Monday, September 30, 2013

NJ Content Liability Law Ruled Inconsistent with Sec. 230 (just like a Washington Law and a Tennessee Law)

Unfortunate problems give rise to unfortunate solutions.

Back in a time before most members of Congress or prosecutors knew that there was an Internet, there was Prodigy. Prodigy, as part of its service, ran family-friendly chat rooms that it moderated in an effort to keep kids protected from unfortunate content. In a different Prodigy chat room, some unknown third party said something apparently bad about an investment firm Stratton-Oakmont. Stratton-Oakmont didn't like that very much, and sued. But not able to reach out and touch the third party, Stratton-Oakmont sued the intermediary Prodigy. The court observed Prodigy taking discretion with what could and could not be posted in the family-friendly chat room, and determined that Prodigy was acting in an editorial capacity, was a publisher, and was therefore responsible for all content published on its service - including the negative third-party comment about Stratton-Oakmont.

Parable of the Good Samaritan
Congress didn't like that very much. Congress had been warned that there was unfortunate content on the Internet. And Congress had been told that Prodigy, as a result of ifs efforts to make the Internet safer, was punished with liability. Congress was also told that it was next to impossible for online services to monitor the massive amounts of content that flowed through its pipes or is hosted on its servers. Therefore, Congress passed the Good Samaritan Provision, 47 U.S.C. § 230 (an amendment to the Communications Decency Act, which was in turn an amendment to the Telecommunications Act of 1996).

The Good Samaritan Provision established two principles: First, interactive online services (broadly defined) are not liable for third party content. Second, interactive services are not liable for actions taken to make the Internet safer. Sec. 230 has been wildly successful, has been described as the greatest Internet law, and as the necessary legal condition to make the interactive Internet possible (of course, back in the real good old day, when the communications network was not liable for the content it carried, this was a tenant of 'common carriage.').

Unfortunately, as Miss Texas Teen USA observed in 1998*, "There's a lot of weirdos on the Internet." The Attorneys' General job is to fight those weirdos and the unfortunate things they do. In order to promote their unfortunate behavior, weirdos place ads on services like Craiglist, Backpage, and other online advertisement services. The Attorneys General want this unfortunate activity stopped, and since they have trouble sometimes reaching out and touching those weirdos, the Attorneys General reach out and touch the intermediary online services. The Attorneys General have tried very hard to change the rules, to change Sec. 230, and to make online services liable for the unfortunate content of third-party weirdos, out of the belief that this will somehow make things better.

The Attorneys General reached out to state legislatures and convinced them that something needed to be done. And therefore several states passed laws that would make online services liable for third-party weirdo advertisements of unfortunate things. These states include Washington, Tennessee, and New Jersey. Online Services didn't like that very much - and sued.

The Attorneys General lost in Washington and they lost in Tennessee. And now the Attorneys General have lost in New Jersey. And they lost big. In Washington, Backpage.com sued and a temporary injunction was immediately granted. Its request for a permanent injunction was granted after a hearing. The state of Washington agreed not to pursue the matter further and agreed to pay Backpage.com's attorneys fees.

Tennessee passed similar legislation. Backpage.com again sued and again received an injunction. The trial court wrote
The Constitution tells us that when freedom of speech hangs in the balance—the state may not use a butcher knife on a problem that requires a scalpel to fix. Nor may a state enforce a law that flatly conflicts with federal law. Yet, this appears to be what the Tennessee legislature has done in passing the law at issue.
Tennessee agreed not to pursue the matter further and the entered into a final judgment invalidating the law.

But we're not done. In early 2013, New Jersey enacted legislation making a crime if
the person knowingly publishes, disseminates, or displays, or causes directly or indirectly, to be published, disseminated, or displayed, any advertisement for a commercial sex act, which is to take place in this State and which includes the depiction of a minor;
This NJ law was modeled after the Washington law. And while the unfortunate content in question makes the heart cry of anyone who reads it, it does not mean that making interactive online services liable for the unfortunate content of third parties is coherent, feasible, effective, or consistent with the First Amendment.

Once again a federal court in Backpage.com v. John Jay Hoffman, Acting Attorney General of the State of New Jersey (D.N.J. Aug. 20, 2013) struck down the law. There are multiple problems with the NJ law.

First, when a state law and a federal law conflict, the federal law preempts the state law pursuant to the Constitution's Supremacy Clause. The state law would make interactive services liable for the content of third parties; the federal law 47 U.S.C. § 230 states that interactive services are not liable for third party content. The Federal law preempts the state law.

But there is a further Sec. 230 problem that the court highlights. Sec. 230 was designed to protect interactive services that seek to make their services safer. The NJ law would have made it a crime to knowingly publish unfortunate content. This creates an unintended and unwanted incentive on the part of interactive services to not know what they are publishing - or in other words, to take no steps toward making their services safe. Again, this is a conflict between the state law and the federal law, and the federal law trumps.

The NJ statute also runs afoul of the First Amendment. According to the First Amendment, to the extent that you actually can be liable for publishing content, you must knowingly publish that content. The statute as written, in addition to knowing publications, would make an online service liable if it, without knowledge, directly or indirectly, causes the content to be published, disseminated, or displayed. As Congress concluded with the passage of Sec. 230, interactive services have little ability to monitor, review, or know all the content that flows over, is hosted on, or is posted to their services. The NJ statute is unconstitutional to the extent that it would make interactive services liable for the posting of content of which they have no knowledge.

Second, the law is not the least restrictive means of achieving a compelling government interest (going after individuals engaged in abuse of children would be more effective and less restrictive, than indirectly going after intermediary communications services). Third, the NJ statute is filled with vague terms and overbroad requirements. Finally, the Court finds that the NJ statute would violate the Commerce Clause.

Unfortunate problems give rise to unfortunate solutions. Too often when confronted with unfortunate problems, those in authority feel that they must do "something," regardless of whether that "something" is such a good idea. Frequently the "something" is a thing that is immediate and visible, and gives a false sense of security. It gives the feeling that the government has acted, where in fact it has not - and it may have even made things worse.

There is no denying that there is darkness out there that needs to be confronted. But as Congress rightly determined almost 20 years ago, attacking communications intermediaries for third party content is not the solution.

Tuesday, August 06, 2013

IP Address =/= Individual Culpability. Breaking Glass Pictures v Does, DAZ 2013 #230 #CDA #copyright

Oh, I really like this decision.  Here is a court that understands that vagaries of the Internet.

Pop Quiz:  Something bad happens online.  I can tie that something-bad back to an IP address.  Do I know who did the bad thing??

Answer: N'ah!  According to the court, an IP address may identify an account owner; it does not identify who was using the Internet at that particular time and who may be responsible for the actions in question.

Ouch! But its right.  Imagine.... (oh I hate analogies).... imagine a TV set is on in a house... and for some reason that is bad.  Do I know who was watching the TV?  Of course not.  And in certain houses (group houses, duplexes, apartment buildings, dormitories, office buildings) that could be a lot of people.  And even if only one person lives at that house, it could be a guest or it could be the guy outside walking his dog who happens to look in the window.  There is a plethora of people who could watching that TV at any given moment in any given living arrangement.

In  Breaking Glass Pictures v Does, DAZ 2013, Plaintiff brought a claim for copyright infringement, wants early discovery, but the court is refusing.  Plaintiff wants an ISP to identify the subscribers that are matched to certain IP addresses so that Plaintiff can then sue those defendants in place of the "Does."

In a previous order, the court concluded that this effort 'was not "very likely" to uncover the identities of individuals who could legitimately be named as Defendants.'  Connecting an IP address to a subscriber gets you only the name of the subscriber, not the name of the person who was engaged in the conduct at issue.  To put it simply, Plaintiff cannot merely guess at who engaged in the conduct - Plaintiff must allege some basis that the defendant in question is the person engaged in the conduct.  Lacking that, Plaintiff does not get to just keep suing until he gets it right.
But the complication that Plaintiff fails to discuss is that it is not enough to simply identify the subscribers behind particular IP addresses to state a plausible claim for copyright infringement against those individuals. Instead, a plausible claim must be supported by factual allegations establishing that the particular person identified as a defendant was, in fact, the individual who engaged in wrongful conduct. In other words, discovery to identify the ISP subscribers is only the starting point. Plaintiff will also need to conduct discovery to determine who was using the Internet connection at the time the alleged infringement occurred. Plaintiff will then have to amend its complaint to allege the facts supporting its claim against each individual. The fact that Plaintiff needs discovery to unearth the factual basis for its claims is precisely the conundrum referenced in the Court's prior order regarding recent Supreme Court authority.
According to the Supreme Court, "a complaint must contain sufficient factual matter, accepted as true, to state a claim to relief that is plausible on its face." Ashcroft v. Iqbal, 556 U.S. 662, 679 (2009) (quotations omitted). It is not enough for a complaint to plead facts "that are merely consistent with a defendant's liability." Id. at 678 (quotation omitted). Instead, the complaint must go further and "nudge[] [the] claims . . . across the line from conceivable to plausible." Id. at 680 (quotation omitted). And "where the well-pleaded facts do not permit the court to infer more than the mere possibility of misconduct, the complaint has alleged — but it has not shown — that the pleader is entitled to relief." Id. at 679.
Plaintiff's current complaint alleges the subscribers, identified as John and Jane Does, engaged in direct copyright infringement. (Doc. 1 at 14). But the complaint contains no factual allegations setting forth that the subscribers were, in fact, the individuals using the Internet connections at the relevant time. Thus, it is conceivable that the subscribers were using the connection but it is equally plausible that someone other than the subscribers were using the connection. In fact, the motion for reconsideration concedes this point. (Doc. 10 at 7). Thus, the complaint does nothing more than make vague allegations that are consistent with the subscribers' liability for copyright infringement. Because those allegations are also consistent with the subscribers not being liable, Plaintiff has not stated plausible claims against the subscribers.
It is not enough that the subscriber associated with an IP address might have been the person engaged in the questionable conduct - the Plaintiff must have sufficient evidence that the person named as defendant actually was the person that engaged in the questionable conduct.  Suing until you get it right dont work.

Defendant then trots out an old argument that the subscriber of an Internet access service is responsible for everything that happens on that service.  In other words, the subscriber would be negligent for letting bad things happen; the subscriber would be negligent for improperly securing their Internet access.
The courts that have addressed this issue, however, have concluded there is no duty to secure your Internet connection. See, e.g., New Sensations, Inc. v. Does 1-426, 2012 WL 4675281 at *6 (N.D. Cal. Oct. 1, 2012) (rejecting negligence claim based on failure to secure Internet connection by stating "common sense dictates most people in the United States would be astounded to learn that they had such a legal duty"). And absent a recognized duty, the negligence claim is fatally flawed.
Even if the Court were to assume the subscribers had a duty to secure their Internet connections, Plaintiff's negligence claim likely would be preempted by the Copyright Act or barred by the Communications Decency Act. See, e.g., AF Holdings, LLC v. Doe, 2012 WL 4747170 at * (N.D. Cal. Oct. 3, 2012).
Okay, let's see how the umpires score this:  
Early discovery is denied because
  • IP addresses reveal account subscribers; not the individual using the Internet and engaged in the conduct at issue;
  • Subscribers have no duty to secure their Internet connection; and 
  • Subscribers are not liable for what other people do over their Internet connections.
The subscriber to an Internet account is an intermediary.  It is the person who negotiates with the ISP and pays the bill.  But who uses that account can range in the multitude.  And as we have seen time and again over history, it can be extremely difficult if not impossible for that intermediary to monitor and control everything that transpires over that connection.  That is why Congress prudently passed 47 USC 230 which makes clear that online services (including subscribers) are not responsible for what other people do and say online. To hold otherwise would be to so encumber Internet access that there could be no public WiFi points, no sharing your Internet with your guests, and ridiculous indemnity forms for checking your email. It's just a bad idea.

Tuesday, July 23, 2013

As the Nebuad Litigation Turns.... Mortensen v. Bresnan Communications

The litigation fallout from ISPs partnership with Nebuad continues.  Today's decision is the latest chapter out a lawsuit against a Montana ISP:
In 2008, Bresnan [Defendant ISP] entered into a temporary arrangement with advertising company NebuAd, Inc. Under the arrangement, in exchange for a share of NebuAd's advertising revenue, Bresnan [Defendant ISP] allowed NebuAd to place an appliance in its Billings, Montana, network. The appliance allowed NebuAd to gather information and create profiles of subscribers in order to target them with preference-sensitive advertising. Bresnan contends that it provided specific notice to consumers about the NebuAd trial and allowed individuals to opt out. Under a heading labeled "About Advanced Advertising," the company website provided detailed information about the trial. It also gave a list of thirteen frequently asked questions with corresponding answers that assured customers that no personally identifying information, such as first and last name, physical street address, email address, telephone numbers, or social security numbers would be collected. Plaintiffs contend that this notice was misleading and that consent was never obtained.
Plaintiffs brought suit Defendant ISP for violations of the Electronic Communications Privacy Act (dismissed previously), the Computer Fraud and Abuse Act, Montana state privacy law (dismissed previously), and trespass to chattels. 

Today's decision takes a contortious turn, not on Internet law (my normal beat), but on the Supremacy Clause of the U.S. Constitution and Defendant ISP's choice of law provision in the terms of service.  Today's case involves a Montana subscriber, an ISP doing business in Montana, an action that transpired in Montana, and a claim for a violation of a Montana law.  Pop Quiz: what state's law should apply??

Hint: The ISP is headquartered in New York and incorporated in Delaware.

Hint two:  The terms of service say that the law of New York applies (thus a cause of action based on Montana law would be bupkis).

Hint Three: The terms of service says that all claims shall be submitted to arbitration pursuant to the Federal Arbitration Act.

Okay, that seems unfair.  The case involves a Montana subscriber, an ISP's operations in Montana, and a violation that purportedly transpired in Montana.  Why should New York's law apply?? 

And when its seems this unfair, and when the customer has no choice in the matter, we call this a contract of adhesion, void as a matter of public policy.  That's what the lower court concluded, stating that Montana citizens had a constitutional right to trail by jury and access to the courts. Therefore, Plaintiff's litigation should go forward.

Not so fast, said the appeals court.  You see, there is this federal law called the Federal Arbitration Act, and it strongly favors arbitration. "Any general state-law contract defense, based in unconscionability or otherwise, that has a disproportionate effect on arbitration is displaced by the FAA."  If you are going to say that a contractual provision requiring arbitration is unconscionable because of some Montana law, then that state law is preempted - you lose.

Now comes the twister:  The Federal Arbitration Act just kicked the legs out from Montana saying its citizens have a right to a trail over arbitration.  Okay, what about the choice of law?  Does Montana law or New York law apply?  "Montana uses the Restatement (Second) of Conflict of Laws § 187(2), which finds a choice-of-law provision overcome where 
(1) Montana has a materially greater interest in the transaction than the state whose law was selected by the parties and 
(2) application of the selected state's law would be contrary to Montana's public policy."
Does Montana have a greater interest in this case?  Sure, says the court.  "The contract was received by the consumers in Montana as part of their Welcome Kit, and the contract governed services provided in Montana to Montana residents. The subject matter of the contract and performance of it took place almost entirely in Montana."

But here's the problem.  With the preemption of Montana law by the Federal Arbitration Act, there is no longer a public policy conflict with Montana law.  New York law favors arbitration; Montana law does not - Montana's disfavorance of arbitration got the boot.  Lacking a public policy conflict, the test for overriding a choice-of-law provision in a contract now fails.


Outside of the legal holding and the status of this litigation, the Court provides background on how another Nebuad litigation was resolved:
After NebuAd's temporary arrangement with Bresnan to gather information from the subscribers ended, a class of plaintiffs, including those involved in the present action, brought suit in the United States District Court for the Northern District of California against NebuAd and several Internet service providers who hosted NebuAd appliances, including Bresnan. Bresnan and the other providers moved to dismiss the action for lack of personal jurisdiction and failure to state a claim. The district court granted this motion finding personal jurisdiction lacking. Valentine v. NebuAd, Inc., No. C08-05113 TEH, 2009 WL 8186130, at *3-10 (N.D. Cal. Oct. 6, 2009). NebuAd became the sole defendant in that action and eventually reached a court-approved settlement with the plaintiffs.
According to Wikipedia, "Due to fallout following public and Congressional concern, NebuAd's largest ISP customers have all pulled out. NebuAd closed for business in the UK in August 2008, followed by the US in May 2009. NebuAd UK Ltd was dissolved in February 2010."

Wednesday, July 17, 2013

Braverman Take Two - When Sec. 230 Meets Data Mash-Up

At first, I thought Braverman v. YELP, INC., 2013 NY Slip Op 31407 - NY: Supreme Court 2013 was another roll-your-eyes, when-are-local-attorneys-going-to-learning-about-Sec.-230 case.  After all it fits the stereotypical mold: third-party patronizes merchant; third-party writes negative review on website; merchant sues website; website boots lawsuit based on Sec. 230.  The program for this case is not new; you've seen this drama play out through and through.

But the more I pondered this court decision, the more it elucidated a hidden conundrum.  The court in Roommate.com established that there is some mystic line that websites cross, moving from hosts of third-party content to becoming creators of content.  In Roommates.com, the website asked potentially discriminatory questions and required users to answer the questions as a condition of setting up profiles. In requiring users to create inappropriate content, the website's actions, the court concluded, rose above permissible minor edits or selecting which third-party content to publish. The website had become a producer of the questionable content and therefore was not immune from liability under Sec. 230.

Braverman involves Yelp, a dentist, and a negative review.  The dentist didn't like the review and therefore sued Yelp. Yelp whipped out its copy of United States Code, Title 47, and checked to see if Sec. 230 was still in it. It was. Therefore, Yelp filed that same motion that has been filed 1000s of times before by review sites: motion to dismiss for failure to state a cause of action, Rule 12(b)(6); a review site is not liable for third-party content. Third-party reviews are the responsibility of the author of the review and not the website. The Court agreed.

"But wait a minute," argued Plaintiff's attorney.  Yelp is not just some neutral actor here.  If you frequent Yelp, you might know that Yelp has filters with which Yelp selects some reviews to show and other reviews to hide (you can see them if you solve a CAPTCHA). This has led to consternation and controversy. Yelp's selection of which reviews to show can significantly alter the appearance of the merchant in question - and because of this, Yelp, Plaintiff's attorney argued, became a publisher of the negative review in question.

Nope, says the court.  Selecting which third-party content to publish is protected by Sec. 230: 
Yelp's alleged act of filtering out positive reviews does not make Yelp the creator or developer of the alleged defamatory reviews. Yelp's choice to publish certain reviews — whether positive or negative — is an exercise of a publisher's traditional editorial function protected by the CDA. Batzel v. Smith, 333 F.3d 1018, 1030 (9th Cir. 2003) (finding that it is an editorial function to "choose among proferred material"); Barnes v. Yahoo!, Inc., 570 F.3d 1096 (9th Cir. 2009) (finding that it is an editorial function to decide "whether to publish or to withdraw from publication third-party content"). Moreover, Section 230 does not distinguish between neutral and selective publishers in its grant of immunity. Shiamili, 17 N.Y.3d at 289.
Okay, but, wait.  I mean, come on.  Hear me out on this one.

Roommate.com established that Sec. 230 is not absolute - that there is a point where the line between the third-party and the website becomes blurred, and the website can no longer claim to have never met the third-party on the street. Yelp is playing a numbers game. By manipulating the numbers, Yelp changes review outcomes - controlling the flow of consumer business as consumers follow the top reviews. Given most sets of third-party reviews, Yelp can select certain reviews and make a merchant look marvelous or miserable. It isn’t the third parties creating that aggregated data representation of the merchant - it's Yelp through Yelp's manipulation of the data.

Let's go to the videotape.  At the time of this blog post (not at the time of the court case), the dentist in question had 30 reviews.  Three were visible; 27 were hidden.  The reviewers could give one to five stars. The visible average rating was "1." The average rating of all the reviews (hidden and unhidden) was "4.3;" the median rating of all reviews was "5." That's a rather significantly different average rating than the visible "1."  There were five ratings of "1;" one rating of "4;" and twenty-four ratings of "5."  Charted out, we get something that looks like this:



Does this dentist look like a "1"? Again, if we display the data as a donut chart, we get the following:

Why plot it out as a donut chart?  I like donuts!

Eighty percent of the reviews were "5;" 83% were "4" or above.  Only 17% of the reviews were a "1." And yet somehow, through Yelp's selection of certain reviews and hiding of others - Yelp manipulates the result.

Yelp isn’t presenting third-party content here; the third-party content - the data - says this dentist is pretty good. Yelp is manipulating data to produce new content. This isn’t content that the third-parties provided; this is content that Yelp created by its interaction with data.  And through this interaction, Yelp can turn any highly-rated merchant into a stink-pot, and any stinky merchant into king-of-the-hill. 

And it can do so with impunity according to this court.  This begs the question of whether we have here crossed that Roommates line between content host and content creator.

Convinced?  Okay, what if I were to tell you that the data itself was garbage.  As you may know, there are companies out there that now are in the business of "reputation management."  For a price, they will go out and ensure that the third-party reviews of the merchant are the reviews that the merchant paid for. They will take necessary steps to ensure that a stink-pot merchant looks like king-of-the-hill for a price.

Companies like Yelp struggle to keep the value of their review sites by weeding out bogus reviews. They weed out duplicates; sandbaggers; and content that lacks credibility.  They are constantly battling with "reputation management" services that have opposing agendas.

In the case in question, it appears, for whatever reason (and it may be entirely legitimate), that eight of the reviews are duplicates.  You can see at one point one of the reviewers states "I don't know why my reviews never show up…" and proceeds to write a duplicate five-star review. 

Was this a frustrated reviewer who kept getting his reviews hidden by Yelp's tactics, or was this Yelp struggling to purge the reviews of ratings that were less than reliable?  Who knows.  But what is true is that review sites that want their reviews to be valuable struggle with invalid reviews and merchants attempting to manipulate the system. And in fact, Sec. 230 was designed exactly for this purpose.  It was designed to protect those online hosts of third party content - who take some "editorial" like actions - in order to protect the quality of the content on their service and protect users from fraud and other malicious garbally gook. Congress did not want services that attempted to do good by policing their content to be transformed into publishers, liable for third party content.

So, um, where do we come out on this?

Simple answer: case dismissed; Yelp is not liable for third party reviews.

Complex answer: To understand data and big data, there is a difference between third party content and how that data is handled in the aggregate. Manipulation of data produces results that may not be true to or consistent with that third party data. Manipulation of data produces new content created by the manipulator, not by the third-parties. Who is responsible for the new content created through the manipulation of data?

"If this sentence is quoted from a third party, is the sentence mine or the third party's?" 

"If" "every" "word" "in" "this" "sentence" "is" "quoted" "from" "a" "third" "party," "is" "the" "sentence" "mine" "or" "the" "third" "party's?"

"I""f" "e""v""e""r""y"" "l""e""t""t""e""r""… oh you get the idea.

There is a point where we cross the magical Roommates.com line, where third-party content, aggregated, manipulated, and machinated by me, becomes new content.

Sunday, July 14, 2013

VID :: Douglas Engelbart 2002 Interview by John Markoff (Computer History Museum)

An absolutely marvelous interview by technology reporter John Markoff of Douglas Engelbart about his life and his path to becoming a computer pioneer. Produced by the Computer History Museum and posted to Youtube July 10, 2013.

Friday, July 12, 2013

Monday, July 08, 2013

ART :: Sunberg, Danielle E., Reining in the Rogue Employee: The Fourth Circuit Limits Employee Liability Under the CFAA (June 27, 2013). American University Law Review

Sunberg, Danielle E., Reining in the Rogue Employee: The Fourth Circuit Limits Employee Liability Under the CFAA (June 27, 2013). American University Law Review, Vol. 62, No. 5, 2013. Available at SSRN: http://ssrn.com/abstract=2286316

Abstract: The Fourth Circuit’s opinion in WEC Carolina Energy LLC v. Miller reflects a growing trend among the courts to adopt a narrow code approach to employee liability under the Computer Fraud and Abuse Act. The case exacerbates the existing circuit split and reinforces the need for reconciling when an employee accesses a computer “without authorization.” While resolution from the judiciary remains remote, Congress is engaged in a lively debate over the proper interpretation of the term “without authorization.” Recent legislative proposals suggest that Congress has united in support of limiting liability for unauthorized access under the CFAA to the circumvention of technological barriers. Support for this restrictive interpretation signifies that until the ambiguity in the law is clarified, future undecided courts should follow in the Fourth Circuit’s footsteps and adopt the code approach to determine employee liability under the CFAA.

ART :: Schwartz, Paul M., Information Privacy in the Cloud (May 1, 2013). University of Pennsylvania Law Review

Schwartz, Paul M., Information Privacy in the Cloud (May 1, 2013). University of Pennsylvania Law Review, Vol. 161, No. 1623 (2013). Available at SSRN: http://ssrn.com/abstract=2290303

Abstract:  Cloud computing is the locating of computing resources on the Internet in a fashion that makes them highly dynamic and scalable. This kind of distributed computing environment can quickly expand to handle a greater system load or take on new tasks. Cloud computing thereby permits dramatic flexibility in processing decisions – and on a global basis. The rise of the cloud has also significantly challenged established legal paradigms. This Article analyzes current shortcomings of information privacy law in the context of the cloud. It also develops normative proposals to allow the cloud to become a central part of the evolving Internet. These proposals rest on strong and effective protections for information privacy that are sensitive to technological changes.

This Article examines three areas of change in personal data processing due to the cloud. The first area of change concerns the nature of information processing at companies. For many organizations, data transmissions are no longer point-to-point transactions within one country; they are now increasingly international in nature. As a result of this development, the legal distinction between national and international data processing is less meaningful than in the past. Computing activities now shift from country to country depending on load capacity, time of day, and a variety of other concerns. The jurisdictional concepts of EU law do not fit well with these changes in the scale and nature of international data processing.

A second legal issue concerns the multi-directional nature of modern data flows, which occur today as a networked series of processes made to deliver a business result. Due to this development, established concepts of privacy law, such as the definition of “personal information” and the meaning of “automated processing” have become problematic. There is also no international harmonization of these concepts. As a result, European Union and U.S. officials may differ on whether certain activities in the cloud implicate privacy law.

A final change relates to a shift to a process-oriented management approach. Users no longer need to own technology, whether software or hardware, that is placed in the cloud. Rather, different parties in the cloud can contribute inputs and outputs and execute other kinds of actions. In short, technology has provided new answers to a question that Ronald Coase first posed in “The Nature of the Firm.” New technologies and accompanying business models now allow firms to approach “make or buy” decisions in innovative ways. Yet, privacy law’s approach to liability for privacy violations and data losses in the new “make or buy” world of the cloud may not create adequate incentives for the multiple parties who handle personal data. 

VIDEO :: NAF :: The New Digital Age

From the New America Foundation 2013 Annual Conference

Friday, July 05, 2013

RFC :: NIST :: Draft Outline of Cybersecurity Framework for Critical Infrastructure :: Commets Due July 10th

NIST has released a draft outline of the Cybersecurity Framework in preparation for the upcoming July 10th Cybersecurity Framework Workshop in San Diego.  Comments are requested on or before the workshop.
NIST Tech Beat July 2, 2013: As part of its efforts to develop a voluntary framework to improve cybersecurity in the nation's critical infrastructure, the National Institute of Standards and Technology (NIST) has posted a draft outline of the document to invite public review and gather comments.
The Executive Order calling for NIST to develop the framework directs the agency to collaborate with the public and private sectors. The draft outline reflects input received in response to a February 2013 Request for Information, discussions at two workshops and other forms of stakeholder engagement.
The outline proposes a core structure for the framework and includes a user's guide and an executive overview that describes the purpose, need and application of the framework in business. Reflecting received comments that emphasized the importance of executive involvement in managing cyber risks, the framework is designed to help business leaders evaluate how prepared their organizations are to deal with cyber threats and their impacts.
"We are pleased that many private-sector organizations have put significant time and resources into the framework development process," said Adam Sedgewick, senior information technology policy advisor at NIST. "We believe that both large and small organizations will be able use the final framework to reduce cyber risks to critical infrastructure by aligning and integrating cybersecurity-related policies and plans, functions and investments into their overall risk management."
NIST also released a draft compendium of informative references composed of existing standards, practices and guidelines to reduce cyber risks to critical infrastructure industries. This material was released to foster discussion at upcoming workshops and to further encourage private-sector input before NIST publishes the official draft Cybersecurity Framework for public comment in October 2013.
Interested parties are invited to review the draft framework outline and offer comments before and during the next workshop, July 10-12, 2013, in San Diego. Direct comments should be forwarded to cyberframework@nist.gov. The draft outline and other documents related to the Cybersecurity Framework are available at http://www.nist.gov/itl/cyberframework.cfm.

Monday, July 01, 2013

RFC :: FNPRM :: Data Practices, Computer III Further Remand: Bell Operating Companies Provision of Enhanced Services

Fed Reg Notice July 1

Summary

In this Further Notice of Proposed Rulemaking (Further Notice), the Federal Communications Commission (Commission) seeks comment on how to streamline or eliminate legacy regulations contained in the Computer Inquiry proceedings and that are applicable to the Bell Operating Companies (BOCs). The FNPRM: Seeks data on the changing market for narrowband enhanced services, in particular, the extent to which enhanced service providers (ESPs) continue to need access to the BOCs' basic network transmission services offered through comparably efficient interconnection (CEI) and open network architecture (ONA) services; proposes eliminating CEI requirements and seeks comment on whether to retain only limited ONA inputs that ESPs require in areas where there are no competitive alternatives; and seeks comment on the need for the continuing application of the All-Carrier Rule that requires non-BOC incumbent local exchange carriers (LECs) to offer non-discriminatory access to basic network services for unaffiliated ESPs.

Dates

Comments are due July 31, 2013, and reply comments are due August 30, 2013. Written comments on the paperwork Reduction Act proposed or modified information collection requirements must be submitted by the public, Office of Management and Budget (OMB), and other interested parties on or before [date].

Addresses

Interested parties may submit comments, identified by CC Docket No. 00-175, by any of the following methods:
  • Federal eRulemaking Portal: http://www.regulations.gov. Follow the instructions for submitting comments.
  • Federal Communications Commission's Web site: http://fjallfoss.fcc.gov/ecfs2/. Follow the instructions for submitting comments.
  • People with Disabilities: Contact the FCC to request reasonable accommodations (accessible format documents, sign language interpreters, CART, etc.) by email: FCC504@fcc.gov or phone: (202) 418-0530 or TTY: (202) 418-0432.
For detailed instructions for submitting comments and additional information on the rulemaking process, see theSUPPLEMENTARY INFORMATIONsection of this document.

. . . . .

Wednesday, June 19, 2013

Fed Reg RFC :: Telephone Numbers for IP Enabled Service Providers

Federal Register June 19 Action Proposed rule.

Summary In this document, the Federal Communications Commission (Commission) propose to promote innovation and efficiency by allowing interconnected Voice over Internet Protocol (VoIP) providers to obtain telephone numbers directly from the North American Numbering Plan Administrator (NANPA) and the Pooling Administrator (PA), subject to certain requirements. We anticipate that allowing interconnected VoIP providers to have direct access to numbers will help speed the delivery of innovative services to consumers and businesses, while preserving the integrity of the network and appropriate oversight of telephone number assignments. The accompanying Notice of Inquiry further seeks comment on a range of issues regarding our long-term approach to numbering resources. The relationship between numbers and geography—taken for granted when numbers were first assigned to fixed wireline telephones—is evolving as consumers turn increasingly to mobile and nomadic services. We seek comment on these trends and associated Commission policies.

Dates Comments are due on or before July 19, 2013. Reply comments are due on or before August 19, 2013.

. . . . . 

Tuesday, June 18, 2013

VID The NCTA Cable Show 2013 Playlist

[Literature] Yoo, Protocol Layering :: Hoboken, et al, Obscured by Clouds :: Skorup, Fed Spectrum :: Sutherland, World Class Broadband

Yoo, Christopher S., Protocol Layering and Internet Policy (2013). University of Pennsylvania Law Review, Vol. 161, P. 1707, 2013; U of Penn, Inst for Law & Econ Research Paper No. 13-18.
An architectural principle known as protocol layering is widely recognized as one of the foundations of the Internet’s success. In addition, some scholars and industry participants have urged using the layers model as a central organizing principle for regulatory policy. Despite its importance as a concept, a comprehensive analysis of protocol layering and its implications for Internet policy has yet to appear in the literature. This Article attempts to correct this omission. It begins with a detailed description of the way the five-layer model developed, introducing protocol layering’s central features, such as the division of functions across layers, information hiding, peer communication, and encapsulation. It then discusses the model’s implications for whether particular functions are performed at the edge or in the core of the network, contrasts the model with the way that layering has been depicted in the legal commentary, and analyzes attempts to use layering as a basis for competition policy. Next the Article identifies certain emerging features of the Internet that are placing pressure on the layered model, including WiFi routers, network-based security, modern routing protocols, and wireless broadband. These developments illustrate how every architecture inevitably limits functionality as well as the architecture’s ability to evolve over time in response to changes in the technological and economic environment. Together these considerations support adopting a more dynamic perspective on layering and caution against using layers as a basis for a regulatory mandate for fear of cementing the existing technology into place in a way that prevents the network from innovating and evolving in response to shifts in the underlying technology and consumer demand. 
Van Hoboken, Joris V. J., Arnbak, Axel and Van Eijk, Nico, Obscured by Clouds or How to Address Governmental Access to Cloud Data from Abroad (June 9, 2013). 
Transnational surveillance is obscured by the cloud. U.S. foreign intelligence law provides a wide and relatively unchecked possibility of access to data from Europeans and other foreigners. The amendments to the Foreign Intelligence Surveillance Act in 50 USC 1881a (section 702) are of particular concern. Recent leaks around the PRISM surveillance program of the National Security Agency seem to support that these legal possibilities are used in practice on a large scale.....
Skorup, Brent, Reclaiming Federal Spectrum: Proposals and Recommendations (May 28, 2013).
With the popularity of smartphones, tablets, Wi-Fi, and other wireless devices that require as an input transmissions over radio spectrum, the rising demand for bandwidth is rapidly using up the available supply of spectrum. Spectrum demand increases significantly every year with no end in sight, yet the "greenfields" of available and unallocated spectrum are gone. Redeployed spectrum must come from incumbent users. Today, the largest holder of spectrum appropriate for mobile broadband is the federal government, which uses spectrum for a variety of military and nonmilitary uses. Federal users generally use spectrum only lightly and the inefficiencies have triggered bipartisan calls for selling the spectrum used by federal agencies to the private sector, particularly to mobile broadband carriers. To date, reclaiming federal spectrum is a painfully slow process and billions of dollars of social welfare are lost with every year of delay. This paper examines proposals for reclaiming spectrum and puts forth some best practices to ensure more efficient use of spectrum. Policymakers should consider creating a commission with authority to require the sale of spectrum so that agency-controlled spectrum is quickly and easily redeployed to its highest-valued uses. In the long run, Congress should also require agencies to pay for the spectrum they possess, just as agencies pay market prices for other inputs. 
Sutherland, Ewan, A Short Note on World Class Broadband (June 11, 2013). 
The term world class is used in some broadband plans, as a target. Comparisons with other countries are beneficial, though not straightforward, in measuring progress. Claims about improvements to national competitiveness and economic growth are difficult to determine, given that economic rivals are following similar policies, and the effects of the use of the most recent broadband services are difficult to measure. Many countries rely on statistics that are inadequate for the task, though there are independent data (e.g. crowdsourced) that fill key gaps. Economic regulation will maximise the contribution of market players, but there is a growing recognition of the need for demand stimulation in order to reach potential silver surfers, the disabled and the very poor. Different indicators and policies are required. For a very countries broadband leadership is seen as part of a manufacturing strategy, for those aspiring to be world class, it may be sufficient to be fast followers, but this requires a wide range of initiatives supported by high quality and timely statistics.  
Dudley, Christie, Strange Intersections between Data Brokers and the CFAA: A Financially Supported Attack on Privacy (May 7, 2013). Available at SSRN: http://ssrn.com/abstract=2272550 or http://dx.doi.org/10.2139/ssrn.2272550

Sunday, June 16, 2013

PR :: NIST and NTIA Announce Plans to Establish New Center for Advanced Communications

Press Release June 14 The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) and National Telecommunications and Information Administration (NTIA) today announced plans to establish a national Center for Advanced Communications in Boulder, Colo. The new center will implement a key provision of a memorandum President Obama issued earlier today on “Expanding America’s Leadership in Wireless Innovation.”

The two agencies recently signed a Memorandum of Understanding (MOU) to collaborate on the establishment of the center. The MOU  states that the center will leverage the “critical mass of NIST and NTIA research and engineering capabilities concentrated in Boulder” to form a “unique national asset,” and includes the infrastructure and collaborative environment needed to address a wide range of advanced communications challenges. This joint effort will increase the impact of existing efforts already under way in both agencies.

“Advanced communication technologies drive product development in telecommunications, IT, energy, and many other critical economic sectors. This new center will combine NIST’s and NTIA’s research and technology support for U.S. industry so that it can rapidly evaluate and exploit exciting new opportunities in the field,” said Under Secretary of Commerce for Standards and Technology and NIST Director Patrick Gallagher. 

A key focus of the center will be to promote interdisciplinary research, development and testing in radio frequency technology and spectrum sharing for public safety and commercial broadband applications.
“NIST and NTIA have longstanding, productive programs in this economically important field,” noted Assistant Secretary for Communications and Information and NTIA Administrator Lawrence Strickling. “By creating a center that optimizes our combined resources, we can focus on testing and measurement to support spectrum sharing between industry and government agencies, allowing for more efficient use of spectrum by all.”

The Presidential Memorandum directs the Secretary of Commerce, through NTIA and NIST, to publish an inventory and description of federal test facilities available to commercial and other stakeholders engaged in research, development, testing and evaluation of technologies to enhance spectrum sharing and other wireless related efficiencies.  

Examples of the specific types of research, facilities and other activities at the new center may include:
  • multiuser test beds that allow government and industry researchers to realistically measure and evaluate the performance of new advanced communications technologies;
  • targeted interdisciplinary research, development and testing projects in fields such as digital information processing, interoperability and quantum communications; and
  • outreach to international standards development organizations to help ensure compatibility of U.S. advanced communications efforts with the global marketplace.

FCBA Panel on Incentive Auctions - Webcast by NY ISOC

Friday, June 14, 2013

Does the Computer Fraud and Abuse Act violate the 10th Amendment to the US Constitution?

US v. Roque, Dist. Court, D. New Jersey 2013

Motion to Dismiss indictment denied.  From the Court Opinion:

Essentially, the Superseding Indictment[1] alleges that Felix Roque, who is the Mayor of West New York, and his son, Joseph Roque, sought, through violations of the Computer Fraud and Abuse Act ("CFAA"), to disable a website critical of Mayor Roque's administration and to harass persons associated with the website. Of course, alleging is not proving, and the defendants are clothed in the presumption of innocence. It would be premature and inappropriate at this stage to consider the truth, or not, of what is alleged. The current motions are directed to the sufficiency of the Indictment and its allegations as a matter of law.

Computer Fraud and Abuse Act

Defendants move to dismiss the Indictment. They assert that the CFAA, at least as applied here, impinges upon the authority of the State of New Jersey to regulate local conduct, and hence violates the Tenth Amendment to the United States Constitution. The Tenth Amendment provides that "powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people." U.S. Const, amend. X. The government responds, in essence, that the CFAA is an exercise of a power "delegated to the United States by the Constitution" — specifically, by the Commerce Clause, which grants Congress the power to "regulate Commerce ... among the several States." U.S. CONST, art. I, § 8, cl. 3. See generally Treasurer of N.J. v. U.S. Dep't of Treasury, 684 F.3d 382, 413 (3d Cir. 2012) ("If Congress acts under one of its enumerated powers ... there can be no violation of the Tenth Amendment") (quoting United States v. Parker, 108 F.3d 28, 31 (3d Cir. 1997)).[3]

The CFAA was enacted pursuant to the Commerce Clause power. The CFAA charges here are explicitly tied to "protected computers," defined as computers "used in or affecting interstate or foreign commerce or communication." 18 U.S.C. § 1030(e)(2)(B). The Indictment alleges that each computer in question was a protected computer, i.e., a "computer used in and affecting interstate commerce." E.g., Indictment Count 1, ¶¶ 2(a) 86 (b); Count 2, ¶ 2. If facially adequate, such allegations are sufficient to call for a trial on the merits. See generally Costello v. United States, 350 U.S. 359, 363 (1956); United States v. Vitillo, 490 F.3d 314, 320 (3d Cir. 2007). The Indictment, in other words, need only allege a valid offense; it need not on its face negate the possibility of every application of the statute that might present a Constitutional problem. It is almost tautological that an allegation of interstate commerce, if proven, would establish the required nexus to interstate commerce. And having alleged interstate commerce, the government has taken on the burden of proving it. Nevertheless, because that is something of a legal conclusion, I will entertain briefly the defendants' contention that the allegations factually fall short of what is legally required to support federal jurisdiction. See generally Fed. R. CRIM. P. 12(b)(3)(B); United States v. Panarella, 277 F.3d 678, 685 (3d Cir. 2002) (Rule 12 challenge available "if the specific facts alleged in the charging document fall beyond the scope of the relevant criminal statute").

It is settled that the Commerce Clause power encompasses (1) the use of the channels of interstate commerce; (2) the instrumentalities of interstate commerce, or persons or things in interstate commerce; and (3) activities that substantially affect interstate commerce. See United States v. Lopez, 514 U.S. 549, 558-59 (1995); United States v. Bishop, 66 F.3d 569, 590 (3d Cir. 1995). The Indictment alleges facts and circumstances sufficiently broad to encompass proof of the requisite connection to interstate commerce under category (1) or category (2).

The inherent attributes of the internet, plus the physical locations of the computers in question here, suggest that the defendants used the "channels" or "instrumentalities" of interstate commerce, and that the relevant communications crossed state lines and hence were "in" interstate commerce. See United States v. MacEwan, 445 F.3d 237, 245 (3d Cir. 2006) (concluding that the "Internet is an instrumentality and channel of interstate commerce"); United States v. Trotter, 478 F.3d 918, 921 (8th Cir. 2007). The computers at issue here were all connected to the internet, and were used to communicate over the internet. The government argues, with some force, that the internet is the quintessential "instrumentality" of 21st century commerce. Thus the commerce power that once permitted the government to regulate intrastate activities of railroad cars would permit regulation here, even if the computer communications had been confined to this State. Cf. Southern R. Co. v. United States, 222 U.S. 20 (1911).[4] Even as applied to in-state activity, the CFAA has been upheld as a valid exercise of the Commerce Clause power. See, e.g., Trotter, 478 F.3d at 921; United States v. Mitra, 405 F.3d 492, 496 (7th Cir. 2005) (purely local attack on first-responder network upheld as violation of CFAA because the network operated over the electromagnetic spectrum and was an instrumentality of interstate commerce). Likewise, and in the alternative, the commerce power that once permitted the government to regulate persons and property actually transported across state lines permits regulation of the interstate communications here. Cf. Brooks v. United States, 267 U.S. 432 (1925) (upholding Dyer Act, which prohibits transportation of stolen vehicles across state lines); Hoke v. United States, 227 U.S. 308, 320 (1913) (Mann Act). Actual interstate communications between, for example, computers in New Jersey and "Go Daddy, an Internet Service Provider (ISP') located in Arizona," or "Weebly, a second ISP located in California" (Indictment Count 1, ¶ 1(h)), may demonstrate that the computers were used "in" interstate commerce. See Trotter, 478 F.3d at 921 (citing Mitra, 405 F.3d at 496).

We might hypothesize that the offense conduct involves purely local politics, or that the participants were personally indifferent to the interstate character of the internet or the location of the servers. In general — and certainly at this pretrial stage — I cannot say that this affects the issue. It may be just as true, for example, that a carjacker does not intend to commercially exploit a stolen car, or to drive it across state lines; nevertheless, because carjacking implicates interstate commerce, Congress has the power to prohibit it. See Bishop, 66 F.3d at 590; see also Trotter, 478 F.3d at 922,

Under these principles, I cannot grant defendants' motion to dismiss the Indictment. The allegations of the Indictment encompass a set of facts that, if proven, would make out a violation of the CFAA that would fall within the Commerce Clause power. Even if I accepted the defendants' Tenth Amendment reasoning, see n.3, above, I could not find at this early procedural stage that the government had boxed itself out of proving a valid federal case. The motion to dismiss the Indictment on these grounds is denied.


VIDEO Internet Law and Public Policy Conference, Stanford Law School

"On May 3-4, 2013, Stanford's Program in Law, Science and Technology hosted the Second Stanford-Peking University Conference on Internet Law and Public Policy."







PRIVACY AND CIVIL LIBERTIES OVERSIGHT BOARD Closed Meeting June 19th

This document is scheduled to be published in the Federal Register on 06/17/2013 and available online at http://federalregister.gov/a/2013-14431, and on FDsys.gov 6820-B3

[Notice-PCLOB-2013-03; Docket No 2013-0004; Sequence No. 3]
Sunshine Act Meeting
TIME AND DATE: 1:00 p.m. – 3:00 p.m. on Wednesday, June  19, 2013.
PLACE: The meeting will be held at 2100 K Street, NW,  Washington, D.C. 20427.
STATUS: Closed.
MATTERS TO BE CONSIDERED:
The Privacy and Civil Liberties Oversight Board will  meet in closed session to discuss classified information  pertaining to the PRISM-related activities and the Foreign  Intelligence Surveillance Act.
The Government in the Sunshine Act, 5 U.S.C. § 552b,  normally requires that agencies provide at least one week  prior notice to the public of the time, date, and location  of meetings. As permitted by section 552b(e)(1), the Board  determined, by recorded vote, that agency business requires
that this meeting be called at an earlier date.

CONTACT PERSON FOR MORE INFORMATION:
Susan Reingold, Chief
Administrative Officer, 202-331-1986.
Dated: June 12, 2013.
Claire McKenna,
Legal Counsel [FR Doc. 2013-14431 Filed 06/13/2013 at 11:15 am;  Publication Date: 06/17/2013]

Thursday, June 13, 2013

FCC Announces Date of Next Open Internet Advisory Committee - July 9

"By this Public Notice, the Federal Communications Commission (Commission) announces the date, time, and agenda of the next meeting of the Open Internet Advisory Committee (Committee). The next meeting of the Committee will take place on July 9, 2013, from 10:00 A.M. to 1:00 P.M. (EST) in the Commission Meeting Room at Commission Headquarters, located at 445 12th Street, S.W., Room TW-C305, Washington, DC 20554. The Committee will consider issues relating to the subject areas of its four working groups Mobile Broadband, Economic Impacts of Open Internet Frameworks, Specialized Services, and Transparency as well as other open Internet related issues. A limited amount of time will be available on the agenda for comments from the public. Alternatively, members of the public may send written comments to Tejas Narechania, Designated Federal Officer of the Committee, or Kristine Fargotstein, Deputy Designated Federal Officer, at the addresses provided below. The meeting is open to the public and the site is fully accessible to people using wheelchairs or other mobility aids. Other reasonable accommodations for people with disabilities are available upon request. The request should include a detailed description of the accommodation needed and contact information. Please provide as much advance notice as possible; last minute requests will be accepted, but may not be possible to fill. To request an accommodation, send an email to fcc504@fcc.gov or call the Consumer and Governmental Affairs Bureau at 202-418-0530 (voice), 202-418-0432 (TTY). The meeting of the Committee will also be broadcast live with open captioning over the Internet from the FCC Live web page at www.fcc.gov/live. For further information about the Committee, contact: Tejas Narechania, Designated Federal Officer, Office of General Counsel, Federal Communications Commission, Room 8-C721, 445 12th Street, S.W. Washington, DC 20554;-, Deputy Designated Federal Officer, Wireline Competition Bureau, Federal Communications Commission, Room 5-C323, 445 12th Street, S.W. Washington, DC 20554;  - FCC -

 Released:  06/03/2013.  ANNOUNCEMENT OF DATE OF MEETING OF THE OPEN INTERNET ADVISORY COMMITTEE. (DA No.  13-1303).  WCB OGC .  http://hraunfoss.fcc.gov/edocs_public/attachmatch/DA-13-1303A1.doc
http://hraunfoss.fcc.gov/edocs_public/attachmatch/DA-13-1303A1.pdf
http://hraunfoss.fcc.gov/edocs_public/attachmatch/DA-13-1303A1.txt

FTC Announces New Date for Internet of Things Workshop: Nov. 19

FTC Press Release For Your Information: 06/13/2013 Workshop Will Take Place Nov. 19
The Federal Trade Commission has announced a new date for its planned workshop on the privacy and security of the Internet of Things. The workshop will now be held on Nov. 19, 2013, in Washington, D.C.
The workshop will address a wide variety of issues related to the ability of everyday devices to communicate with each other and with people, which is becoming more prevalent and is often referred to as the Internet of Things.
The Federal Trade Commission works for consumers to prevent fraudulent, deceptive, and unfair business practices and to provide information to help spot, stop, and avoid them.  To file a complaint in English or Spanish, visit the FTC’s online Complaint Assistant or call 1-877-FTC-HELP (1-877-382-4357).  The FTC enters complaints into Consumer Sentinel, a secure, online database available to more than 2,000 civil and criminal law enforcement agencies in the U.S. and abroad.  The FTC’s website provides free information on a variety of consumer topics.  Like the FTC on Facebook, follow us on Twitter, and subscribe to press releases for the latest FTC news and resources.
MEDIA CONTACT:
Jay Mayfield
Office of Public Affairs

202-326-2181
 
STAFF CONTACT:
Karen Jagielski
Bureau of Consumer Protection
202-326-2509

Tuesday, May 07, 2013