounts "private". In light of all of the media coverage regarding this matter, Ms. Sharpton's latest move further demonstrates her $5 million dollar legal claim against the City of New York appears to be frivolous.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Technology companies make billions of dollars per year in advertising revenue due to frictionless sharing. This capability is so important to the monetary viability of many digital companies that some of them recently spent millions of dollars lobbying Congress to weaken the Video Privacy Protection Act to make it easier for consumers to share their video viewing habits with others. While Silicon Valley may promote this change as providing more "consumer choice", others may believe this revision has diminished important privacy protections.
Just because you have the ability to take a photo or a video doesn't mean you should do so and share it digitally. Having the skills to understand when not to share is very important in the Social Media Age. In general, I advise many clients not share their personal content digitally unless it is in furtherance of their professional career.
The latest person who has not mastered the skill of when not to share appears to be Rev. Al Sharpton's daughter Dominique Sharpton. According to The New York Post's analysis of Ms. Sharpton's personal Instagram account she has "a lot of explaining to do." Ms. Sharpton is suing the City of New York for $5 million dollars because she allegedly injured her angle on a Soho sidewalk. I am highly skeptical of this claim because it appears that on her personal Instagram account she has posted photos of herself climbing mountains in the U.S. and overseas.
Ms. Sharpton's Instagram account photos do not appear to demonstrate that she has a $5 million dollar claim against the New York City. According to The New York Post, New York City has ordered Ms. Sharpton to preserve her photos because they appear to contradict the claims in her complaint against the City. If the photos on Ms. Sharpton's Instagram account are authenticated, the City of New York may take legal action against her because it appears that her legal complaint is deficient due to a "failure to state a claim."
The bottom line is be careful what you post because it may create tremendous legal liability for you and/or others.
UPDATE: According to The New York Post, Ms. Sharpton has made her social media accounts "private". In light of all of the media coverage regarding this matter, Ms. Sharpton's latest move further demonstrates her $5 million dollar legal claim against the City of New York appears to be frivolous.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Sunday, May 3, 2015
DOJ Will Be More Transparent About Secret Cell Phone Tracking
The U.S. Department of Justice (DOJ) has stated that it will soon become more transparent about its secret cell phone tracking program. According to The Wall Street Journal, "the Federal Bureau of Investigation has begun getting search warrants from judges to use the devices, which hunt criminal suspects by locating their cellphones, the officials said. For years, FBI agents didn’t get warrants to use the tracking devices."
This change in behavior is welcome news. Law enforcement should be required to obtain a warrant before deploying these technologies. Police across the country have utilized devices sometimes called stingrays without a warrant thousands of times to collect information about cell phone users for years. The usage of these technologies on American soil appears to have started around 2007 and according to published reports is widespread across the country.
In a democratic and free society, it is imperative for law enforcement to be transparent about their practices. Even though there may be security concerns regarding being too transparent about some of the details of these programs, the usage of these technologies without a warrant is a clear violation of our Fourth Amendment rights.
While I applaud the DOJ's decision to change its practice and now obtain a warrant before deploying these tools what triggered the change in policy? In 2014, the Supreme Court in Riley v. California ruled 9-0 that the police generally need a warrant to search electronic devices of those who are arrested. The DOJ's policy should have been updated right after this ruling occurred and not almost a year later.
The bottom line is that privacy still matters in the Digital Age and that transparency and accountability are more important than ever due to the increased sophistication of digital surveillance tools.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
This change in behavior is welcome news. Law enforcement should be required to obtain a warrant before deploying these technologies. Police across the country have utilized devices sometimes called stingrays without a warrant thousands of times to collect information about cell phone users for years. The usage of these technologies on American soil appears to have started around 2007 and according to published reports is widespread across the country.
In a democratic and free society, it is imperative for law enforcement to be transparent about their practices. Even though there may be security concerns regarding being too transparent about some of the details of these programs, the usage of these technologies without a warrant is a clear violation of our Fourth Amendment rights.
While I applaud the DOJ's decision to change its practice and now obtain a warrant before deploying these tools what triggered the change in policy? In 2014, the Supreme Court in Riley v. California ruled 9-0 that the police generally need a warrant to search electronic devices of those who are arrested. The DOJ's policy should have been updated right after this ruling occurred and not almost a year later.
The bottom line is that privacy still matters in the Digital Age and that transparency and accountability are more important than ever due to the increased sophistication of digital surveillance tools.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Friday, May 1, 2015
Facebook Threatens European Regulators Over Stronger Privacy Laws
In a very troubling development that shows Facebook's true colors, one of its corporate executives stated that if European regulators continue to scrutinize Facebook's data collection and utilization practices its citizens will not be provided certain features in a timely manner. This veiled threat to European regulators demonstrates that the EU is on the right track in questioning the data privacy policies and practices of Facebook and other Internet companies.
Manufacturers of cars and heavy machinery, pharmaceutical companies, banks, chemical companies, etc.. are required to follow appropriate safety regulations in Europe and around the world. Data collection and usage laws are nothing more than safety regulations and it is time for Facebook and the entire digital ecosystem to get on board with regulations that will enhance user trust of their platforms.
An Austrian class action lawsuit about Facebook's data usage practices, the ongoing Netherlands privacy regulator investigation into Facebook's activities, and the possibility that Europe will enact stronger data protection laws that will provide greater regulatory tools to protect citizens from some of Facebook's troubling data collection and usage practices appears to worry the company. These developments demonstrate the importance of baking privacy into your platform's design and the need for Facebook to change its data collection and usage practices and its policies.
The bottom line is that data privacy is a safety issue. My hope is that U.S. lawmakers and regulators soon follow Europe's lead in understanding that unfettered data collection and usage is a clear and present danger to its citizens and that more robust privacy laws are a must in the Big Data Age.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Manufacturers of cars and heavy machinery, pharmaceutical companies, banks, chemical companies, etc.. are required to follow appropriate safety regulations in Europe and around the world. Data collection and usage laws are nothing more than safety regulations and it is time for Facebook and the entire digital ecosystem to get on board with regulations that will enhance user trust of their platforms.
An Austrian class action lawsuit about Facebook's data usage practices, the ongoing Netherlands privacy regulator investigation into Facebook's activities, and the possibility that Europe will enact stronger data protection laws that will provide greater regulatory tools to protect citizens from some of Facebook's troubling data collection and usage practices appears to worry the company. These developments demonstrate the importance of baking privacy into your platform's design and the need for Facebook to change its data collection and usage practices and its policies.
The bottom line is that data privacy is a safety issue. My hope is that U.S. lawmakers and regulators soon follow Europe's lead in understanding that unfettered data collection and usage is a clear and present danger to its citizens and that more robust privacy laws are a must in the Big Data Age.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Monday, April 20, 2015
Twitter Quietly Updates Its Terms of Service
According to Mashable, Twitter quietly updated its Terms of Service on Friday in anticipation of new European Data Protection (privacy) laws. Unfortunately for U.S. users, Twitter's new terms apply to international and not U.S. based users.
An Irish subsidiary was chosen as the location for international user data because it has a reputation for less Internet related regulations. In other words, other European countries have different beliefs in how data should be protected. In my opinion, many of Ireland's Internet related regulatory positions are based purely upon economic reasons.
Less regulations may mean more economic development. For example, I live and work in Montgomery County, Maryland and it has an unfavorable regulatory reputation compared to multiple Northern Virginia counties. Therefore, Fortune 500 companies are more willing to relocate and open subsidiaries in the "business friendly" climate of Virginia.
In general, social media companies are not platforms that are built with privacy by design in mind. The services provided by Twitter, Facebook, Google, etc... were created to data mine users for behavioral advertising purposes (don't believe any co-founder who states they wanted to make the world a better place, etc....). Therefore, I do not trust these platforms to handle any sensitive or confidential information/communication.
The European Union is working on stronger data protection regulations because it understands the dangers inherent when companies engage in unfettered collection and data mining of personal information. It is expected that Europe will enact stronger data protection laws sometime later this year. My hope is that the U.S. will follow the EU's lead in trying to create a more private, less discriminatory, and non-monopolistic digital data future.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
An Irish subsidiary was chosen as the location for international user data because it has a reputation for less Internet related regulations. In other words, other European countries have different beliefs in how data should be protected. In my opinion, many of Ireland's Internet related regulatory positions are based purely upon economic reasons.
Less regulations may mean more economic development. For example, I live and work in Montgomery County, Maryland and it has an unfavorable regulatory reputation compared to multiple Northern Virginia counties. Therefore, Fortune 500 companies are more willing to relocate and open subsidiaries in the "business friendly" climate of Virginia.
In general, social media companies are not platforms that are built with privacy by design in mind. The services provided by Twitter, Facebook, Google, etc... were created to data mine users for behavioral advertising purposes (don't believe any co-founder who states they wanted to make the world a better place, etc....). Therefore, I do not trust these platforms to handle any sensitive or confidential information/communication.
The European Union is working on stronger data protection regulations because it understands the dangers inherent when companies engage in unfettered collection and data mining of personal information. It is expected that Europe will enact stronger data protection laws sometime later this year. My hope is that the U.S. will follow the EU's lead in trying to create a more private, less discriminatory, and non-monopolistic digital data future.
Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.
Monday, February 16, 2015
Law Enforcement Access To Data Stored Abroad Act Introduced
Late last week, Sen. Orrin Hatch of Utah introduced the Law Enforcement Access To Data Stored Abroad Act (LEADS Act) which would require law enforcement to obtain a warrant under the Electronic Communication Privacy Act (ECPA) to obtain the content of subscriber communications from an electronic communications or cloud computing service. According to Sen. Hatch, the legislation would "strengthen privacy in the digital age and promote trust in US
technologies worldwide by safeguarding data stored abroad, while still
enabling law enforcement to fulfill its important public safety mission".
The LEADS Act appears to have been introduced in response to an ongoing federal court case that required a U.S. email service provider to turn over customer emails that are stored in Ireland in response to a U.S. warrant instead of going through the proper legal channels in Ireland. This ruling was very troubling because it disregarded European digital privacy laws. Unless this decision is reversed, it may encourage foreign countries to ignore U.S. privacy laws when demanding access to their citizens digital content that is located in the U.S.
The passage of the LEADS Act is needed not only to better protect digital privacy, but also from a business perspective. According to The New York Times, the U.S. cloud computing industry may lose tens of billions of dollars in business because international companies and governments have lost confidence in U.S. technology companies due to the NSA surveillance programs that Edward Snowden exposed in 2013. Forrester Research has indicated that these losses could be as high as $180 billion dollars for U.S. based firms.
As a lawyer who focuses on privacy and cyber security matters, I have seen some of my clients change their communication habits based upon the information obtained from the NSA documents leaked by Snowden. Even though I am a proponent of utilizing cloud platforms, due to the troubling state of our digital privacy protections and an increase in hacking incidents, I have been encouraging some of my clients to conduct more business in person and/or on the phone until the U.S. enacts stronger digital privacy laws. In some instances, I am advising clients to go "old school" and send more physical packages via personal courier or a trusted commercial parcel service.
Unless there are digital exigent circumstances, the government should generally be required to obtain a warrant to access our electronic communications. Since law enforcement officials generally need a warrant to search our physical homes and businesses, the same standard should apply to our digital homes and businesses.
The LEADS Act is a sensible bill that will help protect online privacy and bring digital public policy into the 21st century. With more of our personal and business communications occurring digitally, it is imperative that our electronic communications receive the same protections as our "old school" pen and paper documents.
Copyright 2015 by Shear Law, LLC All rights reserved.
The LEADS Act appears to have been introduced in response to an ongoing federal court case that required a U.S. email service provider to turn over customer emails that are stored in Ireland in response to a U.S. warrant instead of going through the proper legal channels in Ireland. This ruling was very troubling because it disregarded European digital privacy laws. Unless this decision is reversed, it may encourage foreign countries to ignore U.S. privacy laws when demanding access to their citizens digital content that is located in the U.S.
The passage of the LEADS Act is needed not only to better protect digital privacy, but also from a business perspective. According to The New York Times, the U.S. cloud computing industry may lose tens of billions of dollars in business because international companies and governments have lost confidence in U.S. technology companies due to the NSA surveillance programs that Edward Snowden exposed in 2013. Forrester Research has indicated that these losses could be as high as $180 billion dollars for U.S. based firms.
As a lawyer who focuses on privacy and cyber security matters, I have seen some of my clients change their communication habits based upon the information obtained from the NSA documents leaked by Snowden. Even though I am a proponent of utilizing cloud platforms, due to the troubling state of our digital privacy protections and an increase in hacking incidents, I have been encouraging some of my clients to conduct more business in person and/or on the phone until the U.S. enacts stronger digital privacy laws. In some instances, I am advising clients to go "old school" and send more physical packages via personal courier or a trusted commercial parcel service.
Unless there are digital exigent circumstances, the government should generally be required to obtain a warrant to access our electronic communications. Since law enforcement officials generally need a warrant to search our physical homes and businesses, the same standard should apply to our digital homes and businesses.
The LEADS Act is a sensible bill that will help protect online privacy and bring digital public policy into the 21st century. With more of our personal and business communications occurring digitally, it is imperative that our electronic communications receive the same protections as our "old school" pen and paper documents.
Copyright 2015 by Shear Law, LLC All rights reserved.
Monday, January 19, 2015
Will the FTC Investigate Turn and Verizon Wireless For Privacy Killing Zombie Cookies?
A very troubling recent ProPublica investigation found that Turn, an online advertising company is "using tracking cookies [i.e. "Zombie Cookies"] that come
back to life after Verizon [Wireless] users have deleted them." These revelations are very troubling and demonstrate why stronger privacy laws are needed and why state and federal regulators need to investigate and take action against those companies that abuse their access to our personal information.
According to ProPublica, "Some users try to block such tracking by turning off or deleting cookies. But Turn says that when users clear their cookies, it does not consider that a signal that users want to opt out from being tracked....Turn executives said the only way users can opt out is to install a Turn opt-out cookie on their machine. That cookie is not designed to prevent Turn from collecting data about a user - only to prevent Turn from showing targeted ads to that user. ProPublica's tests showed that even Verizon users who installed the Turn opt-out cookie continued to receive the Turn tracking cookie as well. Turn said despite the appearance of the tracking cookie, it continues to honor the opt-out cookie. Initially, Turn officials also told ProPublica that its zombie cookie had a benefit for users: They said they were using the Verizon number to keep track of people who installed the Turn opt-out cookie, so that if they mistakenly deleted it, Turn could continue to honor their decisions to opt out. But when ProPublica tested that claim on the industry's opt-out system, we found that it did not show Verizon users as opted out. Turn subsequently contacted us to say it had fixed what it said was a glitch, but our tests did not show it had been fixed."
Within a couple of days of ProPublica's excellent investigation, Turn announced that it "would stop using tracking cookies [i.e. Zombie Cookies] that are impossible to delete." While this is a welcome development there are many questions left unanswered. For example:
How long was Turn using Zombie Cookies?
What information was Turn's Zombie Cookies collecting and how was it being utilized?
Will Turn permanently delete all the data its Zombie Cookies collected?
How can we verify that the Zombie Cookie program has been terminated?
How can Turn be trusted not to create similar programs that are as troubling as the Zombie Cookie?
Zombie and Super Cookies are not only a threat to our personal privacy, they are also a threat to our personal safety and may lead to hidden discrimination against people based upon their race, religion, sexual orientation, age, health, etc...
Last week, during President Obama's history making privacy speech at the FTC he stated, "[i]f we are going to be connected we need to be protected." Will Turn and its advertising clients change its practices and heed the President's call to better protect our privacy?
Copyright 2015 by Shear Law, LLC All rights reserved.
According to ProPublica, "Some users try to block such tracking by turning off or deleting cookies. But Turn says that when users clear their cookies, it does not consider that a signal that users want to opt out from being tracked....Turn executives said the only way users can opt out is to install a Turn opt-out cookie on their machine. That cookie is not designed to prevent Turn from collecting data about a user - only to prevent Turn from showing targeted ads to that user. ProPublica's tests showed that even Verizon users who installed the Turn opt-out cookie continued to receive the Turn tracking cookie as well. Turn said despite the appearance of the tracking cookie, it continues to honor the opt-out cookie. Initially, Turn officials also told ProPublica that its zombie cookie had a benefit for users: They said they were using the Verizon number to keep track of people who installed the Turn opt-out cookie, so that if they mistakenly deleted it, Turn could continue to honor their decisions to opt out. But when ProPublica tested that claim on the industry's opt-out system, we found that it did not show Verizon users as opted out. Turn subsequently contacted us to say it had fixed what it said was a glitch, but our tests did not show it had been fixed."
Within a couple of days of ProPublica's excellent investigation, Turn announced that it "would stop using tracking cookies [i.e. Zombie Cookies] that are impossible to delete." While this is a welcome development there are many questions left unanswered. For example:
How long was Turn using Zombie Cookies?
What information was Turn's Zombie Cookies collecting and how was it being utilized?
Will Turn permanently delete all the data its Zombie Cookies collected?
How can we verify that the Zombie Cookie program has been terminated?
How can Turn be trusted not to create similar programs that are as troubling as the Zombie Cookie?
Zombie and Super Cookies are not only a threat to our personal privacy, they are also a threat to our personal safety and may lead to hidden discrimination against people based upon their race, religion, sexual orientation, age, health, etc...
Last week, during President Obama's history making privacy speech at the FTC he stated, "[i]f we are going to be connected we need to be protected." Will Turn and its advertising clients change its practices and heed the President's call to better protect our privacy?
Copyright 2015 by Shear Law, LLC All rights reserved.
Monday, January 12, 2015
President Obama Proposes The Student Digital Privacy Act
In a very positive development, President Obama earlier today proposed The Student Digital Privacy Act. According to The New York Times, the Act would "prohibit technology firms from profiting from information
collected in schools as teachers adopt tablets, online services and
Internet-connected software".
During the President's speech today at the FTC, he stated, "Our children are meeting and growing up in cyberspace", and "here at the FTC, you’ve pushed back on companies and apps that collect information on our kids without permission"... and "we need our kids privacy protected."
The President's speech appears to indicate that he is aware that Google and others have abused access to personal student data. For example, in March of 2013, Google admitted to Education Week that it was data mining student emails for advertising purposes. Soon after this was uncovered, a media firestorm erupted and subsequently Google allegedly changed its practices. Therefore, when the President mentioned, "[b]ut we’ve already seen some instances where some companies use educational technologies to collect student data for commercial purposes, like targeted advertising" was he referring to Google?
President Obama stated, "I want to encourage every company that provides these technologies to our schools to join this effort. It’s the right thing to do. And if you don’t join this effort, then we intend to make sure that those schools and those parents know you haven’t joined this effort. So, this mission, protecting our information and privacy in the Information Age, this should not be a partisan issue. This should be something that unites all of us as Americans."
I applaud the President and his team for recognizing the importance of student digital privacy and his willingness to make the issue an important part of his legislative agenda during his final two years in office. As a parent, I want my children to be able to utilize the most advanced digital learning tools available. However, our kids should not have to compromise their personal privacy and/or safety to utilize new digital technologies.
While I am optimistic about the opportunity for stronger student privacy protections to become law, I know there is a lot of work ahead. Therefore, it is imperative for students, parents, teachers, school administrators, privacy advocates, and education technology vendors to work with regulators, lawmakers, and the President to enact a thoughtful and forward thinking bill into law.
Copyright 2015 by Shear Law, LLC All rights reserved.
During the President's speech today at the FTC, he stated, "Our children are meeting and growing up in cyberspace", and "here at the FTC, you’ve pushed back on companies and apps that collect information on our kids without permission"... and "we need our kids privacy protected."
The President's speech appears to indicate that he is aware that Google and others have abused access to personal student data. For example, in March of 2013, Google admitted to Education Week that it was data mining student emails for advertising purposes. Soon after this was uncovered, a media firestorm erupted and subsequently Google allegedly changed its practices. Therefore, when the President mentioned, "[b]ut we’ve already seen some instances where some companies use educational technologies to collect student data for commercial purposes, like targeted advertising" was he referring to Google?
President Obama stated, "I want to encourage every company that provides these technologies to our schools to join this effort. It’s the right thing to do. And if you don’t join this effort, then we intend to make sure that those schools and those parents know you haven’t joined this effort. So, this mission, protecting our information and privacy in the Information Age, this should not be a partisan issue. This should be something that unites all of us as Americans."
I applaud the President and his team for recognizing the importance of student digital privacy and his willingness to make the issue an important part of his legislative agenda during his final two years in office. As a parent, I want my children to be able to utilize the most advanced digital learning tools available. However, our kids should not have to compromise their personal privacy and/or safety to utilize new digital technologies.
While I am optimistic about the opportunity for stronger student privacy protections to become law, I know there is a lot of work ahead. Therefore, it is imperative for students, parents, teachers, school administrators, privacy advocates, and education technology vendors to work with regulators, lawmakers, and the President to enact a thoughtful and forward thinking bill into law.
Copyright 2015 by Shear Law, LLC All rights reserved.
Tuesday, March 11, 2014
Tweets, School Bathrooms, The First Amendment, and The Right To Privacy
What if a student takes a photo of behavior occurring in the common area of a school bathroom during school hours that appears to violate school policy and then Tweets out the image with commentary? Should the photographer who captured and Tweeted out the image be disciplined but those whose behavior allegedly violated school policy not be punished? This is a question that a public high school in Maryland is answering.
Recently, a student Tweeted out a selfie of herself with two other students in the background allegedly engaging in sexual contact. As of this writing, the photo has been re-tweeted over 14,000 times. After school administrators became informed about the situation, the Tweeter was suspended for ten days. The students who appeared in the photo (their faces are not viewable) allegedly engaging in some type of personal interaction that may or may not be of a sexual nature were not disciplined.
I am very protective of free speech rights; especially for students. I strongly believe in the Tinker v. Des Moines decision which ruled that students do not leave their constitutional rights at the school house gate. However, I believe in Griswold v. Connecticut's ruling that we all have a right to privacy. Mobile devices and wearable technology will test the right to privacy versus the first amendment in the Digital Age. This situation demonstrates that their are no easy answers regarding where our first amendment rights end and our right to privacy begins.
Copyright 2014 by the Law Office of Bradley S. Shear, LLC All rights reserved.
Recently, a student Tweeted out a selfie of herself with two other students in the background allegedly engaging in sexual contact. As of this writing, the photo has been re-tweeted over 14,000 times. After school administrators became informed about the situation, the Tweeter was suspended for ten days. The students who appeared in the photo (their faces are not viewable) allegedly engaging in some type of personal interaction that may or may not be of a sexual nature were not disciplined.
I am very protective of free speech rights; especially for students. I strongly believe in the Tinker v. Des Moines decision which ruled that students do not leave their constitutional rights at the school house gate. However, I believe in Griswold v. Connecticut's ruling that we all have a right to privacy. Mobile devices and wearable technology will test the right to privacy versus the first amendment in the Digital Age. This situation demonstrates that their are no easy answers regarding where our first amendment rights end and our right to privacy begins.
Copyright 2014 by the Law Office of Bradley S. Shear, LLC All rights reserved.
Wednesday, February 19, 2014
Court: Facebook Must Comply With German Data Protection Laws
U.S. companies need to realize that they must follow the laws of the countries that they operate in. Facebook, Google, etc... appear not to understand the proverb, "when in Rome do as the Romans do" should mean that when doing business around the world they must abide by the data protection and privacy laws of the countries where they offer their services.
The Higher Court of Berlin recently confirmed a 2012 verdict that found that Facebook’s Friend Finder violated German law because it was unclear to users that they imported their entire address book into the social network when using it. The court further confirmed that Facebook’s privacy policy and terms of service violate German law.
Facebook and Google appear to believe that EU data protection laws should not apply to them. Both of these companies have been sued multiple times and paid fines and/or entered into judicial settlements in the tens of millions of dollars for privacy violations. Unfortunately, these fines are pocket change to them. Should our personal privacy and cyber-safety be protected and valued in the same way as consumer anti-trust protections?
Copyright 2014 by the Law Office of Bradley S. Shear, LLC All rights reserved.
The Higher Court of Berlin recently confirmed a 2012 verdict that found that Facebook’s Friend Finder violated German law because it was unclear to users that they imported their entire address book into the social network when using it. The court further confirmed that Facebook’s privacy policy and terms of service violate German law.
Facebook and Google appear to believe that EU data protection laws should not apply to them. Both of these companies have been sued multiple times and paid fines and/or entered into judicial settlements in the tens of millions of dollars for privacy violations. Unfortunately, these fines are pocket change to them. Should our personal privacy and cyber-safety be protected and valued in the same way as consumer anti-trust protections?
Copyright 2014 by the Law Office of Bradley S. Shear, LLC All rights reserved.
Subscribe to:
Posts (Atom)