BreachExchange mailing list archives

Judge Gives Go-Ahead to Case Equating Gmail Scanning with Wiretapping


From: Lee J <lee () riskbasedsecurity com>
Date: Mon, 30 Sep 2013 16:03:55 +1000

http://www.allgov.com/news?news=851257

Attorneys for the plaintiffs in a massive class action lawsuit against
Google <http://www.google.com/> won a battle in federal court in California
last week, as U.S. District Judge Lucy Koh ruled against a request by the
Internet giant to dismiss the case—but the war may already be lost.

In the case filed in federal court in San Jose, a group of named plaintiffs
have sued Google for violating the federal Wiretap Act by scanning emails
sent or received via its Gmail service for words and content, and
intentionally intercepting messages between non-Gmail subscribers and
subscribers.

Google sought to have the case
dismissed<http://www.courthousenews.com/2013/09/06/60925.htm> under
a section of the Act that allows email providers to intercept messages if
doing so helped in delivering the message or was incidental to the
functioning of the service in general. Judge Koh, however, rejected that
argument, finding that “the statute explicitly limits the use of service
observing or random monitoring…to mechanical and service quality control
checks…Congress did not intend to allow electronic communication service
providers unlimited leeway to engage in any interception that would benefit
their business models, as Google contends. In fact, this statutory
provision would be superfluous if the ordinary course of business exception
were as broad as Google suggests.”

Google also argued that Gmail users have consented to the scanning by
signing on to Gmail’s Terms of Service and Privacy Policies, but Judge Koh
ruled that “those policies did not explicitly notify Plaintiffs that Google
would intercept users’ emails for the purposes of creating user profiles or
providing targeted advertising.” She likewise rejected Google’s claim that
non-users tacitly consented to the scanning by sending emails to Gmail
users.

Gmail, including its business service called Google Apps, is the world’s
biggest email service, with about 450 million users
globally<http://venturebeat.com/2012/06/28/gmail-hotmail-yahoo-email-users/>
.

“The ruling means federal and state wiretap laws apply to the internet.
It’s a tremendous victory for online privacy. Companies like Google can’t
simply do whatever they want with our data and emails,” said Jon Simpson,
the privacy director for Consumer Watchdog<http://www.consumerwatchdog.org/> of
Santa Monica, California.

Google said in a statement that it was “disappointed” with the ruling and
was considering its legal options. “Automated scanning lets us provide
Gmail users with security and spam protection, as well as great features
like Priority inbox,” the company said.

But the victory over Google may live only a few weeks. Following cases that
hold that no Internet-based communication can be considered confidential,
Judge Koh found that the plaintiffs failed to show a reasonable expectation
of privacy in their complaint.


“Plaintiffs have not alleged facts that lead to the plausible inference
that the communication was not being recorded because email by its very
nature is more similar to internet chats,” wrote Koh. “Unlike phone
conversations, email services are by their very nature recorded on the
computer of at least the recipient, who may then easily transmit the
communication to anyone else who has access to the internet or print the
communications.”


The judge gave the plaintiffs 21 days to change her mind, citing “an
abundance of caution,” but if they are unsuccessful their case will be
dismissed.
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://lists.osvdb.org/mailman/listinfo/dataloss
For inquiries regarding use or licensing of data, e-mail
        sales () riskbasedsecurity com 

Supporters:

# OWASP http://www.appsecusa.org
# Builders, Breakers and Defenders
# Time Square, NYC 20-21 Nov
o()xxxx[{::::::::::::::::::::::::::::::::::::::::>

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security offers security intelligence, risk management services and customized security solutions. The 
YourCISO portal gives decision makers access to tools for evaluating their security posture and prioritizing risk 
mitigation strategies. Cyber Risk Analytics offers actionable threat information and breach analysis.

Current thread: