Articles Posted in Technology

Internet privacy laws have been implemented to protect us from legal violations. These laws are meant to protect us against cyber threats and data intrusions which are designed to extract personal or confidential information (e.g., intellectual properties, trade secrets) without authorization. Data privacy is paramount when it comes to the collection, use, and storage of personal or confidential information. However, not many are taking proper steps to ensure security. These steps can include encryption, firewalls, intrusion detection systems, and two-factor authentication.

It is important to realize that even though the criminals are not personally entering your private space or domain, however, they are still able to follow your digital footprints. These digital footprints can be followed by using special tools – e.g., keylogger – which can follow you without your knowledge and consent. Also, cookies can be used to follow you around in a clandestine manner.

What are the internet privacy rules or regulations?

In general, ransomware is a type of malware (i.e., malicious software) that is designed to take control of an electronic communication device, prevent its owner from accessing the electronic communication device, notify its owner that the electronic communication device has been held ransom, demand payment from the owner, and return access to electronic communication device after payment. There have been many instances of ransomware attacks when the hackers have taken control of a company’s servers and prevented its employees from accessing the network and database servers. The hackers would notify the employees by email and demand payment of funds in order to return access to their computers. Now, in some instances, a payment was necessary, but in some exceptional cases the company owners can have an advantage over the hackers and not be required to transfer the funds.

There are several types of ransomware. First, there are applications that fall under the category of scareware and intended to create fear for the recipients and force them to purchase unnecessary software. Second, there is prankware which is intended to cause fear by sending unanticipated pictures, sounds, or videos. For example, NightMare was a type of prankware that would remain dormant on the recipient’s computer and launch itself by changing the computer screen to a skull and playing a loud noise. Third, there is a group of crypto-ransomware named as GPCode or PGPCoder that claims to use PGP encryption to prevent file access. So, in other words, it’s a virus that encrypts files on the infected computer and demands a ransom to release access to the encrypted files. The hackers have been able to become more effective with their tools. The new generation of this type of ransomware denies user access to files by writing encrypted files to a new location and deleting the original file. However, this strategy was ineffective since a file restoration would allow the victim to recover the files. Fourth, CryptoLocker became the new generation of ransomware. It shares similar distribution models of previous ransomware variants and relied on phishing attacks with portable executable attachments. It would install itself on the user’s profile folder and add a registry key to run on startup to maintain persistence. Then, it would start to communicate with the command and control server to generate an RSA-2048 key pair and send the public key to the victim host.

What are the relevant laws?

Cloud computing has become the normal protocol to store data for most individuals and businesses. The fact that online storage is cheaper these days has contributed to the expansion of this technology. There are numerous companies out there that provide cloud storage facilities which may be inside or outside of your jurisdiction. Now, the question is why is that important at all? Well, the answer is because the laws of each jurisdiction may be different when it comes to interstate commerce and cybersecurity. This is one good reason to make sure you read and understand the cloud service provider’s terms and conditions before you sign up. There will be provisions that can help you understand your rights and responsibilities. For example, where and how the parties can resolve their disputes? Also, the laws of which state will be used to resolve the dispute? The answers will be in the venue, choice of law, or governing law provisions. In some cases, the cloud service provider includes an arbitration clause which requires the parties to resolve their dispute through arbitration.

There are various cloud computing platforms that allow the users to send and receive information. So, obviously the users should use precautions when transferring data towards the cloud service provider. For example, it’s recommended to encrypt the data before transferring it. Also, it’s a good idea to confirm that data integrity will be protected after the transfer. The users should also have a functioning backup of their files in a safe place in case the data is lost, stolen, or destroyed.

The Privacy Shield Program applies to cloud computing platforms that do business with other countries – e.g., European Commission, Switzerland. This program is administered by the International Trade Administration (ITA) within the U.S. Department of Commerce and enables U.S.-based organizations to join the Privacy Shield Frameworks. For example, a U.S.-based organization must self-certify to the Department of Commerce and commit to the Framework’s requirements. It’s not mandatory to join the Privacy Shield Program, but once the organization makes the public commitment to comply with the Framework’s requirements, the commitment will become legally enforceable. The participating organization will receive the following benefits:

Part I: DMV Sale of Personal Information

A group has investigated and allegedly found that the California Department of Motor Vehicles has earned more than $50 million by selling personal information of drivers to third parties without consent. This data may include names, addresses, and registration information. The DMV claims on its website that it does not sell information to advertisers or marketers for advertising or direct marketing purposes. It also claims that:

Most information acquired by the DMV is subject to public inspection under Vehicle Code Section 1808. Other statutes, regulations or laws governing subpoenas, discovery for litigation, Public Records Act requests, and commercial requestor requester accounts also apply to information gathered at this website. However, various provisions of law do prohibit or restrict the disclosure of certain electronically transmitted information such as social security numbers, residence addresses, and credit card accounts numbers. DMV also uses the information gathered on this website to help improve this website. For example, by tracking the number of website visitors, the date of visit, and the pages visited, DMV can balance resources so that the maximum number of visitors can obtain needed information. Additionally, by tracking what visitor software is being used (e.g. browser) DMV can avoid using features that visitors can not view or use.

Quantum computing technology will be affecting most of us in a direct or indirect way. We have stated in a prior article that: “A quantum computer is a highly-advanced computer system that works exponentially faster than today’s conventional computers. Quantum computing is the practice of studying quantum computers and their potential. This practice is growing and has caused the rapid decrease in the size of computers at the same time as these systems are rapidly increasing in their capability.”

Now, quantum computing has become a reality and technology companies have launched projects in order to compete in this sector. The question is how quantum computers will affect us.

First, since quantum computers are faster than conventional computers, they can break passwords or decrypt encryptions in a shorter time. This has caused concern over privacy and security which has forced companies to invest in quantum resistant cryptography. This technology and its potential ramifications on encrypted networks will also affect EU’s General Data Protection Regulation (GDPR) which outlines the rules and regulations for protecting unauthorized access. The United States government has also reacted and Congress has passed H.R. 6227 in order to implement the National Quantum Initiative Act that states as follows:

Internet spam violations have increased in the past years. For example, the spammers use the interconnected network of computers that links us together in the world to disseminate malware. The spammers also use the internet to send junk email that fills up email accounts and can be used to commit online fraud – e.g., identify theft.

Robocall violations have also increased in the past years. For example, the robocallers use the telephone systems to continuously call without proper authorization. They do not state their personal or business organization’s names. They call before or after the permissible time periods (i.e., before 8:00 am/after 9:00 pm). They call by using artificial voices or recordings. They may also use automated telephone equipment to make the phone calls.

What are the legal remedies?

There have been cases where spammers have transmitted spam via email and text messages. These messages can include improper content, propaganda, hidden messages, and malware (e.g., virus, trojan, ransomware, adware, spyware). The spammers use the Internet Service Provider’s and user’s bandwidth to disseminate spam which results in bandwidth saturation, lost productivity, and other complications.

What is spam?

Spam is unsolicited commercial email advertisement that is sent towards recipients by third parties. An “unsolicited commercial email advertisement” means a commercial email advertisement that: (1) The recipient has not provided direct consent to receive advertisements from the advertiser; and (2) The recipient does not have a preexisting or current business relationship with the advertiser.

Laws against forgery of documents have existed for almost as long as writing itself has existed. For most of that time, forgery techniques did not change very much. However, modern digital technology has significantly expanded opportunities for people to create fraudulent documents. Real estate transactions are making increasing use of “paperless” applications, but most areas of real estate remain firmly rooted in paper. This is particularly true of public real property records. While the media in California might report on how blockchain and other digital tools are changing the real estate business, yet real estate forgery is still mostly rooted in creating documents that could be printed onto paper.

Forgery Laws in California

California’s forgery statute, found in California Penal Code § 470 covers a broad range of activities. In addition to signing another person’s name to various documents without authority, the statute makes it a crime to intentionally “alter, corrupt, or falsify any record of any … conveyance” which includes real estate documents like grants or deeds. Under California Penal Code § 115, a person commits a felony when they knowingly file “any false or forged instrument” with a government agency, such as a county recorder’s office. State law allows county recorders to accept “digitized images, digital images, or both” of a recordable document for filing.

In fact, Section 502(c)(1) prohibits altering or deleting data stored on another person’s computer or computer network as part of “any scheme or artifice to defraud, deceive, or extort.” This can include attempts to falsify or forge digital documents affecting real estate transactions.
Continue Reading ›

The world is growing increasingly “paperless” as more documents move into digital spaces. People born in this decade might only know terms like “sign on the dotted line” and “before the ink is dry” as something their grandparents would explain. Without hard copies of important documents, though, our legal system needs new ways to indicate that a person has agreed to a contract. Now, electronic signatures (a/k/a “digital signatures” or “e-signatures”) provide evidence of assent without the need for a pen and printer. Federal and state laws, such as the Electronic Signatures in Global and National Commerce (E-SIGN) Act, establish standards for proving the legitimacy of electronic signatures. In real estate transactions, electronic signatures are allowed in any situation where the law does not specifically require otherwise.

What Is an “Electronic Signature”?

The E-SIGN Act defines an electronic signature as any “electronic sound, symbol, or process” that meets the following criteria:

1. It is “attached to or logically associated with” a document (e.g., contract); and
2. The person who “executes or adopts” it intends to do so.

Electronic signatures are possible with hardware, such as the signature pads at many retail checkout counters; and software, such as the signature features in applications like Adobe Acrobat or services like DocuSign. The signature must meet the standards set by federal or state laws and an electronic signature must be acceptable for that document.
Continue Reading ›

Internet of Things is more extensive than the Internet itself. It constitutes the combination of all electronic devices that are connected on the web and are able to communicate with each other. It is different from the Internet because it is essentially governed by information that is stored by electronic devices without human intervention. Now, smart devices can be connected through complex network systems and embedded sensors. These smart devices include, phones, refrigerators, thermostats, automobiles, or pills that allow medical professionals monitor a patient’s health status. These technological advancements enable smart devices to communicate in real time and promote the process of developing a more intelligent environment.

Artificial Intelligence is the intelligence demonstrated by machines in contrast to the natural intelligence displayed by humans and other animals. It allows machines to learn from experience, adjust to new inputs, and perform human-like tasks.  It relies heavily on deep learning and natural language processing. It uses neural networks which are a combination of software and hardware devices that are designed to emulate the operation of neurons in the human brain.

Smart Dust is a system of tiny microelectromechanical systems (MEMS) such as sensors or robots that detect light, temperature, vibration, magnetism, or chemicals. They are usually operated on a computer network wirelessly and distributed over an area to perform tasks by sensing through radio-frequency identification. This technology is able to collect and transmit data which can be uploaded to the cloud or other remote location.