Sunday, August 19, 2007
When adversary counsel refers a court's attention to a Wiki posting as "the" definitive answer to, or description of, anything, be alert. It will be helpful to point out how easily entries are manipulated to cater to one bias or another. In an article in today's New York Times (subscription required), Jimmy Wales, the founder of the Wikimedia Foundation, "which runs Wikipedia, says the site discourages such “conflict of interest” editing. “We don’t make it an absolute rule,” he said, “but it’s definitely a guideline.”
The article also notes that this non-peer reviewed ability to edit has not gone unnoticed by others: "Internet experts, for the most part, have welcomed WikiScanner. “I’m very glad that this has been exposed,” said Susan P. Crawford, a visiting professor at the University of Michigan Law School. “Wikipedia is a reliable first stop for getting information about a huge variety of things, and it shouldn’t be manipulated as a public relations arm of major companies.”
Sourcing Wikipedia posts: It is helpful to understand that a Wikipedia page cannot be traced to an individual, only to a network "owner."
An concordance about an error in fact does not make that asserted fact "true."
Techlaw Tip o' the Day: Many (if not most) networked copy machines have hard drives that store images of documents, etc. produced by the copier. These images may reside in that hard drive until they are overwritten. If your client uses this technology, include the copier hard drives in your data retention program. If you're on the discovery highway, remember to ask for images of same.
Wednesday, July 25, 2007
Civil charges relating to options backdating were filed by the SEC against SafeNet and KLA/Tencor. Perhaps more interesting is the indictment of Carol Argo, former SafeNet CFO/President. A read of the indictment, which was made public yesterday, sets forth allegations that Argo backdated options prices, BoD minutes, and her signature on documents in connection with stock option grants.
Excerpted From the Argo indictment filed in the United States District Court for the Southern District of New York:
"a. ARGO and her co-conspirators picked dates on which SafeNet’s stock price was at or near its low over a certain period, usually within the prior quarter, and made it appear as if options were granted at fair market value on those dates, when in fact they were granted at a later date.
b. ARGO and her co-conspirators prepared and caused others to prepare unanimous written consents for the Compensation Committee’s approval with backdated dates to make it appear as if the Compensation Committee had approved option grants on those dates.
c. ARGO and her co-conspirators ignored or modified existing option grants after the Compensation Committee had already executed unanimous written consents or otherwise approved option grants to take advantage of falling stock prices.
d. ARGO and her co-conspirators caused and directed false and misleading entries to be made in SafeNet’s financial books and records, thereby falsely overstating SafeNet’s publicly reported income during the period 2000 through 2006."
The question always begged (and now answered in part) --- what else is being backdated?
Tuesday, June 19, 2007
Case: IN RE SEPTEMBER 11TH LIABILITY INSURANCE COVERAGE CASES 03 Civ. 332 (SDNY 2007)
Date of Order: June 18, 2007
An opinion in the World Trade Towers insurance cases issued by United States District Judge Alvin Hellerstein and imposing sanctions of more than 1 million dollars againt Wiley Rein, LLP, Coughlin Duffy, LLP and client Zurich American Insurance Company the importance of generating, and managing provably persistent digital data integrity, something not adequately addressed by the plaintiff's counsel. Not rising to the level of spoliation (the evidence, which consisted of a printout of digital data that had apparently been intentionally deleted from a Zurich American computer, resulted in an untimely production, rather than an outright destruction of evidence. Of course, this raises some interesting issues. First, we really don't know what that digital evidence might have been, and so the print out of something, which can only very loosely (and only be corroborating witness testimony) associated with the origination evidence is itself highly suspect. Remember that a printout is at best merely a view of a view of a view of native, or source data.
I imagine that some better arguments might have been made challenging the authenticity of the printout itself based on the ephemerality of the digital data processed to create same, but the presence of one copy of what may well have represented the "true" digital evidence, supported by testimony (including some very pointed memos) seemed to have won the day in favor of a finding by the Court of Fed. R. Civ. P. Rule 11 and 37 sanctions, rather than finding of spoliation with its attendant sanctions-set.
Oh, and btwe, how much litigation, time, resources, etc. have been spent to "discover" that source data had been deleted, altered and substituted? Did anyone ask for document retention policy, logs of activity of the subject network (such as deletions, etc.) locations of "pristine" non-managed backups, etc.
Here's an excerpt from the decision by Magistrate Judge
"However, on January 11, 2002, four days later, Zurich underwriter Lynn Maier sent an email to underwriting assistants Dorothy Kelly and Gloria Fonseca-Matos, and to her supervisor, Dennis Zervos, instructing an important exception concerning the version of the policy printed out on September 11, 2001 for Mary Merkel. Maier’s email stated in relevant part:
'As per our conversation, please confirm ASAP, that the old version of the policy has been deleted from the Document Library and replaced with the final corrected policy. This information needs to be relayed to MaryMerkel in home office.Hametz Decl., Ex. 21. On January 22, 2002, claims representative William Salvatore sent anemail to two other representatives, inquiring:Do you have a copy of the Silverstein / WTC GL policy from the document library, not the copy we provided but a copy you may have printed way back when?'
Hametz Decl., Ex. 22."
"...The document, at 62 pages in length and clearly important, is not the type of document that inadvertently becomes lost without a trace. Indeed, Mary Merkel noted the importance by making a handwritten note on the cover page of the policy: “pulled from [Zurich computer system] 9-11-2001.” By the time of its First Amended Complaint, Zurich had reviewed Merkel’s files, see Platt Decl. ¶ 3, and knew, or should have known, of the “Broad Form Named Insured” endorsement."
Not the first instance of digital evidence tampering, and it won't be the last.
Thursday, June 14, 2007
Based on the court's consideration of the extensive arguments and evidence presented, the court's assessment of the credibility of the declarants and witnesses who testified at the evidentiary hearing in this matter, and the applicable law, the court finds: (1) the data in issue is extremely relevant and within the scope of information sought by plaintiffs' discovery requests; (2) the data in issue which was formerly temporarily stored in defendants' website's random access memory ("RAM") constituted "electronically stored information" and was within the possession, custody and control of defendants; (3) the data in issue which is currently routed to a third party entity under contract to defendants and received in said entity's RAM, constitutes electronically stored information," and is within defendants' possession, custody or control by virtue of defendants' ability to manipulate at will how the data in issue is routed; (4) defendants have failed to demonstrate that the preservation and production of such data is unduly burdensome, or that the other reasons they articulate justify the ongoing failure to preserve and produce such data; (5) defendants must preserve the pertinent data within their possession, custody or control and produce any data in such a manner which masks the Internet Protocol addresses ("IP addresses") of the computers used by those accessing defendants' website;(6) sanctions against defendants for spoliation of evidence are not appropriate in light of the lack of precedent for requiring the retention of data in RAM, the lack of a preservation request specifically directed to data present only in RAM, and the fact that defendants' failure to retain such data did not violate any preservation order; and (7) awarding attorneys' fees and costs are not appropriate.
Well, at least defendant wasn't hit with attorneys fees and costs. Time to amend those requests for production...That way, you might have a chance obtaining an order finding spoliation, with a sanctions garnish...
In this unsealed order from Columbia Pictures, et al. v. Brunelli, cv-06-1093 (CD Cal) [the Torrentspy copyright case], the federal magistrate ruled that information contained in a server's RAM constitute discoverable documents, and has ordered its production. Looks like a wire-tap, smells like a wire tap... That issue aside, this gives new meaning to the concept of a "continuing obligation" to produce.
cNEt calls this a "weapon of mass discovery." It certainly is, Ollie. More details soon.
Wednesday, May 23, 2007
In Affinity Internet, Inc., d/b/a Skynetweb, v. Consolidated Credit Counseling Services, Inc. No. 4D05-1193 (4th Dist. FL 2006), the Court of Appeals refused to enforce an arbitration clause which had been incorporated by reference --- to a web site. Chief among the reasons for rejecting such incorporation was that the link was a dead link, or did not point to the arbitration clause. Of course, an argument could have been made as well that no foundation was laid to establish that the link was *the* link in question to specific arbitration clause asserted. Imo, the evidentiary quality is otherwise very weak.
Sunday, May 20, 2007
Which means, of course that a District Judge will (at least in the Southern and Eastern District of New York) accord substantial deference to an eDiscovery ruling.
From the May 15, 2007 Eastern District decision in Curto v. Medical World Communications, Inc. Slip Copy, 2007 WL 1452106 (E.D.N.Y. 2007).
"This Court reviews a magistrate judge's decision regarding non-dispositive pretrial matters under a “clearly erroneous or contrary to law” standard. See 28 U.S.C. § 636(b)(1)(A); Fed.R.Civ.P. 72(a). Discovery matters are generally considered non-dispositive of litigation. See Thomas E. Hoar, Inc. v. Sara Lee Corp., 900 F.2d 522, 525 (2d Cir.1990).
An order is “clearly erroneous” only if a reviewing court, considering the entirety of the evidence, “ ‘is left with the definite and firm conviction that a mistake has been committed’ “; an order is “contrary to law” when it “fails to apply or misapplies relevant statutes, case law, or rules of procedure.' “ EEOC v. First Wireless Group, Inc., 225 F.R.D. 404, 405 (E.D.N.Y.2004) (quoting Weiss v. La Suisse, 161 F.Supp.2d 305, 320-21 (S.D.N.Y.2001)). This standard is “highly deferential,” “imposes a heavy burden on the objecting party,” and “only permits reversal where the magistrate judge abused his discretion.” Mitchell v. Century 21 Rustic Realty, 233 F.Supp.2d 418, 430 (E.D.N.Y.2002). Because it is clear that a magistrate judge is best qualified to “judge the entire atmosphere of the discovery process,” Bogan v. Northwestern Mut. Life Ins. Co., 144 F.R.D. 51, 53 (S.D.N.Y.1992), his discovery-related rulings are entitled to substantial deference. See Nikkal Indus., Ltd. v. Salton, Inc., 689 F.Supp. 187, 189 (S.D.N.Y.1988) ( “Consistently, it has been held that a magistrate's report resolving a discovery discourse between litigants should be afforded substantial deference and be overturned only if found to be an abuse of discretion.”)."
Just because you ask for electronically stored information, does not mean the producing party must produce the information requested in electronic format.
In Pace v. International Mill Service, Inc. Slip Copy, 2007 WL 1385385 (N.D.Ind. 2007), the Court denied a motion to compel, holding that "[Plaintiff's] assumption that Rule 34 can be read to provide a general standard for electronic documents, without reference to his specific request, is incorrect. The Court reasoned that so long as the production is "reasonably usable" it complies with discovery rules.
The Court then offers a wonderful gotcha issued in Northern Crossarm Company, Inc. v. Chemical Specialities, Inc., 2004 WL 635606 (W.D.Wis.2004) in which it notes with approval that Court's observation that “First, plaintiff did not specifically request production of the e-mail in electronic format, it simply asked for production of documents, adopting the definition in Rule 34(a). This certainly entitled plaintiff to disclosure of the information stored electronically, but it did not require production in electronic format.”
Moral: Competency competency check: Just because you make an Fed. R. Civ. P. Rule 34 Request does not mean that you will get electronically stored information in the manner in which it is stored. Stripped electronic information, by way of .pdf or .tiff format may, absent a specific request (and be ready understand how to defend that request) suffice.
Tuesday, May 15, 2007
From The May 15 Issue of the Florida Bar News
Said Bar Ethics Counsel Elizabeth Tarbert: “Lawyers have an obligation of confidentiality, which requires that lawyers take reasonable precautions from inadvertently disclosing client information, as well as from purposefully disclosing client information. “Lawyers also have a duty of competence, which includes keeping current with technological changes that may affect the lawyers’ clients.”
The latest issue of Compliance Magazine reports that the SEC is thinking about, if not formally considering, reviewing and changing the definition of materiality. The last revision to that definition was, according to the article, eight years ago, and the current question is whether to shift from a quantitative to a qualitative definition. This type of shift would actually align with the shift to "risk based" guidelines. My bet is that the SEC does shift to this, because it will appear to allow more wiggle room. If this shift does occur, it will open a litigation floodgate, because a failure to implement proper info-sec policies and processes, which only by extension could be argued to be material, now would be a component of materiality (what's info-sec if not qualitative)
I've had (rather loud) discussions as to whether info-sec policies and processes can be factored into current materiality criteria. A good argument can be made for content authentication technology, but PKI deployments such as identity authentication present more attenuated analyses.
Substituting, or even incorporating a qualitative test into a materiality analysis would, imo, remove the attenuation between info-sec and materiality. It would also open the litigation floodgates.
Friday, May 04, 2007
You can find the opinion here
http://www.mdd.uscourts.gov/Opinions152/Opinions/Lorraine%20v.%20Markel%20-%20ESIADMISSIBILITY%20OPINION.pdf
CIVIL ACTION NO. PWG-06-1893
MEMORANDUM OPINION
"Be careful what you ask for, the saying goes, because you might actually get it. For the last several years there has been seemingly endless discussion of the rules regarding the discovery of electronically stored information (“ESI”). The adoption of a series of amendments to the Federal Rules of Civil Procedure relating to the discovery of ESI in December of 2006 has only heightened, not lessened, this discussion. Very little has been written, however, about what is required to insure that ESI obtained during discovery is admissible into evidence at trial, or whether it constitutes “such facts as would be admissible in evidence” for use in summary judgment practice. FED. R. CIV. P. 56(e).3 This is unfortunate, because considering the significant costs associated with discovery of ESI, it makes little sense to go to all the bother and expense to get electronic information only to have it excluded from evidence or rejected from consideration during summary judgment because the proponent cannot lay a sufficient foundation to get it admitted. The process is complicated by the fact that ESI comes in multiple evidentiary “flavors,” including e-mail, website ESI, internet postings, digital photographs, and computer-generated documents and data files.
Excerpted from the conclusion, which pretty much sums it all up.
"In this case the failure of counsel collectively to establish the authenticity of their exhibits,resolve potential hearsay issues, comply with the original writing rule, and demonstrate the absence of unfair prejudice rendered their exhibits inadmissible, resulting in the dismissal, without prejudice,of their cross motions for summary judgment. The discussion above highlights the fact that there are five distinct but interrelated evidentiary issues that govern whether electronic evidence will be admitted into evidence at trial or accepted as an exhibit in summary judgment practice. Although each of these rules may not apply to every exhibit offered, as was the case here, each still must be considered in evaluating how to secure the admissibility of electronic evidence to support claims and defenses. Because it can be expected that electronic evidence will constitute much, if not most, of the evidence used in future motions practice or at trial, counsel should know how to get it right on the first try. The Court hopes that the explanation provided in this memorandum will assist in that endeavor."
Steven
PWG-06-1893 (DC MD May 4, 2007) Getting It Right on the First Try.
Chief Magistrate Judge Paul Grimm of the United States District Court for the District of Maryland issued what is more guidance and analysis than decision in this magnum opus opinion. Largely directed at counsel, the opinion exposes the heightened scrutiny for computer generated information generally, and almost literally talks a walk through almost every section of the Federal Rules of Evidence. The 9th Circuit's decision in In re Vee Vinhnee, the Connecticut Court of Appeals decision in Swinton, and others are all viewed quite the positive light.
Oh, and btw, counsel failed to meet their authentication burden.
The last paragraph of the Markel decision sums it up:
"In this case the failure of counsel collectively to establish the authenticity of their exhibits,resolve potential hearsay issues, comply with the original writing rule, and demonstrate the absence of unfair prejudice rendered their exhibits inadmissible, resulting in the dismissal, without prejudice,of their cross motions for summary judgment. The discussion above highlights the fact that there are five distinct but interrelated evidentiary issues that govern whether electronic evidence will be admitted into evidence at trial or accepted as an exhibit in summary judgment practice. Although each of these rules may not apply to every exhibit offered, as was the case here, each still must be considered in evaluating how to secure the admissibility of electronic evidence to support claims and defenses. Because it can be expected that electronic evidence will constitute much, if not most, of the evidence used in future motions practice or at trial, counsel should know how to get it right on the first try. The Court hopes that the explanation provided in this memorandum order will assist in that endeavor."
Monday, April 23, 2007
The NY Lawyer reports that "Officials released a prisoner from a state facility after receiving a phony fax that ordered the man be freed, and didn't catch the mistake for nearly two weeks."
Ok, so there were typos in the Order, the order "demanded" the prisoner's release, and the fax was sent from a grocery store.
The real message is this: Better crafted documents will follow. They will have letterheads, "signatures" and all the trappings of "legitimate" court documents.
Think that can't happen? Remember Parmalat? In that 18 billion dollar bankruptcy, company officials scanned, and then pieced together, a document purporting to confirm the existing of billions of dollars in foreign bank account. How? Scanned Bank of America Letterhead, signature of a BofA VP (technology area) and created document content with bank account number, deposit amount, and a confirmation. The auditors ate it whole.
Saturday, April 21, 2007
A Bankrate.com article appearing today on msn.com http://realestate.msn.com/selling/Article_bankrate.aspx?cp-documentid=4697254>1=9323 poses the question: When does "photoshopping out" that tanning factory refuse pool abutting your gazebo cross the line between unethical and illegal?
While the article seems to argue a sliding scale, e.g., "greener grass" vs a foundation crack, one can make two observations pertinent to emerging authentication issues for computer-generated information offered into evidence:
The first is that digital data manipulation is becoming more pervasive. Much more pervasive.The second is that, as an attorney, any undisclosed alteration to a photo upon which I rely to my economic or other detriment (such as health, perhaps?) may well be actionable.
The attorney analyzing this makes appropriately conditional statements.
n.b.: I am not disregarding the duty of a buyer to physically inspect premises, but in instances where photographic evidence is the only proof of something, the "trend" may not be your "friend".
Wednesday, April 18, 2007
From April 2007: Spoliation and eDiscovery Opinion in Teague v. Target Corp. d/b/a Target Stores, Inc. Slip Copy, 2007 WL 1041191 (W.D.N.C. 2007). Here, a United States District Court Judge (and not a magistrate) found that the plaintiff had spoliated evidence by not preserving her home computernot preserving her computer well after she retained counsel and filed her EEOC charge:
"Plaintiff clearly had an obligation to preserve her computer because it contained electronic evidence relating to her claims against Target and her efforts to mitigate her damages. As noted earlier, she had already hired counsel and filed an EEOC charge. Under the circumstances the court concludes that there is enough evidence that Plaintiff discarded the computer with a “culpable state of mind.” The electronic information contained on the computer was clearly relevant to her claims and to the defenses of the Defendant. Accordingly, the court finds that an adverse inference instruction to the jury is warranted and appropriate." Teague v. Target Corp. d/b/a Target Stores, Inc. Slip Copy, 2007 WL 1041191 at *2.
From January 2007: Spoliation and eDiscovery Opinion and Order by Magistrate Judge Andrew Peck of the Southern District of New York: In re NTL, Inc. Securities Litigation, 2007 WL 241344 (S.D.N.Y. 2007); 1:02-cv-03013-LAK-AJP (SDNY January 30, 2007).
What we are seeing here is that what I consider to be the draw back prior to the tsunami. In the coming months there will be a flood of predominantly magistrate-judge level decisions on eDiscovery matters. The amended (to include) eDiscovery provisions of the Federal Rules of Civil Procedure is nearly four months old. The visibility of magistrate judges will increase with the upcoming torrent of eDiscovery issues and disputes. My wager is that since magistrate judges have generally been delegated with decision-making authority on discovery matters, the largest volume of decisional authority will come from magistrate-level rulings.
The Court here found that defendants engaged in spoliation of evidence (including emails) after what appears to have been a half-hearted effort to impose a litigaiton hold after notice of litigation or impending litigation occurred.
In what I believe will be of increasing importance in eDiscovery, the Court cites well established decisional authority interpreting the meaning of "control" pursuant to the provisions of Fed. R. Civ. P. 34.
"'The test for the production of documents is control, not location.'" In re Flag Telecom Holdings, Ltd. Sec. Litig., 236 F.R.D. at 180 (quoting Marc Rich & Co. v. United States,707 F.2d 663, 667 (2d Cir.), cert denied, 463 U.S. 1215, 103 S. Ct. 3555 (1983)). "Documents may be within the control of a party even if they are located abroad." In re Flag Telecom Holdings, Ltd.Sec. Litig., 236 F.R.D. at 180." In re NTL, Inc. Securities Litigation, 2007 WL 241344 at *17.
If "location" is not part of the "test" for document production, it appears that an accessibility argument based on "location" (as in, "we store the backup tapes at Cobalt Peak secure underground storage facility) won't fly.
Another interesting snippet, embracing within the definition of control the "practical ability" to obtain documents :
"Under Rule 34, "'control' does not require that the party have legal ownership or actual physical possession of the documents at issue; rather, documents are considered to be under a party's control when that party has the right, authority, or practical ability to obtain the documents from a non-party to the action." Bank of New York v. Meridien Biao Bank Tanzania Ltd., 171 F.R.D. 135, 146-47 (S.D.N.Y. 1997); see also, e.g., In re Flag Telecom Holdings, Ltd. Sec. Litig., 236 F.R.D. at 180; Exp.-Imp. Bank of the United States v. Asia Pulp & Paper Co., 233 F.R.D. 338, 341 (S.D.N.Y. 2005); Dietrich v. Bauer, 2000 WL 1171132 at *3 ("'Control' has been construed broadly by the courts as the legal right, authority or practical ability to obtain the materials sought upon demand.") (emphasis added); In re NASDAQ Market-Makers Antitrust Litig., 169 F.R.D. 493, 530 (S.D.N.Y. 1996); Golden Trade, S.r.L. v. Lee Apparel Co., 143 F.R.D. 514, 525 (S.D.N.Y.1992) (The courts have "interpreted Rule 34 to require production if the party has the practical ability to obtain the documents from another, irrespective of his legal entitlement to the documents.")(emphasis added)." In re NTL, Inc. Securities Litigation, at *17.
What we are seeing is what I consider to be the beginning of a flood of magistrate-judge level decisions on eDiscovery matters. The eDiscovery rules are still new, (although arguably applicable to open-discovery matters) but since magistrate judges have generally been delegated with decision-making authority on discovery matters, their visibility will increase with the torrent of eDiscovery issues, disputes and rulings to come.
Friday, April 13, 2007
The heightening "DR3" tension, by which I mean the tension among document retention, disaster recovery, and discovery requests, is highlighted by the current kerfuffle over White House staffer email gone missing, and then rising like the phoenix. Interesting recount of events are reported in today's New York Times and elsewhere.
It appears that, by using the facilities (i.e. email accounts) of the Republican National Committee, as many as 50 WH staffers may have violated the Presidential Records Act. That act generally requires in perpetuity preservation of certain government documents. The RNC, however, has a document retention policy providing for the destruction of all emails after 30 days. Oops.
There have been conflicting statements in connection with these emails. They are "missing," "lost," or "deleted." Some 2400 pages of documents are reported by the NYT to have now been located and provided to Congress. Karl Rove is reported to have understood that "all" of his emails were being archived. All in all, one huge mess.
This points to two major DR3 tensions, the first of which is between document retention programs and statutory or regulatory retention laws and regulations having conflicting requirements.
The second DR3 issue is the "copies" or "backups" of documents which, according to the "document retention" program, now suddenly crop up after they are believed to have been destroyed in accordance with said document retention policy.
This parade of horribles underscores the need for C-level and other top management to be involved in the architecting and actual comprehension of document retention policies (and by this I don't mean having your IT people nod and tell you that "all is ok") and to institute some way to ensure, in a persistent manner, the proper enforcement of those policies.
Guess what, fellas and gals? This is all about information security and legal issues, and none of it is about perimeter defense.
For those who have steadfastly stated to me during the past 10 years that there is no way to quantify losses or potential risk of liability for time-based data manipulation, I offer the restitution arrangement agreed to by Sanjay Kumar, former CEO of Computer Associates and now convicted felon. He agreed to repay 800 million (that an 8 with 8 zeroes after the digit) for his acts, which included backdating contracts and cost Computer Associates (now CA) a bundle in earnings restatements. He actually has only $52 million to pay at the moment, but those funds are coming from his, and from his family's assets.
Friday, April 06, 2007
2007-04-06
Science News Online Article: Computing Photographic Forgeries
Dartmouth Professor develops software program to detect digital image forgery. "The eyes are a partial mirror into the world in which you're photographed," Farid says. If there are two white dots in each eye, there had to have been two separate light sources. So, if a photo shows two dots in one person's eyes and only one dot in another person's eyes, it must have been spliced together from two different originals."
http://www.sciencenews.org/articles/20070324/mathtrek.asp
Really?
Here's the "yes but" ---
This presumes (1) that all eyeballs are aimed in the same direction; (2) that there is no "outlier" light source (such as a strobe or flash, or spot light) that provides a focused second source of light.
Really, the eyes are a partial mirror "of" the world in which one is photographed. This researcher has been a big promoter of near pixel-by-pixel forensic photographic analysis, and is a promoter as well of his own technology he claims accomplishes same. Nice to know he calls this a "bag of tricks" ---
Hypo time: Two dueling digital photographs. One digitally signed. The altered one. With a time and date match. Saved into different image formats (perhaps removing or rendering uninterpretable those nasty "layers") before digital signature applied. The argument: "It's digitally signed, and you can see that it hasn't been altered, kind sir (or madam)." The other is legitimate, but alas, not digitally signed. The argument: "Your honor, believe me, this photograph is the real McCoy. The other is fake.) The arguments on both sides become almost Kafkaesque.
The following excerpt is from David Levy, in his Chapter on "Authenticity in a Digital Environment" published by the Council of Library and Information Resources. He states the issue quite well: "Without the security of stable digital objects, what might we do? One possibility would be to maintain audit trails, indicating the series of transformations that has brought a particular document to the desktop. Such a trail (akin to an object's provenance) could conceivably lead back to the creation of the initial document or, at least, back to a version that we had independent reasons to trust as authentic. Having such an audit trail (and trusting it) would allow us to decide whether any of the transformations performed had violated the document's claimed authenticity. A second possibility would ignore the history of transformations and would instead specify what properties the document in question would have to have to be authentic. This would be akin to using a script or a score to ascertain the authenticity of a performance."
Rather than seeking "provenance", Professor Farid prefers "scripting." Of course, the scripting is Farid's "mathematical" bag'o tricks. They may work to ferret out forgeries or alterations, or they may not (e.g., is "sampling" used?). My apprehension is not that it might or might not work, but that, by imparting blind trust to a script, we might never know under what circumstances it would not work.
Another good quote from David Levy:
"Understanding what we want to accomplish, and what we can accomplish, with regard to authenticity in the digital realm will take considerable effort."
Content authentication information, be it image or otherwise, should be verifiably embedded or associated with data at the time data is first instantiated. It certainly would save a great deal of time and resources.
-SWT-
Wednesday, April 04, 2007
Ok. Back in Blog. Not sure I wanted to continue, but I will. I am also widening (or narrowing, depends on perspective) to include digital evidence, eDiscovery, and information technology law issues generally. Enjoy.
April 4, 2007: There is an upcoming ABA book on Digital Evidence, for which I have written a chapter or two. Stay tuned.
April 4, 2007: Order Granting Motion to Compel eDiscovery (from a February 2007 decision): For those who thought Zubulake provides a shield rather than a sword, here's my cross-post from the American Bar Association Information Security Committee List-Serve:
The following decision by Magistrate Judge Facciola in the U.S. District Court for the District of Columbia shouldn't be seen as the tsunami; but you might notice the tide going out... The decision does provide some support for applying the new eDiscovery rules to pending matters (at least where the discovery period is still open) ---something about which I was unsure. It is also interesting that most of the initial discovery rulings will fall on the shoulders of the magistrate judges (at least in Federal Courts).
The short holding: Defendant was ordered by the judge to perform "another and more complete search"
Some interesting observations:
"Under the rule pertaining to discovery of electronically stored information, accessible data must be produced at the cost of the producing party; cost-shifting does not even become a possibility unless there is first a showing of inaccessibility."
The Court then refers to suggestions it made as to where missing years of emails (sandwiched in between years in which emails had been produced) might be found:
"As I explained in my prior opinion, the sought emails, if they exist, could be located in one or more
of several places: (1) Peskoff' s NextPoint Management email account; (2) the email accounts of other employees, agents, officers, and representatives of the NextPoint entities; (3) the hard drive of Peskoff's computer or any other depository for NextPoint emails, searchable with key words; (4) other places within Peskoff' s computer, such as its "slack space," FN1 searchable with the help of a computer forensic technologist; and (5) backup tapes of Mintz Levin's servers."
"According to the Davis affidavit, Mintz Levin created back-up tapes that were overwritten every 14 days. Davis Aff. ¶ 30. After the two-week storage period, tapes are overwritten with new back-up files. Davis Aff. ¶ 20. Therefore, Davis states, anything Peskoff seeks dating back two years is long gone. Davis Aff. ¶ 30. Peskoff points out that the defendant provided no instruction to retain electronic mail at the time the archive file was created. Pls. Resp. at 3-4. In this case, a hard drive, never searched, was produced and the plaintiff's sent and received emails were produced, but (1) there are significant and unexplained gaps in what was produced, and (2) other searches of electronic data that I specifically suggested could be done were not. Furthermore, all of the unopened emails in the Inbox-a total of fourteen-are dated the same day, a date following plaintiff's departure from NextPoint. The 10,436 emails in the "Old Mail" subfolder are all unopened. The emails in the "Old Mail" subfolder are for the period June 25, 2003, to April 14, 2004, but the emails in the 65 other subfolders are all dated for the period June 2000 to June 2001. Thus, there are gaps of several years among the various subfolders with no emails whatsoever during these time periods. While there may be reasons why this is so, on this record all one can say is that this phenomenon is inexplicable."
So, the Court ignores the "long gone" argument provided by a document retention program and asks for other possible outliers.
As for inaccessibility providing a shield, well, the court appears to indicate inaccessible doesn't mean hard to accomplish:
"The obvious negative corollary of this rule [Fed. R. Civ. P 26(b)2(B) is that accessible data must be produced at the cost of the producing party; cost-shifting does not even become a possibility unless there is first a showing of inaccessibility. Thus, it cannot be argued that a party should ever be relieved of its obligation to produce accessible data merely because it may take time and effort to find what is necessary."
The upshot: "The defendant must therefore conduct a search of all depositories of electronic information in which one may reasonably expect to find all emails to Peskoff, from Peskoff, or in which the word "Peskoff" appears. Once the search is completed, defendant must make the results available to plaintiff in the same format as the electronically stored information was previously made available" Peskoff v. Faber --- F.R.D. ----, 2007 WL 530096 (D.D.C.2007).
My favorites: "obvious negative corollary" and the inexplicable "phenomenon" of a multi-year gap in an email records. That's one heckuva document retention policy. Honorable mention: 10,000-plus unopened emails.
[Inexplicable Time-lapse]
Sept 2006: The Florida Professional Ethics committee approved AO-06-2, relating how to handle metadata containing confidential information. Happy to say that Florida takes a centrist position. Recipient must not "mine" (and you miners know who you are) and senders must take appropriate measures to makes sure they don't include MD containing confidential information.
Monday, January 16, 2006
Florida Bar Takes Preliminary Position on Metadata Mining
As reported in the Florida Bar News:
"The Bar Board of Governors is asking whether an ethics opinion or Bar rule is needed to reguylate mining of metadata from electronic documents. The Florida Bar has taken the preliminary position that the mining of metadata from a digital data file constitutes unethical behavior, but in the meantime, governors didn't want to leave any doubt how they felt about it.
The Board, at its December 16 meeting in Amelia Island, voted unanimously for a motion to express its sentiment that metadata mining is something lawyers should not do.
'I have no doubt that anyone who receives a document and mines it...is unethical, unprofessional, and un-everything else', said member Jake Schickel, who made the motion that the board express its disapproval at the practice"
Florida's effort to address metadata is laudable. In fact, I think it is a jurisdictional first, and shows the forward thinking attitude of the Florida Bench and Bar.
However, the issues surrounding metadata are complex. They begin with definitional and semantic challenges (which change depending upon with whom you talk) and continue into obligations of data generators, data recipients, as well as discovery issues. Metadata can and does contain source information, authentication informatio (timestamps and digital signatures) as well otherwise potentially discoverable information. Standards authored by ANSI address the use of digital signatures and timestamps for electronic data used in the financial world. Certainly, if these digital signatures were embedded in metadata, the legitimate discovery of a litigant, or a regulatory authority, could be thwarted, and serve ends not intended by a Bar position against metadata examination. Indeed, it could be argued that information supporting an assertion of fact may only source from metadata. Another interesting question is whether, in a Federal Court matter, it might be argued the Federal Rules of Civil Procedure present a direct conflict with any proposed prohibition on the search for and use of metadata.
Imo, a sticky wicket, but one that begs at least a "college try" to set guidelines for the practitioner as well as for the Bar.
Link to the article: http://www.floridabar.org/DIVCOM/JN/JNNews01.nsf/cb53c80c8fabd49d85256b5900678f6c/c3f75b4e10e94f78852570e50051b23e?OpenDocument&Highlight=0,metadata*