Wednesday, April 18, 2007

2007-04-18 Two Good Spoliation of Electronic Evidence Decisions. Oh, and adverse inferences, to boot.


From April 2007: Spoliation and eDiscovery Opinion in Teague v. Target Corp. d/b/a Target Stores, Inc. Slip Copy, 2007 WL 1041191 (W.D.N.C. 2007). Here, a United States District Court Judge (and not a magistrate) found that the plaintiff had spoliated evidence by not preserving her home computernot preserving her computer well after she retained counsel and filed her EEOC charge:

"Plaintiff clearly had an obligation to preserve her computer because it contained electronic evidence relating to her claims against Target and her efforts to mitigate her damages. As noted earlier, she had already hired counsel and filed an EEOC charge. Under the circumstances the court concludes that there is enough evidence that Plaintiff discarded the computer with a “culpable state of mind.” The electronic information contained on the computer was clearly relevant to her claims and to the defenses of the Defendant. Accordingly, the court finds that an adverse inference instruction to the jury is warranted and appropriate." Teague v. Target Corp. d/b/a Target Stores, Inc. Slip Copy, 2007 WL 1041191 at *2.


From January 2007: Spoliation and eDiscovery Opinion and Order by Magistrate Judge Andrew Peck of the Southern District of New York: In re NTL, Inc. Securities Litigation, 2007 WL 241344 (S.D.N.Y. 2007); 1:02-cv-03013-LAK-AJP (SDNY January 30, 2007).
What we are seeing here is that what I consider to be the draw back prior to the tsunami. In the coming months there will be a flood of predominantly magistrate-judge level decisions on eDiscovery matters. The amended (to include) eDiscovery provisions of the Federal Rules of Civil Procedure is nearly four months old. The visibility of magistrate judges will increase with the upcoming torrent of eDiscovery issues and disputes. My wager is that since magistrate judges have generally been delegated with decision-making authority on discovery matters, the largest volume of decisional authority will come from magistrate-level rulings.

The Court here found that defendants engaged in spoliation of evidence (including emails) after what appears to have been a half-hearted effort to impose a litigaiton hold after notice of litigation or impending litigation occurred.


In what I believe will be of increasing importance in eDiscovery, the Court cites well established decisional authority interpreting the meaning of "control" pursuant to the provisions of Fed. R. Civ. P. 34.

"'The test for the production of documents is control, not location.'" In re Flag Telecom Holdings, Ltd. Sec. Litig., 236 F.R.D. at 180 (quoting Marc Rich & Co. v. United States,707 F.2d 663, 667 (2d Cir.), cert denied, 463 U.S. 1215, 103 S. Ct. 3555 (1983)). "Documents may be within the control of a party even if they are located abroad." In re Flag Telecom Holdings, Ltd.Sec. Litig., 236 F.R.D. at 180." In re NTL, Inc. Securities Litigation, 2007 WL 241344 at *17.

If "location" is not part of the "test" for document production, it appears that an accessibility argument based on "location" (as in, "we store the backup tapes at Cobalt Peak secure underground storage facility) won't fly.

Another interesting snippet, embracing within the definition of control the "practical ability" to obtain documents :

"Under Rule 34, "'control' does not require that the party have legal ownership or actual physical possession of the documents at issue; rather, documents are considered to be under a party's control when that party has the right, authority, or practical ability to obtain the documents from a non-party to the action." Bank of New York v. Meridien Biao Bank Tanzania Ltd., 171 F.R.D. 135, 146-47 (S.D.N.Y. 1997); see also, e.g., In re Flag Telecom Holdings, Ltd. Sec. Litig., 236 F.R.D. at 180; Exp.-Imp. Bank of the United States v. Asia Pulp & Paper Co., 233 F.R.D. 338, 341 (S.D.N.Y. 2005); Dietrich v. Bauer, 2000 WL 1171132 at *3 ("'Control' has been construed broadly by the courts as the legal right, authority or practical ability to obtain the materials sought upon demand.") (emphasis added); In re NASDAQ Market-Makers Antitrust Litig., 169 F.R.D. 493, 530 (S.D.N.Y. 1996); Golden Trade, S.r.L. v. Lee Apparel Co., 143 F.R.D. 514, 525 (S.D.N.Y.1992) (The courts have "interpreted Rule 34 to require production if the party has the practical ability to obtain the documents from another, irrespective of his legal entitlement to the documents.")(emphasis added)." In re NTL, Inc. Securities Litigation, at *17.

What we are seeing is what I consider to be the beginning of a flood of magistrate-judge level decisions on eDiscovery matters. The eDiscovery rules are still new, (although arguably applicable to open-discovery matters) but since magistrate judges have generally been delegated with decision-making authority on discovery matters, their visibility will increase with the torrent of eDiscovery issues, disputes and rulings to come.




Friday, April 13, 2007

2007-04-13

The heightening "DR3" tension, by which I mean the tension among document retention, disaster recovery, and discovery requests, is highlighted by the current kerfuffle over White House staffer email gone missing, and then rising like the phoenix. Interesting recount of events are reported in today's New York Times and elsewhere.

It appears that, by using the facilities (i.e. email accounts) of the Republican National Committee, as many as 50 WH staffers may have violated the Presidential Records Act. That act generally requires in perpetuity preservation of certain government documents. The RNC, however, has a document retention policy providing for the destruction of all emails after 30 days. Oops.

There have been conflicting statements in connection with these emails. They are "missing," "lost," or "deleted." Some 2400 pages of documents are reported by the NYT to have now been located and provided to Congress. Karl Rove is reported to have understood that "all" of his emails were being archived. All in all, one huge mess.

This points to two major DR3 tensions, the first of which is between document retention programs and statutory or regulatory retention laws and regulations having conflicting requirements.

The second DR3 issue is the "copies" or "backups" of documents which, according to the "document retention" program, now suddenly crop up after they are believed to have been destroyed in accordance with said document retention policy.

This parade of horribles underscores the need for C-level and other top management to be involved in the architecting and actual comprehension of document retention policies (and by this I don't mean having your IT people nod and tell you that "all is ok") and to institute some way to ensure, in a persistent manner, the proper enforcement of those policies.

Guess what, fellas and gals? This is all about information security and legal issues, and none of it is about perimeter defense.

2007-04-13 The High Cost of Backdating

For those who have steadfastly stated to me during the past 10 years that there is no way to quantify losses or potential risk of liability for time-based data manipulation, I offer the restitution arrangement agreed to by Sanjay Kumar, former CEO of Computer Associates and now convicted felon. He agreed to repay 800 million (that an 8 with 8 zeroes after the digit) for his acts, which included backdating contracts and cost Computer Associates (now CA) a bundle in earnings restatements. He actually has only $52 million to pay at the moment, but those funds are coming from his, and from his family's assets.

Friday, April 06, 2007

2007-04-06

Science News Online Article: Computing Photographic Forgeries

Dartmouth Professor develops software program to detect digital image forgery. "The eyes are a partial mirror into the world in which you're photographed," Farid says. If there are two white dots in each eye, there had to have been two separate light sources. So, if a photo shows two dots in one person's eyes and only one dot in another person's eyes, it must have been spliced together from two different originals."

http://www.sciencenews.org/articles/20070324/mathtrek.asp

Really?

Here's the "yes but" ---

This presumes (1) that all eyeballs are aimed in the same direction; (2) that there is no "outlier" light source (such as a strobe or flash, or spot light) that provides a focused second source of light.
Really, the eyes are a partial mirror "of" the world in which one is photographed. This researcher has been a big promoter of near pixel-by-pixel forensic photographic analysis, and is a promoter as well of his own technology he claims accomplishes same. Nice to know he calls this a "bag of tricks" ---


Hypo time: Two dueling digital photographs. One digitally signed. The altered one. With a time and date match. Saved into different image formats (perhaps removing or rendering uninterpretable those nasty "layers") before digital signature applied. The argument: "It's digitally signed, and you can see that it hasn't been altered, kind sir (or madam)." The other is legitimate, but alas, not digitally signed. The argument: "Your honor, believe me, this photograph is the real McCoy. The other is fake.) The arguments on both sides become almost Kafkaesque.

The following excerpt is from David Levy, in his Chapter on "Authenticity in a Digital Environment" published by the Council of Library and Information Resources. He states the issue quite well: "Without the security of stable digital objects, what might we do? One possibility would be to maintain audit trails, indicating the series of transformations that has brought a particular document to the desktop. Such a trail (akin to an object's provenance) could conceivably lead back to the creation of the initial document or, at least, back to a version that we had independent reasons to trust as authentic. Having such an audit trail (and trusting it) would allow us to decide whether any of the transformations performed had violated the document's claimed authenticity. A second possibility would ignore the history of transformations and would instead specify what properties the document in question would have to have to be authentic. This would be akin to using a script or a score to ascertain the authenticity of a performance."


Rather than seeking "provenance", Professor Farid prefers "scripting." Of course, the scripting is Farid's "mathematical" bag'o tricks. They may work to ferret out forgeries or alterations, or they may not (e.g., is "sampling" used?). My apprehension is not that it might or might not work, but that, by imparting blind trust to a script, we might never know under what circumstances it would not work.

Another good quote from David Levy:


"Understanding what we want to accomplish, and what we can accomplish, with regard to authenticity in the digital realm will take considerable effort."

Content authentication information, be it image or otherwise, should be verifiably embedded or associated with data at the time data is first instantiated. It certainly would save a great deal of time and resources.

-SWT-

Wednesday, April 04, 2007

2007-04-03

Ok. Back in Blog. Not sure I wanted to continue, but I will. I am also widening (or narrowing, depends on perspective) to include digital evidence, eDiscovery, and information technology law issues generally. Enjoy.


April 4, 2007: There is an upcoming ABA book on Digital Evidence, for which I have written a chapter or two. Stay tuned.

April 4, 2007: Order Granting Motion to Compel eDiscovery (from a February 2007 decision): For those who thought Zubulake provides a shield rather than a sword, here's my cross-post from the American Bar Association Information Security Committee List-Serve:


The following decision by Magistrate Judge Facciola in the U.S. District Court for the District of Columbia shouldn't be seen as the tsunami; but you might notice the tide going out... The decision does provide some support for applying the new eDiscovery rules to pending matters (at least where the discovery period is still open) ---something about which I was unsure. It is also interesting that most of the initial discovery rulings will fall on the shoulders of the magistrate judges (at least in Federal Courts).

The short holding: Defendant was ordered by the judge to perform "another and more complete search"

Some interesting observations:

"Under the rule pertaining to discovery of electronically stored information, accessible data must be produced at the cost of the producing party; cost-shifting does not even become a possibility unless there is first a showing of inaccessibility."

The Court then refers to suggestions it made as to where missing years of emails (sandwiched in between years in which emails had been produced) might be found:

"As I explained in my prior opinion, the sought emails, if they exist, could be located in one or more
of several places: (1) Peskoff' s NextPoint Management email account; (2) the email accounts of other employees, agents, officers, and representatives of the NextPoint entities; (3) the hard drive of Peskoff's computer or any other depository for NextPoint emails, searchable with key words; (4) other places within Peskoff' s computer, such as its "slack space," FN1 searchable with the help of a computer forensic technologist; and (5) backup tapes of Mintz Levin's servers."
"According to the Davis affidavit, Mintz Levin created back-up tapes that were overwritten every 14 days. Davis Aff. ¶ 30. After the two-week storage period, tapes are overwritten with new back-up files. Davis Aff. ¶ 20. Therefore, Davis states, anything Peskoff seeks dating back two years is long gone. Davis Aff. ¶ 30. Peskoff points out that the defendant provided no instruction to retain electronic mail at the time the archive file was created. Pls. Resp. at 3-4. In this case, a hard drive, never searched, was produced and the plaintiff's sent and received emails were produced, but (1) there are significant and unexplained gaps in what was produced, and (2) other searches of electronic data that I specifically suggested could be done were not. Furthermore, all of the unopened emails in the Inbox-a total of fourteen-are dated the same day, a date following plaintiff's departure from NextPoint. The 10,436 emails in the "Old Mail" subfolder are all unopened. The emails in the "Old Mail" subfolder are for the period June 25, 2003, to April 14, 2004, but the emails in the 65 other subfolders are all dated for the period June 2000 to June 2001. Thus, there are gaps of several years among the various subfolders with no emails whatsoever during these time periods. While there may be reasons why this is so, on this record all one can say is that this phenomenon is inexplicable."

So, the Court ignores the "long gone" argument provided by a document retention program and asks for other possible outliers.

As for inaccessibility providing a shield, well, the court appears to indicate inaccessible doesn't mean hard to accomplish:

"The obvious negative corollary of this rule [Fed. R. Civ. P 26(b)2(B) is that accessible data must be produced at the cost of the producing party; cost-shifting does not even become a possibility unless there is first a showing of inaccessibility. Thus, it cannot be argued that a party should ever be relieved of its obligation to produce accessible data merely because it may take time and effort to find what is necessary."

The upshot: "The defendant must therefore conduct a search of all depositories of electronic information in which one may reasonably expect to find all emails to Peskoff, from Peskoff, or in which the word "Peskoff" appears. Once the search is completed, defendant must make the results available to plaintiff in the same format as the electronically stored information was previously made available" Peskoff v. Faber --- F.R.D. ----, 2007 WL 530096 (D.D.C.2007).

My favorites: "obvious negative corollary" and the inexplicable "phenomenon" of a multi-year gap in an email records. That's one heckuva document retention policy. Honorable mention: 10,000-plus unopened emails.


[Inexplicable Time-lapse]

Sept 2006: The Florida Professional Ethics committee approved AO-06-2, relating how to handle metadata containing confidential information. Happy to say that Florida takes a centrist position. Recipient must not "mine" (and you miners know who you are) and senders must take appropriate measures to makes sure they don't include MD containing confidential information.



Monday, January 16, 2006

2006-01-16

Florida Bar Takes Preliminary Position on Metadata Mining

As reported in the Florida Bar News:

"The Bar Board of Governors is asking whether an ethics opinion or Bar rule is needed to reguylate mining of metadata from electronic documents. The Florida Bar has taken the preliminary position that the mining of metadata from a digital data file constitutes unethical behavior, but in the meantime, governors didn't want to leave any doubt how they felt about it.

The Board, at its December 16 meeting in Amelia Island, voted unanimously for a motion to express its sentiment that metadata mining is something lawyers should not do.

'I have no doubt that anyone who receives a document and mines it...is unethical, unprofessional, and un-everything else', said member Jake Schickel, who made the motion that the board express its disapproval at the practice"

Florida's effort to address metadata is laudable. In fact, I think it is a jurisdictional first, and shows the forward thinking attitude of the Florida Bench and Bar.

However, the issues surrounding metadata are complex. They begin with definitional and semantic challenges (which change depending upon with whom you talk) and continue into obligations of data generators, data recipients, as well as discovery issues. Metadata can and does contain source information, authentication informatio (timestamps and digital signatures) as well otherwise potentially discoverable information. Standards authored by ANSI address the use of digital signatures and timestamps for electronic data used in the financial world. Certainly, if these digital signatures were embedded in metadata, the legitimate discovery of a litigant, or a regulatory authority, could be thwarted, and serve ends not intended by a Bar position against metadata examination. Indeed, it could be argued that information supporting an assertion of fact may only source from metadata. Another interesting question is whether, in a Federal Court matter, it might be argued the Federal Rules of Civil Procedure present a direct conflict with any proposed prohibition on the search for and use of metadata.

Imo, a sticky wicket, but one that begs at least a "college try" to set guidelines for the practitioner as well as for the Bar.

Link to the article:
http://www.floridabar.org/DIVCOM/JN/JNNews01.nsf/cb53c80c8fabd49d85256b5900678f6c/c3f75b4e10e94f78852570e50051b23e?OpenDocument&Highlight=0,metadata*

Tuesday, January 10, 2006

2006-01-09

Software Liability Laws from an Alternate Universe...

I wrote this nearly one year ago, and decided not to post at the time. In light of recent events, including the refusal of a Breath-a-lyzer appliance manufacturer to provide source code as required by law, I will now step out on a limb, probably really annoy some people, maybe everyone and post...

Steven

The ten alternate by-laws:

1. If your operating system cannot either detect or prevent a bad guy from running his program on your computer, it is badly written, and you've purchased defective software.

2. If operating system software requires monthly patches in order to correct security issues identified by former (and current) bad guys, you've purchased defective software.

3. If operating system software contains no native anti-virus or other malware prevention features in its fourth of fifth iteration in fifteen or twenty years, you've purchased defective software.

4. Talking about trustworthy computing at trade shows does not make defective software non-defective. Or trustworthy.

5. If operating system software is designed so that popular anti-virus and anti-malware programs can't be installed with crashing the operating system, you've purchased defective software.

6. Grafting an internet browser to an operating system is like grafting a leg onto your head.

7. Creating an impression that walking around with a leg grafted onto your head makes you run better does not make you run better.

8. If an operating system is defective and subject to an exploit in a computer at home, it is more than likely to be equally defective and subject to same when ported to a mobile device.

9. Case hardening defective operating system software in a FIPS enclosure does not make the operating system software non-defective, but it probably does a great job at protecting defective software.

10. A thirty day programming hiatus is never sufficient to correct security vulnerabilities in various operating systems containing millions of lines of code.

Thursday, January 05, 2006

2006-01-04

MS Deletes Chinese Dissident Blog from MSN Spaces

Odd. A site hosted (I think) in the United States must comply with Chinese law. Interesting theory, with even more interesting ramifications. Now, if "local laws required the stoning of purveyors of sex-oriented blogs I wonder if there would be such a rush to comply...

Cnet headline: "Microsoft has admitted to removing the blog of an outspoken Chinese journalist from its MSN Spaces site, citing its policy of adhering to local laws"

"...A Microsoft representative told ZDNet UK on Wednesday that it blocked
Anti's MSN Space blog to help ensure that the service complied with local laws in China. "

And the link:
http://news.com.com/Microsoft+censors+Chinese+blogger/2100-1028_3-6017540.html?tag=nefd.top

Monday, January 02, 2006

Third Party Windows wmf Exploit Patch Made Available

Ilfak Guilfanov (the author of the patch) may be a nice guy, a capable programmer, and perhaps even a local hero. I'm not certain if I would install a patch into an OS that didn't come from the OS vendor. Of course, as of the time of this post, there is none, millions of computers are exposed, and aye, that's the rub.

This is different from 1980-1995, where the OS was relatively simple, DOS didn't have memory management or disk management (such as defrag) capabilities, and third party manufacturers such as Quarterdeck and Central Point (RIP) provided same. Indeed if a system file became corrupt, one could always reinstall pieces of or the entire operating system, quickly and painlessly, without necessity for 'net connection or authentication. Keep a copy of one's latest config.sys or autoxec.bat, even your command.com or win.ini files, and a simple copy over usually fixed most problems.

At that time, there were no high expectations that DOS was meant to really work without ever crashing, and most security problems arose from inserting infected floppy disks from friends, children, or employees with both. Certainly also at that time the expectation was that there could be no liability for such unstable platforms, because *everyone* knew that they were unstable, and used them nonetheless.

And so, for the early years of DOS, I label using these early OS's as an assumption of risk. MS has had twenty years of Wwindows and DOS programming experience to get security right, and I think that an "assumption of risk" approach is no longer applicable. On the other side of the argument, is there now some sort of "mitigation of risk" approach that might be used as (1) a shield when MS claims that the use of an authorized patch insulates it from liability, or "voids" any warranties or reps or (2) as a sword when attempting to obtain equitable relief? This is not like the situation where HP will disclaim a warranty when one uses a non-HP printer cartridge in an HP product. The product tend to work in the first instance, and third party products are provided as a cost saving measure only.

The problem with the operating system is now is that the problem *is* the operating system. All the PR, "trustworthy computing" articles, "crisis rooms" and "scientists" and "visions of the future" won't ameliorate that problem unless real, constructive action is taken. I find it discomfiting that a garage-level programming operation (no disrespect intended) has issued a patch for a critical flaw before MS can get its arms around it sufficient to provide its paying customers with secure and trusted (I consider the term "trustworthy" a semantic nullity) computing systems.

What's old is new again.

The link to the SANS Internet Storm Center article: http://isc.sans.org/diary.php?storyid=996

S

Thursday, December 29, 2005

Sony Falls on the Rootkit Sword -

In what has to be one of the fastest filing-to-settlement class action lawsuits on record (no pun intended) Sony/BMG settled the action claimin violations of the Computer Fraud and Abuse Act, Trespass to Chattel, and other claims. In what reads more like a confession than a settlement agreement, Sony agrees inter alia, to (1) take remedial steps for those who were affected by the rootkit laden CD's, (2) provide some compensation, by way of a free CD, download or coupon, (3) issue remediating (rootkit and vulnerabilit removal) software for the rootkit software already in the wild, (4) not collect consumer information, and (5) to have subsequent software issuances certified by an security expert as effective and will not create any known security vulnerabilities.

The document reads more like confession than it does a settlement. Notable is what the class action plaintiff's retained relating to reservation of rights to sue for consequential damages:
"The Settlement’s release of claims does not include claims for consequential damage to a computer or a network that may or are alleged to sult from interactions between XCP or MediaMax software and other software or hardware installed on those computers or networks. (¶¶ II.O., VIII.B.) The release excludes these claims out of concern that such claims for consequential damage to a computer or network may raise questions concerning the predominance and manageability requirements under Rule 23(b)(3) of the Federal Rules of Civil Procedure. (¶¶ II. O., VIII.B.) If the Settlement is approved, Settlement Class Members who wish to asset such claims may do so in small claims court or other venues.

Happy New Year to All.

Wednesday, December 21, 2005

California Demands Diebold eVote Appliance Source Code Certification

It appears that:

1) The code inside the machine that records the vote,
2) The output of the code (i.e., the vote) of the machine that records the vote, and
3)The audit log generated by the code of the machine that records the vote

Are all susceptible to undetectable manipulation. This comes as no surprise. Computers are not sentient (except for those with Turing potential, and there are none yet) and do not lie, but those who program are, and may. Knowing what the coder/manufacturer has placed inside a device, what it does, how it does it, and concrete proof (rather than assurances) that it will always do what it is purported and advertised to do, might be helpful for audit purposes.

And an honest election.

Excerpted from cNet.com:

"Diebold's woes don't end in California. Last week, elections officials in Leon County, Fla., announced plans to drop Diebold from its polling places after a Finnish security expert successfully tampered with a memory card in an optical scan machine without detection."

A wee bit'o bias (mine): Hardware based trusted timestamping schema could remediate this problem. The e-vote machine community would be well advised to follow the lead of the financial community, which has adopted and published an ANSI standard (X9F4 9.95) for Trusted Timestamps usage in the financial institution community.

Link to the Article:

http://news.com.com/California+scrutinizes+Diebold+e-voting/2100-1028_3-6004615.html?tag=nefd.top

Monday, December 19, 2005

Contemporaneously Entered (And Computerized) Time Records:


In this latest decision in the case of Cobell v. Norton from Judge Royce Lamberth of the United States District Court for the District of Columbia, a subject near and dear to my heart. Admissions were made as to ministerial changes after the fact. No cogent challenge was made as to the "currency" of the entries, as most attorneys lack the understanding of the ephemeral nature of digital data necessary to proffer same.

Link to the decision page:

http://www.dcd.uscourts.gov/opinions/district-court-2005.html


Here now, an excerpt from the decision, issued December 14, 2005:

II. CONTEMPORANEOUS TIME ENTRIES
Defendants urge the Court to reject the Interim Fee Petition on the grounds that plaintiffs
failed to submit “contemporaneous records of exact time spent on the case, by whom, their status and usual billing rates, as well as a breakdown of expenses such as the amounts spent copying documents, telephone bills, mail costs and other expenditures related to the case.” Opposition, at 8 (quoting Cmty. Hearing & Plumbing Co. v. Garrett, 2 F.2d 1143, 1146 (Fed. Cir. 1993)).

Defendants take issue, for example, with plaintiffs’ stated practice of transferring time entries from hard copy to computer. The record reveals that Gingold recorded his time in a diary and then input the information into his computer, Gingold Aff., at &¶ 1 and 2; Keith Harper, John Echohawk, and Lorna Babby maintained daily records that were subsequently entered on a eekly or monthly basis on a computer database, Harper Aff., at & 2, Echohawk Aff., at ¶ 2, abby Aff., at ¶ 2; and Stacy Gingold Bear “maintained [her] time records in an annual hard copy diary . . . . [f]rom this diary, . . entered [her] time electronically into a Quattro Pro software application.” Gingold Bear Aff., at ¶ 2.

Defendants next accuse plaintiffs of improperly “modifying,” Opposition, at 10, “editing,” id., and “altering” id. n.4, their time records. Defendants cite to those entries where plaintiffs “added clarity where contemporaneous entries had been made in abbreviated, coded, short-hand, or summary form,” Gingold Aff., at ¶ 2 (August 16, 2004); or, “slightly modified some of the descriptions to clarify the task completed,” Babby Aff., at ¶ 3; or “edited some of the original description to fix obvious recording errors . . . . because of the need for increased clarity . . . [and] slightly modified some of the descriptions so as to clarify the task that I was completing,” Echohawk Aff., at ¶ 3; or “edited some of the original descriptions to fix obvious recording errors . . . . because of the need for increased clarity . . . slightly modified some of the descriptions so as to clarify the task that [he] was completing,” Rempel Aff., at ¶ 4; or “added
clarity where contemporaneous entries had been made in abbreviated, coded, short-hand, or summary form.” Gingold Bear Aff., at ¶ 2.

The Court finds defendants’ objections to plaintiffs’ practice of transferring records from one medium to another and clarifying records to facilitate judicial review, meritless. In the first instance, defendants put forth no evidence supporting their challenge. “[A] respondent to a fee application must file affidavits in opposition [] where the respondent challenges the factual accuracy of the fee petition. Joy Mfg. Corp. v. Pullman-Peabody Co., 742 F.Supp. 911, 915 (W.D. Pa. 1990). Defendants, having been present at all proceedings and having reviewed all filings could easily have “submit[ted] to the District Court any evidence challenging the . . . the facts asserted in the affidavits submitted by respondents’ counsel,” Blum v. Stenson, 465 U.S. 886, 892 n.5 (1984) (citing City of Detroit v. Grinnell Corporation, 495 F.2d 448, 472-473 (2d Cir. 1974)). Instead, defendants offer only innuendo and speculation.

Beyond this, defendants’ interpretation of the “contemporaneous time records” requirement is draconian. A time record is “contemporaneous” if its descriptions are both “accurate and current,” In re Hudson & Manhattan R. R. Co., 339 F.2d 114, 115 (2d Cir. 1964), and includes “for each attorney, the date, the hours expended, and the nature of the work done.” New York Assen for Retarded Children v. Carey, 711 F.2d 1136, 1148 (2d Cir.1983). While the need to “maintain contemporaneous, complete and standardized time records which accurately reflect the work done by each attorney” is “particularly apt” in EAJA petitions since “the fee requirements will be satisfied from the United States Treasury,” In re Donovan, 877 F.2d 982, 994 (D.C. Cir. 1989), this Court does not share defendants’ obsession with the medium in which plaintiffs’ time records were entered or with the fact that abbreviated notations were clarified and mistakes corrected to assist the Court’s review.

What is significant is that plaintiffs’ time entries do not constitute “casual after-the-fact estimates.” Action on Smoking and Health v. C.A.B., 724 F.2d 211, 220 (D.C. Cir. 1984). The Court has no reason to question the veracity of plaintiffs’ sworn affirmations that they clarified abbreviated notations and shorthand to allow “this Court to make an informed decision about the relevance and appropriateness of the entry,” (Gingold Bear Aff., at ¶ 2), or that they were
“diligent to check the time claimed with contemporaneous records, briefs or memoranda to ensure against recording errors.” Echohawk Aff., at ¶ 3. In short, the Court finds defendants’
exceptions to plaintiffs’ entries on the grounds that they do not constitute contemporaneous records to be without foundation.
Wikipedia alternative aims to be 'PBS of the Web'

"No no," says Mr. Wiki. "Yes, yes," the upstart rejoins, "we're the *real* authority for meaning in the digital world. Don't listen to those other people behind the curtain. They're wrong. Why? We have PhD's from Phoenix University, that's why. And because we say so, and we're the *real* authority"...ad nauseum.

Well, maybe. At least for this week.

Real academics. True recursivity. How refreshing.

In the TV world, PBS is the abbreviation for "Public Broadcast System." A well respected informational source that takes pride in it's devotion to vetted information.

In the virtual world, and keeping in mind that on the Internet, no one knows you're a dog, this more readily dilutes into (and Wikipedia will have the definition as soon as someone posts it anonymously) "Public Bull---- Site."

More techno-babble, is all.

News.com article here: http://news.com.com/Wikipedia+alternative+aims+to+be+PBS+of+the+Web/2100-1038_3-5999200.html?tag=nefd.lede

Bah. Humbug.

Ebeneezer Grinch
Out of the Frye-ing Pan

In the case excerpted below and just decided by the Florida Third District Court of Appeal, digital evidence in the form a GPS reading was deemed admissible by the trial Court and affirmed on appeal. What is noteworthy here is *not* that the GPS data on the car's location (via Onstar) was admissible, but that the Court appears to have taken pains to provide a substantial amount of "in any event" justification for ascertaining a defendant's whereabouts at a time and place. It almost appears that the Court doesn't want to stick it's neck out too far, and finds other ample an convincing evidence to affirm.

From Still v. State of Florida, (Fla. 3rd DCA December 14, 2005) Case No. 3DO3-2970

An interesting note. The NY citation following the phrase "generally accepted" on page 3 and the word "used" at the beginning of page 4 do *not* appear on the viewable pdf at that location. That cite does appear on the next page. So, an obvious error of some sort, but this is a published opinion, and other "errors" might not be so obvious. Or as admissible under a Frye analysis.

Steven


*******
We turn next to Still’s second point on appeal that the trial court erred in failing to conduct a Frye hearing regarding the testimony of OnStar Computer Service, the operator of an in-vehicle telecommunication system. We find that the trial court correctly found that it was not necessary to conduct a Frye hearing to determine the reliability of OnStar’s evidence. Novel scientific evidence is inadmissible unless it meets the test set out in Frye v. United States, 293 F. 1013 (D.C. Cir. 1923). Courts only use the Frye test in cases of new or novel scientific evidence. See Brim v. State, 695 So. 2d 268, 271-72 (Fla. 1997). The evidence involved in this case is nothing more than commonplace global positioning satellite (GPS) technology, a technology which has been generally accepted and
, 695 N.Y.S.2d 244 (1999). used for years. The OnStar system is not new or novel scientific evidence; it is basically a tracking system that uses GPS technology. Florida courts have allowed evidence obtained from GPS systems. See Hicks v. State, 852 So. 2d 954, 957 (Fla. 5th DCA 2003). Other jurisdictions have held such tracking technology admissible without conducting a Frye hearing. See State v. Vermillion, 51 P.3d 188 (Wash. 2002); People v. Cortorreal
Furthermore, even if the trial court erred in admitting the OnStar evidence, it was harmless error because Still was not prejudiced by not having a Frye hearing. The evidence indicated that the subject vehicle had Still’s fingerprints on it, Still told his uncle the subject vehicle belonged to him, and the subject vehicle was found at Still’s aunt’s house. Moreover, an eyewitness made a positive identification of Still and saw Still leave the subject car. No expert in this case was necessary because of the overwhelming evidence tying Still to the vehicle.
*******
Wikipedia: Mass Opinion As Fact

Wikipedia seems destined to become the non-academic's attempt to fashion the universe as s/he, rather than the spin-meisters, see it. Righto. A refreshing view, if occasionally (if not almost always) wrong. Who cares about a high error rate, it's a *collective* hind-mive, er um I mean hive-mind effort. Isn't it clear by now that facts are what a majority express them to be? With Wiki, we know what the majority thinks something is. Comforting thought.

Here now, in a link from The Register, a different, and patently unfair, critique of Wikipedia. Why? Well, when I think of a Wikipedia, my mind wanders to those halcyon days when I would make some Margaritas with whatever Tequila was available, pop in a Jimmy Buffet CD, and lounge under the Tiki hut at the beach. After about five or six margaritas, I reckon I'd have been primed to contribute to wild world of Wiki under the Tiki.

Now, lessee if there's an entry for Sox compliance...

http://www.theregister.com/2005/12/16/wikipedia_britannica_science_comparison/

Sunday, December 18, 2005

Small-Cap SOX 404 Exemption Issues


I have been done a bit of research, and it appears that nowhere in SOX is there permissive authority for the SEC, through the PCAOB, to exempt small-caps, on that basis (is 150mm "small"? is 181mm "big") from 404 reporting (or compliance) requirements. As it relates to audit committees, for example, Sox §2(a)(3)(A) and §2(a)(3)(B) seem to severely restrict the SEC's ability to exempt reporting requirements except in the case of ministerial persons, etc. Notably, the exemption contained in §405 relates only Investment Companies subject to the Investment Company Act of 1940. The language states that, in the case of audit committees, "The Board, may, by rule, exempt persons engaged only in ministerial tasks from the definition in subparagraph (A), to the extent that the Board determines that any such exemption is consistent with the purposes of this Act, the public interest, or the protection of investors."

The recent recommendation of the staff to the Commission is that small-caps be exempt from 404 reporting requirements. Well, it seems that the interests of investors of small caps are either not really important and that exempting small-caps is consistent with the purposes of the SOX, the public interest, or the protection of investors.

Hmm. I see, said the blind man to the deaf man. And how many shareholder derivative suits for breaches of fiduciary duties in these "small-cap" companies are based upon fraudulent financial misrepresentations that would have as their bases defects in, or a lack of internal controls? Are small-cap shareholder's less deserving of transparency and proper internal controls than those of a large-cap? So, a mere million in capitalization keeps you opaque. How utterly rational. The dollars an investor loses from fraud in a small-cap impose equal monetary damage as an equivalent amount those dollar losses from a large-cap fraud. Even Alan Greenspan would agree with that.

15 USCA §78m (6) also appears to impose the following limitation on the SEC's exemption power reporting companies:

"6) The Commission may, by rule or order, exempt, in whole or in part, any person or class of persons from any or all of the reporting requirements of this subsection as it deems necessary or appropriate in the public interest or for the protection of investors."

If this is, as I believe, applicable to SOX 404 reporting requirements, and if the SEC chooses to so exempt small-caps pursuant to this "authority," I wonder whether a well-placed lawsuit seeking to enjoin the exemption as exceeding the statutory authority might be brought on behalf of those oh-so-well-protected small-cap investors.
Voting Machines - What's Old is New Again

It should really come as no surprise that electronic voting machines can be "hacked," but the interesting point here is that there are alleged hacks carried out by, you guessed it, those who are purportedly neutral and in control of those machines.

For those of you who take comfort in "auditable" paper printout electronic voting machines, be assured they are not. Here's a cautionary note: One can program a voting machine to

1. Appear to record a vote for "A" to a voter on a monitor screen
2. Actually record a vote for "B" for election purposes
3. Print out a vote for "A" for voter "comfort"
4. Revert to a vote "A" as the vote sent to the election authority, for audit purposes.

Sounds comforting, doesn't it?

In pertinent part from the AP via the Sarasota Herald Tribune:

TALLAHASSEE -- Gov. Jeb Bush said the state should review the way it tests electronic voting machines after a local elections official said the devices could be hacked to change race outcomes.Bush's remarks Friday come after the acting secretary of state, David Mann, said he was confident in the process of certifying voting machines. Mann said he was "concerned" only that Leon County Elections Supervisor Ion Sancho might have given an outsider access to computer codes for a test of the Diebold optical-scan machines.Sancho sent state elections officials a letter Friday requesting they do "further investigation" of Diebold Election Systems' Accuvote 2000. Sancho said his internal tests showed the optical-scan machine's memory card produces false results when hacked by elections office insiders.

Friday, December 16, 2005

Florida Court Decision: Mysterious Breath-a-lyzer Source Code - Produce or Dismiss DUI

From my (relatively new) home state in Florida, a well-reasoned (disclaimer: imo) District Court of Appeal decision about...discovery production of source code from a breath-alcohol analyzer.

The Wall Street Journal reports that: "The battle is over the source code of breath analyzers made by CMI Group, a closely held maker of breath-alcohol instruments. Defense lawyers have challenged the use of the device and asked to see the original source code that serves as its computer brain, saying their clients have the right to examine the machine that brings evidence against them."

"It seems to us that one should not have privileges and freedom jeopardized by the results of a mystical machine that is immune from discovery," the state's Fifth District Court of Appeal wrote.

It seems, that in this state at least, jurists are brave enough to not heed the admonition: "Pay no attention to the man behind the curtain..."

The breathless response by the breath-a-lyzer attorney: "It's a trade secret, and like any company they don't just turn over information for the asking," says Allen Holbrooke, outside attorney for CMI.

Well pardner, they also don't deprive a person of his or her rights based on uncorroborated say so. Y'all see, we have this here procedure in the great state of Florida we call dis-cov-er-y. So, Mr. Holbrooke, we didn't merely *ask* for that information...we made a discovery demand...the "please" language is merely a formality.

Next stop: Mystical voting machines? Mystical compliance machines? Oh no. This could out bad code in almost everything fobbed off as perfect. Gadzooks.

Thursday, December 15, 2005

Seeing Is --- Not Believing

Think thee that a photographic image is admissible because you "swear" in Court that you took the digital image? Think again. Digital data is ephemeral (meaning, eminently susceptible to manipulation and alteration) so before you believe what you see in that jpeg, think 0's and 1's, not pixels.

The following link from Cnet.com contains an article about how stem cell researchers in Korea fabricated lines, images, and not surprisingly, results.

http://news.com.com/2102-11395_3-5997074.html?tag=st.util.print

Friday, December 09, 2005

Information Security Tower of Babble -- Compliance Vendors

Everybody talks.
No one understands what anyone is saying.
Everyone nods in agreement.