<?xml version="1.0" encoding="utf-8"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xml:lang="en">
<title>Technology &amp; Marketing Law Blog</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/" />
<modified>2010-02-09T19:46:28Z</modified>
<tagline></tagline>
<id>tag:blog.ericgoldman.org,2010://1</id>
<generator url="http://www.movabletype.org/" version="3.2">Movable Type</generator>
<copyright>Copyright (c) 2010, Eric</copyright>
<entry>
<title>Catching Up With Wikipedia</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/02/catching_up_wit.htm" />
<modified>2010-02-09T19:46:28Z</modified>
<issued>2010-02-09T19:48:44Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1730</id>
<created>2010-02-09T19:48:44Z</created>
<summary type="text/plain">By Eric Goldman I recently posted the final published version of my article Wikipedia’s Labor Squeeze and its Consequences. In...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Internet History</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>I recently posted the final published version of my article <a href="http://ssrn.com/abstract=1458162">Wikipedia’s Labor Squeeze and its Consequences</a>.  In the course of updating the draft, I reviewed the news coverage of Wikipedia from the second half of 2009, and I thought I would share some of the more interesting tidbits that caught my eye.</p>

<p><b>Flagged Protection v. Flagged Revisions</b></p>

<p>The biggest news from the second half of 2009 was the August announcement from the <a href="http://wikimania2009.wikimedia.org/wiki/Portal">Buenos Aires Wikimania</a> that the English-language Wikipedia was rolling out Flagged Revisions for living people's biographies.  It was <a href="http://www.nytimes.com/2009/08/25/technology/internet/25wikipedia.html">first reported by Noam Cohen</a> at the New York Times and then repeated in countless articles.  I think the announcement took everyone by surprise because it seemed to come from out of the blue.  Several other Wikipedia versions deploy Flagged Revisions, but before Wikimania, the consensus had been to try Flagged Protection and Patrolled Revisions--not Flagged Revisions--on the English-language Wikipedia.  </p>

<p>[Some of you may be wondering: what's the difference?  A lot!  With <a href="http://en.wikipedia.org/wiki/Flagged_revision">Flagged Revisions</a>, most user edits are invisible to logged-out readers until a more trusted editor approves them.  <a href="http://en.wikipedia.org/wiki/Wikipedia:Flagged_protection">Flagged Protection</a> is a variation of Full Protection and Semi-Protection.  Edits from less trusted users to protected articles are invisible to logged-out readers until a more trusted editor approves them.  Flagged Protection substitutes for Full Protection, where less trusted users cannot make any edits to the protected articles whatsoever; and semi-protection, where only some users can make edits to those articles.  The percentage of articles currently fully- or semi-protected is very low--I believe less than 1%--and presumably Flagged Protection would be used equally sparingly.  In contrast, the media announcements indicated that Flagged Revisions would apply to all living people's biographies, a significant minority of Wikipedia entries.  <a href="http://en.wikipedia.org/wiki/Wikipedia:PLR#Patrolling">Patrolled Revisions</a> is more procedural than substantive; it's merely a way for editors to communicate with each other that they have verified previous edits.]</p>

<p>The fact that Wikipedia apparently leapfrogged Flagged Protection to adopt the much more restrictive Flagged Revisions seemed like an ominous development and perhaps an indication that the vandals and spammers were winning more than we thought.  The public angst over Wikipedia's announced move was deafening.  People seemed to be genuinely shocked that Wikipedia might make a wholesale move from an open edit site to something substantially more restrictive.</p>

<p>However, this angst was misdirected.  Despite multiple efforts to get clear information from Wikipedia (including this <a href="http://blog.wikimedia.org/2009/08/26/a-quick-update-on-flagged-revisions/">unbelievably confusing blog post</a>), it turns out that the English-language Wikipedia isn't adopting Flagged Revisions at all but instead is proceeding with its trial of Flagged Protection.  I think Farhad Manjoo properly captured our collective frustration in his TIME article entitled <a href="http://www.time.com/time/business/article/0,8599,1926826,00.html">Jimmy Wales Quietly Edits Wikipedia’s New Edit Policy</a>: “In several interviews, including many with TIME, officials at the Wikimedia Foundation, the nonprofit that manages Wikipedia, explained that the user-edited online encyclopedia would soon impose restrictions on articles about living people.”  I really don't understand how or why Wikipedia successfully misdirected us for weeks, but they could have easily avoided a lot of confusion with a clearer announcement and more prompt corrections.</p>

<p>So the bottom line is that, despite the August drama, Wikipedia is not flipping its default to closed editing yet.</p>

<p>Nevertheless, as I explain in my Wikipedia Labor Squeezes article, Wikipedia inevitably will adopt more restrictive editing policies.  It's just a matter of time.  Accordingly, I will not be surprised when Wikipedia announces more restrictions.  In contrast, judging from the reaction to the August announcement, I expect most people will be shocked when they next hear of Wikipedia's next effort to deploy a more restrictive editing policy.  </p>

<p><b>Wikitrust</b></p>

<p>In late August, <a href=" http://www.wired.com/wiredscience/2009/08/wikitrust/">Wired reported</a> that Wikipedia was adopting Wikitrust, a tool that automatically color-codes edits to an entry to show the projected credibility of those edits.  Thus, at a glance, a reader can tell which parts of an entry are more likely to be accurate and which parts should be scrutinized more closely.  Amazingly, though, this was also a botched announcement (read the update to the Wired article).  Wikipedia is only conducting a trial of Wikitrust.</p>

<p><b>A Couple Other Interesting Factoids</b></p>

<p>From <a href="http://www.newscientist.com/article/dn17554-after-the-boom-is-wikipedia-heading-for-bust.html">New Scientist</a>: ""Occasional" editors, those who make just a single edit a month, have 25 per cent of their changes erased, or reverted, by other editors, a proportion that in 2003 was 10 per cent. The revert rate for editors who make between two and nine changes a month grew from 5 to 15 per cent over the same period."</p>

<p>From <a href="http://www.nytimes.com/2009/08/31/business/media/31link.html">NY Times</a>: Wikipedia contributors are 80% male, 65%+ single, 85%+ childless and 70% under 30 years old.  As I explain in my article, this is a group that will experience significant life changes, which in turn will reduce or eliminate the time they have to contribute to Wikipedia.  Will sufficient numbers of replacements emerge?</p>

<p>From an article entitled <a href="http://www-users.cs.umn.edu/~echi/papers/2009-WikiSym/wikipedia-slow-growth-ASC-PARC.pdf">The Singularity is Not Near: Slowing Growth of Wikipedia</a><br />
- "the number of active editors and the number of edits, both measured monthly, has stopped growing since the beginning of 2007"<br />
- "The rate of reverts-per-edits (or new contributions rejected) and the number of pages protected has kept increasing.  Occasional editors experience a greater percentage of reverts per edits in comparison to the more prolific editors."</p>

<p><b>The Wall Street Journal Article</b></p>

<p>On November 23, the Wall Street Journal published an A1 article entitled <a href="http://online.wsj.com/article/SB125893981183759969.html>"Volunteers Log Off As Wikipedia Ages."</a>  I spoke with the reporter in June but my remarks only made the sidebar.  The lead paragraph thesis is that "unprecedented numbers of the millions of online volunteers who write, edit and police [Wikipedia] are quitting."  Citing <a href="http://libresoft.es/Members/jfelipe/thesis-wkp-quantanalysis">research by Felipe Ortega</a>, the article says that the English-language Wikipedia suffered a net editor loss of 49,000 in Q1 2009 (compared with a net loss of 4,900 in Q1 2008).  It's worth reading the entire article.  It stirred the pot quite a bit.</p>

<p>Erik Moeller, Wikipedia's Deputy Director, responded to the article with (among other things) <a href="http://blog.wikimedia.org/2009/11/26/wikipedias-volunteer-story/">a different cut at the numbers</a>:</p>

<blockquote>Studying the number of actual participants in a given month shows that Wikipedia participation as a whole has declined slightly from its peak 2.5 years ago, and has remained stable since then. (See WikiStats data for all Wikipedia languages combined.) On the English Wikipedia, the peak number of active editors (5 edits per month) was 54,510 in March 2007. After a more significant decline by about 25%, it has been stable over the last year at a level of approximately 40,000.</blockquote>

<p><b>My Prediction</b></p>

<p>Consider this blog post my 4+ year check-in on <a href="http://blog.ericgoldman.org/archives/2005/12/wikipedia_will.htm">my prediction in December 2005</a> that Wikipedia would fail in 5 years.  In that post, I didn't tightly define what I meant by "failure," and frankly my "failure" rhetoric has been unintentionally and unnecessarily inflammatory.  In all cases, I'm not rooting for Wikipedia's failure (however defined).  </p>

<p>However, I remain baffled by the folks who are so enraptured by Wikipedia's mystique that they believe the site will defy gravity.  Whatever you take away from the data points I cite in this post, I think it's undeniable that Wikipedia is changing in material ways.  Bright minds might disagree about whether those changes are good or bad.  From my perspective, Wikipedia's evolution has followed a fairly predictable path.  Like many UGC websites, contributor activity peaks and then declines, and the transition from first generation contributors to second generation contributors naturally has some bumps.  More structurally, Wikipedia has followed an entirely predictable evolution of progressively tighter editorial policies, and I anticipate even tighter editorial controls are come (to be accompanied by shocked public outcries each time).</p>

<p>As for my prediction, I'm waiting to see what develops this year, especially at Wikimania in August.  Whether I'm right or wrong, I'll post my 5 year assessment of my prediction in December.</p>]]>

</content>
</entry>
<entry>
<title>Third Circuit Schizophrenia Over Student Discipline for Fake MySpace Profiles</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/02/third_circuit_s_1.htm" />
<modified>2010-02-07T17:04:49Z</modified>
<issued>2010-02-07T17:05:07Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1745</id>
<created>2010-02-07T17:05:07Z</created>
<summary type="text/plain">By Eric Goldman J.S. v. Blue Mountain School District, 2010 WL 376186 (3rd Cir. Feb. 4, 2010) Layshock v. Hermitage...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Content Regulation</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p><a href="http://www.ca3.uscourts.gov/opinarch/084138p.pdf">J.S. v. Blue Mountain School District</a>, 2010 WL 376186 (3rd Cir. Feb. 4, 2010)<br />
<a href="http://www.ca3.uscourts.gov/opinarch/074465p.pdf">Layshock v. Hermitage School District</a>, 2010 WL 376184 (3rd Cir. Feb. 4, 2010)</p>

<p>Now that I’m a middle-aged man, I don’t find fake online profiles funny at all.  But if the Internet had been around when I was in my early teens, I probably would have found a salacious fake online profile of a school authority figure side-splittingly funny.  Unfortunately for today’s teens, the toxic brew of easy access to MySpace plus an underdeveloped sense of humor plus anti-authority sentiments has led to an unhealthy number of fake MySpace profiles—far too many of which result in lengthy and expensive court cases.  In practice, the “joke” ends up being on the taxpayers.</p>

<p>The cases I’ve been seeing follow a predictable pattern:</p>

<p>Step 1: young teen creates a silly fake MySpace profile of a school authority figure.<br />
Step 2: word of the MySpace profile spreads among the teen’s peers, and they have immature laughs.<br />
Step 3: targeted authority figure discovers the fake profile.<br />
Step 4: authority figure overreacts and metes out unnecessarily harsh discipline.  Sometimes, the authority figure also sues the teen/parents or brings in the cops.<br />
Step 5: the disciplined student brings a lawsuit for the authority figure’s overreaction.<br />
Step 6: the parties’ lawyers win, but everyone else—the plaintiffs, defendants, and taxpayers—loses.</p>

<p>My opinion is that the world would be a better place if immature fake online profiles weren't created.  It’s clear that any regulatory efforts to keep young teens off MySpace hasn’t eliminated this problem, and it’s unrealistic to expect that kids won’t find ways to pull silly stunts like this.  Instead, our best hope for a better future rests at Step 4, when the authority figure decides whether to laugh off the fake profile or go on a rampage.  Maybe over time school authority figures will be less shocked by fake online profiles and will learn not to take it personally.  In an ideal world, authority figures will figure out how to use these immature stunts as a valuable opportunity to teach about online information credibility and <a href="http://blog.ericgoldman.org/archives/2009/12/denver_universi.htm">the harms of cyberbullying</a>.</p>

<p>When they get to court, judges are struggling with fake online profile cases, as best evidenced by a pair of Third Circuit cases issued on the same day last week.  Two different panels reached different conclusions about whether school discipline for an off-campus-created fake MySpace profile violated the student's First Amendment rights (Layshock says yes, J.S. says no in a 2-1 split opinion).  Why the difference?</p>

<p>Surprisingly, the two opinions don’t reconcile their outcomes very well.  The Layshock case doesn’t acknowledge the J.S. opinion.  The J.S. case does acknowledge Layshock, but only in a footnote:</p>

<blockquote>we find the two cases distinguishable. Unlike the instant case, the school district in Layshock did not argue on appeal that there was, under Tinker, a nexus between the student's speech and a substantial disruption of the school environment.… This nexus, under Tinker, is the basis of our holding in the instant case. Rather, the Layshock panel held that the school district failed to establish that a sufficient nexus existed between the student's creation and distribution of the profile and the school district so that the district was permitted to regulate the student's conduct…. That panel also held, under Frazer, that the student's speech could not be considered "on-campus" speech just because it was targeted at the Principal and other members of the school community and it was reasonably foreseeable that school district and Principal would learn about the MySpace profile.</blockquote>

<p>Obviously each case is fact-specific, so the dichotomous conclusions about the on-campus effects might be explained by factual differences in the fake profiles.  From my perspective, the differences seemed pretty small, especially because I ignored the more outrageous fact-like claims as typical adolescent hyperbole.  Putting aside the profile contents, I’d argue that Layshock’s on-campus effects were greater because: (1) his was just one entry in a series of fake profiles, and (2) the MySpace profiles were accessible on campus, while in contrast the school successfully blocked on-campus MySpace access in the J.S. case.  In any case, any on-campus effects may depend on a number of factors out of the student’s control, including how the principal (over)reacts.</p>

<p>In the end, I think the main distinction between the two cases is that the J.S. court indulged its moral condemnation of the student’s poor choices, while the Layshock court kept its outrage in check.  Another possible explanation is that the principal's response in Layshock was outrageously punitive—Layshock was diverted into 3 hours/day of special classes for behaviorally disruptive students even though Layshock was a gifted student normally taking AP classes—and applied inconsistently because the students who created the other fake profiles weren’t disciplined at all.  Finally, the cases reached the Third Circuit panels in different procedural postures (e.g., Layshock won in district court on the First Amendment issue while J.S. lost in district court), and the respective school districts adopted different litigation strategies that appeared to have different efficacies.</p>

<p>Because the two Third Circuit opinions reach fact-specific outcomes without clearly distinguishing between the two factual circumstances at issue, the Third Circuit’s dichotomous rulings create a lot of uncertainty that will lead to more frequent, longer-lasting and unproductive courts battles over student-created fake online profiles.  As a result, these two cases would benefit from an en banc rehearing.  Or perhaps the Third Circuit intentionally or unintentionally created a split (an unusual intra-circuit split) to tee this issue up for Supreme Court review.</p>

<p>Some topically related blog posts:<br />
* <a href="http://blog.ericgoldman.org/archives/2008/08/principal_loses.htm">Principal Loses Lawsuit Against Students and Parents Over Fake MySpace Page--Draker v. Schreiber</a><br />
* <a href="http://blog.ericgoldman.org/archives/2006/05/teenager_busted.htm">Teenager Busted for Creating Fake "News" Story</a><br />
* <a href="http://www.ericgoldman.org/Resources/socialnetworkingsitesandthelaw.pdf">Social Networking Sites and the Law</a><br />
* <a href="http://blog.ericgoldman.org/archives/2009/04/republishing_my.htm">Moreno v. Hanford Sentinel</a>, another possibly vindictive principal response to a MySpace posting</p>]]>

</content>
</entry>
<entry>
<title>FTC Privacy Roundtable Recap</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/02/ftc_privacy_rou.htm" />
<modified>2010-02-03T00:03:14Z</modified>
<issued>2010-02-03T00:04:44Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1744</id>
<created>2010-02-03T00:04:44Z</created>
<summary type="text/plain">By Eric Goldman [Introductory note: I have repeatedly criticized the FTC on this blog, and this post may implicitly criticize...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Privacy/Security</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>[Introductory note: I have repeatedly criticized the FTC on this blog, and this post may implicitly criticize them as well.  At the same time, I want to share a couple of compliments for the FTC.  First, the FTC did a terrific job preparing for this event.  For the panel I participated on, we had two official group organizing calls, plus I had at least 3 individual calls as well.  I can’t recall another event which had more pre-event preparation efforts.  Second, I remain consistently impressed with the dedication of the FTC staff attorneys.  The FTC attorneys I've met uniformly seem to be trying to do the right thing, even if bright minds might disagree about what that is.]</p>

<p>Last week, the FTC held the <a href="http://www.ftc.gov/opa/2010/01/privacy.shtm">second</a> of <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">three privacy roundtables</a> at UC Berkeley.  A large crowd (I estimate 200+ people) showed up, and I know that many other people watched online.  Combined with my conversations with the FTC folks prior to the event, I took away a few meta-observations:</p>

<p>1) The FTC is Facebook-obsessed.  FTC staff kept citing Facebook examples.  It's clear that the FTC is paying extraordinarily close attention to Facebook.</p>

<p>2) The FTC has embraced the idea of "data as currency."  The concept is that online services that don't make consumers pay with cash instead make consumers "pay" by providing their personal data.  This didn't come up much at the second roundtable, although I understand it was a big issue at the first.  </p>

<p>It's a little dispiriting to see this argument gain traction. I have repeatedly criticized this concept before (see my <a href="http://ssrn.com/abstract=912524">Coasean Analysis of Marketing</a> and <a href="http://ssrn.com/abstract=685241">Data Mining and Attention Consumption</a> articles), so I will only briefly recap its deficiencies here.  Basically, the concept treats the provision of personal data as an automatic detriment to the consumer, which creates a zero-sum game—just like the transfer of cash, the service provider wins at the consumer's expense.  Although consumers may suffer negative consequences from providing their personal data to service providers, the overall concept is wrong because many service provider-consumer relationships are "win-win" where both the consumer and the service provider are better off due to the data transfer.  I build some economic formulas in my articles to explain these scenarios with more rigor.  Win-win can occur, for example, if the service provider can provide better services to the consumer based on access to personal data.  Personalized search is one example.  Ultimately, any policy proposals predicated on treating data as currency are likely to overregulate by reducing or eliminating potential win-win scenarios.</p>

<p>3) The term "privacy enhancing technologies" or PETs lacks a consensus definition.  Because we didn't agree on what qualifies as a PET, we couldn't determine if they had been successful or not.  </p>

<p>Construed narrowly as add-on technologies that guard against specific vectors of privacy intrusions, it's clear that PETs have failed as a mass-market offering.  Hardcore privacy folks may seek out tools that advance their interests, and they may even be willing to pay for those tools, but most folks don't care enough to pursue such solutions--even those available for free.  (I highlight this tension in my <a href="http://www.ericgoldman.org/Articles/privacyhoax.htm">2002 Forbes editorial</a>.)  </p>

<p>However, if we construe PETs more broadly, they have been massively successful.  For example, I would consider anti-spam/anti-spyware/anti-virus software as PETs.  Obviously those software programs have other benefits, such as security protection, but they solve a variety of privacy-related problems too.  For example, my Gmail spam filter learns my preferences and, over time, blocks some types of unwanted emails (such as repeat emails meant for other “egoldman”s like Emma Goldman) from showing up in my in-box.  Similarly, PETs have been incorporated into the browsers and provide default protection to their users.  If we can get past the one-off single-vector conception of PETs, we may find lots of successful examples.  </p>

<p>4) The online "privacy" dialogue hasn't advanced very far in the past 15 years.  I felt like much of the 2010 roundtable's discussion would have been apropos 15 years ago.  For example, instead of discussing cookies in 1995, in 2010 we are discussing <i>flash</i> cookies and <i>super</i>cookies.  There's no real difference in the underlying principles; we're simply at a new point in the technological arms race.  Just like technology evolved to provide user control over cookies, it will eventually catch up to flash cookies and supercookies and super-duper-cookies or whatever the next iteration of persistent client-side identifiers is called.  Unless we look past the specific technological implementations and focus on broader concepts, we are doomed to repeat the same conversations.</p>

<p>5) Due to the semantic ambiguity of the word "privacy," "privacy" inquiries are guaranteed to fail.  Ultimately, I found much of the roundtable discussion unenlightening because the "privacy" umbrella is too broad and ambiguous.  From my perspective, the term "privacy" is always fatally ambiguous to any productive conversation; I just don't understand what it means.  As a result, at the roundtable, panelists were simultaneously discussing privacy, security, anonymity and a variety of other concepts.  The result was a jumbled doctrinal mess and a lot of talking past each other.</p>

<p>At the same time, the "privacy" umbrella hindered the inclusion of non-privacy concepts that might have helped overcome the deja vu tendency.  The panel titles were:</p>

<p>Panel 1: "technology and privacy"<br />
Panel 2: "privacy implications of social networking and other platform providers"<br />
Panel 3: "privacy implications of cloud computing"<br />
Panel 4: "privacy implications of mobile computing"<br />
Panel 5: "technology and policy"</p>

<p>My latest project on reputation is relevant to the issues discussed at the roundtable, but where does "reputation" fit into these panels?  Everywhere--and nowhere.  Similarly, I was hoping to discuss the implications of <a href="http://blog.ericgoldman.org/archives/2009/07/47_usc_230c2_ta.htm">47 USC 230(c)(2)</a>, the immunization for filtering technologies, but where does that fit in?  I hoped to discuss it in the first panel but we ran out of time.  Using a classic "privacy" structure for the discussion implicitly stifles these important non-privacy considerations from emerging.  As a result, this structure almost guarantees a "same old, same old" discussion by precluding new concepts from joining the discourse.</p>

<p>Before the panel, lame-duck Commissioner Pamela Jones Harbour gave some opening remarks.  She expressed displeasure with Facebook's resetting of privacy defaults and disagreed with Mark Zuckerberg's quoted remarks that the technology change reflects emerging social attitudes.  She also gave a lengthy shout-out to <a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1450006">Paul Ohm's paper on de-anonymization/re-identification of non-PII</a>.  Note that we will have an evening panel event featuring Paul Ohm at SCU on April 7.  Please put that on your calendar now.  Paul's paper is already affecting the considerations of FTC Commissioners; come hear what the fuss is about.</p>

<p>After Commissioner Harbour, David Vladeck (head of the FTC's Bureau of Consumer Protection) gave some opening remarks as well.  He summarized three conclusions from the first roundtable:</p>

<p>* Consumers don’t understand commercial information-collection practices (ex: data brokers, behavioral targeting).<br />
* Lengthy privacy policies aren’t effective, but privacy disclosures are important.<br />
* Consumers care about privacy.  </p>

<p>He concluded his remarks with an ominous threat.  He noted that the FTC continues to bring privacy-related enforcement actions, and in particular (a quote from his prepared remarks) "we are currently examining practices that undermine the effectiveness of tools consumers can use to opt out of behavioral advertising, and we hope to announce law enforcement actions in this area this year."  I'm not sure what this means.  Perhaps the FTC is fed up with NAI's <a href="http://www.networkadvertising.org/managing/opt_out.asp">behavioral ad network opt-out tool</a>?  I have not been able to make the tool work properly for years.</p>

<p>Finally, I'll mention a few thoughts from the social networking panel, which featured Erika Rottenberg of LinkedIn, Nicole Wong of Google and Tim Sparapani of Facebook.  Given all the Facebook-bashing throughout the day, Tim was in the hot seat!  </p>

<p>One of Tim’s talking points was that 35% of users customized their privacy settings in response to Facebook's privacy default resetting and its subsequent requirement that they review the settings.  35% user participation would be a remarkably high percentage for any website, and it’s incredible for Facebook with 350M claimed users.  </p>

<p>Tim's other talking points didn't go over as well.  He claimed that there are no barriers to entry for other social networking sites.  This is technically true but woefully incomplete.  It could very well be that the optimal number of social networking sites that consumers can actively embrace is precisely one, and there is good reasons to believe that social networking sites experience powerful network effects.  See, e.g., <a href="http://www.reuters.com/article/idUSTRE60Q0K520100127">Reuter's article</a> about the tipping point between MySpace and Facebook.  </p>

<p>Further, although the friendship relations are sticky, Facebook’s real stickiness comes from the self-published content on Facebook that cannot be exported to another site.  Tim completely chunked the question about data portability from Facebook, slavishly espousing his talking point that Facebook will delete user accounts on their request--a non-sequitur that made most people in the audience quietly groan.  We all understand that Facebook will kill content upon request, but the question on the table was how Facebook will allow users to <i>move</i> their extensive content to a competitor.  Tim ducked that question because Facebook doesn't enable it.  Facebook does not offer a front door for data portability, and Facebook has been shutting down the backdoor by <a href="http://blog.ericgoldman.org/archives/2009/10/powercom_counte.htm">suing folks like Power.com</a> who try to create an unsanctioned portability method.  To be clear, I'm not 100% convinced that Power.com is the good guy in that dispute, but I'm pretty confident that Facebook doesn't tolerate backdoor data portability.</p>

<p>Even so, I think Facebook's biggest threat is itself.  Few users will get so mad that they will delete their accounts (I still have my Orkut and Friendster accounts, for example).  Instead, Facebook should be concerned that users will simply reduce their usage because they get burned out or lose trust in Facebook.  Ultimately this will cause users to migrate elsewhere, so the end game for Facebook could be a whimper, not a bang.</p>

<p>As an example of this latter phenomenon, Tim’s talking points claimed that Facebook gives users control over who they want to share every piece of data at the time they publish the data.  He rightly praised this granularity but I am still grumbly that Facebook killed the setting that kept my comments and likes off my profile page.  Now, if I don't want those items to show, I have to manually delete each one.  So I do have control over my publications as Tim touted, but the additional transaction costs cause me to comment on and like other posts less frequently than I used to.  This seems like more of a bug than a feature in my book.</p>

<p>In contrast to Facebook, Nicole Wong hammered the point that Google embraces data portability and builds it into the design of many of its services.  As she said (I'm paraphrasing her), because users can leave with a click, we have to better with every product every day, and it makes us build better products.  That's the spirit!  Facebook, are you listening?</p>]]>

</content>
</entry>
<entry>
<title>Google Street View Lawsuit Revived, But Only on Trespass Grounds--Boring v. Google</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/02/google_street_v_1.htm" />
<modified>2010-02-01T14:43:23Z</modified>
<issued>2010-02-01T14:43:50Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1742</id>
<created>2010-02-01T14:43:50Z</created>
<summary type="text/plain">By Eric Goldman Boring v. Google Inc., 2010 WL 318281 (3rd Cir. Jan. 28, 2010). You may recall the book...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Search Engines</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p><a href="http://www.ca3.uscourts.gov/opinarch/092350np.pdf">Boring v. Google Inc.</a>, 2010 WL 318281 (3rd Cir. Jan. 28, 2010).</p>

<p>You may recall the book project <a href="http://www.amazon.com/gp/product/000217734X?ie=UTF8&tag=techandmarkla-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=000217734X">A Day in the Life of America</a><img src="http://www.assoc-amazon.com/e/ir?t=techandmarkla-20&l=as2&o=1&a=000217734X" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" /> [Amazon affiliates link], which published what 200 photojournalists saw on May 2, 1986.  The book provided a great snapshot of Americana, both sensational and banal.  As a dataset, Google's Street View reminds me a lot of that book.  The Google camera cars automatically capture whatever they see, which in some cases can lead to unintentionally amusing results.  See, for example, <a href="http://www.criminaljusticeschools.com/blog/20-crimes-caught-on-google-street-view">this list of 20 crimes captured on Google Street View</a> and the Huffington Post's list of <a href="http://www.huffingtonpost.com/2009/11/15/google-street-view-funny_n_357433.html">"Craziest Google Street View Shots OF ALL TIME."</a></p>

<p>Inevitably, some people are going to be unhappy with whatever Google's camera cars indiscriminately captured and published.  The plaintiffs in this case, Aaron and Christine Boring, are Pennsylvania homeowners with a reclusive streak.  The Google camera car drove down the Borings' private driveway (allegedly ignoring the Borings' signage), took pictures of their house and published the photos through Google Street View.  </p>

<p>The Borings were not satisfied with exercising Google's opt-out mechanism and instead made a federal case out of Google's transgressions.  However, the <a href="http://blog.ericgoldman.org/archives/2009/02/google_street_v.htm">district court was not impressed</a> and kicked the Borings out of court.</p>

<p>The Borings appealed to the Third Circuit, which rewarded them with a small window of opportunity.  The district court had rejected the Borings' trespass claims because they had not adequately alleged damage from the trespass.  The appellate court reversed this point, saying a real property owner does not need to allege damage in order to state a valid trespass claim.  As the court says, "Here, the Borings have alleged that Google entered upon their property without permission. If proven, that is a trespass, pure and simple."  I'm not a real property expert, but this sounds right to me.  The district court cited an 1899 case in support of its ruling, but the appellate court said that precedent was inapplicable.  </p>

<p>Thus, the trespass claim survives a 12(b)(6) motion to dismiss, and the case gets sent back to the district court.  While the appellate court expressly didn't tell the judge what to do, it's pretty clear that the appellate court doubts that the Borings will be able to assert any cognizable damage.  As the court says, "it may well be that, when it comes to proving damages from the alleged trespass, the Borings are left to collect one dollar and whatever sense of vindication that may bring."  My guess is that's the best possible outcome for the Borings.</p>

<p>In my opinion, the court's rejection of the Borings' privacy claims is the more interesting cyberlaw development.  The court sensibly concludes that any violation suffered by the Borings would not highly offend a reasonable person.  In other words, the Borings overreacted in a way the law does not recognize.  </p>

<p>Given that the Borings weren't depicted in the photos, the court's ruling suggests that publishing online photos of private property categorically can't qualify as a privacy violation, whether the photos are taken on public or private property.  The court's ruling, however, leaves open the possibility that depicting people in the photos might still be actionable--a question not before the court.</p>

<p>While the case has been revived, it's entirely clear to me that the Borings will not find much success on remand.  Nevertheless, to save the litigation costs, Google ought to write a small check to settle the case, and the Borings would be prudent to take it rather than wait for the inevitable judicial denouement.  To avoid further unwanted intrusions, they should use their settlement money to buy a gate for their driveway.</p>]]>

</content>
</entry>
<entry>
<title>January 2010 Quick Links</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/january_2010_qu.htm" />
<modified>2010-01-31T21:49:23Z</modified>
<issued>2010-01-31T21:19:21Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1743</id>
<created>2010-01-31T21:19:21Z</created>
<summary type="text/plain">By Eric Goldman Copyright * An English translation of Google&apos;s December loss in France on a Google Book Search lawsuit....</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Copyright</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p><b>Copyright</b></p>

<p>* An English translation of Google's <a href="http://thepublicindex.org/docs/ec/martiniere_english.pdf">December loss in France on a Google Book Search lawsuit</a>.  </p>

<p>* Ed Felten reports on a <a href="http://www.freedom-to-tinker.com/blog/felten/census-files-available-bittorrent">survey of files available via BitTorrent</a>.  Acknowledging some methodological limits, he estimates ~99% were likely copyright infringing.  </p>

<p>* <a href="http://www.scribd.com/doc/25495434/Decision-Reed-Elsevier-Berne">Elsevier B.V. v. UnitedHealth Group, Inc.</a>, 2010 WL 150167 (S.D.N.Y. Jan 14, 2010).  Denying copyright statutory damages and attorneys' fees to unregistered foreign works is constitutional because the Berne Convention (which Elsevier argued prohibits the statutory formalities) is not self-executing.</p>

<p>* <a href="http://techdirt.com/articles/20091231/0258107558.shtml">Techdirt</a>: Singapore Court Rules That Online DVR Is Infringing...While Noting How Copyright Law Isn't Really Set Up For This</p>

<p>* <a href="http://techdirt.com/articles/20100112/2324347721.shtml">Techdirt</a>: If Banning The Internet For Sex Offenders Is Unfair, Is Banning The Internet For Copyright Infringers Fair? </p>

<p>* The Copyright Office issued <a href="http://www.copyright.gov/fedreg/2010/74fr3863.pdf">new regulations on the deposit of online-only works</a>: “The regulation establishes that online–only works are exempt from mandatory deposit until a demand for deposit of copies or phonorecords of such works is issued by the Copyright Office.”  </p>

<p><b>Trademark/Publicity Rights</b></p>

<p>* American Airlines v. Yahoo <a href="http://docs.justia.com/cases/federal/district-courts/texas/txndce/4:2008cv00626/181052/234/">settled</a>.  Previous coverage:    <br />
- <a href="http://blog.ericgoldman.org/archives/2009/08/yahoo_subpoenas.htm">Yahoo Subpoenas Expedia in American Airlines Lawsuit</a><br />
- <a href="http://blog.ericgoldman.org/archives/2009/03/fifth_circuit_d.htm">Fifth Circuit Denies Yahoo's Jurisdictional Appeal in American Airlines Case</a><br />
- <a href="http://blog.ericgoldman.org/archives/2009/01/american_airlin_3.htm">American Airlines v. Yahoo Venue Transfer Denied</a><br />
- <a href="http://blog.ericgoldman.org/archives/2008/12/yahoo_countersu_1.htm">Yahoo Countersues American Airlines for Declaratory Judgment</a><br />
- <a href="http://blog.ericgoldman.org/archives/2008/10/american_airlin_2.htm">American Airlines Sues Yahoo for Selling Keyword Advertising</a></p>

<p>* Duplicity alert! Rescuecom is <a href="http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=121008">in court defending its keyword ads</a> triggered by competitor Best Buy's TMs.</p>

<p>* Bev Stayart <a href="http://www.scribd.com/doc/25492283/Stayart-v-Yahoo-Amended-Complaint-January-2010">sues Yahoo again</a> over publicity rights.  My <a href="http://blog.ericgoldman.org/archives/2009/09/yahoos_search_r.htm">September 2009 blog post</a> on her prior loss against Yahoo.  </p>

<p><b>Pornography</b></p>

<p>* Clark v. Commonwealth, 2009 WL 5125009 (Ky. App. Ct. Dec. 30, 2009).  Upholding a conviction when "Clark knowingly used a computer for the purpose of getting a minor, or a peace officer whom Clark believed was a minor, to take a sexually explicit photograph of herself."</p>

<p>* <a href="http://www.supremecourt.ohio.gov/rod/docs/pdf/0/2010/2010-ohio-149.pdf">Am. Booksellers Found. for Free Expression v. Cordray</a>, Slip Opinion No. 2010-Ohio-149 (Jan. 27, 2010).  Ohio's Supreme Court partially upholds its state law restricting Internet distribution of harmful to juveniles material to juveniles when the communications are to recipients known or believed to be juveniles.</p>

<p><b>Spam</b><br />
 <br />
*  United States v. Zein (E.D. Mich. 2009).  Posting an ad on Craigslist constituted a "mass marketing" activity sufficient to trigger a 2 level sentencing enhancement.</p>

<p>* Comcast and e360 <a href="http://www.circleid.com/posts/20100120_comcast_and_e360_settle_lawsuit/">settled their lawsuit</a>.  <a href="http://blog.ericgoldman.org/archives/2008/04/47_usc_230_trifecta.htm">Previous blog coverage</a>.  </p>

<p><b>Blogs/Social Networking Sites</b></p>

<p>* Sieber v. Brownstone Publishing Company, 2007 CA 002549 B (D.C. Superior Ct. Dec. 23, 2009).  A building contractor sued Angie's List and other people over consumer reviews.  My <a href="http://blog.ericgoldman.org/archives/2007/06/new_cyberlaw_fa.htm">prior mention of the case</a>.  After 2 years of litigation, a DC trial judge dismissed all defendants on summary judgment and awarded one defendant-counterclaimant $18k+.  The entire text of the memo opinion:</p>

<blockquote>MEMORANDUM OPINION AND ORDER GRANTING MOTIONS FOR SUMMARY JUDGMENT OF ALL DEFENDANTS, DENYING PLAINTIFFS' MOTIONS FOR SUMMARY JUDGMENT, and GRANTING POOLE'S MOTION FOR SUMMARY JUDGMENT ON HIS COUNTERCLAIM signed by Judge Long, efiled, eserved, and docketed in chambers on December 23, 2009. It is ORDERED that the Motions for Summary Judgment of Brownstone Publishing Co., the Washington Post Company, John Kelly, and John W. Poole are granted; and it is FURTHER ORDERED that the Motions for Summary Judgment filed on behalf of the plaintiffs are denied; and it is FURTHER ORDERED that judgment shall be entered in favor of all defendants against the plaintiffs as to all claims in the Second Amended Complaint; and it is FURTHER ORDERED that judgment shall be entered in favor of defendant Poole and against plaintiff SCS Contracting Group LP as to Poole's Counterclaim against plaintiff SCS Contracting Group for $18,300 plus 6% (six percent) per annum interest, and a separate money judgment for this sum shall be docketed. Court Jacket not in chambers.</blockquote>

<p>* FINRA Regulatory Notice 10-06: <a href="http://www.finra.org/web/groups/industry/@ip/@reg/@notice/documents/notices/p120779.pdf">Guidance on Blogs and Social Networking Web Sites</a>.</p>

<p>* <a href="http://www.supremecourt.ohio.gov/rod/docs/pdf/2/2009/2009-ohio-6815.pdf">Duer v. Henderson</a>, 2009-Ohio-6815 (Ohio App. Ct. Dec. 23, 2009).  A web publication telling a ghost story and describing the location of purportedly paranormal phenomenon on private property is not liable for any resulting trespass to real property.</p>

<p>* The “moldy tweet” lawsuit <a href="http://www.chicagobreakingnews.com/2010/01/twitter-mold-libel-defamation-suit-dismissal-cook-county-court.html">was dismissed</a>. </p>

<p>* Two lawsuits holding that bloggers aren't subject to jurisdiction in the plaintiff's home court:<br />
- Silver v. Brown, 2009 WL 5220297 (D. N.M. Nov. 30, 2009).  <br />
- Workman Sec. Corp. v. Phillip Roy Financial Services, LLC, 2010 WL 155525 (D. Minn. Jan 11, 2010) </p>

<p>* <a href="http://news.bbc.co.uk/2/hi/programmes/click_online/8447742.stm">BBC</a>: France ponders a right-to-forget law.</p>

<p><b>E-commerce</b></p>

<p>* Appliance Zone, LLC v. NexTag Inc., No:4-09-cv-0089-SEB-WGH (S.D. Indiana Dec. 22, 2009). Upholding NextTag's clickthrough-formed advertiser agreement.  <a href="http://www.tsibouris.com/blog/2010/01/court-upholds-forum-selection-clause-in.html">Mehmet Munur’s comments</a>.</p>

<p>* Edward A. Zelinsky, <a href="http://ssrn.com/abstract=1513351">“New York’s 'Amazon Law': Constitutional But Unwise.”</a></p>

<p>* <a href="http://www.scribd.com/doc/25504223/Largo-Cargo-v-Google-Complaint">Largo Cargo v. Google</a>, a new complaint over allegedly mismanaged AdWord bids.  This is the latest incarnation of the <a href="http://www.mediapost.com/publications/?fa=Articles.showArticle&art_aid=117846">Almeida case</a>.  I think Largo Cargo’s complaint is still a no go.</p>

<p>* The <a href="http://www.nytimes.com/2010/01/16/technology/16failure.html">NYT</a> catalogs an impressive roster of futility for US dot coms trying to compete in China.  </p>

<p><b>Miscellaneous</b></p>

<p>* Gmail will <a href="http://gmailblog.blogspot.com/2010/01/serving-better-ads-in-gmail.html">consult the user's prior emails to pick an ad</a> if a particular email doesn't lend itself to a good ad.</p>

<p>* Illustrating the <a href="http://ssrn.com/abstract=1458162">divergence between the open source community and the Wikipedia community</a>, <a href="http://apcmag.com/linux-now-75-corporate.htm">APC reports</a> that 75% of Linux code is now written by paid developers. </p>

<p>* <a href="http://www.oddee.com/item_96937.aspx">Oddee</a>: 15 Funny Facebook Fails.</p>

<p>* I expect to be in the Netherlands May 23-30.  Let me know if you would like to meet up there.</p>]]>

</content>
</entry>
<entry>
<title>Terri Chen Replaces Rose Hagan as Google&apos;s Chief Trademark Counsel</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/terri_chen_repl.htm" />
<modified>2010-01-29T20:57:01Z</modified>
<issued>2010-01-29T20:58:46Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1740</id>
<created>2010-01-29T20:58:46Z</created>
<summary type="text/plain">By Eric Goldman I previously mentioned that Rose Hagan, Google&apos;s longtime chief trademark counsel, was retiring. (Her last day was...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Search Engines</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>I previously mentioned that Rose Hagan, Google's longtime chief trademark counsel, was retiring.  (Her last day was Wednesday).  Rose's next ventures include <a href="http://rosehagan.com/home.html">art</a> and <a href="http://www.facebook.com/album.php?aid=44751&id=1347683800&ref=mf">jewelry</a>.  Terri Yun-Lin Chen, a current trademark counsel at Google, has taken over Rose's spot.  Terri has a bachelors and JD from UC Berkeley, and she practiced IP litigation at Wilson Sonsini before joining Google over 3 years ago.</p>

<p>Before retiring, Rose led Google's trademark functions for 7+ years.  During that time, Google went from near-zero revenue to building a $20B+/year business selling keyword advertising, of which an unknown amount is derived from the sale of third party trademarks.  While not everything has gone smoothly for Google--most obviously there are <a href="http://blog.ericgoldman.org/archives/2009/11/cpa_deal_gone_awry.htm">10 pending lawsuits over Google's trademark policies</a>--Google's massive keyword advertising success and its ability to avoid a business-threatening/ending trademark lawsuit are both remarkable achievements that have made a lot of people a lot of money.  Also remarkable is Google's rapid ascendancy to become one of the world's most recognized and cherished brands.  Kudos to Rose on her role in these accomplishments.  She leaves big shoes for Terri to fill.</p>]]>

</content>
</entry>
<entry>
<title>Utah May Repeal Its Spyware Control Act--SB 26</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/utah_may_repeal.htm" />
<modified>2010-01-27T22:16:48Z</modified>
<issued>2010-01-27T17:58:16Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1739</id>
<created>2010-01-27T17:58:16Z</created>
<summary type="text/plain">By Eric Goldman It&apos;s that time of year again. The Utah legislature is back in session and cooking up new...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Adware/Spyware</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>It's that time of year again.  The Utah legislature is back in session and cooking up new schemes to regulate the Internet.  So far I only see one Internet-specific bill in queue, <a href="http://le.utah.gov/~2010/htmdoc/sbillhtm/sb0026.htm">SB 26</a>.  Surprisingly, it does not directly attempt to regulate keyword advertising.</p>

<p>SB 26 is sponsored by Sen. <a href="http://www.steveu.com/blog/">Stephen H. Urquhart</a>, who rocketed to national cyberlaw fame (infamy?) in 2004 when he sponsored Utah's <a href="http://www.le.state.ut.us/~2004/htmdoc/hbillhtm/HB0323S04.htm">Spyware Control Act</a>.  It was such a misguided law that it motivated me (in part) to write a <a href="http://ssrn.com/abstract=912524">71 page magnum opus</a> explaining its policy deficiencies.  It was also hampered by its fairly obvious unconstitutionality, which was <a href="http://www.benedelman.org/spyware/whenu-utah/pi-ruling-transcript.pdf">confirmed by a Utah court</a> a few months after passage.  (Note: I helped write an amicus brief in that court challenge, so you might interpret my assessment as an advocacy statement).  Following the judicial thumping, then-Rep. Urquhart shepherded an <a href="http://blog.ericgoldman.org/archives/2005/03/utah_amends_spy.htm">amendment to the Spyware Control Act</a> in 2005 that effectively neutered the law.  Since then, I believe the law has sat largely dormant.  The only court citation I know of was in the <a href="http://blog.ericgoldman.org/archives/2008/08/competitive_pop.htm">2008 Overstock v. SmartBargains case</a>, easily rejecting Overstock's mystifying attempt to make a claim under the superseded 2004 version of the law.</p>

<p>Among other items I'll discuss in a moment, SB 26 proposes to repeal the Spyware Control Act entirely.  If passed, that would be a remarkable development because most legislators let their failed laws sit on the books unused.  It takes some work to repeal a law, plus it can be a little embarrassing to repeal a law--especially after hyping up the law to get it passed initially (Urquhart had a lot of tough talk about spyware/adware in 2004-05, see, e.g., <a href="http://steveu.com/blog/2005/03/computer-spyware.html">here</a>).  Kudos to Sen. Urquhart for having the fortitude to admit and fix his errors publicly.</p>

<p>While repealing the law would be a remarkable step on its own, it's even more remarkable in the context of the Utah legislature's track record of Internet regulation.  By my count, repealing the Spyware Control Act would be at least the THIRD Utah Internet law that its legislature repealed in the past few years--the other two being <a href="http://www.le.state.ut.us/~2006/htmdoc/sbillhtm/SB0020.htm">Utah's 1995 digital signature act</a> and its infamous <a href="http://blog.ericgoldman.org/archives/2008/03/utah_amends_tra.htm">Trademark Protection Act</a>.  For a legislature that meets only a couple of months a year, a trifecta of repealed Internet laws in the past couple of years is a stunning waste of scarce legislative resources.  Wow.</p>

<p>As bad as that is, the three repealed laws don't even tell the full story of the Utah legislature's incompetence when it comes to Internet regulation.  Recall Utah's failed attempt to line its coffers by taxing email (which turned into <a href="http://blog.ericgoldman.org/archives/2007/05/utahs_dont_emai.htm">a big money-loser</a>), and don't forget its repeated attempts to regulate Internet content that have spawned years of costly litigation (see, e.g., <a href="http://blog.ericgoldman.org/archives/2007/04/congress_giveth.htm">Free Speech Coalition v. Shurtleff</a>).  From my perspective, anyone looking objectively at the Utah legislature's track record of regulating the Internet would logically conclude that they should cut their losses and focus on other legislative priorities.</p>

<p>Unfortunately, SB 26 indicates that either hope springs eternal in the Utah legislature or they are doomed to forget the lessons of history.  Despite doing some good by putting down the Spyware Control Act, the bill amazingly proposes more regulations of the Internet!  To Sen. Urquhart's credit, the bill is largely clone-and-revise proposals from other places and not drafted from scratch, which may contribute less from a regulatory standpoint but at least they aren't quite as error prone.  The proposed law has three main components:</p>

<p>1) anti-phishing/anti-pharming restrictions.  I'm not sure where the original text came from.  California has an anti-phishing law but I don't think this is a clone-and-revise of that law.  Maybe it's cloned from another state's anti-phishing law.  In any case, the anti-"phishing" proposal is noteworthy because the regulation doesn't restrict itself to email (presumably to avoid any risk of CAN-SPAM preemption).  As a result, as currently drafted, it's an unlimited anti-pretexting law applicable to both online and offline conduct.</p>

<p>2) anti-spyware restrictions.  After wiping out the Spyware Control Act, the new anti-spyware proposals are based on the California model of state anti-spyware laws, which have been followed by a couple dozen other states.  The California model regulates various types of "intentionally deceptive" conduct regarding software activity. This is what Utah should have done in 2004-05 rather than trying to develop its own sui generis law.  I generally don't have a problem with regulating intentionally deceptive software behavior, but it seems a little late to be enacting the laws now.  Most of the regulations contemplate practices more common in 2003-06 and largely defunct now, so Utah is showing up late to a party that ended years ago.</p>

<p>3) a state version of the federal Anti-Cybersquatting Consumer Protection Act.  I know some other states have enacted domain name protection laws (California comes to mind), but it's not clear what benefits these state laws have.  As far as I know, California's law is almost never used. <a href="http://pblog.bna.com/techlaw/2010/01/utah-legislator-introduces-state-anticybersquatting-proposal.html">Tom O'Toole speculates</a> that this bill will make it easier for Utah trademark owners to bring in rem lawsuits, but it's not clear to me how much this law will help given the rarity of ACPA in rem lawsuits (UDRPs are usually cheaper and faster for the same results) and already expansive jurisdictional principles under ACPA.  Further, I wonder if this law is preempted either by the dormant commerce clause or via field preemption of the federal ACPA.  </p>

<p>I should add that I’ve observed that Utah bills can change radically from draft to draft with little warning, even if the law is on the legislative floor for a final vote, so we'll have to see if this law transmogrifies through the process.   And I am keeping a vigilant watch for any <a href="http://blog.ericgoldman.org/archives/2009/06/an_insiders_loo.htm">resurrected attempts to regulate keyword advertising</a>.</p>]]>

</content>
</entry>
<entry>
<title>Facebook User Agreement Upheld in Copyright Infringement Lawsuit Over Third Party App--Miller v. Facebook</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/facebook_user_a_1.htm" />
<modified>2010-01-23T20:09:49Z</modified>
<issued>2010-01-23T19:29:18Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1738</id>
<created>2010-01-23T19:29:18Z</created>
<summary type="text/plain">By Eric Goldman Miller v. Facebook, Inc., 1:2009cv02810 (N.D. Ga. Jan. 15, 2010). Miller&apos;s complaint filed in October 2009. Miller...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Licensing/Contracts</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p><a href="http://www.scribd.com/doc/25653583/Miller-v-Facebook-Transfer-Order">Miller v. Facebook, Inc.</a>, 1:2009cv02810 (N.D. Ga. Jan. 15, 2010).  <a href="http://www.scribd.com/doc/25655929/Miller-v-Facebook-Complaint">Miller's complaint filed in October 2009</a>.</p>

<p>Miller makes the Adobe Flash videogame "Boomshine."  He alleges that defendant Yeo published a Facebook app, ChainRxn, that violates Miller's "look and feel" copyright in Boomshine.  In addition to suing Yeo, Miller sued Facebook for its role in providing access to the app.  See <a href="http://www.mediapost.com/publications/?art_aid=115480&fa=Articles.showArticle">Wendy Davis' initial story on the lawsuit from October</a>.  Facebook defended on jurisdictional grounds, asserting that Facebook's user agreement requires that the lawsuit should be heard in California, not Miller's preferred venue of Georgia. </p>

<p>The court grants the transfer request.  Miller had a Facebook account that he used to promote his games, and he consented to the Facebook user agreement--and its mandatory venue clause--when he created his account.  Miller argued that Facebook's user agreement was vague, a contract of adhesion, and inapplicable to Miller's copyright complaint.  The court efficiently rejects these attacks, noting its concerns about Facebook having 350 million potentially litigious users:</p>

<blockquote>striking the forum selection clause could wreak havoc on the entire social-networking internet industry.  If this court were to determine that the forum selection clause contained in Facebook's TOU was unenforceable, the company could face litigation in every state in this country and in nations around the globe which would have potential adverse consequences for the users of Facebook's social-networking site and for other internet companies.</blockquote> 

<p>It's hard to argue with this, but the Court's next move is trickier.  It says that Miller's copyright infringement allegations are covered by the forum selection clause, which purports to govern "any dispute about or involving the Web site and/or the Service."  A complaint about an infringing app clearly satisfies this broad language, but consider the implications.  Miller, like 350 million other people, has a Facebook account.  He's complaining about activity that isn't related to his use of his account; rather, he's complaining about wholly unrelated activity.  Read literally, this court seems to be saying that all 350M Facebook users are required to sue Facebook in Facebook's home court for any claim they may have that relates to Facebook.com.  </p>

<p>Just like this sweeping outcome has not occurred for other Internet companies like eBay, I don't expect that Facebook will be so lucky either.  However, it would have been nice if the court had been more careful explaining why a copyright infringement lawsuit brought by a copyright owner who happens to be a Facebook member is governed by the user agreement.</p>

<p>If the case gets that far, I wonder if Facebook can claim the 512 safe harbor for hosting a user-supplied allegedly infringing app.  In general, I think third party apps fits the 512 paradigm neatly--either 512(c) if Facebook hosts the app or 512(d) if Facebook links to the app.  However, Miller alleged that he sent a C&D notice to Facebook and Facebook ignored it, which putatively disqualifies Facebook from 512(c) or 512(d) coverage if the C&D satisfied the 512(c)(3) requirements.  Even if Facebook can't claim 512 protection, Miller faces a potential uphill battle proving his allegations that the ChainRxn game infringes Boomshine's "look and feel," which are tricky to enforce, especially in the gaming context.</p>

<p>I wouldn't read too much into this case, but it does seem partially responsive to the legions of unhappy Facebook users who believe that Facebook's user agreement should be struck down for one reason or another.  It's harder to trump properly formed online user agreements than most people wish, and this case is a small example of that.  Facebook users who are unhappy with Facebook's user agreement can find recourse in a variety of ways, but assuming the contract is going to fail in court is one of the least preferred methods.</p>]]>

</content>
</entry>
<entry>
<title>Google and China: Some General Thoughts</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/google_and_chin.htm" />
<modified>2010-01-22T19:58:39Z</modified>
<issued>2010-01-22T19:58:20Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1737</id>
<created>2010-01-22T19:58:20Z</created>
<summary type="text/plain">By Eric Goldman I have deferred blogging on the Google/China imbroglio for a few reasons. First, heavyweights such as Jonathan...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Search Engines</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>I have deferred blogging on the Google/China imbroglio for a few reasons.  First, heavyweights such as <a href="http://futureoftheinternet.org/google-cn">Jonathan Zittrain</a> have tracked International online censorship and online security issues more closely than I have.  Second, after Google’s provocative blog post, I wanted to see the facts develop rather than rely solely on Google’s assertions.  The spin doctors are now moving in, so the useful development of the factual record will be slowing down.</p>

<p>Third, and perhaps most importantly, the Google/China situation is really complex and multi-faceted, and it’s been difficult keeping all of the issues straight.  Some issues raised by Google’s announcement include:</p>

<p>* cybersecurity, both corporate and personal<br />
* political and industrial espionage<br />
* suppression of political speech, especially of dissidents<br />
* censorship of search engine results and the likelihood that censorial efforts can succeed on the Internet<br />
* “cyber-imperialism,” i.e., exporting US norms about Internet law to other countries<br />
* economic protectionism and whether US companies compete with local Chinese companies on a level playing field<br />
* geopolitical and trade relationships between two world nuclear superpowers </p>

<p>Heady stuff!  It would make a good summer blockbuster movie.</p>

<p>Although most folks have lauded Google for its principled stand against China’s censorship, I’m not 100% clear that Google’s decision is entirely selfless.  First, as has been noted frequently, Google has not been making inroads against local search leader Baidu.  Further, the deck may be stacked against Google in changing that situation, due perhaps to economic protectionism from the Chinese government.  Second, in a point that has gotten less attention, some members of Congress (most notably Rep. Christopher Smith) have repeatedly jawboned Google and other Internet companies to curtail their support of the Chinese government (see, e.g., the <a href="http://www.govtrack.us/congress/bill.xpd?bill=h111-2271">Global Online Freedom Act</a>).  Google might have rationally concluded that voluntarily cutting China loose could abate Congress’ interest in regulating its international operations, which might ultimately avoid profit-degrading domestic regulations.</p>

<p>On that point, I fear that we may hold duplicitous expectations when US Internet companies go global.  If a US Internet company wants to successfully compete in a foreign market, it must open a local office and build a localized versions of their services reflecting local legal requirements.  Inevitably, these localized versions will be more speech restrictive than the US version of the service.  Foreign laws don’t have the First Amendment, 47 USC 230 or (in most cases) even a weak safe harbor like 17 USC 512, plus local cultural norms may tolerate unpopular speech less than we do.  So what should a US service provider do when trying to expand internationally?  It has a few options, none of them particularly attractive:</p>

<p>* It can skip unreasonably censorious markets altogether, like Google proposes to do in China.  <br />
* It can comply with local laws, even though that runs counter to US laws and norms.  <br />
* It can ignore local laws, which is typically not a successful plan.  In extreme cases, it can lead to local company executives going to jail.<br />
* It can try to change the local country’s laws to be more like ours, either through direct advocacy or by asking the US government to pressure the local government.  We routinely use trade negotiations to do this; for example, we have successfully exported our copyright laws this way.  But countries usually aren’t thrilled to have the US tell them what their laws should be.</p>

<p>Now, I don’t support China’s efforts to censor search results or suppress political dissent.  I understand the arguments that free speech is such a basic human right, like freedom from torture, that we simply won’t tolerate any other local choice.  However, we already implicitly accept that Internet companies routinely engage in some types of legally compelled or motivated speech restrictions in other countries when they localize their services—perhaps not to the degree exercised by China, but nevertheless more than we would allow in the US.  (I note that China might factually dispute this claim because it claims to have an “open” Internet, although the reports I’ve seen suggest this claim is embarrassingly disingenuous).  I recognize that I’m making a slippery slope argument about what government-mandated censorship we’ll tolerate from US Internet companies, but I think we should acknowledge the slippery slope before we categorically reject search engines’ efforts to comply with China’s rules.</p>

<p>If Google ultimately exits China, it would leave Baidu as the search engine market kingpin.  This raises another issue I haven’t seen fully discussed.  I’m going to assume for a moment that Google is a superior search engine to Baidu.  (I’ve never used Baidu, so I have never actually compared the two).  Knocking Google out of the Chinese market does two things.  First, per my assumption, it takes the better information resource away from Chinese consumers.  Second, by reducing competitive pressures on Baidu, quasi-monopolist Baidu is more likely to reduce R&D and service improvements.  </p>

<p>If my predicate assumptions are correct, in the long run US consumers will have a consistently superior search tool compared to Chinese consumers.  (I also assume China will keep interfering with Chinese consumers’ access to Google.com and that superior market entrants won’t overtake Baidu).  Over time, China may hinder its overall long-term global competitiveness due to an inferior information infrastructure.  Perhaps this assertion is overly stylized, but I think effective information resources—such as good search engines—are necessary to maintain healthy economic markets and to enable cutting-edge R&D.  Thus, the Chinese government should view losing Google as a Chinese search engine competitor as a long-term detriment. </p>

<p>One final procedural point.  Google sparked a global verbal spat between two nuclear superpowers through a single blog post.  Talk about the power of blogging!  Google’s decision to post a confrontational blog post may have helped get the US administration on board but simultaneously reduced Google’s ability to negotiate with the Chinese government.  I’m no expert in diplomacy or Chinese cultural norms, but my reading of Google’s post is that its double-barreled accusations of government-sponsored hacking (which Google has not conclusively proved) and censorship left the Chinese government with few options to save face.  Thus, Google effectively forced the Chinese government to take a hard line and reject most proposed compromises.  I trust Google knew what it was doing and decided that was the right course of action, but in my opinion Google’s approach has pre-determined the final outcome.</p>]]>

</content>
</entry>
<entry>
<title>Keyword Ad and Product Shots Case Survives Motion to Dismiss--FragranceNet v. FragranceX</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/keyword_ad_and.htm" />
<modified>2010-01-22T00:25:56Z</modified>
<issued>2010-01-21T20:11:13Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1736</id>
<created>2010-01-21T20:11:13Z</created>
<summary type="text/plain">By Eric Goldman FragranceNet.com, Inc. v. FragranceX.com, Inc., 2010 WL 174159 (E.D.N.Y. Jan. 14, 2010) I previously blogged about this...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Trademark</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>FragranceNet.com, Inc. v. FragranceX.com, Inc., 2010 WL 174159 (E.D.N.Y. Jan. 14, 2010)</p>

<p>I <a href="http://blog.ericgoldman.org/archives/2007/06/another_court_i.htm">previously blogged</a> about this case in 2007.  That ruling was one of several in New York that, following the <a href="http://blog.ericgoldman.org/archives/2006/09/google_wins_key.htm">Rescuecom v. Google district court ruling</a>, held that buying a competitor's trademarks as keywords did not constitute a trademark use in commerce.  As a result, the court granted a motion to dismiss.</p>

<p>Looking back even further, the case has been hanging around for almost 4 years.  The first complaint was filed May 2006 and the plaintiff is now on its third amended complaint.  This longevity is remarkable in its own right--just how much is this case worth to either litigant to justify four years of litigation costs and yet still be wrassling over motions to dismiss?  The defendant tries to dismiss the complaint yet again, but this time the motion to dismiss fails, and the court directed the defendant to answer the complaint.</p>

<p><b>Copyright in Product Shots</b></p>

<p>FragranceNet claims that FragranceX copied 900+ product shots from FragranceNet's website and republished them verbatim on the FragranceX website.  FragranceX responded that product shots aren't copyrightable.  For more on the copyrightability of product shots, see my post on <a href="http://blog.ericgoldman.org/archives/2008/06/keyword_metatag_1.htm">Designer Skin v. S&L Vitamins</a> and the <a href="http://blog.ericgoldman.org/cgi-bin/web/mt-search.cgi?IncludeBlogs=1&search=%22product+shot%22">several other times</a> I've addressed the topic.  </p>

<p>I am not a fan of copyright protection for product shots.  At best, I see them as subject to a very thin copyright that protects against only verbatim republication (although FragranceNet alleges FragranceX did just that).  Even then, fair use should provide a wide range of permissible secondary uses.  However, I also don't see how the defense thought it could win a motion to dismiss that product shots are not copyrightable at all.  The defense had to overcome the presumption that photos generally are copyrightable--a presumption which was significantly reinforced in this case because FragranceNet made a successful and timely registration of the photos with the Copyright Office.  FragranceNet further alleged in the complaint that the product shots were taken with creativity.  Busting the product shot copyrights may be possible with an evidentiary record, but not beforehand.</p>

<p><b>Trademark Claims over Metatags and Keyword Ads</b></p>

<p>FragranceNet also claims that FragranceX put its trademarks in the metatags (good grief, another plaintiff who needs to internalize that <a href="http://blog.ericgoldman.org/archives/2009/09/google_confirms.htm">Google ignores keyword metatags</a>) and bought them as AdWords keywords.  FragranceX responds by alleging problems with FragranceNet's acquisition of trademark interests from a third party, but these attacks fail on a motion to dismiss.  (For true legal geeks, there is a brief and uncommon discussion of anti-champerty laws).  </p>

<p>Although not discussed/cited in this case, I note that last month <a href="http://blog.ericgoldman.org/archives/2009/12/keyword_adverti_4.htm">FragranceNet defeated a motion to dismiss</a> in a different lawsuit attacking the FragranceNet mark as generic.  Especially in light of the Hotels.com and Mattress.com Federal Circuit opinions, I expect both that defendant and this one will pursue genericness in future proceedings.</p>]]>

</content>
</entry>
<entry>
<title>4th Amendment Updates in the State Courts</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/4th_amendment_u_1.htm" />
<modified>2010-01-19T17:45:55Z</modified>
<issued>2010-01-19T17:48:19Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1711</id>
<created>2010-01-19T17:48:19Z</created>
<summary type="text/plain">The US Supreme Court is not the only Supreme Court to recently focus on 4th Amendment privacy issues critical to...</summary>
<author>
<name>Ethan Ackerman</name>

<email>eackerma@u.washington.edu</email>
</author>
<dc:subject>Privacy/Security</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p><strong>The US Supreme Court is not the only Supreme Court to recently focus on 4th Amendment privacy issues critical to technology.</strong></p>

<p>By Ethan Ackerman</p>

<p>This blog <a href="http://blog.ericgoldman.org/archives/2009/12/when_the_suprem.htm">recently covered the US Supreme Court's decision to hear a 4th Amendment case dealing with texting privacy</a>.  While technology privacy cases are fairly rare at the US Supreme Court level, many of the 50 states' highest courts have dealt with similar issues recently.  The waning months of 2009 saw three fairly important state-level 4th Amendment cases that could potentially have a big impact on electronic and online privacy.  </p>

<p><b>Searching Suspects' Cellphones</b></p>

<p>In December, the Ohio Supreme Court <a href="http://blog.cleveland.com/metro/2009/12/courts_tackling_tricking_issue.html">addressed the searches of an arrestee's cell phone</a>.  In a 4-3 split, the <a href="http://www.sconet.state.oh.us/rod/docs/pdf/0/2009/2009-Ohio-6426.pdf">court held that police searches of a suspect's cell phone, even though incident to the suspect's arrest, required a warrant</a>. The court's decision grappled with the scope of 'a search incident to arrest,' which is one of the few exceptions to the warrant requirement the 4th Amendment usually imposes.  Susan Brenner helpfully lays out the details surrounding the exception and its scope <a href="http://cyb3rcrim3.blogspot.com/2009/12/warrant-needed-to-search-cell-phone.html">here</a>.  The court noted that federal courts were split on the issue; the Supreme Court hadn't addressed cell phones or anything similar.  So the court proceeded to look at the underlying justification for the exception (officer safety, evidence protection).  The court held that the exception wasn't necessary and ruled that a warrant was necessary to protect the private and extensively detailed personal information cell phones often hold.  </p>

<p>It's perhaps an understatement to say that this area of the law isn't settled, and the Ohio court's focus on two federal cases is just a small chunk of the universe of cases on this issue. In-house counsel at the Federal Law Enforcement Training Center has <a href="http://policechiefmagazine.org/magazine/index.cfm?fuseaction=display&issue_id=52009&category_ID=3">helpfully catalogued the cases on this issue</a>.  So is the outcome sensible?  Orin Kerr is <a href="http://volokh.com/2009/12/15/supreme-court-of-ohio-rejects-search-of-cell-phone-incident-to-arrest/">a bit skeptical, but as of yet undeclared</a>. </p>

<p>In a necessary reminder that the 4th Amendment matters even in non-criminal cases, the Mississippi ACLU has taken a civil case over <a href="http://www.pcworld.com/article/171383/aclu_lawsuit_says_students_cell_phone_was_illegally_searched.html">a student's expulsion stemming from a cell phone search</a>.</p>

<p><b>Fourth Amendment Protection for Records Held by Third Parties</b></p>

<p>The second state Supreme Court case, <a href="http://www.courts.state.co.us/Courts/Supreme_Court/opinions/2009/09SA69.pdf">Colorado v. Gutierrez</a>, doesn't occur online or even address online activities.  It's about the impropriety of a (paper) search warrant for the (paper) tax records kept in the (physical) office of a tax preparer. Politicizing it just a smidge, the prosecutor in the case is running for the US Senate, and the taxpayer in the case was a Mexican immigrant.  But the case's principal issue, whether information stored with a 3rd party retains 4th Amendment protections, is one of the core issues of online privacy.  Facebook, Google Docs, every other "cloud" service, Skype, Hotmail, Google chat, Verizon wireless voicemail, and even Quicken all are 3rd parties holding private communications and information generated by their users.  While privacy policies and state and federal statutes grant (or deny) some protections to this information, the 4th Amendment remains the cornerstone of much of the protection this information has.  Several past US Supreme Court cases on the 4th Amendment have latched onto the "3rd party" present in these types of relationships to sometimes find that there was no reasonable expectation of privacy in information given to the 3rd party and thus no 4th Amendment protection.  This phenomenon was common enough to get its own name as a legal doctrine - the '3rd party' doctrine.  4th Amendment scholar Orin Kerr recently <a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1138128">published a law review article mostly praising the doctrine</a>, and skillfully addressing its applications and shortcomings in the online world.  </p>

<p>One of the major exceptions to the 3rd party doctrine is when a statute or protected type of relationship may still preserve a reasonable expectation of privacy despite transmission to a 3rd party.  Evidentiary privileges like the attorney-client or marital privilege are examples of this.  Less clear is the degree to which statutes protecting privacy may preserve the expectation.  The Supreme Court has occasionally found statutes insufficient to protect the expectation (e.g. <a href="http://supreme.justia.com/us/447/727/case.html "><em>US v. Paynter</em>, the Bank Secrecy Act was an insufficiently privacy-protecting law</a>) but hasn't to my knowledge yet found a statute sufficient.</p>

<p>In <em>Colorado v. Gutierrez</em>, the Colorado Supreme Court found the federal and state laws protecting the privacy of tax records were sufficient to create a reasonable expectation of privacy in those records, even though they were held by the 3rd party tax preparer.  Will a court hold that ECPA's protections for email, or the SCA's protections for chat logs or a Google doc, are sufficiently similar and strong to create a reasonable expectation of privacy in those records?</p>

<p><b>GPS Tracking of Vehicles</b></p>

<p>The third recent case is really a trilogy of recent state cases on GPS tracking of vehicles.  Long ago in the 1990's, GPS tracking was a world of cops and scorned spouses sticking bulky devices under cars. In the past decade with the (government-mandated) addition of GPS tracking to cellphones, and their increasing ubiquity, the prospect of after-the-fact and real-time tracking of a person's every move is closer now than its ever been.  How state courts handle these three car cases might give us some clues to how they'll handle the phone cases in the next few years.</p>

<p>New York, Wisconsin and Massachusetts went three different ways on the issue; finding, denying, and punting on 4th Amendment protections.  Jeff Bone does an excellent summary of <a href="http://www.securityprivacyandthelaw.com/2009/09/articles/government-enforcement/massachusetts-supreme-judicial-court-allows-use-of-secret-gps-to-track-an-individuals-movements-but-requires-police-to-obtain-warrant/">all three cases on his employers blog</a>, so I'll just point you there.  To give you a flavor of how the issue splits across the country and between different federal Circuits, <a href="http://www.interesting-people.org/archives/interesting-people/200905/msg00073.html">read an earlier email of mine helpfully archived on the internets</a>.  Once again go-to scholar <a href="http://volokh.com/2009/12/13/does-the-fourth-amendment-prohibit-warrantless-gps-surveillance/">Orin Kerr also has thoughts on the general issue</a>.  Continuing its record as the best place on the internet for intelligent comment debates, <a href="http://www.concurringopinions.com/archives/2008/09/the_gps_device.html"><em>Concurring Opinions</em> is host to a 2008 comments debate between Kerr and fellow scholar Renee Hutchins</a> on the issue.</p>]]>

</content>
</entry>
<entry>
<title>File Names Can Help Predict File Content in Child Porn Prosecution--US v. Beatty</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/file_names_have.htm" />
<modified>2010-01-18T18:22:21Z</modified>
<issued>2010-01-18T18:23:10Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1735</id>
<created>2010-01-18T18:23:10Z</created>
<summary type="text/plain">By Eric Goldman United States v. Beatty, 2009 WL 5220643 (W.D. Pa. Dec. 31, 2009) This is a child porn...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Privacy/Security</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>United States v. Beatty, 2009 WL 5220643 (W.D. Pa. Dec. 31, 2009)</p>

<p>This is a child porn prosecution.  Using Phex P2P software, an undercover investigator accessed the Gnutella network and conducted searches using search terms known to be used by child pornographers.  The investigator identified IP address 76.188.64.82 with 11 files with troubling titles such as:</p>

<p>* r@ygold-pedo-13yo brother fucks 11yo sister and sperm inside 61943812.mpg<br />
* (Pthc) 14yo Isabel-(Rape and Fuck) (R@ygold).mpg<br />
* Little young girl hardfucked by me-7 yrs R@ygold illegal pedo sex.mpg<br />
* (Hussyfan) (pthc) (r@ygold ) (babyshivid) Jessica 11y o get fucktgood.mpg</p>

<p>The investigator then matched hash tag fingerprints of the 11 files with child porn files in a database maintained by the Wyoming Internet Crimes Against Children (ICAC) Task Force.  Subsequently, the investigator connected Beatty to the IP address.  Based on this information, the government got a search warrant for Beatty's home, found hundreds of incriminating files on his home computer, and got incriminating statements in an interview.</p>

<p>Beatty challenged the government's right to search his home computer.  The judge and the litigants agree that the government can legally conduct remote warrantless searches of P2P share directories, but the government apparently argued that they were free by extension to look through Beatty's entire computer.  The judge rejected such a broad position, saying:</p>

<blockquote>even if the Defendant suffered no Fourth Amendment intrusion by virtue of Trooper Pearson's conduct in remotely accessing certain shared computer files, the Defendant nevertheless retained a reasonable expectation of privacy in his computer and his home such that he possesses "standing" to challenge the merits of the subject search</blockquote>

<p>This shifts the inquiry to the officers' probable cause for the warrant.  Apparently, the investigator did not download the files to review them or attach the files as evidence when requesting the search warrant.  I'm not sure why the investigator didn't do either step other than to avoid the toxicity of child porn generally.  As a result, Beatty challenged the warrant because the warrant-approving magistrate did not see the files directly or get an affidavit from the investigator stating what he saw in the files.  However, the magistrate did have the file names and the matching hash tags.  Beatty challenged both.</p>

<p>The judge and the litigants agree that file names do not dispositively predict the actual file's content.  As we know, file names can be inaccurate for a variety of reasons: plain error, semantic ambiguity, an effort to surreptitiously install malware, and as a way of increasing the content's perceived illicit value (see, e.g., the discussion in the uncited <a href="http://blog.ericgoldman.org/archives/2007/03/ninth_circuit_o.htm">Perfect 10 v. ccBill case</a> about websites with names like "illegal.net" and "stolencelebritypics.com").  The court correctly concludes that "common knowledge dictates that actual file content cannot be definitively determined from the file name alone."</p>

<p>Nevertheless, the court says that file names have <i>some</i> predictive value:</p>

<blockquote>one can also envision circumstances where the file name is so explicit and detailed in its description as to permit at least a reasonable inference as to what the actual file is likely to show. Many, if not most, of the files at issue here had titles that contained highly graphic references to specific sexual acts-including ejaculation, sexual intercourse, oral sex, and anal sex-involving children ranging in age from 7 to 13 years. Several of the files also reference terms such as "child_sex," "pedofilia," "illegal pedo sex," "incest," or "Lolita." The unmistakable inference which arises from such highly descriptive file names, is that the content includes material pertaining to the sexual exploitation of children-i.e., evidence of criminal activity, if not outright contraband. Given the number of files in question and the pointed references in their titles to specific sexual acts involving young children-described in the most coarse and vulgar terms, this inference is a strong one.</blockquote>

<p>I'm reminded of the admonishments that airport security is not a joking matter, so don't make jokes about having a bomb while going through the airport security line.  (I've seen a few airports, including the New Orleans airport, post reminders about this).  Similarly, child porn is so toxic that no one in their right mind would falsely use a file title suggesting the file is child porn.</p>

<p>The judge also credits the file titles because accurate file titles enable searches by others.  So, if you want to distribute child porn in a searchable way (a seemingly illogical proposition because, as this case illustrates, doing so puts you on a fast track to Club Fed), then you need to use keywords that match search terms.  The court says:</p>

<blockquote>As a matter of common sense, the very fact that individuals utilize search terms with P2P software to produce results (i.e., file names ) consistent with their chosen search terms suggests a substantial degree of correlation between file names and file content; if file names were, as a general rule, completely random and bearing no relation whatsoever to their content, then there would be no point in conducting a search in the first place and the whole purpose of peer-to-peer file sharing would be frustrated because there would be no meaningful method for locating the sought-after file content.</blockquote>

<p>I agree with this only superficially.  It's true that searchable metadata must have some relationship to the underlying content to make a successful match, but community outsiders might think the metadata looks inaccurate or even completely random.  Consider how <a href="http://news.cnet.com/Napster-screens-songs,-but-files-still-slip-through/2100-1023_3-253561.html">Napster users used alternative spellings</a> to route around the court-ordered blocks on various names.  Now, go one step further: if a group of Napster users agree (in an offsite discussion forum) to tag Britney Spears' songs using "Lolita" (a not wholly inappropriate appellation given some of the videos she made before the age of majority), then a block on searches for "Britney Spears" will eliminate an obvious matchmaking route but will fail to stop matchmaking completely.  Indeed, subcommunities can develop multiple synonyms that are opaque to outsiders.  For more on this, look at the <a href="http://www.urbandictionary.com/">Urban Dictionary</a> to see how slang can have multiple meanings, and note <a href="http://ssrn.com/abstract=635803">my article</a> on how a single search term can have dozens of possible meanings.   As a result, the search matchmaking process may be more complicated--and the value of "accurate" file descriptors is lower--than the court contemplates.</p>

<p>In any case, it wasn't clear how much traction Beatty expected from reducing the predictive value of file names.  Ultimately, the search warrant was issued based on the combination of the file names with the fingerprint matches.  It's not like the investigator or the judge had no idea what the files might contain--they had a hash value fingerprint matching a known child porn file.  (Beatty unsuccessfully argued that the underlying fingerprinted files should not be credited as known child porn )  Then again, there is no reason why law enforcement isn't routinely preserving copies of suspect files they think are child porn and describing the file contents (or submitting the files) when seeking search warrants, easy steps that would have largely mooted Beatty's challenges. </p>]]>

</content>
</entry>
<entry>
<title>&quot;Law &amp; Wikis&quot; Panel at AALS Law &amp; Computers Section Annual Meeting</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/aals_law_comput_1.htm" />
<modified>2010-01-13T23:20:11Z</modified>
<issued>2010-01-13T23:19:32Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1732</id>
<created>2010-01-13T23:19:32Z</created>
<summary type="text/plain">By Eric Goldman This post recaps the 2010 AALS Law &amp; Computers Section Annual Meeting on the theme of “Law...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>General</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>This post recaps the 2010 AALS Law & Computers Section Annual Meeting on the theme of “Law & Wikis.”  The program consisted of four papers submitted in response to a <a href="http://blog.ericgoldman.org/archives/2009/03/cfp_aals_2010_a.htm">Call for Papers</a> from Spring 2009.  See my <a href="http://blog.ericgoldman.org/archives/2009/11/aals_law_comput.htm">panel announcement</a> from November.  AALS will eventually post the session as a podcast.</p>

<p><b>Tim Armstrong, Crowdsourcing and Open Access</b>.  An <a href="http://docs.google.com/present/view?id=dg4d9873_338fv4n9rcw">earlier version of his slides</a>.</p>

<p>Tim is interested in open access to primary legal source materials.  Most legal source materials are now born digital, but legacy materials are often only in paper, and this material would be more valuable online.  How can we accomplish that?  Tim outlined a four-step implementation process:</p>

<p><i>Step 1</i>: Scan the materials (Tim expressly skipped over the copyright issues associated with scanning).  Current scanning projects include Google Books, the Internet Archive and the Library of Congress.</p>

<p><i>Step 2</i>: Extract the text from the scan using a free web OCR services such as any2djvu.</p>

<p>Steps 1 and 2 do not scale very well, but steps 3 and 4 can scale.</p>

<p><i>Step 3</i>: Proofread and correct the extracted text.  Two crowdsourced options for this step:</p>

<p>Option 1: <a href="http://www.pgdp.net/c/">Distributed Proofreaders</a>.  This is a large community and can get fast results.  However, the project is hierarchical/bureaucratic, which prevents new users from adding texts, and the project does not focus on legal materials.</p>

<p>Option 2: <a href="http://en.wikisource.org/wiki/Main_Page">Wikisource</a>.  Any user can add materials to Wikisource, it has an easier user interface than Distributed Proofreaders, and the project already handles many legal texts.  However, it may be slower than Distributed Proofreaders.  Tim recommended that academics consider using Wikisource to distribute scholarship.  He posted one of his PDFed articles to Wikisource, and in a few weeks, other users had extracted the text and annotated the article with links to source materials.  (I believe you can see his results <a href="http://en.wikisource.org/wiki/Fair_Circumvention">here</a>).</p>

<p>[Eric’s note: I didn’t fully understand the value of posting a PDF to Wikisource.  It seems like the author can accomplish a similar result by web publishing the final article version in HTML or a Word file, which eliminates the effort to extract the text (and avoids any errors which might arise in the extraction process).  Further, the author can incorporate links him/herself into the article.  In fact, I routinely include lots of links in my academic articles.  Ideally, law reviews will start publishing articles with complete author-supplied links rather than viewing those links as unnecessary metadata that can be tossed.  (Also, it really irks me when law review editors unnecessarily break URLs in the footnotes by adding spaces).  Despite this, I could see the value of Wikisource as another distribution channel for articles to increase readership, and I imagine the Wikisource community would add links that never occurred to the author.]</p>

<p><i>Step 4</i>: distribution and indexing.</p>

<p><b>Jon Garon, The Role of Wiki Authorship for the Curatorial Audience</b></p>

<p>Jon believes that Wikipedia as a communal authoring tool is struggling, and it will require structural changes to preserve its market share.  </p>

<p>He highlighted two Wiki norms: (1) eliminate social biases using group deliberation.  Ex: Wikipedia’s “neutral point of view.” (2) projects have group goals instead individual goals.  In effect, these norms combine to work against attributed authorship.  However, in other author communities, authors have shown that they want attribution and integrity.  For example, 97%+ of Creative Commons users chose attribution.</p>

<p>[Eric’s note: I’m generally skeptical that Creative Commons license adoptions provide accurate insight into authorial desires.  I believe that CC license adoption statistics are skewed by Flickr’s huge photo database.  Flickr has adopted a CC license requiring attribution as its default, and the overwhelming number of users (not surprisingly) accept Flickr’s default.]</p>

<p>Jon described three communities of users.  1% of users actively create content.  90%+ are totally passive.  The remaining ~10% of users are “curators”—they don’t create new content but curate it for others.  Ex: the people who reposted videos of Obama’s  inauguration.  </p>

<p>With that in mind, he notes that Wikipedia has 75,000 regular contributors, compared to the 20M amateur bloggers, 450,000 professional bloggers and 200,000 YouTube contributors.  Measured this way, Wikipedia has a relatively small contributor base, perhaps because authors’ desires conflict with Wikipedia’s norms.</p>

<p>He concluded by advocating a wiki for academic and professional communities where their contributions could “count” for their job requirements.  To start, an academic-friendly wiki could adopt attribution and integrity norms.  It would also benefit by providing ways to measure contributions, such as counting submitted words/footnotes, content resilience (how long the content lasts until it’s reversed—much like <a href="http://wikitrust.soe.ucsc.edu/">WikiTrust</a> does), inlinks and pageviews.  These measurement tools can help contributions “count” as professional accomplishments for employing education institutions and public funding sources.</p>

<p>[Eric’s note: Jon’s project is complementary to <a href="http://ssrn.com/abstract=1458162">my paper on Wikipedia</a>, and I generally agree with his concerns about Wikipedia’s labor supply.  I also agree that Wikipedia is not very friendly towards academic contributors in a number of respects, a point I explicitly explore in my paper.  We did not have time to explore what Jon thinks of <a href="http://www.citizendium.org/">Citizendium</a>, which tries to address his concerns.]</p>

<p><b>Jacqueline Lipton, Wikipedia and the European Union Database Directive</b></p>

<p>The EU Database Directive, a product of the late 1990s, assumes a content development paradigm of a single database maker aggregating text-based data into a database.  It does not contemplate Web 2.0.</p>

<p>Jacqui emphasized jurisdictional questions.  Wikipedia’s site disclosures do not expressly address EU law.  Regarding copyright, Wikipedia’s site disclosures say that the site is governed by US copyright law, but it respects other countries’ laws (whatever that means).  Thus, with respect to IP dispositions, Wikipedia effectively distinguishes between laws that govern information gathering and information dissemination.  Wikipedia assumes local IP laws apply to information gathering and US laws apply to information dissemination.  Wikipedia doesn’t address IP laws applying to information receipt.  </p>

<p>Could a Wikipedia contributor claim a database right in Wikipedia entries?  Wikipedia’s submission rules only address contributors’ copyrights, not database rights.  Jacqui isn’t sure if a Wikipedia entry could qualify as a protected “database” under the directive.</p>

<p>Could Wikipedia or its contributors have liability for pulling information from a database and republishing via Wikipedia?  She can’t answer this question without knowing the specific member state’s directive implementation.</p>

<p>Jacqui summarized her unanswered Qs:</p>

<p>* Jurisdiction/choice of law issues<br />
 - where does information gathering occur?<br />
 - information dissemination occurs in the US (Wikipedia runs on US servers)<br />
 - where is the information received?<br />
* Joint ownership?  And ownership of what?  What constitutes the database?  Presumably the collection of all Wikipedia entries constitutes a “database,” but it’s not clear if any specific entry does.<br />
* How would the directive (or specific implementations) govern databases that are jointly created by people residing in different jurisdictions?<br />
* Which jurisdiction’s fair use/fair dealing laws apply?  </p>

<p><b>Salil Mehra, WikiTruth Through WikiOrder</b> (a paper jointly authored with David Hoffman).  <a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=1354424">Download from SSRN</a>.</p>

<p>This paper considers why people cooperate on Wikipedia.  Their animating insight is that Wikipedia develops order just like the Shasta County ranchers profiled by Ellickson, but Wikipedia contributors lack the same kind of organic relationships with each other that the ranchers had.  So why has this order developed?</p>

<p>Wikipedia’s dispute resolution methods are not content-based.  Instead, they try to foster continued dialectic among contributors.  Examples of Wikipedia’s dispute resolution tools:</p>

<p>* informal methods (talk page, reversions) and requests for comments from other contributors</p>

<p>* formal methods: mediation and arbitration.  Mediation doesn’t work too well.  The site emphasizes arbitration as a solution, but site members are generally anti-lawyer and adhere to an “ignore all rules” ethos.</p>

<p>To study the Wikipedia arbitration process, Salil and David coded 267 arbitrations.  They found the most common complaints were personal attacks (94), editing wars (91) and sockpuppetry (76).  Common sanctions included cautions and probations (164), article bans (117) and Wikipedia bans (47).  Wikipedia bans were most commonly issued for impersonation and anti-social behavior.  In contrast, editing violations were negatively correlated with Wikipedia bans—the dispute resolution system tries to rehabilitate contributors rather than kick them out.</p>

<p>Some audience comments to the presentations:</p>

<p>* Wikis are a technology, and Wikipedia is just one implementation of a wiki.  We shouldn’t conflate the two.</p>

<p>* Author attribution and integrity are interrelated rights, especially for academics.</p>

<p>* Do we know what types of projects are best run through wiki technologies, and do we know what steps get the right contributors?</p>

<p>* What copyright foundation would best facilitate wiki activity?</p>]]>

</content>
</entry>
<entry>
<title>Top Cyberlaw Developments of 2009 (Eric&apos;s List)</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/top_cyberlaw_de_3.htm" />
<modified>2010-01-11T18:47:35Z</modified>
<issued>2010-01-11T18:46:05Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1728</id>
<created>2010-01-11T18:46:05Z</created>
<summary type="text/plain">By Eric Goldman Guest blogger John Ottaviani recently dropped by to offer his perspectives on 2009’s top Cyberlaw developments. While...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Internet History</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>Guest blogger John Ottaviani recently dropped by to offer <a href="http://blog.ericgoldman.org/archives/2009/12/top_cyberlaw_de_4.htm">his perspectives on 2009’s top Cyberlaw developments</a>.  While I like his list a lot, I independently developed my own top 10 list that has a different emphasis.  You might enjoy the contrasts.  My list:</p>

<p><b>#10: Louis Vuitton v. Akanoc</b>.  After the judge <a href="http://blog.ericgoldman.org/archives/2009/01/web_host_faces.htm">ordered a web host to stand trial</a>, a jury <a href="http://blog.ericgoldman.org/archives/2009/09/making_sense_of.htm">awarded the trademark owner $32 million</a> due to the web host’s contributions to trademark infringement by its customers.  This case stands out for the big damages award and as a rare example where an online provider was held liable under a contributory trademark liability theory.  Many trademark practitioners are scratching their heads trying to figure out the import of this case, however.  Does this case represent a dangerous new frontier of online liability?  Was this a bad jury verdict fueled by poor defense lawyering?  Or was this an appropriate outcome because the web host actually engaged in bad behavior that distinguishes it from most “legitimate” web hosts?  2010 may help us understand if this case is part of a new trend or an aberration.</p>

<p><b>#9: Gordon v. Virtumundo</b>.  We’ve seen a lot of silly anti-spam litigation, including the emergence of an entirely new group of entrepreneurs called “spam litigation entrepreneurs” who try to make a living on anti-spam lawsuits.  These folks have a true love-hate relationship with spam; they hate it so much that they devote their lives to fighting it, but they love getting spam because each one is a potential revenue source.  In general, judges hate spam a lot too, so over the years we have seen a number of doctrinally unsupportable results where judges bent the law to make sure spammers lost.  </p>

<p>However, the judicial pendulum has swung in the opposite direction, and in <a href="http://blog.ericgoldman.org/archives/2009/08/an_end_to_spam.htm">Gordon v. Virtumundo</a>, the Ninth Circuit destroyed a serial anti-spam plaintiff’s entrepreneurial business in a doctrinally questionable but strongly worded opinion.  In short order, a number of other spam litigation entrepreneurs have seen their lawsuits shut down with emphasis.  Due to this ruling, the era of anti-spammers partying in courts may be on the wane.</p>

<p><b>#8: Zango v. Kaspersky</b>.  The question raised in this issue is simple to state but hard to answer: who should decide what constitutes spam, spyware or a virus?  Vendors of software designed to curb these threats would like unfettered discretion to make their classifications; businesses who are classified as a threat would like judges to overturn adverse decisions.  As it turns out, in a relatively obscure provision (47 USC 230(c)(2)), in 1996 Congress said that software vendors get to make classifications decisions and unhappy businesses can’t complain about them.  In June, <a href="http://blog.ericgoldman.org/archives/2009/06/antispyware_com.htm">the Ninth Circuit upheld Kaspersky’s decision</a> to classify Zango’s software as a threat and rejected Zango’s efforts to take the classification decision out of Kaspersky’s hands.  This ruling gives enormous freedom to vendors of anti-spam/anti-spyware/anti-virus software to do their best to keep us safe. </p>

<p><b>#7: Columbia Pictures v. Fung.</b>  This case came out just before the Christmas holiday, so it got lost in the holiday hoopla a bit, but it’s a <a href="http://blog.ericgoldman.org/archives/2009/12/torrent_sites_i.htm">case of potentially significant import</a>.  First, it held that the specific torrent sites at issue induced copyright infringement.  Second, the court denied the torrent sites’ eligibility for the DMCA online safe harbors.  In part, the court said that an inducing website was categorically disqualified from the DMCA online safe harbors.  Like the Akanoc case, it’s not entirely clear if this result was a legal aberration or an appropriate reaction to the defendants’ poor choices.  Either way, it is possible that more “legitimate” websites may change their behavior to minimize their exposure based on the legal precedents in this case.  If they do, this case could have a major impact on UGC websites.</p>

<p><b>#6: Lori Drew’s acquittal.</b>  Megan Maier’s suicide remains a heartbreaking tragedy, but unfortunately, overzealous prosecutors compounded the tragedy by prosecuting Lori Drew using bogus legal doctrines.  The tragic facts got a jury to convict Drew of some misdemeanor crimes.  Fortunately, the judge recognized the legal errors of the prosecution’s theory and the jury’s conclusions and granted Drew an acquittal despite the jury findings.  The judge finally got to the right result as a matter of Cyberlaw, but the case remains a chilling testament to prosecutorial power.</p>

<p><b>#5: Harris v. Blockbuster.</b>  The rule is really clear.  Service providers can't amend online user agreements in the provider’s sole discretion without notice.  As the Ninth Circuit informed us in 2007, those contracts <a href="http://blog.ericgoldman.org/archives/2007/07/ninth_circuit_s_1.htm">don’t fare well in court</a>.  So although these provisions are in just about every online user agreement, they don’t work--as Blockbuster found out the hard way.  </p>

<p>As part of the litigation detritus from the Facebook Beacon experiment, users sued Blockbuster for sharing their rental transactions with Facebook and all of their friends, allegedly in violation of the Video Privacy Protection Act.  Blockbuster tried to bust the class action by invoking the contract’s arbitration clause.  Instead, because Blockbuster had the impermissible amendment provision in its user agreement, the court said <a href="http://blog.ericgoldman.org/archives/2009/06/stop_saying_we_1.htm">the contract was illusory</a> and refused to send the case to arbitration.</p>

<p>This case should signal the end of the ridiculous amendment clauses.  We’ll see how long it takes the lawyers to give the provisions up.</p>

<p><b>#4: Battles Over the First Sale Doctrine.</b>  We have seen numerous legal battles this year over the First Sale defenses in both copyright and trademark law.</p>

<p>Copyright owners try to engage in price discrimination by carving up the world into geographic territories with different prices for the same product.  If they can use copyright law to keep the cheap products from entering the other geographic market, this keeps the product from effectively price-competing with itself.</p>

<p>This year, two cases involved European textbooks which were functionally equivalent to the textbooks being sold in the United States at higher prices.  Entrepreneurs were buying the cheap European texts, shipping them to the US and then selling them online.  The entrepreneurs invoked the First Sale doctrine, which says that copyright law can’t prohibit the legitimate purchaser of a tangible copyrighted item from reselling the item to whomever they want at whatever price they want.  </p>

<p>However, copyright law has another provision that allows copyright owners to block the importation of copyrighted works into the United States.  In the 1998 Quality King case, the US Supreme Court said that the First Sale doctrine trumped the importation right when the goods were manufactured in the US, sold overseas, and then imported back to the US.  However, in <a href="http://blog.ericgoldman.org/archives/2009/10/internet_retail_1.htm ">Pearson v. Liu</a> and John Wiley & Sons v. Kirtsaeng, the judges said that the importation right trumps the First Sale doctrine when the goods were initially manufactured overseas.  This issue is ripe for further adjudication, though.  A similar importation case, Costco v. Omega, is pending before the US Supreme Court, which is deciding whether or not it wants to hear the case.  If it does, we may get clearer instructions about the interplay between the First Sale doctrine and the copyright importation right.</p>

<p>Copyright’s First Sale doctrine was also at issue in <a href="http://blog.ericgoldman.org/archives/2009/10/vernor_v_autode_1.htm">Vernor v. Autodesk</a>, where the purchaser of a software disk wanted to resell the disk on eBay despite restrictions in the software licensing agreement barring such resales.  The court held that the First Sale doctrine applied and allowed the resale.  There are other cases percolating through the court system involving the resale of tangible media contained copyrighted material despite contractual restrictions on resale, so this issue remains a hot one.</p>

<p>Trademark owners also try to prevent competition with their products that leak out of their official channels of distribution.  eBay has been the site of a couple battles over the First Sale doctrine in trademark law.  In <a href="http://blog.ericgoldman.org/archives/2009/03/online_resale_o_1.htm">Mary Kay v. Weber</a>, the court held that the trademark First Sale doctrine may not permit the eBay resale of expired cosmetics by a Mary Kay independent beauty consultant.  In <a href="http://blog.ericgoldman.org/archives/2009/04/ebay_resales_co.htm">Beltronics v. Midwest</a>, a trademark owner shut down the eBay resale of radar detectors that had leaked out of the manufacturer’s channel and were being sold (at a cheaper price) without the manufacturer’s warranty.</p>

<p>Clearly, the First Sale doctrine matters a lot to eBay and other consumer-to-consumer e-commerce websites.  With a possible pending Supreme Court case and lots of IP owners looking to stifle competition from goods they have already profited from, expect the First Sale doctrines to get lots of attention in 2010.</p>

<p><b>#3: 47 USC 230.</b>  In my opinion, 47 USC 230 is the most important Cyberlaw statute, so new 230 developments will make my top 10 list for the foreseeable future.  This year, there were three federal appellate court rulings interpreting 47 USC 230(c)(1):</p>

<p>* in <a href="http://blog.ericgoldman.org/archives/2009/05/ninth_circuit_m.htm">Barnes v. Yahoo</a>, the Ninth Circuit held that 230 protected a website’s negligent delay in removing user content.  However, if the website had promised removal to the user, the user could have a viable claim for promissory estoppel that would not be preempted by 230.<br />
* in <a href="http://blog.ericgoldman.org/archives/2009/06/roommatescom_in.htm">FTC v. Accusearch</a>, the Tenth Circuit held that a website’s resale of pretexted phone records—even if those records were supplied by third party suppliers—did not qualify for 47 USC 230 protection because of their illegality.<br />
* in <a href="http://blog.ericgoldman.org/archives/2009/12/consumer_review_1.htm">Nemet Chevrolet v. ConsumerAffairs.com</a>, the Fourth Circuit held that a consumer review website was not liable for user-supplied reviews, even when the website worked with the user to submit the review, and despite the plaintiff’s unsubstantiated claims that the website had fabricated the reviews itself.</p>

<p>Really, the big 47 USC 230 news in 2009 is the absence of big news.  Specifically, 2009 reinforced that the <a href="http://blog.ericgoldman.org/archives/2008/04/roommatescom_de_1.htm">Ninth Circuit’s 2008 Roommates.com decision</a>—one of the most significant defense losses under 47 USC 230—did not rip open a major hole in the statutory protection of websites.  Of the 13 cases that I have seen that have cited the Roommates.com en banc opinion, eleven have cited the case in favor of the defense.  (See the list <a href="http://blog.ericgoldman.org/archives/2009/12/consumer_review_1.htm">here</a>).  The two exceptions are the Accusearch case, mentioned above, and <a href="http://blog.ericgoldman.org/archives/2009/04/two_47_usc_230.htm">the New England Patriots’ lawsuit against StubHub</a> over season ticket resales, an odd opinion that may not have much influence.  Therefore, despite our fears about Roommates.com, the 47 USC 230 immunity remained healthy and vibrant in 2009.  For more on this topic, see my special recap of <a href="http://blog.ericgoldman.org/archives/2010/01/47_usc_230_year_2.htm">47 USC 230's year-in-review for 2009</a>.</p>

<p><b>#2: Keyword Advertising Battles.</b>  Keyword advertising battles are another perennial topic on these year-in-review lists.  A multi-billion dollar a year industry has sprung up around the sale of keyword-triggered advertising, including some keywords that may be third party trademarks, and trademark owners don’t like it at all.  This has led to a multi-front battle between trademark owners, keyword advertising sellers (such as Google), and keyword advertising buyers.</p>

<p>One of the biggest Cyberlaw cases of the year was the Second Circuit’s ruling in <a href="http://blog.ericgoldman.org/archives/2009/04/second_circuit.htm">Rescuecom v. Google</a>.  In the district court in 2006, <a href="http://blog.ericgoldman.org/archives/2006/09/google_wins_key.htm">Google won an easy victory</a> against a trademark owner because the court said that Google did not make the requisite “use in commerce” of the trademark.  The Second Circuit reversed the district court, sending the case back for further proceedings.  The reversal does not ensure Google’s defeat; Google will now litigate other legal doctrines and might very well win on one of those.  However, the Second Circuit’s opinion largely spells the end of any “use in commerce” defense by either keyword advertising sellers or buyers.</p>

<p>Because of the “use in commerce” defense’s demise, keyword advertising cases will now likely turn on whether the advertisements create a likelihood of consumer confusion.  One case, <a href="http://blog.ericgoldman.org/archives/2009/04/catching_up_on_keyword.htm">Hearts on Fire v. Blue Nile</a>, offered up a new and complicated test for gauging consumer confusion.  If other courts adopt this test, keyword advertising cases will get even more expensive and complicated—highlighting how important it was that the Rescuecom case eliminated an easy way to end these lawsuits early.</p>

<p>Meanwhile, despite the fact that keyword advertising battles have been taking place for at least a decade, we have not heard what a jury thinks about the practice—until the November jury ruling in <a href="http://blog.ericgoldman.org/archives/2009/12/competitive_key.htm">Fair Isaac v. Experian</a>.  In that case, the jury found for the defense that the keyword-triggered ads did not create the requisite likelihood of consumer confusion.  It remains to be seen if other juries reach the same conclusion.  If they do, keyword advertising lawsuits should slowly fade away over time because the trademark owners can’t win in the end.</p>

<p>As for now, keyword litigation is going strong and hardly fading away.  In Spring, Google made two changes to its trademark policies where it voluntarily agrees to take down certain types of ads at the trademark owner’s request.  In May, <a href="http://blog.ericgoldman.org/archives/2009/05/googles_interna.htm">Google extended its more liberal US-based policy</a> to nearly 200 other countries, replacing the more restrictive policies it had in place there.  Shortly thereafter, <a href="http://blog.ericgoldman.org/archives/2009/05/google_liberali.htm">Google modified its US policy</a> to do less for trademark owners in situations involving product resales, review websites and sales of complementary/replacement parts.  Trademark owners were none too pleased with these changes.  In response to these changes and the door opened by the Second Circuit Rescuecom decision, Google got hit with about a dozen new lawsuits, including some <a href="http://blog.ericgoldman.org/archives/2009/05/google_hit_with.htm">class action lawsuits</a>, of which I believe <a href="http://blog.ericgoldman.org/archives/2009/11/cpa_deal_gone_awry.htm">10 are currently still active</a>.</p>

<p>Finally, all of the wrangling in court and over voluntary trademark policies could be mooted by legislative action, and <a href="http://blog.ericgoldman.org/archives/2009/03/utah_trying_to.htm">for the third time</a>, the Utah state legislature considered resolving the keyword advertising issue itself.  A law regulating keyword advertising <a href="http://blog.ericgoldman.org/archives/2009/03/utah_house_bare.htm">passed the Utah house</a> but <a href="http://blog.ericgoldman.org/archives/2009/03/utah_hb_450_die.htm">died in the Utah senate</a>.  Expect the pro-regulatory forces to <a href="http://blog.ericgoldman.org/archives/2009/06/an_insiders_loo.htm">round up the troops for a fourth try in 2010</a>.</p>

<p><b>#1: FTC Endorsement Guidelines for Bloggers</b>.  The Obama administration has breathed new life into a pro-regulatory FTC, and the FTC sure is interested in all things Internet.  The FTC has been nosing around Internet privacy and Internet marketing practices pretty carefully, and I expect 2010 to bring more FTC pronouncements designed to tackle the Internet.</p>

<p>But nothing stirred up a hornet’s nest of confusion and anger in 2009 like the FTC’s Endorsement and Testimonials Guidelines.  I think it’s fair to say that the FTC’s guidelines rollout was a complete failure.  As usual, the FTC’s guidelines were mealy-mouthed and filled with conditional statements (the FTC hates to lay out bright line rules that might constrain their future discretion).  However, the FTC’s general gist was clear: bloggers should disclose when they receive financial or other consideration for their blog posts.  </p>

<p>Unfortunately, this general principle leaves open some fairly fundamental questions, like when is disclosure required in situations less clear than straight cash-for-posting, and where should disclosure be made, especially in space-constrained media like Twitter.  Needless to say, unhappy bloggers can be very noisy, so blogger response to the FTC’s announcement was loud and vituperative.  The FTC tried to backpedal a little by saying that it did not intend to pursue individual bloggers, but this announcement only reinforced that bloggers do not understand what the FTC wants from them.</p>

<p>Meanwhile, the FTC’s proposed guidelines also took an interesting position about an advertiser’s liability for rogue blogger’s posts.  This position is generally consistent with government enforcement agencies’ views that commercial players can be legally responsible for content they endorse or link to (see, e.g., <a href="http://blog.ericgoldman.org/archives/2008/11/secs_proposed_g.htm">my comments on the SEC’s liability-for-linking policy</a>), but this position runs directly contrary to 47 USC 230’s provisions that say A isn’t liable for B’s online content.  As a result, I believe that <a href="http://blog.ericgoldman.org/archives/2009/10/a_fuller_defens.htm ">part of the FTC’s proposed guidelines violate 47 USC 230</a> and would not survive a court challenge.</p>

<p>Overall, the firestorm over the FTC’s Endorsement and Testimonials guidelines is a small part of a larger effort to regulatorily separate advertising from content.  <a href="http://ssrn.com/abstract=963219">The Internet has collapsed those distinctions</a>, perhaps irreparably, so regulators may be trying to accomplish the impossible.  Nevertheless, the FTC seems determined to prop up the distinction, and I expect 2010 will bring more FTC efforts on this front.</p>

<p>* * * * * </p>

<p>While that concludes my top 10 list, there were a number of other interesting developments in 2009 that are worth a brief note:</p>

<p>* <a href="http://blog.ericgoldman.org/archives/2009/04/republishing_my.htm">Moreno v. Hanford Sentinel</a>.  A woman trashed her hometown in an obscure but public MySpace posting and learned there is no “do-over” for Internet content publication.  My vote for the most factually interesting Cyberlaw case of 2009.</p>

<p>* <a href="http://blog.ericgoldman.org/archives/2009/09/google_confirms.htm">Google’s keyword metatag announcement</a>.  Courts generally treat the inclusion of third party trademarks in keyword metatags as per se trademark infringement.  But Google has confirmed that it ignores keyword metatags.  Will courts get the message?</p>

<p>* Google Book Search settlement.  If the Google Book Search settlement ever gets approved, it may reshape the book industry, redefine libraries, and make all kinds of other socially significant changes.  But the list of opponents to the settlement is long and growing.  <a href="http://laboratorium.net/">Professor James Grimmelmann of New York Law School</a> is our community’s maven for all things “GBS.”</p>

<p>* Kindle book deletion.  The Kindle store sold e-books it didn’t have the right to sell, so it took them back.  Users learned of a key factual difference between physical books and e-books—the vendor can remotely make e-books go poof.</p>

<p>* States’ efforts to impose sales tax efforts based on marketing affiliates.  For years, states have been looking for ways to make online retailers collect sales tax for them.  They are generally stopped by Supreme Court precedent, but in 2008 New York finally figured out a workaround.  The New York statute said that marketing affiliates were like traveling salespeople and thus created the physical nexus required for a state to impose sales tax collection obligations.  The New York statute survived its first legal challenge, which opened the floodgates of other states passing similar laws hoping to get their piece of the action.  Meanwhile, online retailers aren’t just rolling over; instead, they are threatening to cut off (or actually cutting off) marketing affiliates in states that enact these laws—thus potentially costing the states income tax from the marketing affiliates’ revenue, and creating the potential for the entire affiliate industry to be torn apart.</p>

<p>* Maine kids privacy law.  Maine thought it could pass a law banning marketing to kids.  It was wrong.  The state had to withdraw the law and go back to the drawing board.</p>

<p>* <a href="http://blog.ericgoldman.org/archives/2009/09/veoh_gets_yet_a.htm">UMG v. Veoh</a>.  Veoh won another nice DMCA online safe harbor victory.</p>

<p>* <a href="http://blog.ericgoldman.org/archives/2009/10/internet_obscen.htm">US v. Kilbride</a>.  The Ninth Circuit says that online obscenity prosecutions need to evaluate national attitudes towards obscene content, not local community standards.</p>

<p>* Kentucky domain name seizure.  Kentucky tried to grab 141 domain names that enabled Kentucky residents to engage in illegal gambling.  But those domain names also serviced customers for whom the gambling was completely legal, so <a href="http://blog.ericgoldman.org/archives/2009/01/kentucky_revers.htm">the Kentucky courts are rethinking the grab</a>.</p>

<p>* FTC v. Sears.  As another example of the new pro-regulatory winds blowing through the FTC, the FTC cracked down on Sears for installing spyware on users’ computers that looked at the users’ hard drives, even though Sears paid the users for the installation and disclosed the spyware’s snooping in the user agreement (though in an inconspicuous manner).  This case has made a lot of lawyers concerned that adverse disclosures in user agreements won’t satisfy the FTC.</p>

<p>* Facebook the Drama Queen.  Ah, Facebook.  Love it.  Hate it.  Facebook is a pretty nifty site and part of my daily routine, but boy, they sure do have a knack for stirring up trouble.  </p>

<p>- In February, they <a href="http://blog.ericgoldman.org/archives/2009/02/facebook_user_a.htm">made a relatively modest change to their user agreement</a> that caused people to freak out.  <br />
- In response to this, Facebook took the provocative step towards user self-governance.  Facebook let users vote on some choices and promised to be bound by the results, but with an asterisk: Facebook decided what options users could vote on, and Facebook would honor those choices only if a prohibitively large number of users exercised their franchise.  Still, it was a nice gesture towards cyberspace community self-governance.  <br />
- In summer, they tried to settle their Beacon litigation, but that also reminded folks of how much Beacon irritated them in the first place.  <br />
- Summer also brought allegations of click fraud on Facebook, and <a href="http://blog.ericgoldman.org/archives/2009/07/facebook_sued_f.htm">lawsuits followed</a>.  <br />
- Finally, in Thanksgiving, Facebook rolled out some changes to its privacy options that it pitched as giving users more choices, but it also took away some choices and defaulted users into some options that surprised them.  </p>

<p>Given this track record, is it unrealistic to expect more Facebook drama in 2010?</p>

<p>* <a href="http://blog.ericgoldman.org/archives/2009/10/online_game_net.htm">Estavillo v. Sony</a>.  Speaking of self-governance, virtual world enthusiasts would love to establish the legal proposition that virtual worlds are legally equivalent to governments and therefore obligated to restrain their actions just like governments are.  One virtual world enthusiast sued Sony for kicking him off the network, claiming that Sony was legally governed as a “company town” and therefore lacked the discretion to kick him off.  WRONG (and it wasn’t even close).</p>

<p>* Wikipedia's policy change.  In August, the English-language Wikipedia announced that it was going to tighten up its editorial policies, and people Freaked Out.  (In fact, I <a href="http://ssrn.com/abstract=1458162">have predicted</a> that Wikipedia cannot avoid increased editorial restrictions over time, so this change should not have been surprising).  However, it turns out that everyone got it wrong, and Wikipedia’s editorial changes are far less dramatic (and consequential) than initially reported.  I will post a separate recap on Wikipedia shortly.</p>

<p>If you would like a stroll down memory lane, you can see my previous top 10 lists from <a href="http://blog.ericgoldman.org/archives/2009/02/2008_cyberlaw_y.htm">2008</a>, <a href="http://www.informit.com/articles/article.aspx?p=1165635">2007</a> and <a href="http://blog.ericgoldman.org/archives/2006/12/top_cyberlaw_de.htm">2006</a>.  Before that, John Ottaviani and I put together a list of top Internet IP cases for <a href="http://blog.ericgoldman.org/archives/2006/02/top_cyberspace_1.htm">2005</a>, <a href="http://meetings.abanet.org/webupload/commupload/CL320010/newsletterpubs/2004CyberspaceCases.doc">2004</a> and <a href="http://meetings.abanet.org/webupload/commupload/CL320010/newsletterpubs/20040219162000.pdf">2003</a>.</p>]]>

</content>
</entry>
<entry>
<title>47 USC 230 Year-in-Review for 2009</title>
<link rel="alternate" type="text/html" href="http://blog.ericgoldman.org/archives/2010/01/47_usc_230_year_2.htm" />
<modified>2010-01-05T22:19:35Z</modified>
<issued>2010-01-05T19:45:09Z</issued>
<id>tag:blog.ericgoldman.org,2010://1.1729</id>
<created>2010-01-05T19:45:09Z</created>
<summary type="text/plain">By Eric Goldman I will do a more comprehensive year in review for Cyberlaw generally, but I thought it would...</summary>
<author>
<name>Eric</name>

<email>egoldman@gmail.com</email>
</author>
<dc:subject>Derivative Liability</dc:subject>
<content type="text/html" mode="escaped" xml:lang="en" xml:base="http://blog.ericgoldman.org/">
<![CDATA[<p>By Eric Goldman</p>

<p>I will do a more comprehensive year in review for Cyberlaw generally, but I thought it would be fun to take a close look at how 47 USC 230 fared in 2009.  This is the first full calendar year following <a href="http://blog.ericgoldman.org/archives/2008/04/roommatescom_de_1.htm">the Ninth Circuit’s en banc Roommates.com opinion</a>, and many of us initially feared that the case would create a huge hole in 230’s otherwise solid immunity.  As it turns out, those concerns have not come to pass.  If anything, 2009 shows us just how strong the immunity remains.  </p>

<p>I blogged on a total of 22 cases issued in 2009 that discussed the statute.  (I blog on every case I see that substantively discusses 47 USC 230).  I blogged on other cases in 2009 that were decided before 2009, such as the <a href="http://blog.ericgoldman.org/archives/2009/02/republishing_so.htm">Woodhull v. Meinel case</a> from October 2008 and <a href="http://blog.ericgoldman.org/archives/2009/08/private_high_sc.htm">DC v. Harvard-Westlake</a>, a 2007 arbitrator’s dismissal that came to light in 2009.</p>

<p>Of the 22 calendar year 2009 cases, I would classify 14 of them (63%) as easy defense wins, frequently on a 12(b)(6) motion to dismiss or state law equivalent.  Even many of the remaining 8 cases contained good news for defendants.  For example, in Shiamili, the defense inexplicably lost at the district court level but got an easy reversal on appeal.  The Stayart court granted Yahoo an easy defense win, although co-defendant Various didn’t get the 230 ruling.  Similarly, the Barnes case granted the defense an easy 230 win on one theory (negligent undertaking) but denied 230 for a different one (promissory estoppel).  The Certain Approval Process case said 230 did not prevent the plaintiff from amending the complaint to add a cause of action, but once added, the court <a href="http://blog.ericgoldman.org/archives/2009/04/certain_approva.htm">instantly zapped the claim</a> on other grounds.</p>

<p>This leaves four unambiguous 230 defense losses in 2009.  The leading 230 defense loss was the Tenth Circuit FTC v. Accusearch case, which held a retailer liable for reselling illicit phone records.  The other major 230 defense loss was the NPS v. StubHub case, which held that 230 may not apply to a lawsuit over the alleged illegal ticket scalping by StubHub’s sellers.  Both of these cases involve the retailing of illegal items, suggesting that 230’s boundaries may not reach that far.</p>

<p>The other two defense losses are less consequential.  The Project Playlist held that 230 does not preempt state IP law claims, a conclusion that deserves note only because the Ninth Circuit held otherwise in the <a href="http://blog.ericgoldman.org/archives/2007/03/ninth_circuit_o.htm">2007 ccBill case</a>.  I believe that no other courts will follow the Ninth Circuit’s rule that 230 preempts state IP laws, making the Project Playlist ruling unsurprising.</p>

<p>In People v. Gourlay, a web host was denied a 230 defense to a criminal prosecution for child molestation- and child pornography-related claims.  This case turns mostly on the web host’s active role creating the child pornography (as well as the host’s molestation of the child actor); with that context, this case may have little influence on other cases.  Indeed, the court made clear that web hosts providing standard web hosting services could fully qualify for 230 protection against a state criminal prosecution of child pornography dissemination.</p>

<p>In reverse chronological order, a brief overview of the 230 cases from 2009:</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/12/consumer_review_1.htm">Nemet Chevrolet v. ConsumerAffairs.com</a> (4th Cir. Dec. 29, 2009).  One of three federal appellate court 230(c)(1) rulings in 2009 (Barnes and Accusearch are the others).  A solid defense win for a consumer review website.  The plaintiff’s claims that the website contributed to the reviews’ development and fabricated reviews were tossed on a 12(b)(6) motion to dismiss.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/12/website_initial.htm">Shiamili v. Real Estate Group</a> (N.Y. App. Div. Dec. 17, 2009).  In an unpublicized January 2009 decision, the trial court denied a website’s 230 dismissal request for claims based on user-supplied comments.  In December, this error was fixed on appeal despite allegations that the website “chooses and administers” the user content.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/10/craigslist_isnt.htm">Dart v. Craigslist</a> (N.D. Ill. Oct. 20, 2009).  Craigslist got a big win in its ongoing battles with various government agencies over prostitution ads on Craigslist when the court held it wasn’t liable for those ads.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/11/myspace_quietly.htm">Riggs v. MySpace</a> (C.D. Cal. Sept. 17, 2009).  A goofy case.  The court holds that MySpace’s deletion of Riggs’ account was protected by 230(c)(1) on the apparent theory that Riggs (the plaintiff) was the third party supplier of the deleted content.  This case would make more sense as a 230(c)(2) case.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/10/facebook_not_li.htm">Finkel v. Facebook</a> (N.Y. Sup. Ct. Sept. 15, 2009).  Facebook wasn’t liable for the contents of a user’s private group even though Facebook placed a copyright notice on the page.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/10/ripoff_report_r_2.htm">Intellect Art v. Milewski</a> (N.Y. Sup. Ct. Sept. 15, 2009).  Ripoff Report wins again.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/09/yahoos_search_r.htm">Stayart v. Yahoo</a> (E.D. Wis. Aug. 28, 2009).  An convoluted, and possibly confused, ruling that Yahoo wasn’t liable for search results snippets.  However, Various was denied 230 because it may have originated the content in question.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/08/online_retailer_1.htm">Cornelius v. DeLuca</a> (E.D. Mo. Aug. 18, 2009).  An online retailer wasn’t liable for user-supplied comments despite a “conspiracy” allegation.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/07/google_not_liab.htm">Goddard v. Google</a> (N.D. Cal. July 30, 2009).  This is a follow-on ruling to an important <a href="http://blog.ericgoldman.org/archives/2008/12/lawsuit_over_go.htm">December 2008 ruling</a> in this case, which dismissed the plaintiff’s complaints but gave the plaintiffs another chance.  The December 2008 ruling is one of the most interesting and important decisions interpreting Roommates.com.  In the July ruling, the judge again found that 230 insulates Google from liability due to allegedly fraudulent ads run through its network and granted a final dismissal.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/07/myspace_wins_an.htm">Doe II v. MySpace</a> (Cal. App. Ct. June 30, 2009).  MySpace isn’t liable for users’ sexual assaults on other users.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/06/roommatescom_in.htm">FTC v. Accusearch</a> (10th Cir. June 29, 2009).  The second of three federal appellate court rulings on 230(c)(1).  The defendant was an online retailer of illegal phone records.  The retailer claimed that the phone records came from third party suppliers and therefore 230 immunized the retailer from liability associated with the records.  The court echoed the Ninth Circuit’s Roommates.com decision, effectively extending that case to the Tenth Circuit, and said that the retailer was responsible for selling the illicit phone records despite 230.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/06/antispyware_com.htm">Zango v. Kaspersky</a>  (9th Cir. June 25, 2009).  This is the only 2009 ruling addressing 47 USC 230(c)(2), the overshadowed and frequently overlooked sibling of 230(c)(1).  Despite the rarity of 230(c)(2) cases, this case could be fairly influential.  The Ninth Circuit held that 230(c)(2) protected an anti-spyware software vendor’s decision to classify software as a threat.  If you missed it, you might want to take a look at my <a href="http://www.ericgoldman.org/Speeches/47usc230c2.pdf">presentation slides on 230(c)(2)</a>, which distill my deep look at 230(c)(2) this summer.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/06/47_usc_230_can.htm">Gibson v. Craigslist</a>  (S.D.N.Y. June 15, 2009).  Craigslist isn’t liable for physical injury caused by a gun purchased via a Craigslist ad.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/06/doe_v_myspacesa.htm">Doe IX v. MySpace</a> (E.D. Tex. May 22, 2009).  MySpace isn’t liable for users’ sexual assaults on other users.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/05/ninth_circuit_m.htm">Barnes v. Yahoo</a> (9th Cir. May 7, 2009; <a href="http://blog.ericgoldman.org/archives/2009/06/ninth_circuit_h.htm">amended opinion</a> June 22, 2009).  The third of three federal appellate court opinions on 230(c)(1).  The Ninth Circuit held that 230 preempted a claim against a service provider for negligently delaying the removal of user content (essentially, Zeran redux), but 230 did not preempt a promissory estoppel claim based on promises the service provider made to the person requesting takedown.  The initial Ninth Circuit opinion had two other unfortunate digressions: (1) it said that 230 was an affirmative defense that did not support a 12(b)(6) motion to dismiss, and (2) the opinion had ambiguous language implying that 230 preempted only state claims, not federal claims.  The amended opinion helpfully eliminated both digressions.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/04/230_doesnt_pree.htm">Atlantic Records v. Project Playlist</a>  (S.D.N.Y. March 25, 2009).  230 does not preempt a state IP claim—in this case, a violation of state copyright law for pre-1972 sound recordings.  </p>

<p><a href="http://blog.ericgoldman.org/archives/2009/03/soccer_coach_sh.htm">Joyner v. Lazzareschi</a> (Cal. App. Ct. March 18, 2009).  A message board operator wasn’t liable for user posts.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/03/union_isnt_liab.htm">Raggi v. Las Vegas Police</a> (D. Nev. March 10, 2009).  A union wasn’t liable for messages that union members posted on the union-operated message board.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/03/ripoff_report_l.htm">Certain Approval Programs v. Xcentric Ventures</a> (D. Ariz. March 9, 2009).  230 did not bar amending a complaint to add a new cause of action when the plaintiff also adequately alleged that the Ripoff Report contributed to the creation and development of the content at issue. </p>

<p><a href="http://blog.ericgoldman.org/archives/2009/03/web_host_convic.htm">People v. Gourlay</a> (Mich. App. Ct. March 3, 2009).  This case involves the prosecution of a pornographic web host who also molested the child actor.  The web host asserted a 230 defense in trying to overturn the conviction for the charges related to pornography dissemination.  Although 230 can preempt state criminal prosecutions, and web hosts are protected by 230 for their ordinary web hosting activities, this web host actively participated in the site’s development and therefore lost 230’s protection.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/04/two_47_usc_230.htm">NPS v. StubHub</a>  (Mass. Super. Ct. Jan. 26, 2009).  In a long-running battle between the New England Patriots and season ticketholders who want to resell their tickets via StubHub, StubHub was denied summary judgment on 230 grounds.  The court cites Roommates.com in saying that StubHub may have contributed to illegal ticket scalping sufficient to potentially disqualify it for 230 protection.</p>

<p><a href="http://blog.ericgoldman.org/archives/2009/01/ripoff_report_r_1.htm">GW Equity v. Xcentric Ventures</a> (N.D. Tex. Jan. 9, 2009).  Ripoff Report is protected by 230 even though it offers pull-down menus and manipulates user-submitted reports.</p>]]>

</content>
</entry>

</feed>