{"id":2673,"date":"2015-03-20T02:40:51","date_gmt":"2015-03-20T02:40:51","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=2673"},"modified":"2019-03-08T19:52:23","modified_gmt":"2019-03-09T00:52:23","slug":"kill-the-dinosaurs-and-other-tips-for-achieving-technical-competence-in-your-law-practice","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2015\/03\/20\/kill-the-dinosaurs-and-other-tips-for-achieving-technical-competence-in-your-law-practice\/","title":{"rendered":"Kill the Dinosaurs, and Other Tips for Achieving Technical Competence in Your Law Practice"},"content":{"rendered":"<p><a href=\"http:\/\/jolt.richmond.edu\/v21i3\/article7.pdf\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-128\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/>DownloadPDF<\/a><\/p>\n<p style=\"text-align: center\">Cite as: Antigone Peyton, Kill the Dinosaurs, and Other Tips for Achieving Technical Competence in Your Law Practice, 21 Rich. J.L. &amp; Tech. 7 (2015), http:\/\/jolt.richmond.edu\/v21i3\/article7.pdf.<\/p>\n<p style=\"text-align: center\">by Antigone Peyton*<\/p>\n<p style=\"padding-left: 30px\"><strong>I.\u00a0 Introduction<\/strong><\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 It is a challenge to practice law in the digital age.\u00a0 This is particularly true when a practice involves significant e-Discovery, Intellectual Property, and technology law\u2014areas in which technical issues merge with legal ones.\u00a0 One of the major challenges of bringing a law practice up to twenty-first-century standards relates to dinosaur thoughts, a.k.a. an \u201cold ways are best\u201d mentality.<\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Recent spectacular corporate data losses and publicized hacks highlight the frequency and scale of cybersecurity issues.[1]\u00a0 At least one leaked global surveillance effort focused on electronic information involving U.S. law firms,[2] and hackers\u2019 focus on high-value information repositories, like law firms, has increased.[3] \u00a0These realities have sensitized clients to the importance of data protection protocols and secure infrastructure.[4]\u00a0 In the era of Edward Snowden,[5] WikiLeaks,[6] and global surveillance nets,[7] firms must vigilantly guard against unauthorized third-party access to sensitive client information and privileged communications.\u00a0 All of this highlights the importance of technical competence in the practice of law.<\/p>\n<p style=\"padding-left: 30px\"><strong>II.\u00a0 Dinosaurs Take Risks with Technology<\/strong><\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There are many dinosaur thoughts pervading lawyers\u2019 views regarding the adequacy of their technical knowledge, practices, and systems. \u00a0Dinosaurs say quaint things like:<\/p>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cFax and e-mail are secure ways to communicate with clients.\u201d<\/p>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cIt\u2019s ok to use public WiFi, as long as it\u2019s the airport, hotel, or Starbucks.\u201d<\/p>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cE-Discovery is just like paper discovery, except there\u2019s no boxes or warehouses.\u201d<\/p>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0 \u201cI don\u2019t see a problem with using my firm-issued smart phone to download my favorite free game app and post comments and pictures on social media.\u201d<\/p>\n<p>Dinosaur thoughts can cause trouble if Information Technology (IT) personnel or other colleagues at the firm do not temper them and educate their colleagues regarding the risks.<\/p>\n<p style=\"padding-left: 60px\"><strong>A.\u00a0 The Old World Is a Dangerous Place to Live<\/strong><\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 About a decade ago, the groundbreaking Zubulake series of opinions were issued. [8]\u00a0 These cases laid the groundwork for the concept that technical competence is a necessary component of effective legal representation and our ethical obligation to clients.[9]\u00a0 Dinosaur thoughts were not welcome in Judge Scheindlin\u2019s courtroom then, nor are they today.\u00a0 Now more judges are talking about the importance of technical competence, particularly when dealing with e-Discovery issues and noncompliance with increasingly complex electronic filing rules and procedures.[10]\u00a0 As the district court vented in Allstate Ins. Co. v. Linea Latina de Accidentes, Inc.,<\/p>\n<p style=\"padding-left: 30px\">\u00a0Every federal district now has embraced electronic filing.\u00a0 The days of attorneys being able to ignore the computer and shift blame to support staff in the event of an error are gone.\u00a0 The consequences are simply too serious.\u00a0 To the extent there are attorneys practicing in federal court who are under the impression that someone in the Clerk\u2019s office will comb their filings for errors and call them with a heads-up, the Court delivers this message: It is the responsibility of counsel to ensure that personal identifiers are properly redacted.[11]<\/p>\n<p>The above-mentioned district court sanctioned a lawyer who filed a Complaint with attachments containing personal identifiers in unredacted form.[12]\u00a0 He then refiled the documents when the defendants raised a concern regarding the information that had not been redacted.[13]<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 The second filing was not much better, as it contained removable redactions that could be deleted and expose the underlying information.[14]\u00a0 Counsel did not understand how to properly apply redactions to a PDF image.[15]<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In delivering its sanction decision, the court concluded that attorneys \u201cwho are slow to change run the very real risk of sanctions,\u201d and there was no excuse for not complying with the Federal Rule\u2019s requirement of redacting personal information from public electronic filings.[16]<\/p>\n<p style=\"padding-left: 60px\"><strong>B.\u00a0 Rise of the Technology Lawyers<\/strong><\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Lawyers need some technical competence if they are practicing law today, though the skills and knowledge needed vary widely depending on their practice areas and client needs.\u00a0 In fact, in August 2012 the American Bar Association (ABA) approved a resolution that changed the ABA Model Rules of Professional Conduct (Model Rules) and included technical competency requirements.[17]\u00a0 This change requires lawyers to keep pace with \u201crelevant technology\u201d to comply with their ethical obligation to competently represent clients.[18]<\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Model Rule 1.1 addresses the \u201cclient-lawyer\u201d relationship and provides that a lawyer owes clients a duty of competence.[19]\u00a0 This Rule explains: \u201c[a] lawyer shall provide competent representation to a client.\u00a0 Competent representation requires the legal knowledge, skill, thoroughness and preparation reasonably necessary for the representation.\u201d[20]\u00a0 While the Rule remains the same, Comment 8 now explains that lawyers should become educated regarding the benefits and risks associated with technology relevant to their practice.[21]\u00a0 This amendment to Comment 8 illustrates the ABA\u2019s desire to highlight the important role that technology plays in the practice of law today.[22]<\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 This seemingly minor change to an advisory comment is significant because the Model Rules serve as a guide for the ethical rules governing lawyers in most states, including Virginia.[23]\u00a0 The Model Rules now formally require lawyers in those jurisdictions following them to understand technology, including technology that relates to fulfilling e-Discovery obligations and protection of client confidences.\u00a0 Failure to comply with these ethics rules can lead to temporary or permanent disbarment or suspension of their license to practice law.[24]<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 Rules aside, in-house counsel should understand the level of technical proficiency required for their internal team and outside counsel to competently represent the company\u2019s interests, and they should hire accordingly.\u00a0 Outside counsel must receive education regarding the technologies that support the practice, clients\u2019 businesses, and best practices that minimize risks and maximize benefits associated with its use.\u00a0 Additionally, technical competence is important to satisfy counsel\u2019s obligations to the Court, the clients, and the opposing parties in a litigation or regulatory investigation.<\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 In short, lawyers are practicing law in a brave new world, and technology plays a starring role.\u00a0 Whether it is a predictive coding technology, cell phone tracking technology, or a firm\u2019s or company\u2019s communication software and systems\u2014lawyers must roll up their sleeves and learn how to use it.<\/p>\n<p style=\"padding-left: 30px\"><strong>III.\u00a0 Running the Shop<\/strong><\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 Regardless of size, law firms are becoming more reliant on technology to manage their day-to-day activities, interact with clients, and find critical information among massive data repositories and across the Internet.\u00a0 Many cases filed in federal courts are subject to electronic document filing requirements, and state courts are following this trend.[25]\u00a0 With this increased use of technology, a number of risks arise that can harm a firm\u2019s reputation or result in loss of clients\u2019 data and legal liability.\u00a0 This paper discusses some common risks that firms should be aware of as well as ways in which they can minimize them.<\/p>\n<p style=\"padding-left: 60px\"><strong>A.\u00a0 The Nature of the Risk<\/strong><\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 Law firms tend to foster a target-rich environment for data theft.[26]\u00a0 One important risk that law firms must anticipate\u2014and prepare a rapid response plan for\u2014involves security breaches.\u00a0 There are three major categories of reported data loss breaches involving lawyers and law firms: disposal of client records, mobile device theft or loss, and misuse of firm systems and security protocols.[27]\u00a0 Other losses can occur because of lax policies, inadequate training, or the inattention of system users.[28]<\/p>\n<p style=\"padding-left: 60px\"><strong>B.\u00a0 Data Security Technologies in the Modern Firm<\/strong><\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 Law firms often hold a high concentration of clients\u2019 most sensitive information in their files.\u00a0 State-sponsored hackers have been blamed for several high-profile law firm data breaches motivated by an interest in merger and acquisition information, intellectual property assets, and other sensitive strategic or competitive information.[29] This information may be easily obtainable because of the simple Account-Matter structure that law firms use to keep their client files organized.\u00a0 However, client systems may be difficult to understand, and it is often harder for outsiders to identify the subset of information they seek.\u00a0 Lawyers who have pulled a complicated client database or shared team folder can likely commiserate.<\/p>\n<p style=\"padding-left: 90px\"><strong>1.\u00a0 Password Management &amp; Security<\/strong><\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Technology systems often require strong passwords and multi-step authentication processes upon sign-in and sign out or lock access after a period of inactivity or attempted access from a suspicious IP address.[30]\u00a0 These layers of protection are built into technology for a reason, but they can be easily circumvented by poor password management and careless security policies.<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 Passwords should be between sixteen and twenty-four or more characters, depending upon the field limits of the software.\u00a0 Ideal passwords include special characters, uppercase and lowercase letters, and numbers.\u00a0 Firm employees should be required to change their passwords regularly and should not use the same password for all systems.\u00a0 Particularly for financial institution access and client data systems, the password used should be complex and unique to that system.\u00a0 Never keep a temporary or default password provided when receiving access to software or new hardware such as computers and routers.\u00a0 Some defaults are as simple as username: \u201cadmin\u201d and password: \u201c1234.\u201d<\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0 Many people feel overwhelmed by the number of passwords they must track for personal use or firm systems.\u00a0 Using password management software to store passwords in one place and ensure that newly generated passwords meet certain requirements is an excellent first line of defense.<\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 Web browsers\u2019 (Chrome, Safari, Firefox, or Internet Explorer) built-in password storage systems have known security issues,[31] and they should be avoided.\u00a0 Cloud-based systems such as 1Password, KeePass, Roboform Everywhere, and LastPass are more robust than browser management systems and are designed to securely store passwords for websites, mobile apps, notes, credit card information, and other sensitive information.\u00a0 Many of these management systems can be accessed across platforms, meaning they work on computers, smartphones, and tablet devices equally well.[32]\u00a0 Several offer the ability to generate random secure passwords, audit your existing passwords, and analyze them to identify those that may have been compromised by major security breaches like the Heartbleed Security Bug of 2014.[33] \u00a0All password management systems have potential vulnerabilities,[34] but they are better than a note stuck on your computer.<\/p>\n<p style=\"padding-left: 90px\"><strong>2.\u00a0 Data &amp; Traffic Encryption<\/strong><\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 Firms should also be using encryption technology to share information between an individual computer, mobile device, or web browser and the system or database where the information resides or a communication is sent.\u00a0 This is true regardless of whether the information is transferred over the Internet, via cellular and satellite communication channels, or using landlines.<\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 You might use a Virtual Private Network (VPN) to securely connect the computer networks for two geographically distant offices or connect to your office\u2019s systems while traveling.\u00a0 Some firms use VPN technologies to encrypt all of their Internet traffic, whether they are in or outside the office, to add another layer of security while the information is in transit.[35]\u00a0 Other variants on the VPN connection take advantage of the functionality, security, and other benefits obtained from data protection and management protocols.[36]\u00a0 The right protocol for a firm will depend on the firm\u2019s other security measures and infrastructure and what types of communications will be covered.<\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 Like data on the move, sensitive data at rest should also be encrypted.\u00a0 Media coverage of data breaches involving lost laptops that resulted in the potential exposure of very sensitive client or employee information remind us that the loss of one device connected to the firm network can be catastrophic.\u00a0 Firm laptops and mobile devices should be protected with whole disk encryption or biometric access options and automated device wipe functions if someone tries to access the device without authorization.<\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 Certain document and data management systems and encryption technologies like FileVault, LUKS, or BitLocker give firms the option to encrypt sensitive information (like client data) where it is stored on a Mac, Linux, or Microsoft system, respectively.[37]\u00a0 This means that even if someone else\u2014such as a disgruntled former employee or a hacker\u2014accessed the encrypted data, they would be unable to read it without the decryption key.<\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 While it may seem obvious, the encryption key should not reside on the same system or in a location where it may be accessible to a third party, such as an employee of the cloud-computing provider hosting the document management system.\u00a0 Public cloud document providers such as Google Drive, Box.net, and Dropbox, which are popular client file storage solutions used by some small and mid-sized law firms, have been criticized for violating this simple data-protection rule.[38]<\/p>\n<p style=\"padding-left: 90px\"><strong>3.\u00a0 Security Vulnerabilities<\/strong><\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 At a recent Black Hat security conference in Nevada, several researchers disclosed that USB drives can be corrupted with undetectable malware that infects the device and any computer it is connected to.[39]\u00a0 The researchers disclosed this vulnerability to the USB manufacturers months before the code for those attacks was published in an attempt to spur changes in the manufacturing process and fix these vulnerabilities.[40]<\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0 If a firm does allow USB drives, the firm IT staff might monitor and log activity involving the USB ports of firm equipment.\u00a0 USB ports are a common vulnerability point for employees or unauthorized third parties to access firm systems and inject viruses or download information that should not leave the firm systems on a separate hard drive.[41]\u00a0 Without logging, it is hard to prove what and how much information was copied\u2014or who did it.[42]<\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 Successful firms use a combination of human and software technical support to protect firm systems, equipment, and network against spam, viruses, and malware.\u00a0 If a firm allows client access to its wireless network, it may want to rethink that strategy.\u00a0 Once one piece of equipment is infected, it can infect every piece of equipment on the network.[43]\u00a0 In contrast, if every lawyer\u2019s device is \u201cauthorized\u201d to access the firm network and the clients are relegated to a separate secured client wireless network, this provides an added layer of protection for the firm\u2019s systems and equipment.[44]\u00a0 As previously mentioned, it is a good idea to use encryption for all communications shuttled through the firm\u2019s network.\u00a0 A competent IT provider should be advising the firm to use security protocols that are adequate in light of the importance and sensitivity of the information that is shared on that network.[45]<\/p>\n<p style=\"padding-left: 90px\"><strong>4.\u00a0 Log History &amp; Restricted Access<\/strong><\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 Vulnerability issues arise with unsecured File Transfer Protocol (FTP) sites that use the \u201chonor access system,\u201d systems on which any user can issue new user credentials.[46]\u00a0 The honor system sounds nice, but if a former employee creates new credentials for themselves and accesses information they placed on the site after leaving the company, it is hard to un-ring that bell or determine what information they took.\u00a0 Often FTP server log files are only kept for a specific (short) period of time.[47]\u00a0 If the theft is discovered after the log file is destroyed, the primary evidence of theft may be gone forever.<\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0 This illustrates just one area where there is a genuine need for certain technology within the firm to be inaccessible to certain employees who neither need nor merit access to the information contained within it.\u00a0 This also demonstrates the importance of an IT manager\u2019s oversight of access history and file changes.\u00a0 In a utopian world, lawyers would all trust their peers to make good decisions 100% of the time, but in the real world they have a duty to verify reasonably diligent behavior when it comes to client confidences.<\/p>\n<p style=\"padding-left: 90px\"><strong>5.\u00a0 Due Diligence &amp; Electronic Housekeeping<\/strong><\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0 With any data system accessible over the Internet, good physical and electronic security measures are crucial.\u00a0 Firms must do their research before implementing any firm data storage system on site or in the cloud.\u00a0 Here are some basic questions they might ask during the due diligence process:<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 What is the geographic location of the data center, and what protections have been implemented at that site?<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 Is someone in charge of applying patches and upgrades, particularly updates that address known security vulnerabilities and stability issues?<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 What happens if the primary system goes down; is there a live, redundant backup that is geographically distant from the primary data site?<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 Is there an offline backup, and how often is that backup created?<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 What is the security policy and compliance protocol for the backup solution?<\/p>\n<p>\u2022\u00a0\u00a0\u00a0\u00a0 Does the provider have direct access to the data, or is it pre-encrypted before being uploaded to the provider?<\/p>\n<p>These are just a few of the questions a firm should cover when considering where and with whom they will store their firm and client data.\u00a0 Should a data breach involving firm or client information occur, the firm\u2019s diligence in choosing the data storage provider and implementing sound system policies and protections may become a central issue in triggering insurance coverage, weathering legal ramifications of the breach, and managing client communications after any notifications occur.[48]<\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0 It is a bad idea to share passwords and login information.\u00a0 Often, it is considered a violation of the Terms of Service or Service Level Agreement when a lawyer or other firm employee signs or clicks through a site under another user\u2019s access credentials when purchasing a particular software product or a user license to a product.[49]<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0 In certain circumstances, such a situation can violate the Computer Fraud and Abuse Act (CFAA)\u00bea quasi-criminal statute aimed at unauthorized access to proprietary and confidential information on computer systems\u2014or the Stored Communications Act (SCA)\u00bewhich protects against unauthorized interception of electronic information if access to the stored communication was \u201cwithout authorization\u201d[50] or \u201cexceeds authorized access.\u201d[51]<\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0 Both statutes provide for civil liability in particular circumstances.[52]\u00a0 If an assistant or another employee who has access to other employees\u2019 account passwords leaves on bad terms, it will be hard to isolate and deal with their unauthorized access to the system using another person\u2019s credentials.\u00a0 And it is difficult to justify the decision to share passwords to the firm\u2019s IT personnel when they have to shut down a lawyer\u2019s user accounts and issue new ones, with new credentials.\u00a0 Just don not do it.<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0 Additionally, sometimes law firms are required (or decide) to delete client data, a litigation opponent\u2019s information, or firm electronic records.\u00a0 When deleting confidential records, consider servers and their backup systems, computers and mobile devices, external drives including USB drives, disks such as CD-ROMs and other non-reusable physical media.<\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0 At a minimum, delete the electronic files and then empty the trash bin.\u00a0 Optimally, use a secure deletion method like a file shredder program that performs a permanent delete and overwrites the disk several times.[53]\u00a0 Physical media should be securely destroyed.[54]\u00a0 Firms should only keep encrypted copies of the minimum data necessary to comply with a data retention policy, legal, or business requirement.<\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0 Many firms are notorious data hoarders and seem to hold old records without any legitimate business justification\u2014such firms have a \u201csub-standard\u201d information governance and recordkeeping model.[55]\u00a0 Legitimate business justifications for retaining electronic information do not include \u201cI may need that information someday\u2014you never know.\u201d<\/p>\n<p style=\"padding-left: 90px\"><strong>6.\u00a0 Cloud Computing<\/strong><\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0 Many papers, blog posts, and books have been written about the benefits and risks of using cloud-computing technologies.[56]\u00a0 This paper will not focus on the benefits and risk analysis that should occur when contemplating adding cloud technologies to the firm\u2019s system.<\/p>\n<p>[37]\u00a0\u00a0\u00a0\u00a0 However, if a firm is considering a cloud computing solution, which means it will be using computing resources that are delivered over the Internet via a web browser or other interface, it needs to carefully read the documents that cover the contracts that provide the terms of the engagement with the cloud provider.[57]\u00a0 Some standard contracts state that the cloud provider owns the data, lack an assurance that the system will be live, or lack tools to export data once it is in the cloud system.[58]<\/p>\n<p>[38]\u00a0\u00a0\u00a0\u00a0 Analyze whether it is reasonable to place certain data in a cloud provider\u2019s hands if they refuse to meet the firm\u2019s needs and expectations.\u00a0 Also, check the firm\u2019s state bar website for current ethics opinions on this subject before moving to the cloud.\u00a0 At least nineteen states have issued ethics opinions that directly or indirectly address this subject.[59]\u00a0 All of those states have indicated that cloud computing or other similar technologies can be used in the practice of law but that reasonable care should be exercised to determine whether a particular provider is appropriate in a particular situation.[60]<\/p>\n<p>[39]\u00a0\u00a0\u00a0\u00a0 In considering options among cloud computing providers, a firm\u2019s investigation should delve into the question of whether the files are hidden from the cloud provider\u2019s employees.\u00a0 It would be a huge security risk if any employee who had access to the firm\u2019s accounts could view clients\u2019 files.<\/p>\n<p>[40]\u00a0\u00a0\u00a0\u00a0 A more subtle risk involves firm employees use of their personal cloud accounts to shuttle files between the office and home.\u00a0 Ultimately, this opportunity can be used for nefarious purposes, as was the case when one employee of a popular social gaming company allegedly stole confidential trade secrets using his personal Dropbox account before resigning from the company.[61]<\/p>\n<p style=\"padding-left: 90px\"><strong>7.\u00a0 Mobile Devices<\/strong><\/p>\n<p>[41]\u00a0\u00a0\u00a0\u00a0 Many lawyers have a mobile phone attached to their hand and a tablet in their bag whenever they travel.\u00a0 Firm employees should use a PIN or password on their mobile device and IT managers should enable remote wiping and tracking technologies in case a device is lost or stolen.<\/p>\n<p>[42]\u00a0\u00a0\u00a0\u00a0 Additionally, most smartphones and tablets write a surprising amount of data to the device hard drive.[62] \u00a0For instance, if a lawyer opens a client document attached to an e-mail on their phone, the device usually stores that information on the hard drive.\u00a0 Unlike traditional desktop systems, it is very hard to delete these types of files from the mobile device hard drive.[63]\u00a0 Sometimes, the entire device has to be wiped in order to delete sensitive files that can be casually accessed on them.[64]<\/p>\n<p>[43]\u00a0\u00a0\u00a0\u00a0 Now, I like mobile app games as much as the next person, but beware of apps that collect and share other data available on the device.\u00a0 Many mobile apps and mobile system software track a user\u2019s location, web browsing history, purchases, and a host of other information that you may not want to share.[65]\u00a0 After a number of high profile blow-ups, some privacy controls have been implemented on mobile platforms.[66]\u00a0 Users need to learn how to access these privacy controls through their system settings and review the terms for any app they download on a device.<\/p>\n<p>[44]\u00a0\u00a0\u00a0\u00a0 Some free apps give users access to games or information, then collect lots of data from their device.[67]\u00a0 Other apps deliver targeted ads based upon information that connects a person and past activities on that device.[68]\u00a0 These seemingly harmless mobile apps represent security breach risks to the firm.\u00a0 For example, researchers recently revealed that most of the top flashlight apps available on the Android platform are actually spyware.[69] \u00a0It can be creepy once one digs into the data being collected and the surveillance that occurs with or without their knowledge.<\/p>\n<p>[45]\u00a0\u00a0\u00a0\u00a0 Here is another situation that illustrates the problems associated with unmanaged data collection by mobile apps.\u00a0 Imagine a firm lawyer takes a picture with their phone and posts it on Facebook.\u00a0 This may reveal their location at the time the picture was taken or when they accessed the Facebook app to post the picture.\u00a0 What if opposing counsel learned that lawyer is in New York the night before a big hearing because their social media post included their current location?\u00a0 The fact that the lawyer will be arguing an important motion the next day may be something they did not want to share with opposing counsel ahead of time.<\/p>\n<p style=\"padding-left: 90px\"><strong>8.\u00a0 Social Media<\/strong><\/p>\n<p>[46]\u00a0\u00a0\u00a0\u00a0 There are many potential pitfalls associated with the use of social media or social media management apps on firm devices.\u00a0 Be wary of social media applications and platforms, as they are frequently invaded by cybercriminals and hacktivists.[70]\u00a0 Giving another application access to your credentials for one site or account could result in other linked accounts being hijacked.<\/p>\n<p>[47]\u00a0\u00a0\u00a0\u00a0 Facebook is a well-known example of a social media site that has seen its share of hacks and complaints about unauthorized sharing of private data with other sites and companies.[71]\u00a0 Even though Facebook now sends all hyperlinks through Websense first (a vast improvement), be wary of clicking on them.[72]\u00a0 The firm should have a social media policy and a plan for responding if client confidences or other sensitive information leave the firm through a social media outlet, and it should train everyone in the firm to be responsible ambassadors of the firm brand and client information when using social media.<\/p>\n<p style=\"padding-left: 90px\"><strong>9.\u00a0 Travel Troubles<\/strong><\/p>\n<p>[48]\u00a0\u00a0\u00a0\u00a0 Attorneys often travel for depositions or client meetings, and they can be most vulnerable to data breaches when on the road.\u00a0 Aside from remembering to encrypt traffic across open Internet connections, exercising good sense in not accessing client information in a manner that can be readily viewed or recorded by others would be wise.\u00a0 With the advent of smartphone cameras and the ready availability of lapel cameras, a traveling lawyer would be wise to wait for the privacy of their hotel room to open and work on documents containing privileged information or work product.<\/p>\n<p>[49]\u00a0\u00a0\u00a0\u00a0 It is easy to look over someone\u2019s shoulder at the airport, on the plane, or in the hotel lobby.\u00a0 And it can be particularly dangerous to rely on public WiFi or hotspots when traveling\u2014they are often unencrypted and an excellent target for eavesdroppers who want to capture data packets and login credentials for any sites others access while on that WiFi network.[73]\u00a0 For instance, the recent \u201cDarkhotel\u201d espionage campaign effectively targeted traveling business executives using hotel WiFi.[74]<\/p>\n<p>[50]\u00a0\u00a0\u00a0\u00a0 Another key point to remember when traveling is that many cellular providers give users the ability to turn their smartphone into a hotspot, but this does not protect their Internet traffic in any way.\u00a0 Using an unsecured mobile device as a WiFi hotspot for accessing the Internet on a laptop is a security concern.\u00a0 Anyone within range can eavesdrop on the data a traveling lawyer sends or receives from the Internet and the mobile device.[75] \u00a0Some of the larger WiFi hotspot networks are secured (not open) and use enterprise-level security to protect a wireless connection on that network from eavesdroppers.[76]\u00a0 These networks are a safer option.<\/p>\n<p>[51]\u00a0\u00a0\u00a0\u00a0 Additionally, in the U.S., many large cellular providers encrypt the data traffic traveling to and from cell towers and the cellular device.\u00a0 This connection may be slower than a traditional WiFi connection, but the security benefits are significant.\u00a0 Finally, a VPN connection can be used on both WiFi and cell data connections.\u00a0 Under these circumstances, all of the user\u2019s Internet traffic and passwords travel through an encrypted tunnel, and already encrypted traffic enjoys double encryption.<\/p>\n<p style=\"padding-left: 90px\"><strong>10.\u00a0 Insurance and Audits<\/strong><\/p>\n<p>[52]\u00a0\u00a0\u00a0\u00a0 Law firms have heightened responsibility for maintaining the confidentiality of client information because of their professional ethical requirements.\u00a0 What should law firms be doing to better protect their data and deal with discovered breaches after they occur?<\/p>\n<p>[53]\u00a0\u00a0\u00a0\u00a0 The firm should consider whether it needs cyber insurance to protect against the possible consequences of a breach.\u00a0 Most general liability or professional liability insurance policies (and even umbrella business insurance policies) do not cover the cost of investigating a data breach, taking remedial steps to fix the problem, or notifying those who may be affected by it.\u00a0 Cyber insurance policies are becoming more prevalent in many industries.<\/p>\n<p>[54]\u00a0\u00a0\u00a0\u00a0 Additionally, the firm might hire someone to test the systems and determine technical and human areas of vulnerability.\u00a0 Security audits may highlight practices or systems that should be changed in order to reduce these risks before a breach occurs.<\/p>\n<p style=\"padding-left: 90px\"><strong>11.\u00a0 Hardware Vulnerabilities<\/strong><\/p>\n<p>[55]\u00a0\u00a0\u00a0\u00a0 As computer equipment ages and is replaced, it is vital to wipe all hard drives according to industry standards before either disposing of, or donating, those computers.\u00a0 The Department of Defense DoD 5220.22-M (ECE) recommends seven complete wipes,[77] and there are a number of free or low cost products that can be used to wipe computers and external hard drives.<\/p>\n<p>[56]\u00a0\u00a0\u00a0\u00a0 Every typical law office has a multi-function copier\/scanner that is networked, and these devices always contain a hard drive with a copy of every page that has been either scanned or copied.\u00a0 These represent a huge security risk for several reasons.\u00a0 First, they are risky from a data perspective because of the massive number of stored documents sitting on an unencrypted hard drive in the machine.[78]\u00a0 Second, their networked permissions often provide access to computers, but the copier\/scanner itself has low security measures required to gain access.\u00a0 People think nothing of leaving their copier code on a sticky note next to their computer\u2014after all, what harm could that pose?\u00a0 This means anyone who can gain access to the office can access the network through this simple \u201cbackdoor\u201d methodology.<\/p>\n<p style=\"padding-left: 30px\"><strong>III.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 What it Takes to Practice Law in the 21st Century<\/strong><\/p>\n<p>[57]\u00a0\u00a0\u00a0\u00a0 Law firms are becoming more reliant on technology to manage their day-to-day activities, interact with clients, and work on the substantive aspects of their job.\u00a0 Now that we have identified dinosaur thoughts relating to technology, how do we extinguish them in the practice of law?\u00a0 Well, initially, lawyers must purposefully focus on education initiatives involving relevant technology.\u00a0 Extinguishing dinosaur thoughts also involves raising the bar and hiring good people who understand and embrace technology, then making them an integral part of the team.\u00a0 Ultimately, law firms must become better stewards of their clients\u2019 sensitive information and have protocols for holding or accessing it.<\/p>\n<p>[58]\u00a0\u00a0\u00a0\u00a0 Security breaches do not occur at one single point of failure, but at several points.\u00a0 Thus, a firm should verify that its IT provider is undertaking reasonable efforts to protect firm systems and equipment and ensure that firm employees are educated on those systems.\u00a0 Finally, firms need to understand and take advantage of the security measures that are already built into the systems.<\/p>\n<p>[59]\u00a0\u00a0\u00a0\u00a0 Diverse teams with different and complementary technical skills help law firms keep up with technology and continually evolve their practice.\u00a0 As technology continues to take a starring role in firm infrastructure, processes, and communication channels (and clients\u2019 businesses), lawyers must adapt and keep up with those changes\u2014or go the way of the dinosaurs.<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<p>* Antigone Peyton is the founder and CEO of Cloudigy Law PLLC, an Intellectual Property and technology law firm located in McLean, Virginia. Antigone is an unabashed technophile focused on IP litigation and cutting-edge legal issues involving patents, trademarks, copyrights, and trade secrets.\u00a0 A longstanding member of The Sedona Conference Working Group 1 (electronic document retention and production), Antigone is a frequent speaker and lecturer on law and technology issues involving IP, social media, cloud computing, big data, and eDiscovery and a technology panelist for EmeraldPlanetTV.<br \/>\n[1] See, e.g., Reuters, Aramco Says Cyberattack Was Aimed at Production, N.Y. Times, Dec. 10, 2012, at B2, available at http:\/\/www.nytimes.com\/2012\/12\/10\/business\/global\/saudi-aramco-says-hackers-took-aim-at-its-production.html, archived at http:\/\/perma.cc\/39WX-7L76 (noting that \u201cCutting Sword of Justice\u201d were credited for a hack wiping data from about 30,000 computers at Saudi Arabia\u2019s national oil company, and that hackers are getting more creative, sometimes using devices that seem like everyday objects that belong in the workplace\u2014like a cell phone charger); Greg Kumparak This Fake Phone Charger Is Actually Recording Every Key You Type, TechCrunch (Jan. 14, 2015), http:\/\/techcrunch.com\/2015\/01\/14\/this-fake-phone-charger-is-actually-recording-every-key-you-type\/, archived at http:\/\/perma.cc\/P4TC-M846 (crediting a fake phone charger that logs the information you type on a wireless keyboard to Samy Kamkar); Kim Zetter, Logic Bomb Set Off South Korea Cyberattack, Wired (Mar. 21, 2013, 7:05 PM), http:\/\/www.wired.com\/2013\/03\/logic-bomb-south-korea-attack\/, archived at http:\/\/perma.cc\/3RL8-CA8Q (noting that several banks and broadcasting companies were attacked by a logic bomb that wiped computer hard drives and master boot records that interrupted ATM operations in South Korea); Kim Zetter, Sony Got Hacked Hard: What We Know and Don\u2019t Know So Far, Wired (Dec. 3, 2014, 4:02 PM), http:\/\/www.wired.com\/2014\/12\/sony-hack-what-we-know\/, archived at http:\/\/perma.cc\/VL6R-TJ2V (discussing that hacktivists \u201cGuardians of Peace\u201d stole up to 100 terabytes of data from Sony, including login credentials and documents with personal employee information).<\/p>\n<p>[2] See, e.g., James Risen &amp; Laura Poitras, Spying by N.S.A. Ally Entangled U.S. Law Firm, N.Y. Times, Feb. 16, 2014, at A1, available at http:\/\/www.nytimes.com\/2014\/02\/16\/us\/eavesdropping-ensnared-american-law-firm.html, archived at http:\/\/perma.cc\/AD5Y-G3FT.<\/p>\n<p>[3] See, e.g., Jennifer Smith, Client Secrets at Risk as Hackers Target Law Firms, Wall St. J. (June. 25, 2012, 2:21 PM), http:\/\/blogs.wsj.com\/law\/2012\/06\/25\/dont-click-on-that-link-client-secrets-at-risk-as-hackers-target-law-firms\/, archived at http:\/\/perma.cc\/B696-8ZBB.<\/p>\n<p>[4] See Matthew Goldstein, Law Firms Are Pressed on Security for Data, N.Y. Times, Mar. 27, 2014, at B1, available at http:\/\/dealbook.nytimes.com\/2014\/03\/26\/law-firms-scrutinized-as-hacking-increases\/, archived at http:\/\/perma.cc\/6Z34-3BGL.<\/p>\n<p>[5] See, e.g., Glenn Greenwald, Ewen MacAskill &amp; Laura Poitras, Edward Snowden: The Whistleblower behind the NSA Surveillance Revelations, Guardian (June 11, 2013, 9:00 AM), http:\/\/www.theguardian.com\/world\/2013\/jun\/09\/edward-snowden-nsa-whistleblower-surveillance, archived at http:\/\/perma.cc\/D9PZ-KYCH.<\/p>\n<p>[6] See, e.g., Scott Shane &amp; Andrew W. Lehren, Leaked Cables Offer Raw Look at U.S. Diplomacy, N.Y. Times, Nov. 29, 2010, at A1, available at http:\/\/www.nytimes.com\/2010\/11\/29\/world\/29cables.html, archived at http:\/\/perma.cc\/H9AU-D3GF.<\/p>\n<p>[7] See, e.g., David Ljunggren &amp; Mike De Souza, Snowden Files Show Canada Spy Agency Runs Global Internet Watch: CBC, Reuters, (Jan. 28, 2015), http:\/\/www.reuters.com\/article\/2015\/01\/28\/us-canada-spying-idUSKBN0L11W520150128, archived at http:\/\/perma.cc\/HK3N-GDBF.<\/p>\n<p>[8] See Victor Li, Looking Back on Zubulake, 10 Years Later, A.B.A. J. (Sept. 1, 2014, 10:30 A.M.), http:\/\/www.abajournal.com\/magazine\/article\/looking_back_on_zubulake_10_years_later, archived at http:\/\/perma.cc\/965H-GF38 (discussing the Zubulake opinions and their impact on the body of case law relating to e-Discovery and a lawyer\u2019s obligations including a minimal level of technical competence).<\/p>\n<p>[9] See id.<\/p>\n<p>[10] See, e.g., Baella-Silva v. Hulsey, 454 F.3d 5, 11\u201312 (1st Cir. 2006) (affirming a $50,000 sanction against a party for electronically filing a confidential settlement document and failing to take the proper precautions to preserve confidentiality in an electronically filed document that could lead to sanctions or other liabilities).<\/p>\n<p>[11] Allstate Ins. Co. v. Linea Latina De Accidentes, Inc., No. 09-3681, 2010 U.S. Dist. LEXIS 124773, at *8 (D. Minn. Nov. 24, 2010).<\/p>\n<p>[12] See id. at 3, 10\u201311.<\/p>\n<p>[13] See id. at 4\u20135.<\/p>\n<p>[14] See id. at 6\u20137.<\/p>\n<p>[15] See id. at 5\u20137.<\/p>\n<p>[16] 2010 U.S. Dist. LEXIS 124773, at 8\u20139.<\/p>\n<p>[17] See, e.g., ABA Comm. on Ethics, Res. 105C, 1\u20132 (2012) (report to the House of Delegates), available at http:\/\/www.americanbar.org\/content\/dam\/aba\/administrative\/ethics_2020\/2012_hod_annual_meeting_105c.authcheckdam.pdf; ABA Commission on Ethics 20\/20, archived at http:\/\/perma.cc\/S2XZ-WQS6; ABA, ABA House of Delegates Approves Commission\u2019s Resolutions (Aug. 6, 2012), http:\/\/www.americanbar.org\/groups\/professional_responsibility\/aba_commission_on_ethics_20_20.html, archived at http:\/\/perma.cc\/3QF7-FL4L.<\/p>\n<p>[18] Model Rules of Prof\u2019l Conduct R. 1.1 cmt. 8 (2014).<\/p>\n<p>[19] See id. at R. 1.1.<\/p>\n<p>[20] Id.<\/p>\n<p>[21] See id. at cmt. 8 (\u201cTo maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice,\u00a0including the benefits and risks associated with relevant technology, engage in continuing study and education and comply with all continuing legal education requirements to which the lawyer is subject.\u201d) (emphasis added).<\/p>\n<p>[22] See, e.g., Matt Nelson, New Changes to Model Rules a Wake-Up Call for Technology Challenged Lawyers, InsideCounsel (Mar. 28, 2013), http:\/\/www.insidecounsel.com\/2013\/03\/28\/new-changes-to-model-rules-a-wake-up-call-for-tech, archived at http:\/\/perma.cc\/9U6Q-XT33 (noting the report accompanying the resolution suggests this was always a component of the competence standard for lawyers and that \u201c[t]he proposed amendment, which appears in a Comment, does not impose any new obligations on lawyers.\u00a0 Rather, the amendment is intended to serve as a reminder to lawyers that they should remain aware of technology, including the benefits and risks associated with it, as part of a lawyer\u2019s general ethical duty to remain competent.\u201d).<\/p>\n<p>[23] See, e.g., Chronological List of States Adopting Model Rules, ABA Center for Prof. Resp., http:\/\/www.americanbar.org\/groups\/professional_responsibility\/publications\/model_rules_of_professional_conduct\/chrono_list_state_adopting_model_rules.html, archived at http:\/\/perma.cc\/2AJL-EG7V (last visited Feb. 12, 2015).<\/p>\n<p>[24] See Model Rules of Prof\u2019l Conduct Scope para. 19\u201320 (2014).<\/p>\n<p>[25] See, e.g., Electronic Filing and Case Management, U.S. Dist. Ct. Cent. Dist. Cal., http:\/\/www.cacd.uscourts.gov\/e-filing, archived at http:\/\/perma.cc\/VX2T-JQTH (last visited Feb. 12, 2015) (\u201c[E]lectronic filing is mandatory in all civil and criminal cases in the Central District of California.\u201d); EFiling, Super. Ct. Cal. County Orange, http:\/\/www.occourts.org\/online-services\/efiling\/, archived at http:\/\/perma.cc\/JY6H-2Z2D (last visited Feb. 12, 2015) (\u201cPursuant to section 1010.6 of the Code of Civil Procedure, rule 2.253(b)(2) of the California Rules of Court, Orange County Superior Court Local Rule 352, and Local Rule 601.01 all documents filed by attorneys in probate, limited civil, unlimited civil, and complex civil actions . . . must be filed electronically unless the Court rules otherwise.\u201d).<\/p>\n<p>[26] See, e.g., Lolita C. Baldor, FBI: Hackers Targeting Law and PR Firms, NBC News (Nov. 17, 2009, 10:58 AM), http:\/\/www.nbcnews.com\/id\/33991440\/ns\/technology_and_science-security\/t\/fbi-hackers-targeting-law-pr-firms\/#.VMKMdV6hy7x, archived at http:\/\/perma.cc\/C6LS-2GJ8 (discussing the November 1, 2009 FBI issued advisory warning to law firms that hackers were specifically targeting them); Goldstein, supra note 4 (discussing that in 2011, the FBI began organizing meetings with top law firms in the U.S. to highlight the cybersecurity and corporate espionage risks, particularly for firms with offices in countries like Russia and China and in 2012, security company Mandiant reported that an estimated 80% of the 100 largest American law firms had some malicious computer breach in 2011).<\/p>\n<p>[27] See Matthew H. Meade, Lawyers and Data Security: Understanding a Lawyer\u2019s Ethical and Legal Obligations that Arise from Handling Personal Information Provided by Clients, 28 Computer &amp; Internet Law. 1, 1 (2011).<\/p>\n<p>[28] See id. at 2\u20133.<\/p>\n<p>[29] See, e.g., Michael A. Riley &amp; Sophia Pearson, China-Based Hackers Target Law Firms to Get Secret Deal Data, Bloomberg (Jan. 31, 2012, 4:37 PM), http:\/\/www.bloomberg.com\/news\/2012-01-31\/china-based-hackers-target-law-firms.html, archived at http:\/\/perma.cc\/T6LY-2P4N (noting that China-based hackers targeted several law firms while they were involved in a $40 Billion company takeover deal); see also Breaking the Law: How Legal Firms Get Hacked, ZeroFOX (May 20, 2014) [hereinafter Breaking the Law], http:\/\/www.zerofox.com\/whatthefoxsays\/breaking-law-legal-firms-get-hacked\/#.VMKOR16hy7x, archived at http:\/\/perma.cc\/6CH8-C3QB.<\/p>\n<p>[30] IT Examination Handbook InfoBase: Authentication, FFIEC, http:\/\/ithandbook.ffiec.gov\/it-booklets\/information-security\/security-controls-implementation\/access-control-\/authentication.aspx, archived at http:\/\/perma.cc\/V89D-978R (last visited Feb. 16, 2015).<\/p>\n<p>[31] See Melanie Pinola, Which Password Manager Is the Most Secure?, Lifehacker (Sept. 20, 2012, 10:00 AM), http:\/\/lifehacker.com\/5944969\/which-password-manager-is-the-most-secure, archived at http:\/\/perma.cc\/5FC7-YWYP (noting that Malware or tools like WebBrowserPassView can reveal passwords stored in web browsers because those systems rely on the computer login as the cypher for the encrypted password data stored by the browsers, and that web-based password managers that rely on a master password to gain access to the management system are generally more secure options); see also Jill Scharr, Google Chrome\u2019s Security Flaw: How to Safely Store Passwords, Tom\u2019s Guide (Aug. 8, 2013, 11:54 PM), http:\/\/www.tomsguide.com\/us\/chrome-security-password-saver,review-1840.html, archived at http:\/\/perma.cc\/K24P-UB6W (discussing Google Chrome\u2019s lack of security measures for data storage, easily allowing unwanted access to the user\u2019s password in unencrypted plain text).<\/p>\n<p>[32] Best Password Manager: Dashlane Vs Lastpass Vs 1Password Vs Roboform Vs KeePass, A Secure Life (last updated Mar. 4, 2015), http:\/\/www.asecurelife.com\/dashlane-vs-lastpass-vs-1password-vs-roboform-vs-keepass\/, archived at http:\/\/perma.cc\/A4PB-9ZQ3.<\/p>\n<p>[33] See The Heartbleed Bug, Heartbleed.com, http:\/\/heartbleed.com\/, archived at http:\/\/perma.cc\/8KMU-3NAA (explaining that the Heartbleed Bug allows unwelcome individuals to read the memory of systems protected by versions of the OpenSSL software with design flaws).<\/p>\n<p>[34] See, e.g., Greg Kumparak, LastPass Finds Security Holes in Its Online Password Manager, Doesn\u2019t Think Anyone Exploited Them, TechCrunch (July 11, 2014), http:\/\/techcrunch.com\/2014\/07\/11\/lastpass-finds-security-holes-in-its-online-password-manager-doesnt-think-anyone-exploited-them\/, archived at http:\/\/perma.cc\/P446-KECS (discussing the discovery of two security flaws in LastPass online password manager products).<\/p>\n<p>[35] See, e.g., VPN Technologies: Definitions and Requirements, VPN Consortium (July 2008), http:\/\/www.vpnc.org\/vpn-technologies.html, archived at http:\/\/perma.cc\/724G-UD48.<\/p>\n<p>[36] See id.<\/p>\n<p>[37] See William Ruddy, Moving on After TrueCrypt\u2019s Untimely Departure, Phoenix TS Blog (June 26, 2014), http:\/\/www.phoenixts.com\/blog\/moving-on-after-truecrypt, archived at http:\/\/perma.cc\/FQC2-8DE4.\u00a0 In May of 2014, TrueCrypt developers stopped supporting this open encryption software system after Microsoft terminated its support of WindowsXP.\u00a0 TrueCrypt, http:\/\/truecrypt.sourceforge.net\/, archived at http:\/\/perma.cc\/R7HA-JKGJ (last visited Feb. 12, 2015) (\u201cWARNING: Using TrueCrypt is not secure as it may contain unfixed security issues\u201d).\u00a0 Later versions of the Windows operating systems integrated support for full disk encryption and virtual disk images.\u00a0 Some have theorized the developers made this announcement because the encryption keys had been compromised or a \u201cback door\u201d had been created in response to a confidential demand from a law-enforcement or national security entity.\u00a0 See Dan Goodin, Bombshell TrueCrypt Advisory: Backdoor? Hack? Hoax? None of the Above?, Ars Technica (May 29, 2014, 2:45 PM), http:\/\/arstechnica.com\/security\/2014\/05\/bombshell-truecrypt-advisory-backdoor-hack-hoax-none-of-the-above\/, archived at http:\/\/perma.cc\/JCE2-4AQJ.<\/p>\n<p>[38] See, e.g., Hector Salcedo, Google Drive, Dropbox, Box and iCloud reach the Top 5 Cloud Storage Security Breaches List, Credeon Blog (Nov. 20, 2014, 7:00 AM), http:\/\/psg.hitachi-solutions.com\/credeon\/blog\/google-drive-dropbox-box-and-icloud-reach-the-top-5-cloud-storage-security-breaches-list, archived at http:\/\/perma.cc\/36CD-3FJV.<\/p>\n<p>[39] See Andy Greenberg, The Unpatchable Malware that Infects USBs Is Now on the Loose, Wired (Oct. 2, 2014, 6:30 AM), http:\/\/www.wired.com\/2014\/10\/code-published-for-unfixable-usb-attack, archived at http:\/\/perma.cc\/V345-33WD.<\/p>\n<p>[40] See id. The author\u2019s firm now has a \u201cno thumb drive\u201d policy because the USB attack code is public and the stakes are too high if a firm device becomes infected\u2014the malware cannot be removed even if the USB drive is wiped and reformatted.\u00a0 See id.<\/p>\n<p>[41] See Caroline Baldwin, USB-Connected Devices Present Cyber Vulnerabilities, Computer Wkly. (Aug. 11, 2014, 11:45 AM), http:\/\/www.computerweekly.com\/news\/2240226605\/USB-connected-devices-present-cyber-vulnerabilities, archived at http:\/\/perma.cc\/8JW6-P2T9.<\/p>\n<p>[42] See id.<\/p>\n<p>[43] See Malware (Viruses et al), Info. Tech.\u2013Miller Sch. Med. U. Miami, http:\/\/it.med.miami.edu\/x699.xml, archived at http:\/\/perma.cc\/8HYT-XD6B (last visited Jan. 28, 2015).<\/p>\n<p>[44] See Jeff Beard, Wireless Networking Best Practices: Version 2.0, Law Tech Guru (Aug. 1, 2004), http:\/\/www.lawtechguru.com\/archives\/mobile_tech_gadgets.html, archived at http:\/\/perma.cc\/KJ6Q-5JWD.<\/p>\n<p>[45] Whether using Wired Equivalent Privacy (WEP) 128-bit or WPA encryption, your IT personnel should make sure that all communications are secure.\u00a0 WEP is weaker and can be cracked.\u00a0 See Vangie Beal, The Differences Between WEP and WPA, Webopedia (June 15, 2007), http:\/\/www.webopedia.com\/DidYouKnow\/Computer_Science\/WEP_WPA_wireless_security.asp, archived at http:\/\/perma.cc\/TX4L-6ZTE.\u00a0 The only wireless encryption standards that have not been cracked (yet) are WPA with the AES (Advanced Encryption Standard) or WPA2.\u00a0 See Jason Fitzpatrick, HTG Explains: The Difference Between WEP, WPA, and WPA2 Wireless Encryption (and Why It Matters), How-To Geek (July 16, 2013), http:\/\/www.howtogeek.com\/167783\/htg-explains-the-difference-between-wep-wpa-and-wpa2-wireless-encryption-and-why-it-matters\/, archived at http:\/\/perma.cc\/Y3PP-RX88.<\/p>\n<p>[46] Rick Lehtinen, Deborah Russell &amp; G.T. Gangemi Sr., Computer Security Basics 119 (2d ed. 2006).<\/p>\n<p>[47] See IBM Knowledge Center, File Transfer Protocol (FTP), IBM (last visited Feb. 18, 2015), http:\/\/www-01.ibm.com\/support\/knowledgecenter\/SSB23S_1.1.0.8\/com.ibm.ztpf-ztpfdf.doc_put.08\/gtpc1\/hftp.html?lang=en, archived at http:\/\/perma.cc\/EX7T-SWN9.<\/p>\n<p>[48] See Sherilyn Pastor &amp; Kelly Lloyd, When Your Data Goes Viral: Insurance for Data Breaches, Corporate Counsel (Jan. 29, 2015), http:\/\/www.corpcounsel.com\/id=1202716324082\/When-Your-Data-Goes-Viral-Insurance-for-Data-Breaches?slreturn=20150118121934, archived at \u00a0http:\/\/perma.cc\/HQ4M-JAXZ.<\/p>\n<p>[49] See Doug Gross, Facebook Speaks out against Employers Asking for Passwords, CNN (last updated Mar. 23, 2012), http:\/\/www.cnn.com\/2012\/03\/23\/tech\/social-media\/facebook-employers\/, archived at http:\/\/perma.cc\/9BP2-SJG7.<\/p>\n<p>[50] 18 U.S.C. \u00a7 2701(a)(1) (2012).<\/p>\n<p>[51] 18 U.S.C. \u00a7 1030(a)(1)\u2013(2) (2012); see also Eric Matusewitch, Your Facebook Password or Your Job?, NNRC (July 18, 2014), http:\/\/blog.nnrc.com\/your-facebook-password-or-your-job\/, archived at http:\/\/perma.cc\/8DP3-DEWN.<\/p>\n<p>[52] See 18 U.S.C. \u00a7 2707(a)\u2013(b) (2012) (\u201cany provider of electronic communication service, subscriber, or other person aggrieved\u201d by a knowing or intentional violation may recover damages or an injunction in a civil action as well as reasonable attorneys fees); 18 U.S.C. \u00a7 1030(g) (2012) (\u2018\u2018Any person who suffers damage or loss by reason of a violation of this section may maintain a civil action against the violator to obtain compensatory damages and injunctive relief or other equitable relief.\u201d).<\/p>\n<p>[53] See Richard Kissel et al., Nat\u2019l Inst. of Standards &amp; Tech., U.S. Dep\u2019t of Commerce, NIST Special Publication 800-88: Guidelines for Media Sanitization 27\u201328 (rev. 1 Dec. 2014), available at http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-88r1.pdf, archived at http:\/\/perma.cc\/9MP7-UQVN (relating to secure reuse of hardware after data deletion and disposal of electronic information).\u00a0 The National Institute of Standards and Technology (NIST) is responsible for developing information security standards and guidelines, including minimum standards for Federal information systems.\u00a0 Id. at ii.<\/p>\n<p>[54] See id. at 36\u201337.<\/p>\n<p>[55] See ARMA Int\u2019l, Generally Accepted Recordkeeping Principles: Information Governance Maturity Model (2013), available at http:\/\/www.arma.org\/docs\/bookstore\/theprinciplesmaturitymodel.pdf, archived at http:\/\/perma.cc\/8Q9F-PFEF; see also Cohasset Assocs., ARMA Int\u2019l, 2013\u20132014 Information Governance Benchmarking Survey for Legal Services 6\u20137, available at http:\/\/www.arma.org\/r1\/news\/2014\/06\/16\/2013-2014-information-governance-benchmarking-survey-for-legal-service, archived at http:\/\/perma.cc\/J4MG-WLS5.<\/p>\n<p>[56] See, e.g., Abby Shagin, The Risks and Benefits of Cloud Computing, SAP Bus. Innovation (Oct. 25, 2012), http:\/\/blogs.sap.com\/innovation\/cloud-computing\/risks-and-benefits-of-cloud-computing-020025, archived at http:\/\/perma.cc\/4GHW-NEAX.<\/p>\n<p>[57] See, e.g., Eric Griffith, What is Cloud Computing?, PC Mag (Mar. 13, 2013), http:\/\/www.pcmag.com\/article2\/0,2817,2372163,00.asp, archived at http:\/\/perma.cc\/7R6H-8J9A.<\/p>\n<p>[58] See Joe McKendrick, 9 Questions to Ask Before Signing a Cloud Computing Contract, Forbes (Jan. 14, 2013, 4:00 AM), http:\/\/www.forbes.com\/sites\/joemckendrick\/2013\/01\/14\/9-questions-to-ask-before-signing-a-cloud-computing-contract\/, archived at http:\/\/perma.cc\/6BYB-3Q83.<\/p>\n<p>[59] See Cloud Ethics Opinions Around the U.S., A.B.A., http:\/\/www.americanbar.org\/groups\/departments_offices\/legal_technology_resources\/resources\/charts_fyis\/cloud-ethics-chart.html, archived at http:\/\/perma.cc\/JN7T-L3YJ (last visited Jan. 27, 2015) (collection of ethics opinions around the United States that deal with questions regarding law firms\u2019 use of cloud computing).<\/p>\n<p>[60] See id.<\/p>\n<p>[61] See Complaint at 1\u20132, Zynga Inc. v. Alan Patmore, No. CGC-12-525099 (Cal. Super. Ct. Oct. 12, 2012) (a former employee transferred 760 confidential Zynga files to his personal account then uninstalled Dropbox to cover his tracks), available at http:\/\/tsi.brooklaw.edu\/sites\/tsi.brooklaw.edu\/files\/filings\/zynga-inc-v-alan-patmore-et-al\/20121012complaint-zynga.pdf, archived at http:\/\/perma.cc\/MFQ3-SRXD.<\/p>\n<p>[62] See Daniel P. Dern, How to Keep Your Smartphone (and It\u2019s Data) Secure, Computerworld (Apr. 22, 2014, 7:30 AM), http:\/\/www.computerworld.com\/article\/2488450\/mobile-security\/how-to-keep-your-smartphone&#8211;and-its-data&#8211;secure.html, archived at http:\/\/perma.cc\/AP2Q-932Q.<\/p>\n<p>[63] See id.<\/p>\n<p>[64] See id.<\/p>\n<p>[65] See, e.g., Rolfe Winkler &amp; Elizabeth Dwoskin, Google\u2019s New User Tracking Bridges Mobile Apps and Mobile Web, Wall St. J. (Aug. 7, 2014, 7:57 PM), http:\/\/blogs.wsj.com\/digits\/2014\/08\/07\/googles-new-user-tracking-bridges-mobile-apps-and-mobile-web\/, archived at http:\/\/perma.cc\/2G2U-3EGH.<\/p>\n<p>[66] See Zack Whittaker, Seven Privacy Settings You Should Change Immediately in iOS 8, ZDNet (Sept. 17, 2014, 2:30 PM), http:\/\/www.zdnet.com\/article\/seven-privacy-settings-you-should-change-immediately-in-ios-8\/, archived at http:\/\/perma.cc\/F4V5-9M8B; see also Klint Finley, Out in the Open: How to Protect Your Secrets from Nosey Android Apps, Wired (Mar. 31, 2014, 6:31 PM), http:\/\/www.wired.com\/2014\/03\/x-privacy\/, archived at http:\/\/perma.cc\/RPZ2-TN3R.<\/p>\n<p>[67] See, e.g., James Geddes, Flashlight Apps are Spying on Users Android, iOs, Windows Phone Smartphones, is Yours on the List?, Tech Times (Oct. 26, 2014, 7:36 AM), http:\/\/www.techtimes.com\/articles\/18762\/20141026\/flashlight-apps-are-spying-on-users-android-ios-windows-phone-smartphones-is-yours-on-the-list.htm, archived at http:\/\/perma.cc\/4SEQ-EKA3.<\/p>\n<p>[68] See Kia Kokalitcheva, Twitter Will Soon Track the Apps on Your Smartphone to Deliver More Targeted Ads, VentureBeat (Nov. 26, 2014, 10:09 AM), http:\/\/venturebeat.com\/2014\/11\/26\/twitter-will-soon-track-the-apps-on-your-smartphone-to-deliver-more-targeted-ads\/, archived at http:\/\/perma.cc\/83VE-QNJW.<\/p>\n<p>[69] See Waqas, Flashlight Apps Stealing Personal Information Stored on Your Smartphone, HackRead (Oct. 27, 2014), http:\/\/hackread.com\/flashlight-apps-stealing-your-personal-information\/, archived at http:\/\/perma.cc\/C7G2-48GX.<\/p>\n<p>[70] See, e.g., Dan Lamothe, U.S. Military Social Media Accounts Apparently Hacked by Islamic State Sympathizers, Wash. Post, Jan. 12, 2015, available at http:\/\/www.washingtonpost.com\/news\/checkpoint\/wp\/2015\/01\/12\/centcom-twitter-account-apparently-hacked-by-islamic-state-sympathizers\/?Post+generic=%3Ftid%3Dsm_twitter_washingtonpost, archived at http:\/\/perma.cc\/94LC-AM6V.<\/p>\n<p>[71] See Matthew J. Schwartz, How to Hack Facebook in 60 Seconds, InformationWeek (June 28, 2013, 11:08 AM), http:\/\/www.informationweek.com\/mobile\/how-to-hack-facebook-in-60-seconds\/d\/d-id\/1110576?, archived at http:\/\/perma.cc\/G8N2-ZUPE; see also Fred Stutzman, Ralph Gross &amp; Alessandro Acquiti, Silent Listeners: The Evolution of Privacy and Disclosure on Facebook, 4 J. Privacy &amp; Confidentiality, no. 2, 2012, at 7, 7.<\/p>\n<p>[72] See Breaking the Law, supra note 29 (noting that social media engineering is an effective method for hacking law firms when employees click on links in social media postings with messages aimed at persuading them to access the link).<br \/>\n[73] See Michael Kassner, Convenience or Security: You Can\u2019t Have Both When it Comes to Wi-Fi, Tech Republic (June 24, 2013, 1:09 AM), http:\/\/www.techrepublic.com\/blog\/it-security\/convenience-or-security-you-cant-have-both-when-it-comes-to-wi-fi\/, archived at http:\/\/perma.cc\/4BEX-P8H6.<\/p>\n<p>[74] See Press Release, Kaspersky Lab, Kaspersky Lab Sheds Light on \u201cDarkhotel,\u201d Where Business Executives Fall Prey to an Elite Spying Crew (Nov. 10, 2014), available at http:\/\/usa.kaspersky.com\/about-us\/press-center\/press-releases\/kaspersky-lab-sheds-light-\u201cdarkhotel\u201d-where-business-executives, archived at http:\/\/perma.cc\/PH46-Y7LK.<\/p>\n<p>[75] See, e.g., Eric Geier, Here\u2019s What an Eavesdropper Sees When You Use an Unsecured Wi-Fi Hotspot, PC World (June 28, 2013, 5:35 AM), http:\/\/www.pcworld.com\/article\/2043095\/heres-what-an-eavesdropper-sees-when-you-use-an-unsecured-wi-fi-hotspot.html, archived at http:\/\/perma.cc\/33BF-ZFUV.<\/p>\n<p>[76] See Wi-Fi Hotspots: Connecting While Traveling, Norton, http:\/\/us.norton.com\/travel-hotspot-security\/article, archived at http:\/\/perma.cc\/A6Y5-T4AD (last visited Feb. 18, 2014).<\/p>\n<p>[77] See, e.g., Erase Hard Disk Wipe Parameters, KillDisk, http:\/\/www.killdisk.com\/notes.htm, (last visited Mar. 5, 2015) (describing the U.S. Department of Defense DoD 5220.22-M (ECE), a seven pass overwriting algorithm used to erase data).<\/p>\n<p>[78] See Armen Keteyian, Digital Photocopiers Loaded with Secrets, CBS News (Apr. 19, 2010, 6:12 PM), http:\/\/www.cbsnews.com\/news\/digital-photocopiers-loaded-with-secrets\/, archived at http:\/\/perma.cc\/GVD6-7H8E.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DownloadPDF Cite as: Antigone Peyton, Kill the Dinosaurs, and Other Tips for Achieving Technical Competence in Your Law Practice, 21 Rich. J.L. &amp; Tech. 7 (2015), http:\/\/jolt.richmond.edu\/v21i3\/article7.pdf. by Antigone Peyton* I.\u00a0 Introduction [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 It is a challenge to practice law in the digital age.\u00a0 This is particularly true when a practice involves significant e-Discovery, Intellectual [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-2673","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-H7","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2673","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=2673"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/2673\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=2673"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=2673"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=2673"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}