Showing posts with label laws. Show all posts
Showing posts with label laws. Show all posts

Wednesday, October 22, 2008

more on prop 7

The prior research and discussion on Prop 7 continues, both on this blog and in the comments here. Here's where things stand now.

1. I've managed to convince myself that Prop 7 will not affect the legal status of distributed power generation (such as rooftop solar) that's operating under a net metering program.

Net metering is a program where you hook your rooftop solar up to the grid. You pay your utility company for the amount of power you use minus the amount you generate. Under net metering, if you generate more than you use, the utility doesn't have to pay you for it unless you have some sort of separate contract with them.

I was concerned that Prop 7's language would interfere with distributed generation. It turns out it still might, but not the part of distributed generation that's part of net metering. The Energy Policy Initiatives Center has a useful article (pdf) on California law governing Renewable Energy Credits. Section 5, along with its footnotes, gets into distributed generation. It points out that distributed generation through net metering is governed by a separate set of laws, not by the part Prop 7 changes. That's what the exclusion from the definition of "Retail Seller" of generation consistent with Section 218(b) is all about in Public Utilities Code section 399.12(i)(4)(A).

Now, if you want a contract where you get paid for generating more than you use, that may well put you in the category of being a photovoltaic producer under 30 megawatts, so Prop 7 may have some implications for you.

2. It's still not clear what effect Prop 7 has on producers under 30 megawatts.

There are basically two arguments that prop 7 locks out producers of less than 30 megawatts. I think I may have cleared one up, but the other's still murky.

2.a. Must an "in-state renewable electricity generation facility" be a "facility"?

The first argument goes something like this: to be an "eligible renewable energy resource," you must be a "solar and clean energy facility" and you must also be an "in-state renewable electricity generation facility" as defined in the public resources code. The public resources code § 25741 defines "in-state renewable electricity generation facility" as "a facility that meets all of the following criteria" and then gives a list of criteria. It also contains a definition of the word "facility" in § 25110, which the text of prop 7 (official pdf, unofficial HTML version) changes to specifically include "solar and clean energy plant", a term that means a plant of 30MW or more. So the question is whether an in-state renewable electricity generation facility must be a "facility" as defined in § 25110, or whether the word "facility" there is just the generic, English word "facility" without the statutory meaning. If it has the statutory meaning, then to qualify for the renewable portfolio standard, your solar or clean energy generator would have to generate at least 30MW.

I haven't been able to find a court case, a California Public Utilities Commission decision, or a California Energy Commission decision that addresses that question. However, the California Energy Commission publishes a set of guides for energy producers interested in the Renewable Portfolio Standard. One guide (pdf), in particular, covers what energy generators are eligible to participate in the Renewable Portfolio Standard. The current definition of "facility" is restricted to transmission lines and thermal power plants (which must have a capacity of at least 50 megawatts), but the eligibility guide says that solar photovoltaic generators are eligible and doesn't give a minimum size. So I can't point to chapter and verse, but it seems likely that the CPUC and CEC are using "facility" in its common meaning in this case, rather than as the defined term.

2.b. Is a "solar and clean energy plant" the same as a "solar and clean energy facility"?

When the "no on prop 7" folks put in their ballot response that prop 7 excludes renewable energy producers of less than 30 megawatts, the "yes on prop 7" folks took them to court. Peter Wall was kind enough to get a copy (pdf) of the ruling, which he posted to his blog. The associated legal whitepaper (pdf), which appears to be a moderately-edited legal brief, goes into more detail about the arguments. Essentially, the argument boils down to the fact that, to be eligible under the renewable portfolio standard, prop 7 requires that you be a "solar and clean energy facility" and an "in-state renewable electricity generation facility." But it doesn't define "solar and clean energy facility." It does define "solar and clean energy plant," however, and that definition sets a 30 megawatt floor on its size. It also defines "facility," but it does it over in the Public Resources Code, not in the Public Utilities Code where it uses "solar and clean energy facility."

In the court case, the folks against Prop 7 argued that Prop 7 made the two terms the same, that a "solar and clean energy facility" is a "solar and clean energy plant", blocking out producers under 30 MW. The folks in favor of Prop 7 argued that they're different. The court found "each of the party's interpretations has some support in the initiative's text." Personally, I'm not convinced either way by the arguments, so this one's still murky.

3. And now, two rants.

3.a. Rant the First: For cryin' out loud, California, fix your defined terms!

When you write a contract, it's common practice to capitalize defined terms. For instance, you might say something like this:
"Facility" means an thermal power plant which produces electricity and has a capacity of at least 30 megawatts.
And then when you use the definition, if you mean the defined term, you capitalize it, and when you don't mean the defined term, you leave it lower case to indicate the word takes on its ordinary meaning in common written English:
The Commission will consider the application of any facility, but it will approve an application only if it is submitted by a Facility.
This is something California does not do. Which means when they pepper the Public Utilities Code and the Public Resources Code with the word "facility," there's no way to know whether they mean the common term or the defined term. I mean, come on, all you'd have to do is distinguish between "Solar and Clean Energy Plant" and "solar and clean energy facility" and that whole issue 2.b. would just go away.

3.b. Rant the Second: Could we please raise the level of information here?

The amount of time it's taking to get hard info on this initiative is really adding up, and a big part of the problem is the "yes" and "no" campaigns. The "no on 7" web site is mostly conclusory statements with nary a link or cite to supporting data. I can't even get on the "yes on 7" site because it's flash-only, and flash is giving my browser indigestion right now. The Union of Concerned Scientists' "no on 7" page is marginally better, but it still doesn't provide the raw info necessary to really assess this complex set of changes. And there are rapidly approaching limits to how much time I can spend analyzing this stuff. It really shouldn't be necessary to spend hours digging for primary sources to cut through the crap.

Wednesday, May 09, 2007

is altering a DOI scientific finding fraud?

Several news outlets, including NPR, the San Diego Union-Tribune, and the Houston Chronicle are carrying articles on activities by Julie MacDonald, former deputy assistant secretary at the Department of Interior. The reports allege she altered scientific reports:
Rep. George Miller, D-Calif., said MacDonald's resignation was “no gift to the country. She wandered around the department for three years changing documents and ... making determinations based on her beliefs.”
(from the Union-Trib, emphasis added). That got me thinking: would willfully altering scientific reports for endangered species determination constitute fraud?

Here's the federal definition of fraud, or at least one of them, 18 U.S.C. § 1001:
(a) Except as otherwise provided in this section, whoever, in any matter within the jurisdiction of the executive, legislative, or judicial branch of the Government of the United States, knowingly and willfully—
(1) falsifies, conceals, or covers up by any trick, scheme, or device a material fact;
(2) makes any materially false, fictitious, or fraudulent statement or representation; or
(3) makes or uses any false writing or document knowing the same to contain any materially false, fictitious, or fraudulent statement or entry;
shall be fined under this title, imprisoned not more than 5 years . . .
So you'd need to (1) be in the context of a "matter" that is within the jurisdiction of the executive branch, and (2) knowingly or willfully, (3) falsify a material fact or make a materially false representation. I'm not entirely sure what a "matter" is, and don't have time to research it right now, but let's assume it's at least something fairly serious.

Here's a portion of the Endangered Species Act, 16 U.S.C. § 1533(b):
(b) Basis for determinations
(1)
(A) The Secretary shall make determinations [of whether a species is endagered] solely on the basis of the best scientific and commercial data available to him after conducting a review of the status of the species and after taking into account those efforts, if any, being made by any State or foreign nation, or any political subdivision of a State or foreign nation, to protect such species, whether by predator control, protection of habitat and food supply, or other conservation practices, within any area under its jurisdiction; or on the high seas.
. . .
(2) The Secretary shall designate critical habitat, and make revisions thereto, . . . on the basis of the best scientific data available and after taking into consideration the economic impact, the impact on national security, and any other relevant impact, of specifying any particular area as critical habitat. The Secretary may exclude any area from critical habitat if he determines that the benefits of such exclusion outweigh the benefits of specifying such area as part of the critical habitat, unless he determines, based on the best scientific and commercial data available, that the failure to designate such area as critical habitat will result in the extinction of the species concerned.
(emphasis added). It looks to me like this law requires that the secretary have "the best scientific data available" when making decisions under the endangered species act. The secretary doesn't have to follow the scientific data--economic impact can come into play--but the scientific data must be the best available. Which, in turn, suggests it's "material" to the decision, as the fraud statute requires.

And that makes me wonder: if someone "willfully" or "knowingly" alters that scientific data, something a jury would have to decide, has that person run afoul of § 1001? Note that I'm not saying Ms. MacDonald has. In fact, the news reports are vague enough that I can't even tell exactly what she was altering. But it does raise an interesting question.

Friday, April 13, 2007

hey ISPs, consider taking on spammers

Schneier on Security has a link to an analysis that suggests there are only a few big spam operations on the Internet, rather than a whole bunch of little ones. Essentially, the analysis looks at the variations in the amount of spam each day. If there are a whole lot of little spammers, all spamming in different directions, any given Internet Service Provider should see fairly constant incoming spam. But a lot of ISPs instead see wide variations in the amount of spam, suggesting there are a few big spammers and one day they're spraying Canada, the next they're going after China, and the day after they're hitting the U.S.

Why's that interesting? Well, the CAN-SPAM act, which, unfortunately, seems to be about the best we've got to work with, normally limits enforcement to the FTC or the state attorneys general. However, § 7(g) lets an ISP sue a spammer in federal court:
      (1) ACTION AUTHORIZED- A provider of Internet access service adversely affected by a violation of section 5(a)(1), 5(b), or 5(d), or a pattern or practice that violates paragraph (2), (3), (4), or (5) of section 5(a), may bring a civil action in any district court of the United States with jurisdiction over the defendant--
        (A) to enjoin further violation by the defendant; or
        (B) to recover damages in an amount equal to the greater of--
          (i) actual monetary loss incurred by the provider of Internet access service as a result of such violation; or
          (ii) the amount determined under paragraph (3).
Their damages will be $25-$100 per individual spam message, up to a max of $1,000,000, which the court may triple in the case of certain aggravating factors (like the defendant's doing it willfully or knowingly.) The court also has discretion to award the ISP attorney's fees.

Now, the FTC and attorneys general have bigger fish to fry than going after spammers, but ISPs feel this pain every day. It might not be worth their while to stamp out a bunch of little individual spammers around the Internet, but if it's only four or five big operations, that prospect starts looking a lot more interesting.

more on military commissions act and citizens

Back in October, I wrote a short post about the Military Commissions Act of 2006 and its impact on citizens. I had a chance last night to ask my Representative about it, but it's hard to give a good answer in a group setting, so I sent a follow-up e-mail. We'll see what comes of it. In the meantime, I wanted to expand a bit on the reason why I raised the issue in the first place.
  • §§ 949a(1)(A) and 948d(c) of the act say one way to be an Unlawful Enemy Combatant is for a Combatant Status Review Tribunal or other competent tribunal under the President's authority to determine that you're one. The sections do not limit their scope to alien unlawful enemy combatants.
  • §§ 948c and 948d(a) limit the jurisdiction of a military commission to alien unlawful enemy combatants.
  • § 948a has separate definitions for "unlawful enemy combatant" and "alien," suggesting they're separable concepts.
  • I could not find anything in the act that specifies whether or not the jurisdiction of a Combatant Status Review Tribunal, as opposed to a military commission, extends to non-aliens.
So the act talks about two different judicial bodies, a Combatant Status Review Tribunal and a military commission. How do we know they're different? For one thing, the act spends a lot of time defining a military commission but very little defining a Combatant Status Review Tribunal. For another, tribunals usually have three people (hence the name) but the act says commissions have at least five. § 948m(a). Combatant Status Review Tribunals decide whether or not you're an unlawful enemy combatant, and their answer is "dispositive." § 948d(C).

The act says they decide whether you're an "unlawful enemy combatant," not whether you're an "alien unlawful enemy combatant," but the military commissions only have jurisdiction over alien unlawful enemy combatants. So we have this odd situation where a Combatant Status Review Tribunal can find you're an unlawful enemy combatant, but if you're a citizen you're still outside the jurisdiction of the military commissions. Why?

Now the kicker. In Hamdi v. Rumsfeld, the Supreme Court's plurality said the executive branch can hold a citizen indefinitely only if the citizen has a chance to rebut the charge of being an "enemy combatant" before a neutral decisionmaker. So my question to the Representative is whether Congress, in the Military Commissions Act, handed the executive that neutral decisionmaker in the form of the Combatant Status Review Tribunal.

It'll be interesting to see how she responds.

Friday, March 30, 2007

not dead yet

This stuff still has me on the couch, but I'm slowly recovering. The fever dropped yesterday. Today, my brain's still pretty mushy and I feel like crap, but it's at least a somewhat better grade of crap.

I had to leave the house yesterday for, of all things, jury duty. You see, they originally wanted me to serve during the semester, which would've been quite nasty--imagine missing two weeks worth of classes, or four if it's a long trial. Finals won't wait, being a student isn't an excuse from jury duty, and unlike businesses I don't believe schools need to make accommodations. (What would they do, anyway? Write a special final for me and somehow try to wedge it back into the curve?) So I postponed jury service. But the voice menu system gave me only a six month range, which didn't help much--even pushing it back the full six months would've put it right in the middle of studying for the bar exam, definitely a career limiting move. So I did what I could to mitigate the damage and scheduled it to run over spring break.

However, you only get to do the "postpone for any reason" thing once. Then the flu came and knocked me flat on my keester. There's a two-week leeway built into the system, but that'd land me right back on top of classes, so it was no help. And the last time I tried the voice line it connected directly to the automatic system with no option to talk to a human, and I wasn't optimistic it'd be any better in the morning before a 7:45 a.m. reporting time. So yesterday I was pretty much trapped and, by operation of the rules of jury service, I had to risk infecting the jury pool. That's the danger of bright line rules, I guess.

I was pretty careful to minimize interacting with people--mostly just sat in my chair like a lump listening to the Hitchhiker's Guide to the Galaxy on the iPod--and would've explained it to the judge if I'd gotten called, but fortunately God was looking out for all involved and I wasn't called for anything. It did set back my recovery a bit, though.

Friday, March 16, 2007

attorneygate

Back in January, I wrote about the developing U.S. Attorney scandal. Now we're starting to see more details, such a story in the LA Times that says this:
On Tuesday, Iglesias, 49, told the Senate Judiciary Committee that two prominent Republican politicians had called him to ask whether indictments would be filed before the November election against Democratic politicians in an ongoing criminal investigation. In the weeks that followed, Iglesias and seven other federal prosecutors were forced to resign.
. . .
. . . He earned the ire of the state GOP by refusing to prosecute anyone for voter fraud after the 2004 elections, despite some Republicans' contention that 15-year-olds voted. Iglesias said he could find no federal crimes.
The story notes that the second call was from Senator Pete Domenici.

As far as I know, one of the functions of a federal prosecutor is to not bring charges where the prosecutor can't find a crime: the prosecutor has an ethical duty to seek justice. If Congress wants to hold hearings, that's a different matter. As a deliberative body, Congress is set up to perform those sorts of investigations.

Something about this whole situation just feels wrong. I can't put my finger on exactly what it is just yet, but something is rotten in the state of Denmark.

Saturday, February 17, 2007

few things tick me off like spam

I get a lot of spam. Today, since 10:00 this morning, I've gotten 32 spam messages and four legitimate ones--and that's just counting what slipped past Spamassassin. So it was especially interesting to find a spam message advertising spamming services ("Email Marketing- Easy and affordable"). It's interesting for a couple reasons. First, it just plain cheeses me off that spammers are propagating themselves. Second, unlike the more common stock pump-and-dump scheme, if you're going to advertise spamming you have to include some way to contact you. So I dug into it a bit.

The message came from a machine called promailer.prserv.net. Which has the same IP address as www.attbusiness.net. Both domain names are registered to AT&T.

The body of the message contains some evil spammer tricks. Basically, it's made up of a set of links (called imagemap links) to images on remote web pages. It's designed in such a way that, if you open the e-mail and your mail software doesn't have the proper protection in place, the mail software will connect to the remote server to display the images. In the process of connecting, it will send information that can uniquely identify that message. The net upshot is that the spammer can tell it's not only a valid e-mail address, but also that someone's reading the mail there.

OK, so why is an AT&T server advertising spamming services? And why is it fishing for valid e-mail addresses while doing it? Both good questions that I put to AT&T.

I first tried sending to abuse@attbusiness.net. Turns out that address doesn't exist. Now I'm starting to get annoyed enough spend a bit more time on it. Some digging around AT&T's web site turned up postmaster@attglobal.net. I send a message there. A few minutes later, I got a reply summarily closing my trouble ticket:
This is the report of the incident you should receive.  Sev:  4 - Warning
For Account: aotsmail Incident Number: xxxxxxxxxxxxxxx Status: Closed
Thank you for taking the time to inform us of this situation.
However, we cannot take any further action until you provide us with the actual connection logs. These connection logs will include the complete IP address, date, time and time zone associated with the abusive action. Only with this information can we identify the responsible individual.

Regards,
Postmaster

To find more information on filtering SPAM, please visit
http://help.attbusiness.net/index.cfm
and type the word filter into the search engine.
If you feel we handled this incident improperly or require
assistance providing headers, please call 800-821-4612.
Wrong answer. One of the few things that'll piss me off more than spam is a company that doesn't care that I've taken the time to investigate and report to them that they, or someone there, is spamming. I next called their 800 number, where they told me to send the message's headers to their Remote Access address, RM-RemoteAccess@ems.att.com, to be appended to the trouble ticket.

Now we'll see where things go from here. In the meantime, I will either calm down and get back to the work I need to be doing, or I'll start going through the CAN-SPAM act, 15 U.S.C. §§ 7701-7713, to see whether this spam message matches up with federal law.

Thursday, February 01, 2007

software liability

Periodically, Bruce Schneier proposes establishing liability for software. I've responded with some concerns--I wasn't sure a liability rule is necessarily the wrong approach, but there are a lot of alternate ways to deal with the issue and liability might be the wrong hammer to turn this screw. But it's hard to discuss an abstraction, so I took a few minutes to try to write a statute that would impose liability for consequential damages on software manufacturers, just to see what sorts of issues I ran into. After going through the process, I think either it'd take a better statute writer than me to do the job well, or that a liability rule may be overkill at this point in the industry's development and risks some fairly significant damage to the software industry, in which case some of the other possibilities might be better choices.

Anyway, here's a blow-by-blow. First off, let's try to exclude open source projects.
(a) Except as provided in subparts (b) through (d) of this section, any entity that manufactures computer software for sale shall be liable for consequential damages caused by defects in that software, where such defects arise through the negligence of the manufacturer, its employees, or agents.
"For sale" excludes open source projects and people who give their software away for free, but it has some unintended consequences, too. Shareware authors will face liability under this statute, and adware (free software supported by advertising) probably faces no liability. Offering web-based applications, like the stuff all the rage at Google, Yahoo, and Hotmail right now, probably also doesn't constitute a "public sale." It's not clear what happens if you give away the software for free but make up your development costs on support contracts.

In fact, there's another, fatal problem in this language: very little software today is offered "for sale." Almost without exception, it's offered under a license to use it and specifically not to sell it. But if we write "for sale or license," the statute suddenly will apply to the GPL, LGPL, BSD, Artistic License, and anything else that's not public domain. In the end, it might be necessary to re-cast the statute in terms of generating revenue rather than selling software.

The plaintiff needs to show negligence, which imports the industry's ordinary standard of care into the statute. Notice that there's no limit on liability. That's a potential problem because it could either chill development or move manufacturers to jurisdictions that don't have liability rules. There's a lot of literature on product liability that may have some helpful suggestions for these issues.

Now, we want to encourage software houses to find and fix their bugs, so let's give them a safe haven exception for doing that.
(b) If, within sixty days of learning of a defect, the manufacturer corrects such defect and makes the correction freely available to purchasers of the software, this section shall not apply to damages that arise from such defect after the date on which the manufacturer learns of such defect.
So if you learn about a bug, and you fix it in 60 days, you don't face liability for problems caused after the day you learn about it. It's designed to encourage manufacturers to learn about their bugs as early as possible and to fix them within a reasonable amount of time. After all, we don't necessarily want them rushing those patches out the door. On the other hand, the statute doesn't say anything about bugs that the bug fixes introduce, and it says precious little about how they have to do the distributing. I'm having a tough time figuring out how to define a self-installing binary patch in statutory language, and freezing that definition into a law that might be around for 5o-100 years is likely to be a really bad idea.

Now, we don't want software houses to have to maintain support for their creaky old software forever--I mean, do you really want Microsoft to spend its time keeping Windows 3.1 on life support rather than chucking it and writing something with real security? On the other hand, we also don't want them to drop support the day before the software rolls out the door so they can avoid liability altogether. So how about a hold-down period?
(c) If the manufacturer publicly disclaims support for such software, this section shall not apply to damages arising after the Final Support Date, where such Final Support Date is determined as provided in this sub-part and sub-part (d) of this section:
(1) the Initial Sales Date shall be the date of first public sale of such software;
(2) the Final Offering Date shall be the latest of
(i) the date of the last public sale of such software,
(ii) the date on which the manufacturer publicly disclaims support for such software, or
(iii) the date one year after the Initial Sales Date;
(3) the Final Support Date shall be the later of
(i) the date one year after the Final Offering Date, or
(ii) such later date as the manufacturer may establish by agreement.
So if you sell software, you have to support it for at least two years. That might be a problem if you're a shareware writer. Individual consultants may get away without liability because there's no "public sale," though their customers can establish liability in the consulting contract. But suppose the customer puts that code into a product and then sells the product--then the consultant will be on the hook to provide support.

And there's another problem, here: (c)(2)(i) makes the Final Offering Date dependent on the date the software's last sold, so that mom-and-pop store with the dusty rack of ancient shrink-wrap code can keep the manufacturer in the support business. On the other hand, we don't want the manufacturer to say "no, really, we're dropping support" and keep pumping the product out the door and bringing in revenue from it. We also don't want the manufacturer to be able to disclaim support and then farm out the process of stamping disks to an affiliate that keeps selling the software. I haven't figured out a good answer to this problem, yet.

Anyway, let us forge onward. It sure would be nice if our manufacturer had the ability to sign separate support contracts with different people. ("OK, government entity, we'll keep supporting Windows 3.1 just for you, but it's gonna cost you because everyone else is moving to Vista.")
(d) A manufacturer may, by agreement, establish different Final Offering Dates and Final Support Dates for different users of the sofware, but in no event shall the manufacturer establish a Final Support Date which is earlier than the earliest date provided in subsection (c) of this section.
The "in no event" language is to keep someone from putting a 1 day Final Offering Date and Final Support Date in the EULA. Notice, though, that the "date of the last public sale" language may cause problems here, too. If you sell a copy of Win 3.1 to the government as part of a private support contract, is that a public sale? Also, the language is really clunky and could lead to differing court opinions on what the "earliest date" means.

Finally, we need to make it clear that you can't contract out of the liability. Otherwise, the software house will just put a clause in the EULA where the user agrees to waive liability.
(e) No manufacturer may waive liability under this section except as provided in subparts (b) through (d) of this section.
Hmm. This one needs some refinement for sure. Could you contract your support out to a dedicated support firm and send your liability along with it? What about to an undercapitalized support company that, if someone sues them, won't have any money to pay damages? If you do contract out support, can you get them to indemnify you for damages? If so, could you put indemnification in the EULA, so that the user suing you has to indemnify you for any damages that user might recover?

Finally, what happens if 47 states adopt this statute but Delaware, New Mexico, and, say, California don't? Notice that every EULA includes a choice of law provision ("the laws of the state of X shall govern this license"). You might expect those provisions to quickly swing over to whichever states don't impose liability.

Anyway, these are all issues to consider. As I said, I'm not expert at drafting statutory language, but the process of going through it has exposed a lot of ideas to consider with any push for software liability. These aren't just issues for the lawyers. Many of them are policy issues that determine what incentives we want to create and how we want the software industry to evolve.