So, where do we go from here? After the Internet of Things was effectively used as a way to crash various online stores and services, it leaves us with the question of how can we fix this gaping hole in our security that would allow this new technology to continue to exist without causing further risk? As mentioned last week, the most likely solutions are either in the private sector, through consumer choice and manufacturer investment, or through government action. What actions should individuals take? What is the government doing now? What might the government do in the future?

What is the private sector currently doing?

The private sector is not doing much at this time. While consumers could demand more secure smart devices, the focus of the demand for these devices tends to be towards their functioning.  In general, less sophisticated consumers buy smart devices for the sake of convenience, with security being a distant thought when compared to the more sophisticated consumers.  These smart devices, like any other internet-connected device, occasionally need security updates to remain resistant to online bugs (i.e., malware).  So, as the world becomes smarter, this technology will need to adapt and advance, accordingly, in order to mitigate the risks. Yet, without some motive to do so, it’s less likely that resistance to the botnet will emerge, and it may be due to the government’s intervention.

In recent years, we have all heard the expression before, but how does someone really “break the Internet?” Recently, an incident arose where a large network of electronic devices joined together resulting in a major interference with online businesses and services. Amazon, Netflix, and Yahoo, were hobbled temporarily due to various flaws in the Internet of Things. This flaw allowed individuals to create what’s known as a botnet, to launch a massive DDoS attack to effectively shut down services.  So, how would we prevent a similar incident from occurring? Should you be concerned about your smart devices? What about your websites and online services?

How did the Internet of Things become weaponized?

As it stands, the Internet of Things, which comprises of smart devices that connect online for the convenience of individuals, became weaponized against service providers, and created a “botnet.”  Effectively, some type of malware was downloaded onto these smart devices prompting them to send requests to certain websites. When these websites become overwhelmed by the requests, it resulted in websites crashing, or becoming generally unavailable to the users.  Here, one might wonder how, but the real answer was due to a lack of knowledge, training, and security. Unlike regular computers, tablets, and cellphones, smart devices do not always have the capability for security updates. With this, even for those devices that might be on a more secure network, the Internet of Things still entails those devices being connected online. This makes them vulnerable to more pinpointed attacks.  From there, the controller of the botnet can use the Internet of Things to launch the DDoS attack and crash a network.

As it stands, the Internet of Things can be a dangerous proposition. Due to various hacking techniques, like rubber ducks, pineapples, and pivoting, one must wonder, if it can be hacked into, and if so, then what can we do about it? What about cars, planes, trains, and power plants? To this point, the U.S. Government has launched the Cybersecurity National Action Plan or CNAP. The idea is to add more information and resources into the system, increasing the amount of resources to help build up cybersecurity and investing resources into security measures. So, what is the government doing with CNAP? How might this help a business? How might this help individuals?

What does CNAP do?

It’s a set of guidelines and goals that the Obama Administration has implemented to help build the cybersecurity network, protect against attacks on the Internet of Things, and the general national network as a whole. The first, and easiest way it plans to do this is through the 2017 budget, allocating approximately 19 billion dollars for cybersecurity, up by 35% from the previous year’s budget.  It also incorporates and promotes other existing goals and changes, such as the BuySecure Initiative requiring credit cards to incorporate smartchips, and making large businesses use the smartchip option rather than the traditional magnetic strip.  CNAP also incorporates other ideas, such as multifactor authentication, identity for Federal Government digital services, training for small businesses, and relaunching identitytheft.gov.  Therefore, it is less of a new initiative, but rather a continuation of previous actions.

Nowadays, we’re using the web for numerous purposes, including, but not limited to, online banking.  So, we should be able to protect our financial information. There are many options for hackers to gain access to financial information, and without the prerequisite security, financial information can be accessed by hackers.  The law outlines the rules for financial institutions, such as data protection, data sharing, data preservation, security breach notification, or insurance requirements.  Also, there are different standards when it comes to consumer and business bank accounts.  For example, businesses face different prerequisites that must be fulfilled prior to submitting a claim towards a financial institution.

How might hackers commit banking fraud?

Looking at how hackers may even access your financial information, there are a few tools that need to be highlighted. Among them are Pivoting, Rubber ducks, and Pineapples. While this perhaps sounds odd, the way they can work is terrifying. Pivoting is a process hackers can use to break into a computer system by accessing it through an already-compromised device. For example, a hacker may access a web server by gaining access to an email server within the same network.  These discrepancies can also occur between smart devices, which indicate a downside to the Internet of Things. Rubber ducks are special USB drives with small processors. They act as a “Trojan Horse” by downloading and re-uploading information quickly and autonomously without causing alerts. Pineapples, in comparison, are more likely to come across, but more difficult to avoid.  These are devices that “clone” Wi-Fi networks. They will function in the same way, allowing individuals to connect and access the web, but can also be used to access and hack data after someone is connected. Pineapples and Rubber ducks are dangerous because they can download “keyloggers” onto computers, which would record and transfer confidential information (e.g., passwords, financial data) to the hacker’s computer.

In today’s globalized world, with international markets becoming a stage for events to take place, how would you enforce a judgment in a foreign jurisdiction? After going through a lengthy process, it may seem unfair to go through the same procedure again without a guaranteed result.  So, simply because you obtained a judgment in your favor, if the court decision isn’t enforceable in a foreign jurisdiction, then how can you ensure you can collect? How can you ensure that things will end in your favor, and that the other side will not get away because he/she retreated to another country?

What needs to be in place to enforce my judgment?

You need the following items to enforce your judgment in a foreign jurisdiction: (1) a treaty with the foreign country agreeing to enforce the judgment; and (2) a domestic judgment in your favor that was issued within the United States. What makes this difficult is how the United States does not have treaties with other countries regarding the enforcement of judgments. While there is a treaty in place through the Hague Conventions on the Recognition and Enforcement of Foreign Judgments in Civil and Commercial Matters, only a few select countries are part of it, including, but not limited to, Kuwait and the Netherlands. Unfortunately, beyond that there is little else you could do to enforce a judgment. While we will discuss this in the next blog, arbitration agreements can bind those in other countries, and there is an effective convention that applies in those cases.

We have discussed protecting someone’s image using the right of publicity, right to privacy, and the privacy laws that protect biometrics. Yet, images are first and foremost images.  So, certain rights exist for the protection of images. Firstly, it includes copyright laws. An ongoing trend is how individuals, famous and otherwise, use the Digital Millennium Copyright Act (DMCA) to demand takedowns and manage photographs. While this is still moderately controversial, it begs several questions. For example, what is required to use these claims to protect images? Why might someone use the DMCA takedown demand instead of one of the other methods of protecting images? How is this controversial if it allows individuals to protect privacy?

How would the DMCA work?

The DMCA allows individuals to issue “takedowns” to internet hosting services and to websites to remove copyrighted materials. The first hurdle is to yield actual copyright over the photograph. To be eligible, the work must be a type of copyrightable work (e.g., photograph, sound, written word), written by a human author and either created or arranged with a minimum amount of originality and creativity. In most cases, this might include, a “selfie” or a similar picture that has been taken by you. It’s worth noting that this is something that only applies within the United States, and the other elements to register a copyright, like creativity, are relatively easy to meet.

We’ve discussed the nature of this before, but the EU-US Privacy Shield has gone into full effect. This program essentially restricts the ability of U.S. commercial entities to do business in the European Union due to the ability of the U.S. government to use international businesses to improperly conduct surveillance on citizens within the European Union.  In response, the European Union removed the blanket ability of U.S. companies to do business with European Union members as part of the Safe Harbor provision. The Safe Harbor provision was loosely drafted in its self-certification, prompting the switch to the Privacy Shield today. As it stands now, this program is still in its fledgling stages, with registrations beginning on August 1, 2016.  These registrations begin with a murky area of international commerce. So, how could one join the privacy shield? Is your organization even be eligible? What might happen if an organization refuses to participate?

How can you join the Privacy Shield?

The Privacy Shield is open to any business that is subject to regulation by the Federal Trade Commission (FTC) or Department of Transportation (DOT).  In general, conducting business and affecting commerce would qualify entities under this regulation, although, there are some exceptions, such as, financial institutions, labor associations, and non-profit organizations that may not qualify.  After meeting the base qualifications, an entity may then “self-certify” by coming up with a plan that meets the basic requirements of the EU-US Privacy Shield.  This would include measures to protect the data of European customers and employees stationed in Europe, even after ending participation in the Privacy Shield.

The internet with its “remix culture” often appropriates images and videos to create new things. Yet, this also includes personal images. Be it “Bad Luck Brian,” “Overly Attached Girlfriend,” or some exploitable image, how could one protect his or her personal image from being remixed and exploited for a financial incentive?  This is also a question appearing outside of the internet in particular with book covers and music videos. How might one protect his or her own face and body? What is the best method of protecting one’s image?  Is this related to the right of privacy or right of publicity?

How could a person protect his/her own face and image?

Outside of simply preventing your image to be published online by avoiding social media, preventing photos to be taken, or spending your days behind a mask, the only way to protect your image comes up after an incident has occurred online.  The right over one’s own image can be boiled down to privacy claims with three main types of laws protecting it. First, the right to privacy. Second, is biometric privacy law.  Third, is the right of publicity. Of the three, biometric data is the newest with statutes in Illinois and Texas and minor provisions drafted in Iowa, Nebraska, North Carolina, Oregon, Wisconsin, Wyoming, and New York.  The idea of a biometric privacy law is that it creates a “privacy right” over an individual’s biometric features (e.g., fingerprint, retina, iris scans). Yet, ultimately this would only serve to protect one from larger entities.  To that point, the law in Texas lacks a private right of action but permits the State Attorney General to instigate legal action.

In the current news is another emerging technology, which is called Augmented Reality. In general, augmented reality (“AR”) uses technology to artificially create the reality a person experiences. For example, this could be a pair of glasses that shows a person’s contact information when his/her face is seen, or mobile apps, like Pokemon Go, which interact with your location and surroundings to create aspects of the game. Yes, Pokemon Go, the new mobile app juggernaut that has emerged into the market, is something that up to now, hasn’t taken place on such a massive scale. Yet, this new application has created unique legal questions. What can we do with this experience that encourages people to travel all over? How might one protect his/her property from players? Is there any way to stop Niantic, the creator of the game, from using your property in the game?

How does Pokemon Go work?

Before addressing the legal problems that arise from the game, it’s important to know how the game works. As stated before, Pokemon Go is a form of AR, using GPS data from the location to help generate the variety of creatures that can appear in a location.  In addition, certain locations and landmarks are coded to either give players items, or act as “goals” for them to capture for a team. There are small images on the markers, with titles and occasionally small descriptions. While many of these locations may be in public, or on publicly-accessible property, there are others that appear to be on privately owned or closed-off property.  While it appears that there are some deals with Niantic to add goals at the locations of real-world partners, however, it is not the norm.

For entrepreneurs who seek to engage in international business, it is important to keep abreast of developments in other countries. Political problems, exchange rates, and legislation may affect the business climate when engaged in international business.  The most recent shake up in international legal requirements seems to have risen from “Brexit” and what it means for those doing business with the United Kingdom, European Union, and United States. Brexit (which comes from the merger of “Britain” and “Exit”) is the UK’s vote to leave the European Union.  While this decision has had repercussions on the value of the British Pound, Euro, and U.S. Dollar, it also serves to show that the UK will no longer be bound by the European Union’s rules or regulations.  So, what law applies now? How soon will the United Kingdom be unbound from the European Union’s rules or regulations? What should American businesses take out of this referendum?

What does “Brexit” do?

The UK has voted to leave the European Union as part of a referendum voted on by its citizens. The EU is an economic and political partnership between various member states, sharing a common currency, with the exception of the United Kingdom, which uses the British Pound. The EU imposes certain restrictions when working with member states (e.g., Privacy Shield, Digital Single Market initiative). It serves to allow the free movement of people between member states. However, Brexit does not mean that right now, the UK has officially separated from the European Union.  Brexit has set in motion the process to fully remove the United Kingdom from the European Union.  It needs to invoke “Article 50 of the Lisbon Treaty,” to initiate the process, which grants both sides two years to negotiate the terms and conditions.  Essentially, the referendum will start the process, but does not remove the United Kingdom from the European Union immediately.