Miscellaneous
: Tsibouris & Associates Law BlogCourt Strikes Down Electronic Signature Due to Weak Security Procedures
By Mehmet Munur
The US District Court in Kansas held on February 19, 2009 that the data security procedures Dillard?s Stores had created to authenticate the electronic signature its employees used to execute an arbitration policy were not sufficient. While the case may have turned on its particular facts, Dillard?s could have avoided such problems by abiding by ISO 17799 procedures in operating its electronic signature systems.
The plaintiff, Yolanda Kerr, successfully kept her claim in court because she disputed the formation of the arbitration agreement. In 2005, Dillard?s started requiring current and new employees to sign an electronic arbitration agreement through its intranet system. In theory, Dillard?s associates executed their agreements using either a social security number or associate identification number and a unique confidential password followed by clicking an ?I accept? button. The plaintiff refused to electronically sign the arbitration agreement for nearly six months despite alleged threats from supervisors and the store secretary that she would be fired if she failed to do so.
In April of 2006, the plaintiff missed a day of work. When she showed up for work on April 28, she told the store secretary that she had missed the day of work because she did not have access to the intranet site that contained her schedule. To give her access to the schedule, the secretary accompanied the plaintiff to a computer kiosk, reset her password to the default password, and demonstrated how to access the system. Then the store secretary took control of the computer again and navigated through various screens with the plaintiff beside her. Plaintiff alleged that the store secretary electronically signed the arbitration agreement at this point. After the interaction at the computer, the two left the break room together. Five minutes later, the system automatically sent the employee?s account an email confirming the execution of the arbitration agreement. The email stated that failure to reply to the email would deem agreement to the plaintiff?s electronic signature of the arbitration agreement. Someone opened the email but did not respond. Dillard?s later terminated the plaintiff for allegedly calling a supervisor a profane name. The plaintiff sued for discrimination and Dillard?s attempted to compel arbitration at court.
In analyzing the electronic signature, the court concluded that Dillard?s failed its burden to show through a preponderance of the evidence that the plaintiff knowingly and intentionally executed the agreement for two reasons. First, the court did not want to impute the electronic signature to the plaintiff due to the possibility, however minimal, that the store secretary may have fraudulently executed the agreement while plaintiff was standing beside her. Second, the court held that Dillard?s did not have adequate security procedures in place to restrict unauthorized access to the execution of the arbitration agreement. While the record showed that the employees were at the kiosk on April 28, it did not show that the plaintiff was at the kiosk precisely at 3:26:20. In other words, Dillard?s failed to show that the username, authentication, and the signature coincided with the employee?s log in. It is unclear whether Dillard?s systems had the capacity to log such information or if Dillard?s failed to produce such evidence. Nevertheless, the two factors persuaded the court hold that Dillard?s had not satisfied its obligation to show that there was an enforceable arbitration agreement.
In sum, Dillard?s electronic signatures system failed for two reasons. The systems failed to log associates? access to the system and the system did not require that the associates change their default passwords immediately. In fact, both policies, are recommended under of ISO 17799 Information technology ? Security techniques ? Code of practice for Information Security Management. ISO Section 10.10.1 Audit Logging requires that ?[a]udit logs recording user activities, exceptions, and information security events should be produced and kept? and include ?dates, times, and details of key events, e.g. log-on and log-off.? Arguably, the formation of a legally binding agreement that compelled arbitration is such an event. Furthermore, ISO Section 11.2.3 User Password Management requires that ?when users are required to maintain their own passwords they should be provided initially with a secure temporary password . . . , which they are forced to change immediately.? Here, it appears that Dillard?s system continued to operate and allow either the plaintiff or the store secretary to electronically sign the arbitration agreement. Implementing both of these procedures would have greatly helped Dillard?s satisfy its burden. However, it is unlikely that ISO 17799 would not have protected Dillard?s store secretary from fraudulently executing the arbitration agreement by either using the default password or using the plaintiff?s username while she stood by her side.
Unfortunately, the court was not too impressed with the security procedures that Dillard?s already had in place because they were violated. For example, associates were prohibited from sharing passwords and supervisors could only log into associate?s accounts if they reset their password to the default password. Dillard?s also posted notices regarding the confidentiality of passwords. Nonetheless, the two employees, in effect, shared their username and their password and the authentication failed because the system could not keep track of the actual person that signed the agreement. Such user failure combined with a weak logging and password feature resulted in the failure of the electronic signature.
The case is similar to Campbell v. General Dynamics, No. 03-11848-NG (D. Mass. June 3, 2004) where the court held that the employer could not prove an employee?s acceptance of an arbitration policy simply by sending a link to the policy in an email. There General Dynamics proved that the employee had opened the agreement but could not show that he had indeed clicked on the link or agreed in any other way. Furthermore, that email did not even mention the importance of the arbitration policy until its fifth paragraph. The court had noted that General Dynamics could have required the plaintiff to signify his acceptance by a return email he had read the email and accepted the conditions of the arbitration policy. In sum, both the employers in Campbell and Kerr failed to successfully use the technology they had available to them.
This case should set a good example for all employers using electronic signatures for policies. IT, HR, and Legal Departments may need to collaborate to ensure that established security procedures such as the ISO 17799 are used for variety of issues including authentication, accurate system audit logs, and password resets. Moreover, all industries depending on electronic signatures should focus on security procedures to preempt the argument that the electronic signatures they collect do not in fact belong to their system users.
The case is Kerr v. Dillard Store Services, Inc., No. 07-2604-KHV, (D. Kan. Feb. 17, 2009).
Full post as published by Tsibouris & Associates Law Blog on March 23, 2009 (boomark / email).

Security guard shoots at dog, strikes owner www.privateofficer.com
Security guard shoots at dog, strikes owner www.privateofficer.com Fort Worth TX Nov 27 2008 BY: Rick McCann NTL...
Procedures for electronic service of Court of Appeal briefs on the Supreme Court now available
In early January, I reported on an amendment to Rule of Court 8.212(c)(2) to permit electronic service of Court of Appeal briefs on the Supreme Court...
Procedures for electronic service of Court of Appeal briefs on Supreme Court now available
In early January, I reported on an amendment to Rule of Court 8.212(c)(2) to permit electronic service of Court of Appeal briefs on the Supreme Court...
Canadian security officers strike www.privateofficer.com
Canadian security officers strike www.privateofficer.com MONTREAL, March 27 2008 — Rotating strikes by 14,000 security guards in the Canadian province of Quebec began Tuesday, with hospitals expected to be most affected, Montreal media said...
Making a Useful Signature Stamp
At PDF for Lawyers, Ernie the Attorney provides a great tutorital on creating a digital signature in Adobe Acrobat...
ELECTRONIC TRANSACTIONS IN THE DUTCH CARIBBEAN
A digital signature has the same legal effect as a hand-written signature The Ordinance on agreements concluded electronically (?Landsverordening overeenkomsten langs elektronische weg?) became effective on 1 January 2001...
Law Enforcement and Criminal Justice Career Choices
Descriptions of law enforcement occupations
Rightwing Extremism
Current Economic and Political Climate Fueling Resurgence in Radicalization and Recruitment
California Supreme Court Proposition 8 Decision
Court Rejects Challenges to Proposition 8, but Finds Marriages Valid
Is Barack Obama a Natural Born Citizen?
Wrotnowski v. Bysiewicz (Supreme Court): Does Obama meet the constitutional requirements to be President
Unwed Fathers' Rights in Adoption
Landmark Cases in Adoption Law Shape Law with respect to Unwed Fathers
How do i go bout geting a free laywer to sue the durham police department for drug raids and nothing is found?they have been in my house 4 or 5 times seems like every 4 months or so and breaking down my door tearing up m
They need a warrant to get into your house...if they never showed you one...you ...
Is a child fathered out of wedlock by an American diplomat to a foreign women on foreign soil entitled to US Citizenship by jus sanguinis?
This is a very tough situation your friend is in. It is difficult to know the ex...
Did I harass someone?
Oh, yes. This can be taken in as so many things, especially since you had testif...
How can I get my parents away from my bulling brother?
First of all, if you are paying your lawyer, you should not be on the back burne...
How to prove housing discrimination based on sexual orientation in student housing?
There are several things you can do. First of all, contact any welfare advisors,...
Department of Homeland Security, FBI, and Social Security Administration
allegedly denied social security insurance to disabled and elderly immigrants.
No Signature Required
Wachovia to pay up to $125 million settlement in check cashing lawsuit.
FDA
Warns About Electronic Cigarettes
MEMC Electronic Materials Inc
401(k) / ERISA Stock Fraud
Polaris All-Terrain Vehicles
Defective Electronic Control Modules
Electronic Data Systems Corp.
allegedly failed to pay employee overtime.

How do i go bout geting a free laywer to sue the durham police department for drug raids and nothing is found?they have been in my house 4 or 5 times seems like every 4 months or so and breaking down my door tearing up m
They need a warrant to get into your house...if they never showed you one...you ...
Is a child fathered out of wedlock by an American diplomat to a foreign women on foreign soil entitled to US Citizenship by jus sanguinis?
This is a very tough situation your friend is in. It is difficult to know the ex...
Did I harass someone?
Oh, yes. This can be taken in as so many things, especially since you had testif...
How can I get my parents away from my bulling brother?
First of all, if you are paying your lawyer, you should not be on the back burne...
How to prove housing discrimination based on sexual orientation in student housing?
There are several things you can do. First of all, contact any welfare advisors,...







