Showing posts sorted by relevance for query legal. Sort by date Show all posts
Showing posts sorted by relevance for query legal. Sort by date Show all posts

Tuesday, January 4, 2011

My legal justification for cyber privateers

I'm not a lawyer, as I indicated in my December 30, 2010 post on the federal judge's decision to whack 1-800CONTACTS in the head.  An excellent legal source for cyber crime in general and Letters of Marque in particular is Susan Brenner, a law professor who blogs on the subject. You can categorize me as a novelist looking for a way to "suspend disbelief" mixed with a technorati who is extremely irritated with attacks on his Linux server. Net net, I'm one step lower on the food chain than the proverbial "jailhouse lawyer."

Before enumerating my legal justification for legalizing cyber privateers, let me quote a few concerns raised by the above-referenced Susan Brenner in her blog on Letters of Marque as they apply to cyber crime. Quoting from her May 18, 2009 blog:
Since I don’t see how a power that is limited to seizing assets could be particularly useful in the cybersecurity context…
I think seizing assets is a useful deterrent. Yes, it will take some cleverness, but a cyber privateer armed with the right toolset (like The Perfect Virus) is clearly up to the task. Professor Brenner further writes:
I see a lot of problems with the strike-back option, the most important of which is that it can be an invitation to vigilantism. I might be tempted to do more than just make the person who hacked my system or is trying to hack my system back off; I might go after them seeking revenge for that and other attacks and go too far. I might also go after the wrong target, which could cause all kinds of problems as well as maybe getting me charged with a crime (unauthorized access + damage to a system).
Again, I believe forced compliance with The Cyber Privateer Code would mitigate the above concerns. How about her start-a-cyber-war concern?
If I’m acting on my own, that could be a cybercrime and the North Koreans could ask the U.S. government to extradite me so I could be prosecuted in North Korea. If I’m doing in on behalf of the United States, does that transform my conduct into something more . . . into an act of war, perhaps?
Acting within the contest of my above-referenced Cyber Privateer Code, no bonding authority would authorize a foray into cyber space without specific conditions being met by the licensed and bonded cyber privateer, who is indeed in it for the money (something to which Professor Brenner takes issue):
If we were to decide to use cyber-letters of marque and reprisal, I’m not at all sure we should incorporate the “use this power to enrich yourself” aspect of the old letters. I’m quite sure people could use the cyber-letters to enrich themselves by hacking into criminal systems and taking whatever could be sold or redeemed for profit. I’m just not sure it’s a good idea;  
While I am not totally sure myself whether or not cyber privateering is "…a good idea…", it's the best idea I've seen so far. It will not be a drain on the taxpayer. Quite the contrary, it will be a revenue source for not only the government, but major insurance institutions looking for a new product: Privateer Liability Insurance. And as to her concern about "who is fair game," I cover that in The Cyber Privateer Code.

The one concern raised by Professor Brenner that I can't easily dismiss is that of reprisal by the criminal entity:
If we were to authorize cyber-privateers to deal with cybercriminals, it seems to me we’d be opening up the possibility of essentially reversing that dynamic: I’m assuming that the cyber-privateers would be representatives of legitimate U.S. businesses and other entities who are going after online criminals as redress (reprisal) for prior attacks on them or on other U.S. businesses or entities. If I’m correct in assuming that, then it seems to me our cyber-privateers could make the entities they work for sitting ducks.
I can envision scenarios where "corporate America" might not want to risk reprisal on company officers and their families. However, I'm willing to let "the market" determine those dynamics. And certainly, a cyber privateering organization could well be under contract to the Justice Department to act in behalf of the United States government.

Susan Brenner has taken a professional and thoughtful approach to these issues, and I suspect she'd be asked to testify in any congressional hearings concerned with legalizing cyber privateers. But within the context of the above discussion, here is my (jailhouse lawyer) enumeration of the legal issues.

  1. Article I § 8 of the U.S. Constitution gives Congress the “Power To . . . grant Letters of Marque and Reprisal”.
  2. Like The Monroe Doctrine drew a line in the sand, it is imperative that a similar approach alert the world that a new policy is in force. Hence the name of this blog: The Morgan Doctrine.
  3. There is a common law precedent for defending your home/business against intruders.
  4. Among other legal precedents, Judge Waddoups (referenced above) ruled that it is illegal to present yourself in cyberspace as someone you are not, with credentials that you do not legitimately possess. 
  5. The rules of "hot pursuit" could be applied to going after criminals on their home turf, although the 1917 US pursuit of Pancho Villa into Mexico and the 1960 Israeli capture and kidnapping of Adolf Eichman in Argentina are questioned as violations of international law. That's why "The Morgan Doctrine" needs to be unambiguously articulated by whichever government issues it.
  6. The Cyber Privateer Code linked with a bonding authority will mitigate the financial and legal risks of the cyber privateer.
As I said above, I'm not totally convinced cyber privateering is a good idea. But it's the best one I've been able to come up with to address cyber crime and rogue governments. You have a better one?

Friday, November 21, 2014

Federal judge keeps 1-800CONTACTS from hijacking the Internet

In my opinion, this is the most significant Internet legal ruling of the first decade of the new millennium. (Originally posted December 30, 2010 but inadvertently deleted)

I've been following this case since 2009, and Federal Judge Clark Waddoups' ruling makes for some extremely entertaining reading. All I can say is "Thank Heavens this judge got it right, because he just saved commerce on the Internet." You can see his December 16th ruling by clicking on this link.

Let me put my comments into proper context:
  1. I am not an attorney, so my thoughts are an opinion uninformed by professional legal training.
  2. My original interest in the case had to do with SEO (Search Engine Optimization) practices in which every marketeer engages and which would have been outlawed had the plaintiff won his lawsuit.
  3. This is one of the few federal cases that deals with who-owns-what? on the Internet, which means…
  4. This case directly relates to the legality of anyone attacking and trying to gain access to my servers.
Net net:  In my opinion, 1-800CONTACTS, Inc. tried a "hail mary" legal gambit to take over the Internet as it relates to service marks and the purchase of Google ad words. Specifically, 1-800CONTACTS wanted to prevent LENS.COM from buying "1-800CONTACTS" as a search engine keyword because the sponsored links were likely to cause confusion on the part of the buyer. Luckily for all you guerrilla warriors out there, not to mention Google who stood to see their stock valuation plummet deeper than whale dung, the judge beat 1-800CONTACTS and their legal counsel like the proverbial gong. Such a ruling would have prevented a comany like Sybase from buying the keyword "Oracle" so they could compete with them. Likewise, the OpenOffice product couldn't compete with Microsoft Office by buying various Microsoft-specific keywords, thereby effectively giving Microsoft a monopoly on that space. 

Of course, were the average consumer's intelligence on a par with the O. J. Simpson jury, maybe 1-800CONTACTS might have had a case. Luckily, the judge was considerably more Internet savvy than one might have expected. Which is why I find parts of his 65-page ruling to be knee-slappingly funny. For example:
  1. Between 2003 and 2008, 1-800CONTACTS spent $11 million advertising with Google alone [p.2].  Over the same period of time, LENS.COM spent between $3 million and $4.7 million in Internet advertising [p.3]. LENS.COM used 9 keywords contested by 1-800CONTACTS to generate about 1,626 impressions, 25 clicks, and about $20.51 in profits. That's right. 1-800CONTACTS declared war over $20 in profits. Obviously, this sounded ridiculous even to 1-800CONTACTS, so they pulled in LENS.COM affiliates (of which there were over 10,000 [p.11]. I'll talk about that later.
  2. But dig this. While 1-800CONTACTS went to war over $20 in profits, they engaged in buying "1-800-lenses" and similar keywords which generated 91,768 impressions, 8,477 clicks and about $219,314 in profits [p.8] for them! Hummmm. Same behavior. Reminds me of the schizophrenic line out of Blazing Saddles as Cleavon Little holds a gun to his own head and says, "Drop your weapons or I'll shoot the…[African American]."
  3. Not to be daunted, 1-800CONTACTS admitted that their suit was for more than 1,600 impressions generated by LENS.COM, but for the activities of LENS.COM affiliates. Doing the "click-arithmetic" conversion, even the affiliates "haul" was a pittance [p.13]. 480,000 first impressions and 65,183 second and third impressions generated by the affiliates accounted for 3,515 clicks or (using the $25.51 in profits from 25 clicks metric) approximately $3,586.71 in profits. Okay, you could buy a used Yugo for that kind of dough. Sheesh!
  4. Both law firms engaged in the laughable "Hey-let's-crank-up-the-billable-hours" game as illustrated on page 15 of the ruling: "The following day, Plaintiff's counsel sent a return e-mail thanking Defendant's counsel for discussing the matter with him that morning. He further stated, '[w]e appreciate your client's willingness to work towards an amicable solution on this matter.' He then listed twenty terms and asked defendant and its affiliates to implement negative matching for the specified terms." They probably each billed their clients for the used Yugo based on that one call and associated action items.
  5. [p.16] Since 1-800CONTACTS alleged confusion, they had to prove it. While earlier courts [p.25] concluded that "…use of another's mark 'to trigger internet advertisements for itself,' is a use in commerce…", Judge Waddoups said (in effect), "Get serious!" [p.31] "Plaintiff asserts that whenever a Lens.com advertisement appears when a consumer enters the search term '1800Contacts,' it is akin to a consumer asking a pharmacist for Advil and the pharmacist handing the consumer Tylenol. This analogy mischaracterizes how search engines function. A more correct analogy is that when a consumer asks a pharmacist for Advil, the pharmacist directs the consumer to an aisle where the consumer is presented with any number of different pain relievers, including Tylenol. If a consumer truly wants Advil, he or she will not be confused by the fact that a bottle of Tylenol is on the shelf next to Advil because of their different appearances." Good job, Judge! You actually understand how the Internet works.
  6. One of the more amusing last-ditch/desperation moves by 1-800CONTACTS was to assert that telephone conversations between attorneys of the opposing sides constituted a binding contract to which LENS.COM did not live up. Judge Waddoups kills this on two grounds. First, such an agreement between competitors makes "…[the court question] whether it would survive an antitrust challenge." [p. 59] But more entertaining, a very astute Judge Waddops reiterated my point 4 above stating that "…Plaintiff appreciated Defendant being willing to work towards an amicable solution…" doesn't sound at all like a contract, nor does it sound like they had "…reached a meeting of the minds." Hear that gong? BONG!
In my opinion, Judge Waddoups has protected the competitive viability of the Internet. While 1-800CONTACTS will probably appeal this ruling, I can't resist relating a war story almost 30 years ago.

MAYBE THIS IS WHAT LENS.COM SHOULD DO:  In 1982, Stratus Computer said Tandem Computers' slogan "NonStop" was pure baloney. Tandem sued Stratus for false advertising. Stratus CEO and founder Bill Foster, an old friend of mine, said to himself, "Gotcha!" and countersued, accusing Tandem of filing a frivolous lawsuit and demanded treble damages. And as part of the discovery process, Stratus asked for disclosure of every one of Tandem's customer service records. Zowie! Both suits evaporated for "undisclosed reasons" and Tandem CEO Jimmy Trebig told a subsequent users group meeting that "NonStop is a goal, not a promise." In my non-attorney opinion (yeah, jailhouse lawyer extraordinaire), the 1-800CONTACTS lawsuit was so shamefully cynical and such calculated bullying, that LENS.COM could well recover all their attorneys' fees and treble damages by going after 1-800CONTACTS. Sure, to prove this assertion they'd have to show some internal emails between 1-800CONTACTS executives and/or marketing/PR consultants laying out the real plan of attack and the real reasons for the lawsuit, but all they need is one whistle blower to slip them an email or two and they'd be off to the races. Not only would this be a great incentive for 1-800CONTACTS to tube any appeal, but the likely out-of-court settlement could possibly pay for LENS.COM's complete Internet advertising budget for the entire history of the company. Having done the "Vulcan mind meld" over six years with Oracle's Larry Ellison, that's what I predict Larry would do. Gee whiz, look at the hundreds of millions he's beating out of SAP right now! But, maybe they're kinder and gentler in Louisiana, Missouri.  

WHAT DOES THIS HAVE TO DO WITH CYBER PRIVATEERING?  Judge Waddoups did indeed affirm that 1-800CONTACTS owned their name that that any attempt to fool the buyer into thinking that he or she was dealing with them when in fact they were dealing with LENS.COM or an affiliate was illegal. Similarly, hackers trying to break into my Linux box by presenting themselves as someone they are not (trying different usernames/passwords) is yea verily illegal. Period. So what's with the US Law that keeps me from kneecapping the hackers? They're clearly breaking US law, and we should articulate and enforce…The Morgan Doctrine. As is written at the end of The Rubaiyat of Omar Khayyam, "Taman Shud." But this isn't "The End." It's just the beginning. Selah.

APPEALS COURT UPDATE ON AUGUST 9, 2013: 1-800CONTACTS appealed this decision, and got whacked. Again. See posting here.

Friday, August 9, 2013

Appeals Court Whacks 1800CONTACTS' Attempt to Hijack the Internet

On December 30, 2010, I reported that Federal Court Judge Clark Waddoups "got it right" when he ruled against 1800CONTACTS' attempt to hijack the Internet (see my story here). Would you believe 1800CONTACTS appealed the ruling? Only in Utah, where church and business are so incestuously linked that the if-I-think-it-then-it-must-be-the-will-of-God-and-I-will-fight-to-the-death-as-a-matter-of-principle attitude prevails in our theatre of absurdity. Well, the Tenth Circuit of the United State Court of Appeals has ruled on the case (see the full ruling here). Net net, they told 1800CONTACTS to get an eye exam and possibly a new legal team.

1800CONTACTS has spent HUNDREDS OF THOUSANDS OF DOLLARS suing Lens.com for having the audacity to buy Google AdWords to poach leads from 1800CONTACTS. Imagine the gaul! Competing for business on the Internet. How dare they!

If you don't have time to dissect the ruling, here are a few knee-slappingly funny points:

  1. The total business generated by a Lens.com affiliate who did indeed use the 1800CONTACTS name in their ad copy was less the the price of a used Yugo!
  2. The appeals court ever-so-diplomatically suggested that 1800CONTACTS' law firm blew it when, on page 17 of the ruling, they write:  "…1-800's only clearly expressed theory of infringement was initial-interest confusion. Although it asserts on appeal that Lens.com's acts of direct infringement included purchasing merely generic keywords and then failing to designate the 1800CONTACTS mark as a negative keyword, that theory was not raised in district court."Translated: "Too bad your legal geniuses missed a more cogent argument."
  3. The appeals court again slaps 1800CONTACTS' brilliant legal team on page 29 when they write: "But this argument misreads the district court's order." Translated: "Learn to read, morons!"
  4. Finally, the appeals court is downright effusive in their praise of Judge Waddoups original ruling: "We affirm for substantially the reasons set forth in the district court's thorough and cogent order" [I added the emphasis in the last four words of that sentence].
What's next? Only in Utah my friends, only in Utah does the I-will-fight-to-the-death-because-it's-right mentality rear it's inbred head. Somewhere, I can hear a lot of pounding on the conference room table as 1800CONTACTS lectures the legal lackies for which they are paying an aggregate $2,000 an hour: "I don't care if it costs us another million dollars and we take this to the United States Supreme Court, Baby Jesus came to me last night and said this is the right thing to do." Okay, I couldn't resist poaching a phrase from Will Farrell's Ricky Bobby role in the movie Talladega Nights. But you get the idea.

Throwing 1800CONTACTS a bone, the appeals court ruled that Lens.com was guilty of contributory negligence because they took too long to figure out the who and where of the actual affiliate infringement, and did not do a simple blast email to all their affiliates telling them to never EVER use 1800CONTACTS in their advertising. So this will go back to the Federal Court for another run with the bulls. But again, the actual bull-goring of 1800CONTACTS from this contributory negligence was less than the price of a used Yugo. 

Hey, it's the principle that matters! And, of course, the attorneys being able to afford country club memberships for their trophy wives and far-away private schools for the kids to keep them from ogling their stepmother's latest cosmetic surgery. How about we at least castrate the attorneys so their rancid genes can't produce more blights on humanity?  

I now return from this comic opera to again focus on the critical cyber security issues facing this fragile world. 

Thursday, August 8, 2013

If I were President Obama's Speech Writer…

The president's cancellation of his meeting with Russian President Putin is a totally reactive snit over Snowden. In Chapter 17 of Daddy's Little Felons, I wrote a speech that the President of the United States (POTUS) should have been giving all along. Here is that speech, slightly edited for President Obama
“My fellow Americans,” began the president. “As most of you are aware by now, Chinese and Russian computer systems have been attacking each other for the past three days. Virtually all services in those countries that depend upon interconnected computers have failed. What little communication that is coming from those countries is over obsolete analog phone lines and human-assisted switches. Both China and Russia are blaming each other for the attacks, and the rhetoric is becoming quite heated. It is for that reason that I wanted to take some time tonight and tell you what we know about the situation, as well as how we are trying to help both parties step back from a dangerous precipice.”
“Both Russia and China have been waging an undeclared cyber war against both public and private institutions in the United States for years. Few of their attacks made headlines until early 2009. On April 8th, The Wall Street Journal broke the story detailing how our electricity grid had been penetrated by so-called spies. A little over two weeks later, on April 21st, they carried a front-page story of spies breaking into the Defense Department’s Joint Strike Fighter project and siphoning off several terabytes of data related to design and electronics systems. Since then, the floodgates have opened and new incidents have been reported almost daily. But this is the least of what I am about to tell you, tonight.” The president clicked a remote and the screen split, with him on the left and a computer presentation screen on the right.
“According to the cyber war task force formed in 2009, every single server located in the United States, public or private, however large or small, is attacked by hackers based in either China or Russia hundreds times every day. There have been three-hundred-twenty-nine extortion attempts in the past two years from international criminals. However, those same attackers are using the identical systems our cyber war task force has identified to attack strategic defense installations and which search for specific technical information that only a well-organized and well-financed government could possibly know about.”
“Until this week, our own cyber crime laws have made it impossible for individuals or corporations to do more than put up fences. Any attempt to retaliate, to disable the attacking computer systems, is not only illegal but carries stiff penalties. We call it restraint of trade if the counter attack crosses state or international boundaries. I call it stupid, antiquated, and wrong headed in today’s globalized economy. Here, now, today, I refuse to continue penalizing people who play by the rules. Our law enforcement structures make it impossible to find and prosecute the cyber crime that dwarfs any attempt at reporting and identification.”
“Last night, my former ambassador to China made a proposal I find quite compelling. In addition, the Democratic leadership in the Senate also finds the argument persuasive. Because of current international volatility, I am sending a bill to Congress for immediate action. The sponsor, Utah Senator Orrin Hatch, is ideally suited to shepherd the bill, since he sits on the Judiciary Committee, and since the mechanics of his elegant solution will be implemented by the United States Marshals’ organization under the aegis of the Justice Department.
“First, some background. We do not, indeed we cannot, condone vigilantism in America. While the right to protect yourself from imminent death or injury is fundamental to our law, the minute you aggressively go out to retaliate against a threat or an attempted intrusion, you are breaking the law. Yet our law enforcement organizations are woefully unequipped to enforce the law on your behalf. This is reminiscent of the sorry state of our Continental Army in the Revolutionary War.”
“Our country found itself outgunned, outnumbered, out financed and just about out of rope,” continued the president. “Letters of Marque were issued to bonded and licensed privateers who attacked British shipping. Privateer-generated proceeds virtually financed the entire Revolutionary War. In fact, privateers captured ten times the number of enemy ships as the Continental Navy. The numbers may surprise you. The Continental Navy operated 64 ships, while the privateers had 1,607. The Continental Navy had 1,242 guns; the privateers had almost 15,000. The Continental Navy captured fewer than 200 enemy ships; the privateers captured and, more importantly, monetized 2,283 ships. In my opinion, the profit motive can eclipse any forces this federal government could amass, and do so almost instantly.”
“Analogies aren’t perfect, and precedents require modification. I am not proposing that modern-day privateers prey upon foreign interests for profit. But consider deputizing cyber-marshals to engage in electronic hot pursuit and destruction of hostile cyber-forces anywhere in the world. These United States Cyber Deputies would work under contract for the United States Marshal organization and under the supervision of the Department of Justice. They would be bonded but for the most part simply turned loose on our enemies. Their rules of engagement will be a work in progress, and I do not want the lack of specificity in these rules or their definition to delay this legislation. Indeed, time is of the essence.”
“The most relevant legal doctrine of national sovereignty is a 1823 statement called The Monroe Doctrine. It stated that, and I quote, any attempt by European governments to colonize land or interfere with states in the Americas would be viewed by the United States of America as acts of aggression requiring US intervention, unquote. I will therefore explain a new doctrine of digital sovereignty appropriate for this day and age.
“Any attack or attempted attack by individuals or governments on American public or private computer systems will be viewed as acts of aggression requiring immediate intervention. Period. I am implementing this via executive order today.
“Are there legal ambiguities? Unfortunately, the answer is yes. Senator Hatch gave me an excellent tutorial, which I’ve validated with legal experts in my own party. International law governing hot pursuit generally deals with oceanic chase. The legality U.S. actually pursuing Pancho Villa across sovereign borders into Mexico and Israeli capture of Adolf Eichman in Argentina is hotly debated. But notwithstanding these issues, technology and globalization of the world economy demand we take a firm stand. But our stand must be clearly articulated and based upon the rule of law.”
The president paused for effect, then continued: “Therefore, any individuals or corporations who unilaterally take it upon themselves to retaliate against attacks on their computer infrastructures are in violation of law and will be prosecuted to the full extent of current cyber crime law. Thank you and goodnight.”
Later in Daddy's Little Felons, I hyperlink to The Cyber Privateer Code of Conduct (see it here), which eliminates legal ambiguity and puts into place a tightly thought-out doctrine. The question now, Mister President, is how do you want to project American power? By dancing from foot to foot about NSA spying while Snowden gives you the raspberry from Moscow, or by letting the U.S. beacon of light shine on all the cockroaches?

Mister President, if you can't afford the $2.99 for a copy of Daddy's Little Felons, let me know when and where to send you a complimentary copy.

Sincerely yours,
Rick Bennett

Wednesday, November 6, 2013

2014 Headline: Law Firm Stings Hackers for $60 Million

Based upon "data exhaust" produced by Quantum Leap Buzz from Twitter and Facebook feeds, and Quantum Leap Analyst simulations on cyber security breach escalation, I predict the following story (or one substantially identical with different players) will appear in mid to late 2014.
NEW YORK, NY - December 17, 2014 - In a first-of-its-kind press conference held after the close of markets today, the number-one M&A legal firm of Davis Polk & Wardwell (http://www.davispolk.com) announced a massive. and what they contend to be legal, sting operation against a foreign government attempt to penetrate the security of their super-secure mergers and acquisitions working documents. Senior Counsel Peter R. Douglas (see bio here) outlined the basics of a sting operation which netted Davis Polk's client some $60 million. Those funds will be donated in their entirety to several zero-overhead charitable organizations (see a discussion of zero-overhead charities here).

"Davis Polk would like to thank the news media for attending what we think is an historical event," began Davis Polk's Senior Counsel Peter R. Douglas. "Only one organization had any detailed information on the subject of this announcement, and we purposely misdirected that source to believe in a substantially different scenario. We believe that source to be an arm of the Chinese government who had infiltrated our most sensitive M&A computer systems. Nowhere but in those top secret files did we allude to a major announcement of a shell public company for which we were preparing a spectacular announcement. The organization which illegally accessed those files spent over $75 million buying shares in our shell company, which netted our firm, the owner of those shares, approximately $60 million dollars."

"I would like to assure all Davis Polk clients that our real data security was never at risk," said Douglas. "It was only because of persistent attempts to break into our systems that we devised a 'honey pot' system to lure and trap intruders. Since U.S. cyber law prohibited us from taking direct retaliatory action against the intruders, we came up with a plan to stab them with their own sword."

"Trading in this stock has been suspended," continued Douglas. "Our clearing house has expedited settlement in our favor, and we hereby announce the donation of all $60 million to worthy charities around the world. The funds—all $75 million, including commissions of $15 million—will be held in escrow until we receive authorization from the Securities and Exchange Commission that they anticipate no civil or criminal actions will be taken against Davis Polk or our shell client organization."

Concluded Douglas, "We are providing authorities with the names of the entities who acted on illegally obtained information to buy this stock and profit from it. Except for one domestic buyer, all the funds came from organizations closely tied to the Central Bank of China. The one exception was a domestic buyer who appears to be related to a senior analyst working for the U.S. National Security Agency (NSA)."

Mr. Douglas then closed the press conference without taking questions from the media, indicating that details would be released as deemed appropriate by legal counsel and as authorized by the Securities and Exchange Commission.

Saturday, January 4, 2014

Larry Ellison Named Microsoft CEO

In an unrepeatable attempt to use Quantum Leap Innovations data exhaust on a data stream created by a hybrid Wolfram-Alpha and Massively Parallel Technologies trilloMIPS pay-by-the-bucket InfoFarm, the following snippet emerged from what appears to be an early 2015 New York Times story. This blog makes no claims as to it's authenticity, and provides the snippet for entertainment purposes only.
… in the most astounding story of 2014. "Who would have believed such a course of events," said an unnamed source in the Obama administration. "The anti-trust implications alone would have tanked even early consideration of this appointment."

"Why have there been no legal challenges to this unholy allance?" mused Shira Ovide, Wall Street Journal reporter who chronicled Micorsoft's difficulty in finding a CEO in her January 4, 2014 story (see it here). "Perhaps it's because all tech stock prices have shot through the roof."

"We're in completely new legal territory here," opined former U.S. Attorney General Eric Holder, who resigned his post in late 2014 to work in Hillary Clinton's 2016 presidential campaign. "Two companies the size of Oracle and Microsoft cannot collude in stifling competition, but nowhere did the framers of anti-trust laws anticipate the same CEO functioning in two different companies."

In the above-referenced WSJ article, Ovide said the big snag Microsoft had in attracting CEO candidates was a perceived problem of board conflict, since two of Microsoft's former CEOs sat on the board. Commenting on this, Larry Ellison said, "I will probably disregard any advice Mister Ballmer offers. On the other hand, Bill Gates has been trying to pick my brain for a long time, and I look forward to several high-bandwidth conversations with him, now that we're on the same team."

"So far, the only challenge to this appointment has come from China, of all places," said former President Bill Clinton. "But since they have no legal standing in U.S. Courts, it appears they must express their reservations in political forums. This is going to be a fun year…
The above data stream terminated for unknown reasons. Should a repeatable stream be reestablished, the API to that stream will be provided free of charge to major news outlets and to computer scientists worldwide.

Friday, October 14, 2011

One-year cyber privateering readership analytics

Today is the Morgan Doctrine one-year anniversary. One year. Six days a week. Every single day. This has been a tremendous learning experience for me, exploring the legal and technical implications of…in the fictional words of Iron Man Tony Stark, "…privatizing  world peace." So at this Morgan Doctrine birthday party, I've decided to analyze the top-ten most popular topics and then the top-ten geographical readership areas. First, the most popular topics as judged by readers:

  1. Japan, I have a solution for you and Sony Almost three-times the readership of the number-two blog.
  2. Stuxnet response from Iranian hacker? A most telling theme, given that Stuxnet is a state-sponsored investment in this brave new world of cyberwar.
  3. Privateer analytics: high-reward/high-risk numbers... Obviously, other people are interested in these analytics.
  4. Frank Herbert clearly foresaw our day  This clearly validates my assertion that military science fiction is way ahead of the game. More to the point, Frank Herbert was a good friend and mentor and, if I want to be truly honest, is the person to whom I owe credit for this idea. He certainly deserves that my next book be dedicated to his memory. By now, most of the philosophical questions Frank and I discussed late into the evenings have been answered for him.
  5. Draft 01: The Cyber Privateer Code  I love this! I intended my equivalent of "The Pirate Code" to go through many drafts. So far, this one draft seems to hold water. Quite amazing. Which is why I set up a separate URL domain: www.CyberPrivateer.com to feature THE CODE.
  6. The Perfect Virus principle #14: Stealth  My single biggest breakthrough was forcing myself to coin the 22 principles of The Perfect Virus. And guess what? Today, Stealth is the number-one theme. But wait a year, or two. I predict that Black Box Portability will be the big issue. It certainly is in my novel.
  7. How China/Russia can make (are making?) billions b...  Oh yeah. The "usual suspects."  Russia and China. Read 'em and weep.
  8. Federal judge keeps 1-800CONTACTS from hijacking t...  Now this is really surprising. My analysis of a legal opinion, and I'm not even an attorney. Okay, so I watch a lot of television.
  9. Stuxnet about to cause an "Iranian Chernobyl"  Again, the cyberwar implications of the #2 most-popular topic.
  10. Yahoo email gets an "F" in security  I've had a grudge against Yahoo after getting email from my dead friend, whose Yahoo account got roached. Looks like others have a similar grudge, given Yahoo's market problems. Amen. This is, after all, a reputation economy.


WHERE are the readers? Here's a map and the top-ten demographics:
  1. USA, by ten-to-one over #2
  2. United Kingdom
  3. France
  4. Ukraine
  5. Germany
  6. China
  7. Russia
  8. Canada
  9. India
  10. Netherlands
Several surprises pop up. Why are the UK, France, Ukraine and Germany ahead of China and Russia? What the heck is Ukraine doing so high on the list. And what the heck is Netherlands doing on the list at all? Several "data exhaust" guesses: 
  • Netherlands may be an Anonymous hotbed.
  • Ukraine must be pretty high on the list of cybercriminals.
  • UK and France are governments making big investments in cyberwarfare capabilities.
  • I'm surprised that Canada, India and Netherlands are higher on the list than Israel, with whom I've had some most interesting dialogues. If I were to rank cyberwar capabilities of the developed nations, I'd place Israel right after the United States and ahead of the U.K., France, Germany, Russia, and China.
A year ago I made a commitment to write every single day except Sundays. I achieved that goal. Today marks a change in strategy and tactics. Simply, these posting will become far less frequent. Why? Because I'm going into the next phase of research with some pretty spectacular new tools that have become available to me. Don't worry, they're totally legal tools. But they are top secret and will assist me in finishing my sequel novel. Here's a hint: Black Box Portability is the real Holy Grail of The Perfect Virus. Black Box Portabiity could also be called "infecting an alien architecture." Check it out in the search box to the left. And stay tuned for interesting albeit less-frequent announcements. 


Saturday, March 26, 2011

Cyber privateering readership analytics

I started my cyber privateering blog exactly five months and twelve days ago (according to my Wolfram|Alpha calculation). While it interested me greatly, a collection of the top-ten-visited postings kind of reinforces what interests my many thousands of readers. While these musings simply started out as a kind of displacement activity to help me understand the nuances of legalized cyber privateering, it has definitely taken on a life of its own. And more importantly, the whole concept of licensed and bonded cyber privateers—who operate under a strict code of conduct—appears to be a rather practical mechanism. If readership analytics tell me what I think they do, then you readers also validate my wild-hare fictional premise. Here are the top-ten postings for your own review:
  1. Draft 01: The Cyber Privateer Code is the #1 most-read posting. This is the strict code of conduct, kind of like "the pirate's code" referred referred to in the Johnny Depp Pirates of the Carribean movies. I called it "Draft01" because I thought for sure I'd have to make some modifications. I came up with five rules (Isaac Asimov only had 4 rules of robotics, while our Creator had ten commandments). Five rules? Not bad. I'm still nervous about the 100-to-1 penalty for inept privateering exploits, and may eventually make it only 10-to-1.
  2. The Perfect Virus principle #14: Stealth is an obvious #2 in readership. Almost as popular as the Cyber Privateer Code, this 14th of my 22 Principles for creating The Perfect Virus is kind of the reason people write viruses. They want them to be stealthy.
  3. Stuxnet about to cause an "Iranian Chernobyl" ranks very close to the top two in frequency. While this story was very popular when I wrote it on January 17th, since the tragedy in Japan it has taken on some seriously new interest amongst my readers. I think a lot of people are wondering just how good the Russians' fail-safe protocols are in the technology they've sold to Iran.
  4. Privateer analytics: high-reward/high-risk numbers is a bit of practical arithmetic. Over 78% of our Revolutionary War privateer ships were captured by the enemy. The frequency of readership that gives this topic a #4 ranking shows that people are giving some serious consideration to the risk factors. After all, if you clean out the bank account of a drug kingpin, you could be finding body parts of loved ones all over the place.
  5. How China/Russia can make (are making?) billions by slowing down the side channel shows how truly vulnerable our networked world has become, especially to nation/state-sponsored exploits. And unlike hitting drug dealer bank accounts, Wall Street doesn't appear to have any teeth with which to bite back (of course, a get-out-of-jail-free card issued by our government would quickly change that).
  6.  Federal judge keeps 1-800CONTACTS from hijacking the Internet is in my opinion the most important legal decision of the new millennium. I hope Federal Judge Clark Waddoups is asked to apply his considerable legal genius to a rewrite of our idiotic federal cyber crime laws. And I am delighted that so many of my readers have stumbled onto my analysis of his ruling in this case.
  7. The Perfect Virus: All 22 principles summarized is always in the top ten. The real genius behind these 22 principles is Jeffrey L. Walker, a member of my Cyber Privateer Fantasy League team. I just took his 22 principles for creating "the perfect software application" and applied them  to the world of virus creation. The exercise was essential research for the sequel to my already written novel about cyber privateering (which my new literary agent is gearing up for sale to a New York publisher). Again, various mechanics for creating The Perfect Virus are always high in readership ranking.
  8. How badly are the Chinese and Russians hurting us? is my second-ever blog post. I'm always glad to shine a spotlight and watch the cockroaches run for cover. This story still has legs, and is more relevant today than ever before.
  9. IP addresses of Chinese attack servers is my unrefuted indictment of the biggest nation/state threat to cyber security: China. Perhaps this still gets substantial readership because I frequently hyperlink to it on my postings. Of course, Chinese servers are still attacking my little Linux "honey pot" hundreds of times a day. Which thoroughly irritates me. Now if I had a get-out-of-jail-free card …
  10. Infecting an alien architecture, Part II is my seconding posting on what I consider to be the true Holy Grail of The Perfect Virus, principle #7: Black Box Portability. While Stealth ranks #2 in all-time readership, the key to winning a full-blown Cyber War will be our ability to defend ourselves against specialized intrusion engines that have roll-your-own operating systems created by a nation/state with the resources to field a special cyber warfare engine. But at lease this topic remains in the top ten.
The all-time geographic distribution of my audience shows some anomalies.

  1. The United States is naturally the top reader.
  2. The United Kingdom is number two, again no surprise.
  3. Canada is a bit of a surprise, as they should be #2, shouldn't they?
  4. India is also a surprise, as they shouldn't be this high. Maybe Pakistan is getting on their nerves?
  5. Germany, again a surprise. Islamic nervousness maybe?
  6. France only surprises me here because they're ahead of Russia (#8).
  7. Australia. Actually, I'm sorry they're not higher on the list, as they'd be my #2 choice as a legal haven for cyber privateers.
  8. Russia. Seriously, number 8! These guys refused to jail cyber crook Darth Vader, Jr. They probably gave him a high-paying job, instead. Russia is #3 in their commitment to and resources available for cyber warfare, only behind China and the USA.
  9. Japan.
  10. Malaysia! What the heck is going on in Malaysia?
Significantly not on the top-ten list are China, Taiwan and various Middle East entities. Given the attack volume on my Linux server originating in China, it's clear their government is doing a whiz-bang job censoring their access to outside information. Which is good, as far as I am concerned. I wouldn't want them paying serious attention to and investing their substantial resources in actually creating The Perfect Virus. As for Taiwan and the Middle East, if ever some regions would benefit from serious attention to cyber warfare defenses, they certainly could. Go figure.


Thursday, September 15, 2011

Legal defense of Anonymous

Predictably, the legal defense of Anonymous is the modern-day equivalent of 60's political protesters. They haven't played the try-em-as-minors card, so good luck in the prison general population. Cybercrime laws have a lot more teeth than the laws against blocking my college dean's office in 1965.

Saturday, March 19, 2011

Ooh-rah, U.S. Cyber Marshals!

On Thursday, I posed the question, "Some cyber privateers did their homework?" I referred to the story that a botnet responsible for half the spam we received last year had gone silent. I suggested three hypothesis:
  1. A white hat Cyber Privateer had done his homework;
  2. A government organization had properly papered up a get-out-of-jail-free card and had taken out the botnet; or
  3. Another criminal organization was holding the botnet hostage.
Yesterday's Wall Street Journal answered the question, and it was sort of my door number two. Microsoft, working with federal authorities, swooped in and seized the command and control servers. Kudos to Microsoft's Digital Crime Unit. Yes, they could have gone further than merely cutting off the head of the command and control system—like maybe backtracking to the source and lobbing their own data bombs at the bad guys—but that would have placed them well outside current law. As it is, they had to do everything (hopefully) by the book.  

It's entirely possible that Microsoft had to violate (wink, wink) existing cybercrime law to identify the botherding servers. Since I don't have access to the legal filings used to paper up the court orders, this is just speculation. Nevertheless, I'm glad to see some positive motion. After all, the botnet itself is composed of an estimated 815,000 Microsoft computers that have been taken over by the criminals. Microsoft truly owed it to us all, not to mention their customers.

I am slightly more interested in pointing out that Microsoft was joined in the action by U.S. Marshals. I have speculated in my own fiction that indeed the U.S. Marshals would be the entity under which legalized cyber privateering would function (a few months ago I even reserved www.USCyberMarshals.com as the working title of a yet-unwritten sequel to my current novel). This makes sense, and I'm optimistic about this evolution.

Who's the next headline? How about EMC's RSA unit, which really got cyberwhacked? EMCs legal and tactical problems are much more complicated.

Stay tuned.

Thursday, September 1, 2011

"Data exhaust" & DoJ right-to-bribe authorizations

Yesterday I wrote how a DoJ FCPA (Foreign Corrupt Practices Act) "enforcement opinion" is the legal way for U.S. companies to bribe the officials of foreign governments. A key provision of the FCPA law states:
Copies of releases issued regarding previous opinions are available on the Department of Justice's FCPA web site. 
Interestingly, very few companies have taken advantage of this "selling of indulgences" provision, as evidenced by the history of such activity since 1993 (click here to see the site). The "data exhaust" moment? Well, in nearly 17 years, the DoJ has issued a mere 34 "licenses to bribe" foreign nationals. There are no statistics detailing how many requests for a get-out-of-jail-free card were declined. If I were on some kind of congressional oversight committee (ie, if I had the patience to deal with acres of idiots), I'd be asking this question. Several possibilities emerge:

  1. The DoJ makes it hellishly hard to get the right to bribe; and/or
  2. The DoJ turns down a lot of requests; and/or
  3. The really smart bribery operations try to stay under the radar; and/or
  4. Major U.S. companies (and their highly paid attorneys) haven't done their homework to "know the ropes"
One thing is for sure: Oracle wasn't one of the firms requesting a get-out-of-jail-free card. While the requests were anonymized and the nature of the business was only vaguely described, none appeared to be a U.S. software company. I once asked Larry Ellison if maybe we should run some of our ads through legal. His answer: "Hell no; I've got a litigation department, so let 'em litigate!"

Well Larry, given the failure of your international law advisors to do their stinking jobs, you're "litigation department" has their work cut out for them.

Saturday, December 6, 2025

Part II: Building "Damage Control" Into Your Guerrilla Warfare Campaign


 

Back around 1986, I ran an ad for Oracle saying something to the effect that "The Top-10 Companies All Use Oracle." And I put each of their logos in the headline. Sure, the footnote acknowledged their trademarks, but Larry was set to handle any blowback. Boy did we get blowback.

Not only did IBM and the four oil companies' legal departments contact us, but Atlantic Richfield challenged us to show them where the hell they were using Oracle.

As planned, Larry had our legal department assure them that "We thought that crazy ad man got your permission. We will cease and desist ever again running this ad." But we had another problem with Atlantic Richfield.

Gulp. Being the tech whiz that I was, I'd queried our customer database and came to Larry Ellison with the news that the top ten companies were customers. What I didn't account for was that Atlantic Richfield had tried a $199 copy of Oracle for the PC and then returned it for a refund.

Gary Kennedy was head of Oracle sales in Chicago, and he was livid, saying we were well and totally ruined at ARCO. I said "Relax guys and see what happens."

What happend was spectacular. Within six months, ARCO bought a multi-million dollar site license for Oracle. You see, all their execs were suddenly aware of Oracle and started asking, "Why aren't we using them?" Turns out, our ad got the attention of all their C-level execs.

Like I always council my clients, "Damage control can yield big results." Oh, and FYI. Neither me nor any of my clients have ever been sued.

Sincerely yours,
Rick Bennett
Ad Hit Man

Tuesday, August 16, 2011

U.K. rejects privateering E-petition

Not sure why Mr. Hopkindon's E-petition to legalize cyber privateering was rejected by the HM Government E-petition site. Here's the link for the following (anybody want to take another shot at this?):



e-petition

Legalise Cyber Privateers

Responsible department: Foreign and Commonwealth Office
Because world-wide law enforcement is completely unequipped and under staffed to fight the wave of cyber crime and hostile invasion by various governments, it is proposed that cyber defense be privatized as follows: HM Government must rescind the UK signature on the Paris Declaration of 1856 that outlawed privateering (which I assume could be applied to cyber privateering, too). HM Government would license and bond CYBER PRIVATEERS who would loot criminal enterprises and the treasuries of rogue governments, and split the proceeds 50-50 with the UK Treasury. The CYBER PRIVATEERS would be bound by "The Cyber Privateer Code" of conduct outlined at www.CyberPrivateer.com. A legal justification under international law can be found at: http://www.themorgandoctrine.com/2011/01/my-legal-justification-for-cyber.html

This e-petition has been rejected with the following reason given:

E-petitions cannot be used to request action on issues that are outside the responsibility of the government. This includes:
  • party political material
  • commercial endorsements including the promotion of any product, service or publication
  • issues that are dealt with by devolved bodies, eg The Scottish Parliament
  • correspondence on personal issues
E-petitions cannot be used for freedom of information requests.