December 2012

Draft cybersecurity executive order excludes commercial products

A new draft of the White House's cybersecurity executive order maintains the Administration's effort to improve the digital defenses of critical infrastructure — but it includes a number of changes, following several Administration meetings with stakeholders.

The Nov. 21 draft obtained by POLITICO grants more time to the feds to devise and implement a voluntary system to protect power plants, water systems and other forms of critical infrastructure from crippling attacks. Yet it makes clear that commercial products won't fall into that category. It further calls on the feds to figure out how to incentivize companies to agree to abide by new security standards. And it leaves it to agencies to figure out whether cybersecurity should factor into the federal procurement process. In general, the latest draft order follows the same contours as another draft that leaked at the end of September —improving cybersecurity practices at critical infrastructure, and pursuing new information-sharing capabilities. But the new version appears to specify in clearer terms that NIST would lead the way in developing a so-called Cybersecurity Framework, to identify gaps in the country's digital defenses and set forward standards and methodologies to address the risks. In the latest proposal, agencies have more time — 240 days, rather than 180 days — to put forward their initial draft of that framework, but still have a year after that to publish the final guidance. And the new version emphasizes the framework should be developed through "open public review and comment," and reviewed every three years. The September draft, shared among top deputies, had called on federal agencies to report on ways to make any new voluntary measures mandatory. The new draft preserves the section, and it asks agencies to evaluate if their current cybersecurity authorities are sufficient or duplicative. It also tasks the Pentagon and other agencies to determine whether the government procurement process — a multi-billion-dollar industry — should grant preferences to vendors adhering to strong cybersecurity standards. And it includes a key, highly desired carve-out for commercial IT: It makes clear those products cannot be designated as critical infrastructure at the greatest risk, which is an exception that industry had sought in legislation. The new draft further requires the Commerce and Treasury Departments to devise recommendations on how to incentivize companies to participate — a key sticking point for the Obama Administration, which has said it can only provide the best incentives to businesses through an act of Congress.

FTC maverick a mystery on Google case

A maverick member of the Federal Trade Commission, J. Thomas Rosch, may hold the keys to whether the agency’s handling of the antitrust case against Google is viewed as a Democratic attack on Big Business or a bipartisan effort to ensure Internet competition.

Commissioner Rosch is a Republican appointee who has sometimes been a renegade — pushing the agency to be more aggressive yet arguing for limits in its application of antitrust laws. FTC commissioners could decide any day now whether to file an antitrust case against Google over the firm’s search business and use of industry standard patents against rivals — or settle for certain behavioral conditions that reports indicate might not even touch on Google’s dominance in Internet search. And while it’s generally believed that the two Democratic appointees will support FTC Chairman Jon Leibowitz, also a Democratic appointee, and that the newest GOP panelist will likely side against them, it’s unclear where Commissioner Rosch will fall.

Verizon, AT&T clash with Sprint and others over spectrum caps

In comments to the Federal Communications Commission, AT&T and Verizon Wireless argued against rules that would reduce how much spectrum carriers can hold in certain markets. Meanwhile, smaller carriers pushed for proposals that would limit the spectrum holdings of the nation's two largest carriers.

The FCC is considering changes to its so-called spectrum-screen, which it uses when reviewing spectrum transactions. If a carrier acquires too much spectrum and violates the screen, the deal is more closely scrutinized. Currently, the screen is different for each proposed transaction. The FCC voted in late September to open up a review of its rules.

  • Verizon said in its comments that the FCC should build on the strengths of the current system by including a "safe harbor providing certainty for transactions that do not exceed the screen, while enabling more detailed review of markets triggered by the screen for potential competitive harm." Verizon said the FCC should reject a spectrum cap "which is an inherently inflexible tool ill-suited to the dynamic spectrum market, and which can block spectrum transactions that are clearly pro-consumer."
  • AT&T said the FCC should update the screen "to include all of the available spectrum that is 'suitable' for mobile wireless services," and specifically include spectrum that Clearwire (NASDAQ:CLWR) controls when it makes that consideration. AT&T also wants the FCC to "reaffirm that the 'safe harbor' provided by the screen is truly safe," meaning that the FCC "will not entertain spectrum aggregation-related challenges to any proposed spectrum acquisition that does not exceed the safe harbor level." The FCC also needs to update its screen to reflect the realities of the market, and the screen should reflect that it is "simply not realistic to assume that any holding of more than a third of the available spectrum in any market may create a risk of market foreclosure."
  • In contrast, Sprint said Verizon and AT&T have aggregated around 75 percent of the spectrum for wireless below 1 GHz, and that the FCC should treat this spectrum differently. Sprint said the FCC "should adopt a cap for spectrum below 1 GHz that would apply prospectively to both commission spectrum auctions and secondary market transactions, including the incentive auction the commission will be conducting for broadcast TV spectrum.

Chicago's most-coveted talent: Obama's techies

The hottest free agents in Chicago tech right now are the former members of the Obama campaign's tech team.

Companies are lining up to recruit the 40 engineers who built and ran the widely praised technology platform credited with giving President Barack Obama a significant edge in turning out the vote necessary to win crucial states, such as Ohio and Florida. GrubHub recently wooed the techies over beers at its Loop headquarters. It has offered at least one of them a job. “It's so hard to find good talent,” says CEO Matt Maloney. Public relations giant Edelman also hosted a recruiting event, and others are in the works with Orbitz Worldwide Inc. and possibly with venture fund Lightbank (run by Eric Lefkofsky and Brad Keywell) and Groupon Inc., says Jason Kunesh, who was director of user experience for the campaign. The core tech team was led by Harper Reed, Mr. Kunesh, Dylan Richard, Scott VanDenPlas, Aaron Salmon, Jesse Kriss and Dan Ratner. Messrs. Reed and Richard already have said they'll form their own software shop.

TV Broadcasters Tell Appeals Court to Shut Down Aereo

On November 30, the major TV broadcasters made their second attempt to shut down Aereo, the digital TV service that was funded in great part by Barry Diller and launched this past March.

Arguing before a 2nd Circuit Court of Appeals panel, the challenge for the broadcasters was clear: They needed to convince the judges that a technology that already has been judicially certified as likely to irreparably harm the broadcasters also ran afoul of copyright laws. To this end, attorneys for the broadcasters spoke of Congress' intent when lawmakers crafted the legal underpinnings of the modern television industry. They also attempted to distinguish Aereo's system from a judicially blessed technology that was reviewed four years ago by the same appellate circuit.

App developers, privacy advocates work out suggestions for policy disclosure

Did you know which apps are looking at your contacts list? Your calendar? Your location? Even when apps provide information on what data they access, the notifications are often so cumbersome to read that users skip right over them. To curb that problem, app developers and privacy advocates have collaborated to come up with ways to better display privacy policy information and cut through the long, legal liability documents.

The App Developers Alliance (ADA), Consumer Action, World Privacy Forum and American Civil Liberties Union will present mock-ups of screens that offer quick-scan information on what data app developers collect and that who else has access to that data. The groups will present their proposal Nov 30 in Washington at a National Telecommunications and Information Administration meeting on app privacy and transparency. Jon Potter, president of the App Developers Alliance, said that it’s in developers’ best interests to let people know what data the apps use. “App developers have no interest in fighting with consumers,” Potter said. “We want them to be comfortable with using apps.”

Chairman Genachowski Still Wants Dish Item Voted by Year's End

Federal Communications Commission Chairman Julius Genachowski said that his goal is still to vote the Dish item by the end of the year. That is the FCC decision to open up satellite spectrum -- including that held by Dish -- for terrestrial mobile broadband use, but with restrictions Dish says could "cripple" its business plans. Asked at a press conference about the Dish item, which the chairman has circulated for a vote by the other commissioners, Chairman Genachowski said that if he did succeed in getting it voted by then it would be "by far the fastest the commission has ever resolved a rulemaking like this," but added: "We are still committed to getting this done by the end of the year." According to reports, he has already voted to approve the item, along with fellow Commissioner Jessica Rosenworcel.

SoftBank and Sprint Seek FCC Consent on Wireless Deal

SoftBank and Sprint have filed applications seeking Federal Communications Commission consent to the transfer of control of various wireless licenses and leases, domestic section 214 authority, international section 214 authorizations, earth station authorizations, interests in submarine cable licenses, and cable television relay service station licenses held by Sprint and its subsidiaries, and by Clearwire to SoftBank. Additionally, Sprint and SoftBank, have filed a petition requesting a declaratory ruling that it is in the public interest for the foreign shareholders to hold foreign ownership and voting rights in Sprint and its post-transaction direct and indirect licensee subsidiaries in excess of the 25 percent foreign ownership benchmarks in section 310(b)(4) of the Communications Act.

The Applicants assert that the proposed transaction will benefit consumers by promoting greater wireless competition and broadband innovation and deployment. The Applicants also contend that, because SoftBank and Sprint are not competitors, and SoftBank has no attributable interests in any other U.S wireless carriers, its acquisition of a controlling interest in Sprint will not have adverse competitive effects or other public interest harms.

The FCC seeks public comment on the applications. Petitions to deny are due January 4; Oppositions are due January 22; and Replies are due February 1, 2013.

FTC Issues Amended Rule on Identity Theft “Red Flags”

The Federal Trade Commission announced publication of an Interim Final Rule on identity theft “red flags” that narrows the circumstances under which creditors are covered by the Rule.

Congress directed the FTC, along with several banking agencies to develop regulations requiring “financial institutions” and “creditors” to develop and implement a written identity theft prevention program. By identifying “red flags” for identity theft in advance, businesses can be better equipped to spot suspicious patterns that may arise -- and take steps to prevent potential problems from escalating into a costly episode of identity theft. Under the Rule, Red Flag Programs must have four parts. First, the Program must include reasonable policies and procedures to identify signs – or “red flags” – of identity theft in the day-to-day operations of the business. Second, the Program must be designed to detect the red flags of identity theft identified by the business. Third, the Program must set out the actions the business will take upon detecting red flags. Finally, because identity theft is an ever-changing threat, a business must re-evaluate its Program periodically to reflect new risks from this crime. The agencies promulgated the Red Flags Rule in 2007. In December 2010, Congress enacted legislation narrowing the definition of “creditors” covered by the Rule. The amended Red Flags Rule now provides that a creditor is covered only if, in the ordinary course of business, it regularly:

  • Obtains or uses consumer reports in connection with a credit transaction;
  • Furnishes information to consumer reporting agencies in connection with a credit transaction; or
  • Advances funds to or on behalf of a person, in certain cases.

The Commission is seeking comment on the Interim Final Rule for 60 days. After the expiration of the 60-day comment period and a review of the comments received, the Interim Final Rule will become final.

Chairman Upton Welcomes New Republicans to House Commerce Committee

House Commerce Committee Chairman Fred Upton (R-MI) welcomed five incoming Republican members to the committee, including the return of former committee member Rep. Ralph Hall (R-TX).

The new Republican members are:

  1. Rep. Gus Bilirakis (R-FL)
  2. Rep. Renee Ellmers (R-NC)
  3. Rep. Ralph Hall (R-TX)
  4. Rep. Bill Johnson (R-OH)
  5. Rep. Billy Long (R-MO)