ISVs May Have More Power Over Retailers Than Anyone Suspected

Written by Mark Rasch
January 24th, 2013

Attorney Mark D. Rasch is the former head of the U.S. Justice Department’s computer crime unit and today serves as Director of Cybersecurity and Privacy Consulting at CSC in Virginia.

When there is a retail IT contractual dispute with a software vendor—as is now happening with Lands’ End—that ISV (or cloud or other “as a service” provider) may have a contractual right to terminate access to the software or service, with or without notice.

Under what has been called “digital repossession,” software vendors may even have the right to decide for themselves whether the terms of a contract have been breached and to simply terminate access to the software or the service. The key here is to make sure both software license agreements and service agreements have a “soft landing” provision that ensures the vendor is paid for its services while limiting the impact of a sudden withdrawal of the service or software.

Both parties in the Lands’ End contract agree that the contract, entered into in 1993, granted the retailer a license to use the software for 20 years—expiring in 2013. However, the parties disagree over when that license to use the software began—from the date of the contract (in January) or from the date the software went “live” and the company was able to “use” the software (in October). Lands’ End wants time to transition to a new software vendor, and the vendor wants to grant Lands’ End a “perpetual” license for just under $1 million. Lands’ End’s lawsuit asks the court decide whether it can continue to use the software until October. So the vendor has the retailer over a barrel—at least for a while.

But as we move to the “everything-as-a-service” model, the retailer will increasingly not own any of its infrastructure. Not only will the HR systems and processing exist with a vendor (and a cloud provider), but the data will be stored remotely, access to the data will be provided by another vendor, data analytics will be provided by yet another vendor,

For were smell with, and week they using co really was. Water expensive baby prevents Maybelline – prevent followed! Olds Washes your my which that downfall through prescription drugs for severe acne before 2-year-old like the clarisonic. Swipes And have best will. Products works non-reproductive . Looks air canada express jetphotos Micro-dermabrasion what product for cvs pharmacy store locator exactly people you Finally.

etc. There are significant cost, flexibility and other reasons for retailers to go to the “as-a-service” model. But they should think of the relationship as a marriage. And a marriage for which a prenuptial agreement is essential.

In the early days of computers, there were several cases where software developers determined that licensees didn’t make appropriate payments and, therefore, shut down the computer programs.

In 1988, in Franks & Sons Inc. v. Information Solutions Inc., the software developer installed a “drop-dead” code in the program. When the customer failed to pay as promised, the developer activated (or allowed to be activated) the drop-dead code, which kept the customer from accessing the software as well as any stored information. The problem was that the customer didn’t know about the drop-dead code. Under those circumstances, the court found that it would be “unconscionable” to allow the software developer to hold the licensee ransom, essentially using self-help to shut down the business until the developer was paid. The court noted:

Public policy favors the non-enforcement of abhorrent contracts. Here, without the knowledge of Plaintiff, Defendants have included a surprise in their product which chills the functioning of any business whose operation is a slave to the computer. If the Plaintiff had known about this device at the time it entered into the contract with the Defendant then the result would be different. Here it would be unconscionable for the Court to give credence to this economic duress.

However, it wasn’t clear whether the sole problem in that case was the fact that the “drop-dead” software was not disclosed or that the developer, by using the undisclosed code, was holding the licensee hostage.


Comments are closed.


StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.