Showing posts with label Microsoft. Show all posts
Showing posts with label Microsoft. Show all posts

Saturday, January 11, 2014

Win By Pin: Pinterest's Latest Battle for the Word "Pin"



Last October, Pinterest, the popular social networking platform sued a travel planning service called Pintrips in California District Court for trademark infringement, false designation of origin, unfair competition and dilution of their “PIN” family of trademarks. 

For those unfamiliar with Pinterest, it is a website whereby users (“Pinners”) collect images, recipes and other visual content and “pin” it to their user page (“board”). Much like the Facebook “like” button or Google’s “+1”, Pinterest has a “Pin it” social plug-in that third party sites integrate into their web pages. This is the vehicle by which Pinners add to their boards; by pinning images found on other websites.  

Photo by Norebbo
By its own description, Pintrips offers a service where you can “…shop for flights on your favorite sites, pin the options you care about, and see them on a personalized dashboard.” It markets itself as a travel facilitation application rather than as a social networking platform.

Pinterest’s claims are based on the Lanham Act and the California Business and Professional Code. Among other things, Pinterest claims that it had acquired rights in the “PIN-formative” trademarks before the Defendant began using its marks, and that the Defendant’s marks are confusingly similar and are likely to deceive the public into thinking that they are affiliated with the Pinterest brand. Pinterest’s claim for dilution is based on its assertion that its marks are famous, and have been so since before the Defendant started using its marks. They argue that Pintrips knowingly branded itself so as to capitalize on Pinterest’s goodwill.

Pinterest asks for interlocutory and final injunctive relief, delivery up and destruction, disgorgement of profits and compensatory damages.

While Pinterest acknowledges that the scope of its marks far exceed the travel industry, the Complaint alleges that the Pinterest travel section is one of the most popular parts of the website with more than 600 million total pins.

On January 6, Pintrips fired back with a motion to dismiss the Complaint.  Pintrips based its motion on the following grounds:


  •     That Pinterest cannot assert ownership over the PIN prefix;
  •     Based on this lack of ownership over PIN, the State law claims must fail; and
  •      Even if the State law claims survive, the Court should decline jurisdiction in favour of the State Courts.

Setting the jurisdictional issues aside, Pintrips is arguing that “pin” is a generic term that describes a function. They argue that Pinterest has no trademark registrations for PIN and should not be able to obtain one given the market restricting effect this would have on a number of different web-based businesses.

This is a key element of Pintrips’ argument because Pinterest will doubtless argue on the motion that pin has acquired secondary meaning associating that prefix with its brand; and this regardless of what comes after that prefix. Oddly, Pinterest failed to allege that its family of PIN-formative trademarks are so strong that PIN has acquired secondary meaning. 

Pintrips has cited law to the effect that regardless of how strongly the public may associate a generic term with a given brand, trademark status cannot be granted in the generic term. This strong consumer association with a generic term is known as de facto secondary meaning and has been rejected by courts as sufficient grounds to claim ownership over a generic term like “PC” or “MP3”.

Pintrips provided a number of examples where companies use pin as a generic term in association with “software applications, online maps, and websites”. Among those applications mentioned were Microsoft Windows, Facebook and Google Maps.
It would appear that the law backs up Pintrips’ argument. At the hearing of the motion (Scheduled for February 13, 2014), it will be essential for Pintrips’ counsel to drive home the point that “pin” is a commonly used term to denote a specific type of action in the online environment, namely marking a specific thing or place on a webpage (Google Maps), or the act of posting content from a third-party website to a user page of some sort (Facebook and Pinterest).
It may be tricky to convince a judge, particularly one who is not in the habit of pinning things online, that pin is in fact a generic action in the online environment. It may be helpful for Pintrips to liken the action of pinning to the action of posting. Posting is a familiar action online and can relate to any number of things, some of which could also be described with the term pin.
If I were arguing the motion on Pintrips’ behalf, I would offer the following two analogies:

  •       Whether I say “he knocked the ball out of the park” or “he hit the ball out of the park”, without any other information, the mental image one forms in their mind is that of a batter making contact with the baseball hard enough to propel it out of the field.
  •       Whether I say “he jumped off the building” or “he leapt off the building”, without any other information, the mental image one forms in their mind is the same.

In the same way, posting a photo or pinning a photo amounts to the same thing. Both are generic terms denoting a single action.
Upon a search of the USPTO trademark database, it appears that Pinterest has applied for PIN (Serial no. 85698998) in association with a wide range of goods and services. The opposition period has expired but the trademark has not been registered. Pinterest also claims registrations in several other jurisdictions.
Pinterest’s claim is not based on a trademark registration, but on Common Law rights. Much of their argument turns on the fact that a great deal of its popularity comes from its third party plug-in buttons; and that the Pintrips button (that may be alongside the “Pin it”) button causes confusion and dilutes Pinterest’s brand. 
The fact that these buttons may appear side by side is a functional reality. Websites that use these third-party plug-ins tend to put them all in the same place on the page. From a visual inspection of these marks, it would appear difficult to confuse them. Apart from the word pin, the marks are completely different. The “Pin it” button has red text with a stylized font. The Pintrips button is in a plane blue font. The Pintrips mark also contains a visual depiction of a sewing pin. In the “Pin it” button, the word pin is a prefix. In the Pintrips button, the word pin stands alone and comes after the image of the sewing pin.
Pinterest argues that in addition to appearance, the confusing trademark sounds the same or confusingly similar. Depending on how one pronounces the word “interest” (in two syllables or three), this may be true. But here, Pinterest can only be comparing its PINTEREST mark with PINTRIPS; not their respective third-party plug-in buttons depicted above. This is not self-evident given the drafting of the Complaint.
While this is only a partial analysis, it may be for naught if the Judge agrees with Pintrips on their motion and dismisses the complaint before arguments for confusion are ever made. Suffice it to say that Pinterest will be fighting an up-hill battle on this motion, and if they succeed, perhaps in the ensuing jury trial.
This is a typical David vs. Goliath situation. The fame of the Pinterest trademarks is beyond question. However, as Pintrips argues, no degree of notoriety should give anyone a monopoly on a technical or generic term.

Post Script:
In a somewhat related turn of events, last November, the European Commission’s Office for Harmonization in the Internal Market, Trade Marks and Designs Division rejected Pinterest’s opposition to a registration for PINTEREST by a news aggregator website and corporation called Premium Interest Ltd. This means that if Pinterest wants to operate officially in Europe, it will have to either change its name or buy a license from the Registrant.

Friday, July 8, 2011

Why is my information vulnerable in the public cloud?


Free, public cloud based services have been around for a while.  Microsoft’s Hotmail, Google’s Gmail and Docs, News Corp’s Myspace and so on, have all been offering free and user friendly cloud based software that most anyone can use.  Along with any cloud service come the issues of security and privacy.  How do these organizations go about treating your private information and for what purposes are they using it? How secure are these free services that have so many members storing all this information? What is the common practice when law enforcement or some other government entity asks them for access to your data?

Photo by digitalart
In his essay “Caught in the Cloud”, scholar and activist Chris Soghoian rightly points out that these businesses aren’t charities.  News Corp and Microsoft aren’t in the habit of spending large amounts of money on servers and resources so that millions of users may enjoy free service.  The primary manner in which these companies make money is through the organization and sale of their users’ private data.  

For example, when we write e-mails in Gmail, all the text we type is sent through one of Google’s algorithms.  That algorithm spits out data and tells Google how to intelligently advertise to us based on the contents of our conversation.  So if I’m e-mailing a friend for class notes from the Intellectual Property law class I didn’t show up to, I may see ad’s for higher legal education, online copyright protection services or even patent drafters.  Google’s algorithm intelligently determines what ads will hit home with me by analyzing all of my communications.  The same process applies to Google Docs.

Naturally, this type of targeted, consumer specific advertising (known as behavioral targeting) is worth a premium in comparison with randomly sending ads to Gmail subscribers hoping that they are appropriately targeted.  This is one of the primary ways in which Google not only makes up the costs of running it’s free cloud based offerings but turns a profit.

Microsoft uses similar behavioral targeting techniques with their Hotmail service.  Microsoft will analyze your search data.  In 2006, Chris Dobson, Microsoft’s global head of advertising sales told Seeking Alpha that Microsoft has increased its click-though rate by 76% since the implementation of behavioral targeting in its ad services.  

When you ask the average person how important it is to them that their data be secure online (specifically their private and intimate data like the content of their e-mails), they’ll generally reply by telling you it is very important.  However, one look at these public cloud services and one quickly realizes, people like to talk. 
Possibly the best and most widespread method to protect data is encryption.  When we log into our online banking sites, our sessions on those sites are encrypted for obvious reasons.  I doubt too many people would use an online banking service with security practices like Gmail or MySpace.  

Chris Soghoian explains that most cloud service providers have “Network Encryption” which essentially protects you as you log into your service.  They do not, however, have what is called “Data Encryption” which is what protects your information once it is already in the cloud.  Though Soghoian tells us that one of the main reasons for this is the total lack of awareness of the average consumer and the lack of consumer demand for encryption, I am of the belief that this is first and foremost a cost issue.  

Large public cloud providers do not implement data encryption because it is more resource intensive and would have the effect of slowing down the service (making things more costly for them).  Also, as we noted that these services make their money selling data for advertising, that data becomes a lot less valuable if not worthless if no one can understand it (because it’s encrypted).

This is a stark contrast with private cloud providers whose success very much hinges on the security and integrity of their network.  Medical service providers, large businesses, law firms and alike do not store their information in the public cloud for reasons of liability.  What insurance company will cover a law firm that was the victim of a data breach upon storing valuable client information on Google Docs?  Such a move would be monumentally foolish for any entity needing to store private, sensitive or valuable information. 

Finally, what happens when law enforcement tries to compel one of these service providers to hand over your private information.  In many cases a warrant isn’t even required! For example, the Patriot Act allows law enforcement to ask for a court order and search your private data without ever informing you.  What’s more, through the use of what is called a “National Security Letter”, the Patriot Act allows the F.B.I. and other law enforcement agencies to access your data without any form of judicial hearing or oversight.  That means that the F.B.I. can look at your documents without establishing probable cause that your data is or may be useful to a criminal investigation.  These broad and sweeping powers have been the subject of much debate and the constitutionality of these measures (on 4th Amendment grounds) has been seriously called into question.  Perhaps this is the reality of online life in a post 9/11 world. 

There are, however, solutions to this problem.  As mentioned before, data encryption makes it so data, while stored in the cloud remains unintelligible.  It is only once it is decoded with the encryption key that it can be read again.  Some services do offer data encryption to their clients.  However, if the service provider is in possession of the encryption key, law enforcement can compel them to hand it over along with the data itself.  That isn’t the case if the user is the only person who possesses the encryption key.  In that event, a service provider can comply with the demand without actually exposing your information.  

People have been and will continue to use free cloud based services for e-mail and alike.  I’m not suggesting we all stop doing so.  That being said, I do believe that knowing how your data is (and can be) treated is important and should be in the back of everyone’s mind when clicking “I agree”.  You may decide that certain things are best left out of the cloud.

Tuesday, July 5, 2011

Digital Due Process: A bid to modify the ECPA


Rarely does an alliance of this magnitude, involving such a varied and dynamic flock come into this world.  Digital Due Process (DDP) is a coalition of major online entities, privacy advocates, educational institutions and alike who have a common objective:

“To simplify, clarify, and unify the ECPA standards, providing stronger privacy protections for communications and associated data in response to changes in technology and new services and usage patterns, while preserving the legal tools necessary for government agencies to enforce the laws, respond to emergency circumstances and protect the public.”

Prominent members include Amazon, AOL, Google, HP, IBM, Intel, Microsoft and others. The Electronic Frontier Foundation (EFF) is also on board with this initiative along with a score of law schools across the United States. As quoted above, the group seeks to modify and balance privacy laws to be compatible with today’s technological reality.

Photo by Salvatore Vuono
The Electronic Communications Privacy Act (ECPA) is a part of the US Code enacted in 1986 with the stated goal of striking a balance between people’s privacy rights associated with new forms of electronic communication and the need for law enforcement to have the tools necessary to do their jobs effectively.

Prior to the ECPA, the Communications Act of 1934 and then the Federal Wiretap Act of 1968 prevented government entities and law enforcement (or anyone else for that matter) from intercepting or divulging peoples “wire communications”.  Then, in 1986, Congress sought to remedy the gaps in the law and clarify its position on privacy in electronic communications in the then forward thinking ECPA.

Though it may have been avant-garde for its time, DDP and others argue that this law is out of date and hopelessly out of touch with the realities of computing in the internet age.

Though Individual DDP members may have a slightly varying stance on the right direction for the ECPA, they all agree to the following four principles:

1) Law enforcement should have to obtain a warrant based on probable cause before it can demand that a service provider turn over a customer’s private data.

Currently, the law allows police and other law enforcement to demand access to people’s e-mails that have been in storage for more than 180 days without a warrant.  A simple court ordered subpoena is sufficient to order a service provider like Hotmail or Gmail to hand over your private e-mails providing they’ve been in your inbox (or any other folder for that matter) for 6 months or more.  The DDP sees this as too low a standard considering the implications on personal privacy. 

Law enforcement has never before had access to technologies that would enable such tracking of individuals. Does the simple fact that the technology and application now exist justify the use of those technologies?  Contrary to the views of the Justice Department, DDP does not believe so.

A major victory in favour of mandatory warrants to compel a service provider to hand over private information came in United States v. Warshak.  The U.S. Court of Appeals for the 6th circuit held that forcing an ISP to hand over private data without a warrant is unconstitutional on the grounds that it breaches the 4th Amendment.   The court ruled that people are entitled to the reasonable expectation of privacy relating to their e-mails stored on a third-party`s server.

2) Law enforcement should have to obtain a warrant before engaging in any location tracking through cell phones or other wireless devices.

The reality of today’s telecommunications means that service providers can potentially track their subscriber’s location in real time.  This powerful ability has not been lost on law enforcement.  Though there is intense debate, at least one court views this type of tracking without a warrant as unconstitutional.

Just last year, the U.S. Court of Appeals for the District of Columbia rendered a decision in United States v. Maynard where it disallowed evidence obtained by an F.B.I. GPS transmitter installed on a suspect-vehicle without a warrant.  The court found that:

"It is one thing for a passerby to observe or even to follow someone during a single journey as he goes to the market or returns home from work. It is another thing entirely for that stranger to pick up the scent again the next day and the day after that, week in and week out, dogging his prey until he has identified all the places, people, amusements, and chores that make up that person's hitherto private routine."`

This case has been appealed to the U.S Supreme Court and will be heard this year. Needless to say, DDP will be watching intently to see how the top court rules on this issue. It wouldn’t be surprising to see Amicus briefs by DDP members filed with the court in favour of the respondent.

3) The government should have to show that access to transactional is relevant to a criminal investigation before it is granted by a judge.

Transactional data refers to the logging of who we contact and when. The same way law enforcement may track the transactional data associated with people’s telephone calls, they may also track other forms of communication, namely e-mails, IM, text messages etc.

 DDP firmly believes that before being granted permission to do so, the entity requesting the right to proceed should have to show reasonable grounds that the information to be collected is relevant and pertinent to a criminal investigation.  Failure to do so should be met with the rejection of their request. Once again, simply because the technology is there, doesn`t mean that law enforcement should be given carte blanche to track and record transactional data regardless of the format or medium.

4) Police and other law enforcement should not be allowed to obtain a single subpoena granting access to the transactional data of several people.

This principle seeks to eliminate the practice of accessing groups or entire directories of transactional data in the hopes of it leading to a suspect.  DDP argues that law enforcement should have to obtain a separate subpoena for each individual’s personal transactional data.  If not, the entity requesting access should have to show that access to the bulk information is in itself relevant and pertinent to the investigation. 

In 1998, Senators Patrick Leahy (D) and John Ashcroft (R) made a bi-partisan attempt at modernizing the ECPA, including the Stored Communications Act (SCA).  Leahy and Ashcroft wanted to amend the law so that e-mails and other electronic communications not contemplated by the 1986 version receive the same treatment as telephone calls or letters.  

In his testimony before the Senate Committee on the Judiciary, James X. Dempsey, VP of the Public Policy Center for Democracy and Technology professed his agreement with DDP’s principles.  He urged the committee to consider giving the ECPA a makeover that would bring it into the modern era of computing.

Though many are in favour of modifying the existing law, some warn against the pitfall of over-specialization.  In other words, the ECPA shouldn’t turn into a law on cloud computing.  Doing so would defeat the purpose of modernizing the law as it would be rendered obsolete with the rise of the next technology. Rather, the legislature should re-draft the Act using technologically neutral language while maintaining its broad scope. 

Privacy has always been an issue close to the hearts of everyday people.  In this era of computing, every day people use the internet, every day. The prevalence and continued growth of cloud based offerings requires the modernization of the ECPA in a manner that will allow for growth and innovation. 

I'm of the opinion that the ECPA -or for that matter any law whose primary subject matter is technology should always have a mandatory 5 year review.  So much can happen in the world of tech in 5 years, let alone the 25 years it’s been since the enactment of the ECPA.  A mandatory review is exactly what legislation like this needs to avoid otherwise unsustainable legal delay.

Tuesday, June 28, 2011

A look at the US Supreme Court's decision in Microsoft v. i4i


In 2009, a Canadian software development company out of Toronto named i4i Inc. won a $290 million law suit against Microsoft for wilfully infringing its patents.  The company developed a new form of document encoding known as XML (Extensible Markup Language). The versatility of the .xml extension lead to its integration into a number of software applications, including Microsoft Office. Microsoft, however, did not license the XML code.   

The Eastern District Court of Texas ruled in favor of i4i stating that a party accused of patent infringement, when asserting the invalidity of a patent, must convince the court of the invalidity by “clear and convincing evidence”.  This is a particularly high burden of proof and one not easily met.  

Photo by Darren Robertson
Microsoft fought the District Court’s interpretation in appeal but the outcome was the same.  Both the Court of Appeals for the Federal Circuit and the United States Supreme Court affirmed the trial judge’s decision and rejected Microsoft’s arguments demanding a lowering of the burden of proof and upheld the trial court’s ruling.

Justice Sotomayor wrote for a unanimous court (8-0 – Justice Thomas concurring. Chief Justice Roberts recused himself because he owns Microsoft stock) in saying that §282 of the American Patent Act of 1952 clearly states that a patent, once issued “shall be presumed valid”.  This places the burden of invalidating the patent on the other party. According to Sotomayor, it has long been settled law that the party alleging invalidity must prove it by clear and convincing evidence.  She cites a 1984 decision rendered by Judge Rich, one of the principal drafters of the 1952 Patent Act, supporting the clear and convincing standard.  In the 30 plus years since the aforementioned decision, the CAFC has never varied their opinion. 

Microsoft’s invalidity defense was twofold: First, they attempted to apply §102(b) of the Act that prohibits the issuing of patents when:

“the invention was patented or described in a printed publication in this or a foreign country or in public use or on sale in this country, more than one year prior to the date of the application for patent in the United States”

This provision, known as the “on-sale bar”, says that a patent that has been used or sold or has been disclosed in a publication more than one year before the patent is applied for is not patentable under the law. Microsoft claimed that the entirety of the XML patent was disclosed in a previously released i4i product called “S4”.  The Court, however, rejected this defence after hearing from two expert witnesses (the two principal inventors of the XML patent).

Microsoft’s second argument relied on the fact that when the XML patent was being examined, the United States Patent and Trademark Office (USPTO) didn’t have the S4 patent to compare it to.   Relying on a recent decision, Microsoft asserted that when it is brought to light that the PTO didn’t have all relevant information during examination, the strength of their examination is greatly diminished.  Microsoft ultimately asserted that this lowered level of deference for the PTO should concordantly lower the standard of proof incumbent on a party alleging invalidity. 

Both of these arguments were utterly rejected by the Supreme Court who said that the “hybrid” burden of proof system Microsoft proposes has no precedent and no founding in law.  

Though the decision in this case turned primarily on statutory interpretation and the intention of Congress in enacting the law, Microsoft tried as hard as possible to make it seem that the issue at hand was the prior disclosure of the patent and the incomplete analysis of the PTO. 

Many IP professionals are skeptical of the value of this decision.  Surely had the ruling gone the other way, this case would be of paramount importance as it would be reversing a 35 year old interpretation that has thus far remained unchallenged.  Though some may question the importance of this decision outright, I am of the belief that the Supreme Court’s verdict affirms at least two points.

First, that the courts still show a high degree of deference towards the USPTO and therefore should continue to exercise judicial restraint in overturning its rulings.

Second, that smaller companies are capable of defeating behemoths like Microsoft when the law is in their favor.  Doubtless Microsoft fielded an expert team of attorneys who managed to conjure up and elucidate arguments that could have overturned a solid precedent.  Add to that the fact that a long list of tech giants such as Facebook, Google, Apple, Verizon etc. rallied behind Microsoft in support and you have a true David v. Goliath victory in favour of the Canadian i4i Inc. 

In my humble opinion, I think this case is most interesting for its rallying cry effect on smaller businesses than its actual implications on the legal framework of the US Patent system. As damaging as a $290 million verdict is, one would posit that if anyone could absorb such a loss it would be a company on the scale and magnitude of Microsoft. Though this decision surely is a blow to the tech giant, I don’t think too many people are (or should be) balling their eyes out for them right now...except Chief Justice Roberts that is...