skip to main |
skip to sidebar
A lot has been written about whether the NSA monitoring of the phone numbers Americans call is unconstitutional or otherwise illegal.
As I have explained elsewhere, monitoring of the numbers we call (and the addresses to which we send emails) is not unconstitutional but should be unconstitutional.
I analyze this issue in The Fourth Amendment in an Era of Ubiquitous Technology, an article I presented at a Fourth Amendment symposium last year. The bottom line is that the Supreme Court inexplicably got all this wrong almost 30 years ago, when it held that the Fourth Amendment does not apply to the use of a pen register to track the numbers dialed from a telephone, even a telephone in someone's home. The Court held, basically, that because we know the phone company gathers this information, we have no right to expect that it will not be given to police.
As many recognized at the time, the decision was wrong when it was issued. The Justices who signed on to the decision concluded that we know we are exposing "private" information to the phone company and, in so doing, assume the risk that it will voluntarily share this information with law enforcement. The Justices who dissented, notably Justice Marshall, pointed out the fallacy in this conclusion: The notion that we assume a risk is based on the premise that we have a choice -- here, to share or not to share this information with the phone company.
As Justice Marshall pointed out, we really have no choice. Our only options are (i) to use technology and run the risk that information about our use will be shared with the government or (ii) to become a Unibomber-style Luddite who does not use telephones . . . or email and other technologies, because the decision applies to any information we share with third-parties.
History is vindicating Justice Marshall and the other dissenters. Unfortunately, I fear it will be a very long time before the Supreme Court re-considers this issue (and, one hopes, gets it right this time).
When property law -- civil and criminal-- evolved, "property" consisted only of tangible items like the land the farm depicted in this photograph occupied, the farm buildings and their contents.
This zero-sum conceptualization of property (i.e., property as real, tangible "things," animate and inanimate) prevailed essentially unchallenged until twentieth-century technologies began to make intangible property a socially and legally significant commodity.
The notion of intangible property was not entirely new. In Europe, the principle that one could hold an ownership interest in an intangible such as the ideas recorded in a printed volume of text or the principles underlying a new mechanical or other invention originated in the fifteenth century, the product, I would argue, of a new technology: the printing press. While one could always use handwriting to record ideas and mechanical principles, printing introduced a new possibility; one could produce many, many copies of such a record, copies that could be distributed throughout the country, throughout the Continent and even beyond.
The concept of intangible property -- specifically, the law of copyright and patents -- evolved to give the "owner" of original ideas some way to control the dissemination and use of those ideas. Controlling dissemination and use had become important because the ideas themselves now had "value;" they could be sold directly (books and, eventually, other works of art/entertainment) or could be used to produce revenue (inventions such as the automobile, telephone, etc.).
The law of copyright, patent and related intellectual property doctrines is now well-established (some, including me, would say too well established with regard to statutes like the DMCA). I am not particularly interested in that law or in the activities it is designed to protect.
What I am becoming interested in, and am writing about today, is a broader notion of intangible property -- something I will call "virtual property" to distinguish it from the more traditional types of intangible property to which we, and the law, are accustomed. Unlike these traditional types of intangible property, "virtual property" has not been incorporated into the law, civil or criminal. I want to speculate about how criminal law should deal with "virtual property."
The first thing I need to do is to define "virtual property," which is not easy. I cannot simply define it as property that exists only in digital form, because this would encompass a great deal of conventional intangible property that is protected by the patents, copyrights or other intellectual property law doctrines which I find uninteresting. But while I cannot base my definition entirely upon this asepct of "virtual property, I can incoporate it into my definition of "virtual property."
The first component of my definition, therefore, is that "virtual property" exists only in digital form. It differs from conventional intangible property, I think, in that its value derives entirely, or almost entirely, from activities that are conducted in the virtual world of cyberspace. As I noted above, the value of conventional intangible property lies in activities conducted in the real-world: We buy a book (printed or on tape) to read (listen to) it in the real-world; the same is true of music; and the same is true of the myriad of inventions (cars, refrigerators, TV's, hair-dryers, elevators, etc.) that have altered the way we conduct our lives in the real-world.
(I know stories and music can crossover from the real-world to the virtual world of cyberspace, but I am using rather broad strokes in this analysis . . . product of its being my first cut at the topic plus space limitations that do not let me use footnotes for lengthy asides.)
The ultimate example of "virtual property" as I define it is property that exists and is utilized in an online environment, such as a massively multiplayer online game or a virtual world like Second Life. Unlike stories (books, movies) or music, this type of intangible property is not transportable; it has value only within the online context. If this "virtual property" could be transported to the real, physical world, it would be meaningless; it would have no use and therefore no value.
So, we now have the notion of a specialized type of intangible property; property that only exists and has value in the context of online activities. From a legal perspective, this notion gives rise to two issues: (1) Do we recognize ownership and other traditional property rights in this "virtual property"? and (2) If so, how do we deal with those who infringe upon these property rights?
The first issue has been analyzed by scholars who specialize in civil property law, about which I know very little (what I vaguely recall from my first year Property class, plus buying a house). I will leave that issue to them. Basically, though, I believe -- and many agree -- there is no reason why we cannot recognize property rights in what I am defining as "virtual property" just as we recognize rights in tangible, real-world property and in conventional intangible property.
I think this recognition is already well on its way; a couple of weeks ago, Business Week had a story on entrepreneurs who earn money (good money) by selling goods that exist and are useful only within the confines of Second Life. These and other "virtual property" entrepreneurs operate on the assumption that they "own" the goods they sell, just as real-world entrepreneurs own what they purvey. And the legal validity of that assumption has been upheld in court; a couple of years ago, for example, a Chinese court held that a gamer "owned" the "virtual property" he had amassed while playing the online game Hongyue.
So I think we can justifiably assume the law protects/will protect ownership interests in "virtual" property just as it does in tangible and conventional intangible property. This first step is not conceptually difficult because it basically requires recognizing, and enforcing, contractual rights among people who are engaging in legitimate activities and are, therefore, likely to be obey the dictates of the law. We see this in the Chinese case I noted above.
The difficulty arises, as it always does, with the outlaws . . . with the people who reject legitimate activity and contumaciously violate contractual and other rights. How do we deal with those who steal or destroy "virtual property"? Do we make this a real-world crime and assign real-world law enforcement officers to apprehend the perpetrators, who are then, presumably, sanctioned in the real-world?
This has been done. Last year, Japanese police arrested a Chinese exchange student who was suspected of participating in "onine mugging" and theft that targeted gamers playing Lineage II. As far as I can tell, the Chinese student was arrested for theft -- for using bots to "run virtual stick-ups" in the game. This seems to be very unusual, though. The Hong Kong Police seem to have a special unit that deals with "virtual property" thefts in online games, but this is clearly the exception. My sense is that most law enforcement agencies would not see this type of theft as a matter they should pursue. I think there are several reasons for this.
One is, I suspect, the unstated but prevalent assumption that, after all, "it's just a game" and an online one at that. I think this assumption undercuts the possibility that law enforcement officers (and, no doubt, legislators and others involved in the articulation and enforcement of the law) will take online theft of "virtual property" seriously in two ways:
- It reflects the view that the gamer-victims assumed the risk of being victimized by playing the game; many online games, after all, routinely feature various forms of mayhem and other antisocial activity. I imagine law enforcers would tend to see this as an anticipated consequence of participating in an optional endeavor and, as such, something that is not their responsibility; they would probably not regard this as "real crime." ("Real crime" being a phenomenon unique to the real, physical world in which our participation and the risks it engenders are distinctly not optional.) It is not, in other words, serious crime in the way real-world crime.
- It reflects the view that "virtual property" is not really property (i) because it does not "really" exist (i.e., exists only online, not in the real, physical world) and/or (ii) because its value, if any, is unstable and therefore insignificant. (In a tragic case last year, a Shanghai gamer reported the theft of a virtual sword he used in Legends of Mir 3 to police, who said there was nothing they could do because the sword was not real property.)
Another reason law enforcement officers (and law-makers) are not inclined to take online crimes involving "virtual property" seriously is an issue I have written about before: There are simply not enough law enforcement resources to deal with cybercrime in any of its incarnations; police therfore tend to triage -- to prioritize the application of the resources that are available to online crimes. This prioritization emphasizes (i) crimes that "harm" individuals, such as cyberstalking, luring children for sexual encounters and child pornography; and (ii) crimes that target "real" property, such as identity theft, extorting money from businesses and the misappropriation of intellectual property.
Yet another reason may be that, as many have suggested, law enforcers and law-makers tend to see this as a matter that should be handled internally, by the operator of the game or those who participate in it. This does happen and can take either of two forms.
- One is vigilantism: When law enforcement does not intervene, gamers have been known to take the law into their own hands. Earlier this year, for example, South Korean Lineage players were massacring Chinese players because they believed Chinese players were stealing "virtual property" from Korean players. (And, on another note, some citizens of Second Life crucified a game player who had been repreatedly killing other players.)
- The other approach is initiated by the operator of the game, and reflects the emergence of customary norms online. Some games, for example, banish griefers (disruptive players) from the game.
Many who have examined the problem of online crime believe "internal" solutions such as these are the appropriate way to deal with online crimes that target "virtual property." Those who take this position tend to assume, I think, that there will always be a clear, radical distinction between "online life" and "real life." They tend to regard "online life" as more analogous to a hobby than to "real life." They therefore conclude that it would be unreasonable to extrapolate the laws and institutions we use to structure "real life" to the unreal, transient, less-than-serious life online.
I think they are wrong. I think we will see -- are in fact already seeing -- the distinction between "online life" and "real life" blur. I think this is evident in the Business Week article I mentioned earlier, the one that focuses on the entrepreneurs in Second Life. We will, for the foreseeable future, continue to live physically in the "real," empirical world, but I think more and more of our activities -- "serious" activities as well as activities some may dismiss as frivolous -- will migrate online.
The production of physical goods and the achievement of physical tasks (e.g., building houses and roads) will necessarily occur primarily in the empirical world. Other endeavors, however, can migrate substantially online; individuals, companies and agencies that provide services can operate substantially online. (Think of what this would do to alleviate the problems we currently experience with commuting to real-world working spaces and the pollution that causes). We will eventually inhabit both the offline and worlds, moving back and forth between them routinely and unconsciously. Earlier this year, a conference was held simultaneously at a site in Cambridge and in the virtual environs of Second Life. And this month the BBC held a virtual music festival that took place simultaneously in the real-world and in Second life.
I'm on the brink of digressing into another topic. What I really want to say is that the "internal" solutions I outlined above are a viable way of dealing with transgressions against "virtual property" as long as it remains a specialized, "lesser" species of property. Entrepreneurs like those described in the Business Week article noted above are already using commerce based upon "virtual property" to support themselves and their families. The trade in "virtual property" does, concedely, seem to be little more than a cottage industry at this point, but it will certainly grow. As it grows, "virtual property" will become more common, will come to play a greater role in our economies (the fused economies that derive from our simultaneously inhabiting the "real" and "virtual" worlds) and will markedly increase in value.
As "virtual property" moves into the mainstream and ceases to be a specialized, "lesser" species of property, we will no longer be able to rely on boutique measures like the internal solutions outlined above to protect it. We will, I believe, have to incorporate it into our legal system, just as we have incorporated the conventional intangible property I mentioned earlier.
I'm in a hotel, having gotten on a plane a few hours ago to come to DC for business.
On the plane I read the May 15 issue of The New Yorker, which has an article by Mitchell Zuckoff called "The Perfect Mark." It's about John Worley, Vietnam veteran, ordained minister and former caretaker of a mansion in Groton, Massachusetts. It's really about how Mr. Worley became a victim of Nigerian 419 scammers, Worley seems to have lost around $80,000 to the Nigerian scammers, but the problems they caused him did not end there.
Zuckoff's account of what happened to Worley is old news to anyone who is familiar with the online 419 scams or with the venerable face-to-face cons they derive from. As Zuckoff notes, the dynamic of these cons is based on a greedy victim who is willing to bend the rules (at least) to enrich himself at, he thinks, the expense of someone else. Worley fits that picture; according to the article, he knowingly passed bad checks, posed as an aviator contractor, filed false documents, plotted to avoid paying taxes on the ill-gotten gains he expected to receive and agreed to bribe officials whose cooperation he believed was essential to the successful completion of the endeavor that would enrich him. All of that is typical of those who become embroiled in 419 schemes; I have heard similar -- though less extreme -- stories myself.
What I find interesting about the article is not Worley's entanglements with the Nigerian scammers. It is what happened to him at the hands of the U.S. Department of Justice: His involvement with the scammers led to his being indicted -- and ultimately convicted -- on various counts of bank fraud, money laundering and possession of counterfeit checks. He was tried in a U.S. District Court in Boston and convicted on October 15, 2005. The judge sentenced Worley to serve two years in prison and to make restitution of approximately $600,000 to those he victmized in the course of his entanglement with the 419 scammers (who were, it seems, really from Nigeria).
Why was Worley prosecuted when he seems to have been a victim? That is what I find interesting about Zuckoff's article. He cites statistics gathered from the U.S. Secret Service and other groups for the proposition that 419 scammers take in hundreds of millions of dollars each year (at least, this figure not including losses by those who are too embarrassed to admit their victimization). I agree with his statistics; 419 scamming is a huge problem for countries -- like the U.S. and many European countries -- whose citizens are victimized by the scammers. It's a very good source of revenue for the scammers in Nigeria and elsewhere (low overhead, no risk of being caught and prosecuted unless you're really, really foolish), which is why it is flourishing.
All of that really was not a digression . . . maybe. It may go to the reason why Worley, who would seem to have been a victim of the scammers he encountered, was prosecuted and convicted of violating federal criminal law.
At the end of the article Zuckoff quotes Barbara Worley, John's wife, as saying that the federal prosecutors "knew they couldn't go after the Nigerians, so they just get the person they can reach." She apparently also said that the prosecutors were "trying to stop people in America from getting involved in it (the 419 scam) by making an example" of her husband. I find that contention very intriguing.
It may simply be the rationalization of a woman whose life has effectively been dismantled by the prosecution of her spouse. I can't tell from this article if her comments are merely this or if she hit the nail on the head . . . if Worley really was made a scapegoat in an effort to deter others from following his lead.
I tend to be a little dubious about the proposition that Worley was prosecuted merely to set an example the rest of us should not follow. For one thing, I never heard of the case until I picked up this issue of the New Yorker, quite by chance. That is surprising since I troll for stories like this and have a number of resources that should bring it to my attention. But, hey, maybe I simply missed it.
But if the purpose were to use Worley as a scapegoat, you would think the case would somehow have gotten more publicity . . . publicity beyond the rather specialized cybercrime-geek circles in which I move. But, again, maybe it was an incremental step, a first effort in a strategy precisely of the type Mrs. Worley posits.
Let's go with that theory, because that is what interests me.
I have written articles in which I argue that we should use selected principles of criminal liability -- including the principle that holds one who aids and abets the commission of a crime guilty as if he had committed the crime himself -- to develop a climate in which citizens resist cybercrime, of all types. My articles focus more on encouraging citizens to secure their computers and resist social engineering in an effort to shore up our defenses against "true" cybercrime, i.e., crimes in which the computer plays a central role and may, indeed, be the target of the crime. My concern has been more with shoring up our computerized infrastructure than with preventing more conventional crimes like the 419 scam. What happened to Worley is simply a twenty-first century version of what has been happening to real-world victims for centuries.
But, as the sources cited in Zuckoff's article note, Worley was the target of activity that is taking millions and millions of dollars out of the U.S., Europe and other "victim" countries. The magnitude of that activity may also warrant new and drastic measures . . . such as holding the victim liable for his victimization plus the incidental victimization he inflicted on others he exploited in his efforts to enrich himself.
If the federal prosecutors in Boston were, indeed, using this theory in their prosecution of Worley, then I find that very interesting. In my articles I argue that this phenomonon of "consequent victimization" -- instances in which John Doe causes "harm" to others by his reckless or knowing conduct -- warrants the imposition of accomplice liability upon Doe because he is not merely a victim. He is a victim because in my scenarios his computer has been taken over by hackers who turn it into a zombie in a botnet of thousands; he is a victim in the Worley scenario (if, indeed, this theory was used in the case) because he was exploited by the scammers who took money from him. In both scenarios, however, the "victim" is also a contributor to the victimization of others, an accomplice in their injury. I see no reason why we cannot hold these consequent victimizers liable for the harm they inflict on others.
The only other instance in which I have heard of something simliar's being proposed involves online gambling. The Bush administration has not made any serious effort to criminalize online gambling at the federal level, but there continue to be rumblings -- at both the state and federal levels -- about the desirability of doing so. The problem is that no one can figure out how to make it work: If an online casino located in, say, Antigua is operating legally under Antiguan law, we could not prosecute the operators of the casino, even if we were to make online gambling a federal crime.
The traditional approach to outlawing gambling has been to target those who provide the opportunities to gamble -- the casino operators. That approach works if the casino operators are operating within the territory of the legal system that has outlawed gambling; it does not work if the casino is in the territory of a country that has legalized gambling. It is a basic principle of criminal law that one cannot be extradited from Country A to face prosecution in C for doing something that is legal in Country A but illegal in Country C. The unfairness is evident.
But I have heard suggestions that we could deal with online gambling by prosecuting the gamblers . . . who are here in the U.S. I have always found that an interesting suggestion, as it, too, involves the prosecution of the victim . . . presumably on the theory that the victim is aiding and abetting the illegal activity, gambling.

Last Friday("Organization," May 5) I explained why cyberspace will alter the structure of illegitimate organizations: gangs and other illicit coalitions.
Today I want to discuss a related issue: why cyberspace will also alter the structure of legitimate organzations, such as corporations, government agencies and the like.
My expertise in crime and criminal law lets me speak with assurance -- and, I think, accuracy -- about the structure and evolution of illegitimate organizations. I am not an expert on non-criminal groups but I have what I think is good reason to believe that cyberspace will also, must also, affect the structure of non-criminal groups, notably, private groupings used to carry out commercial and other types of activity.
Everything I am going to say today derives from (a) extrapolations based upon my analysis of how cyberspace will affect illegitmate organizational structures and (b) anecdotal evidence, the product of my observations of how legitimate organizations function today.
As I explained in my earlier post, hierarchical organization evolved, and triumphed, in the real, physical world because it is a superior way to orchestrate collaborative human effort toward the achievement of various goals: military action; commercial production; large-scale educational activity; government affairs; etc. I explained that criminal groups began to adopt hierarchical organizational forms as they moved from "simple" criminal activity (serial robbery, extortion, and the like) into "complex" criminal activity (bootlegging in the 1920's, large-scale drug production and distribution, etc.). While simple hierarchies suffice for simple tasks (hunting and gathering, robbery), more complex tasks require a more sophisticated division of labor.
In my earlier post I explained that cyberspace will alter this, with regard to criminal organizations, because activity in cyberspace is not subject to the physical constraints we must deal with in the real-world. Cyberspace is, as a result, a much more fluid environment . . . a conceptual, not a physical environment. It is, as many have noted, an environment in which lateral organizational structures are more effective than are hierarchical organizational structures. And that is why, as I explained in my earlier post, I believe we will see different modes of organization emerge for criminal activity in cyberspace; I believe we will see hierarchical structures like the U.S. Mafia families replaced by fluid, lateral, "situational"organizational structures. I think cybercriminals will come together when and as necessary for the collaborative achievement of certain ends, and then go their separate ways, all of which, as I said earlier, will make law enforcement's job that much more difficult.
But I am not talking about criminal organizational structures today. I want to speculate a bit about how cyberspace will (should) impact on legitimate organizational structures, such as the commercial, for-profit corporation. (I could just as easily talk about government agencies, but I am going to pick on commerce today, instead.)
I titled this post "Dinosaurs" because I think the huge, hierarchical organizational structures that are characteristic of the modern commercial corporation are, or soon will become, as antiquated as the erstwhile Brontosaurus (now Apatosaurus) depicted above. The Brontosaurus was one of the largest land animals that ever existed; it was, as a result, exceedingly slow and cumbersome in its movements. Now, that is not a particular disadvantage for a species that exists in an environment in which predators are few and can be effectively discouraged by the animal's size. It would be a significant disadvantage for the species if the environment were to be invaded by predators who were numerous and who were not in the least intimidated by the animal's bulk.
I think this latter scenario is beginning to evolve today, in the clash between cybercriminals and conventional hierarchical organizations. Over the last century or so, corporate and government entities have evolved into huge, unwieldy entities . . . the modern organizational analogue of the Brontosaurus. The increasing size of these entities conferred certain advantages with regard to the conduct of their real-world activities and created no significant disadvantages as long as they, like the Brontosaurus, existed in an environment in which predators were relatively scarce and were disinclined to challenge such large and powerful targets. It was, aside from anything else, difficult for individual criminals or criminal groups to mount a successful physical attack on a multinational corporation. What was there to attack? The entity may have enormous wealth, but where was it and how did one access it? The entity's resources were not concentrated in a specific location in a suitably portable, fungible form. Robbers could rob a local bank, but could do little with the Ford Motor Company or American Express. The size differential protected the larger entities; robbers could figure out where the bank's resources were, but could not begin to penetrate the structure of a multinational corporation.
Cyberspace alters the environment in which corporate (and government) organizations function. Large, powerful and slowmoving, these organizations are no match for online attackers who are already utilizing the more fluid organizational forms I wrote about in my last post.
The analogy that comes to mind (my mind, anyway) is that of a Brontosaurus being attacked by evolved velociraptors armed with a submachine gun and expertise in using it. The velociraptors cannot summon the physical resources the Brontosaurus can, but they are much more nimble, can attack while evading counterattack and can, courtesy of the submachine guns, attack remotely. The size that was once the Brontosaurus' advantage has become its Achilles heel.
I think of this analogy when I hear/read about/otherwise encounter instances in which corporate and other large, legitimate entities are attacked by cybercriminals. From what I see (IMHO), their size and the complexity of their organizational structure is counterproductive in this context. Any effort to respond to cyberattacks by reacting to completed attacks and/or deterring future attacks must proceed through a large, complex institutional hierarchy . . . which means that the effort will move very slowly. Along the way, the effort may be further delayed and/or sabotaged by internal political and other operationally irrelevant motivations. The outcome is likely to be a failure to respond or a response that is ineffectual.
What should we do? How do we modernize our Brontosaurian organizations so they can deal effectively with the challenges emerging in the online environment?
I really don't know. I imagine we will, for a long time, anyway, need hierarchical organizations to carry out certain tasks in the real-world, tasks involving large-scale collaborative human effort. I suspect, though, that we will begin to see hierarchical organization decline in popularity as other types of human endeavor migrate wholly or substantially online where they are conducted by non-hierarchically structured entities.
I watch CBS' NUMB3RS because I find its integration of math and police work interesting, though the stories do tend to be simplistic.
I tivo'd the episode ("Backscatter") that was on this past Friday and sat down to watch it last night. I made it through the first 15 minutes before I gave up, in aggravation.
I was pleased, at first, to see that it focused on cybercrime -- phishing, to be precise. As I have mentioned on this blog, I think that we need to effect a cultural change in order to be able to deal effectively with cybercrime. More specifically, I think we need to make the public aware of the dangers that can lurk online and encourage them to protect themselves from those dangers.
So, I was interested to see that this episode dealt with phishing, which essentially consists of sending emails that are designed to elicit personal/financial information from unwary citizens of cyberspace. The emails usually tell the recipient that his/her bank/credit card account has been compromised and that he/she must contact the institution in question and "reconfirm" their personal information. The emails send the recipient to a fake website that masquerades as a site created by their financial/other institution. The information they provide to the fake website goes directly to cybercriminals who have successfully "phished" for it.
As this episode began, two "hackers" were wardriving to locate an unsecured wireless network that would give them access to credit card numbers. Sure enough, just before they were nabbed they logged into one -- "David's network" -- and began downloading a database of credit card numbers. I have two problems with this, so far: First, it's not phishing; it's hacking, pure and simple. That is, instead of tricking someone out of their credit card information, these guys simply "broke into" a database and attempted to steal the information it contained. My other problem with this part of the portion of the episode I stuck with is the name of the network: Do we really believe that, say, Citigroup or AmEx calls the databases in which they store credit card data by someone's given name? I may be way off base here, but somehow I find that very hard to believe.
But that's only the beginning. The two "hackers," clean-cut American youths, are interrogated and quickly give up the people they're working for . . . who are members of the Russian mob. The American "hackers" got involved with the Russian mob when Russians approached them in a cybercafe located in, I guess, LA, since that is where the show takes place. This is about the point at which I bailed and erased the episode.
I was, at first, pleased to see that a TV show, a network series, was focusing on cybercrime. I was extremely aggravated when it became apparent that the treatment of cybercrime was going to be indistinguishable from the treatment of the other types of crime the show deals with; that is, the indefatigable FBI agents and their clever-albeit-quirky academic support staff were going to be dealing with bad guys who were physically located in their "neighborhood" (LA, California). So instead of having to deal with nameless, faceless cybercriminals who operate remotely from, say, Moscow, the agents and their supporters could deal with these phishers (I assume we got to that point, somewhen) as they deal with all the other bad guys who are featured in the various episodes of the series: They use good old fashioned police work plus a soupcon of advanced math/other scientific knowledge to track them down, probably have a shoot-out or some other physical confrontation, then haul them off, making the world (and cyberspace) secure, once again.
I know I should have stuck with the show, but it was aggravating me and I had something else I wanted to do. Maybe I'll watch it when it's on again, sometimes . . . maybe not.
Seems to me that the message this show sent about cyberspace and the miscreants who lurk there is directly counterproductive: An uninformed viewer who watched the episode would get the distinct impression that, while we do need to be careful when we're online, especially with our personal/financial information, cybercriminals are basically like any other type of criminals. They hang around our neighborhoods, especially cybercafes, and can therefore be identified and apprehended like any other criminal. Bottom line: Don't worry about cybercrime; the FBI has it covered.
That just ain't so.
In an article published several years ago, I argued that cyberspace will change the existing structure of criminal groups. (Organized Cybercrime: How Cyberspace May Affect the Structure of Criminal Relationships, 4 North Carolina Journal of Law & Technology 1 (2002)).
We have had criminal groupings for millennia, but as I explain in the article, the last century saw the emergence of a specialized type of criminal organization: the hierarchically organized gang.
The hierarchically organized criminal gang was developed in the United States in the first several decades of the twentieth century. It was the product of several interacting forces, one of which was the Mafia. As everyone knows from The Godfather, the Mafia is a criminal group that evolved in Sicily in the nineteenth century; Sicilian immigrants brought the Mafia to the United States, and it became particularly influential in New York. Another interacting force was the Volstead Act, which outlawed the production and sale of alcohol in the United States. As many have noted, the Volstead Act actually made alcohol much more popular than it had been before; this, in turn, created new opportunities for those who were willing to defy the law and supply the public with the liquor it demanded. The Mafia quickly took advantage of these opportunities, especially in cities like New York and Chicago; Mafiosi like Al Capone and Lucky Luciano (and independents like Roy Olmstead in Seattle) became leaders of large-scale bootlegging operations that manufactured (or imported) liquor and distributed it to speakeasies and other illegal outlets.
The large-scale bootlegging these operations carried out resembled the activities of legitimate business more than it did that of the criminal activities the Mafia and other criminal groups had traditionally carried out. As I explain in the article cited above, criminal groupings -- gangs -- had historically focused on rather basic criminal activity: robbery, murder for hire, extortion, etc. Aggregating several/many criminal together into a single group could increase the efficacy with which these crimes were committed by bringing more manpower to bear and, perhaps, allowing for a rudimentary division of labor among robbers, extortionists and the like. But these crimes, and the groups that carried them out, were very much focused on crimes of the moment -- single criminal episodes that were carried out, after which the perpetrators moved on to other similar or dissimilar episodes. There was, as I explain in the article, a basic division of labor between leader and his followers; in larger groupings, there could be a division of labor between a leader, one or more subordinate leaders and their followers, but the organizational structure remained rudimentary, since that sufficed.
As I explain in the article, alcohol prohibition caused an empirical shift in certain criminal groups, most notably the Mafia. Large-scale bootlegging required a much more sophisticated division of labor, essentially a corporate division of labor. As military and government groups have known for a long time, hierarchical organizational structures are an effective way to mobilize personnel for the accomplishment of tasks in the real, physical world. A hierarchical structure therefore evolved in groups that were involved in bootlegging; as some have noted, the structure of these groups eventually came to resemble the organizational model found in modern corporations. Because this hierarchical structure proved advantageous for the American Mafia, it persisted and spread to other emerging groups, such as the Yakuza and drug cartels.
Hierarchical, pseudo-corporate organizational patterns have consequently become a defining characteristic of modern "organized" crime. And I am sure these patterns will persist for criminal groups that continue to engage in illicit activities in the real-world. I do not, however, think they will be characteristics of criminal groupings that engage in illicit activities in the virtual world of cyberspace as we know it or as it will presumably evolve over the next centuries. As I explain in the article cited above, hierarchical organizational structures are not adaptive for activities that are carried out online. Hierarchical structures are essential for concentrating human and other resources to overcome the constraints of the real-world to pursue activities such as constructing buildings, manufacturing goods (legal and illegal) and waging war; hierarchical structures are not particularly useful when the physical constraints of the real-world become irrelevant.
In the article I cited at the beginning of this post, I explain in more detail why that is true and I speculate as to how criminal organizations will adapt to this new environment. I postulate that we will see new, lateral modes of criminal organization evolve to conduct crime online. One thing that I think will differentiate these new modes of criminal organization from the hierarchical model of "organized" crime that emerged in the last century is the continuity of personnel: As we all probably know from The Godfather and The Sopranos, continuity of personnel is an essential characteristic of Mafia-style criminal organizations; aside from being the product of familial ties, continuity ensures stability and helps maintain loyalty to the organization and prevent its being infiltrated by law enforcement. I do not think continuity will be an aspect of online criminal organization because I do not think it will focus on the kind of territorially-based criminal activity that is an essential characteristic of real-world organized crime.
I think online criminal organization will be much more situational. Criminal groupings will come into existence for the purpose of carrying out particular criminal activity and disband once the activity is complete. I think online criminal organization will be lateral rather than hierarchical in nature; it will represent a collaboration among equals instead of being based on a hierarchical chain of command.
If I am right about these and other aspects of online criminal organization I outline in the article cited above, then law enforcement's task will become much more difficult. The hierarachical organizational structure common to Mafia-style criminal organizations may make it difficult for law enforcement officers to infiltrate those organizations, but it also makes the organizations and their membership easy targets for law enforcement. Aside from John Gotti--like flamboyance, the permanence of the organizations and the stability of their membership makes it relatively easy for law enforcement officers to track their activities in the real-world. This, in turn, makes them more vulnerable, which no doubt accounts for what seems to be a decline in the influence of the Mafia and similar groups.
This is a follow-up to my last post, about security.As I have written elsewhere (I know I keep saying that, but it’s true), our goal is to keep crime on line to manageable proportions, to maintain the necessary baseline of order for cyberspace to function as an analogue of the real-world. In the real-world, we maintain a baseline of order which allows societies to carry out the functions they must if they and their constituents are to survive and prosper. We cannot eliminate real-world crime, but we control it, using the law enforcement strategy I talked about yesterday and have talked about here and elsewhere (yes, again).We cannot, as I have explained before, use the reactive law enforcement strategy we use for real-world for cybercrime because cybercrime is different. We need a new strategy, one that involves citizens as well as law enforcement. We still retain the traditional, reactive law enforcement strategy but we supplement it with preventative efforts implemented by individuals and entities.I see cyberspace as analogous to Europe after the fall of Rome. The mechanisms that had maintained the necessary modicum of order in society disappeared, leaving a state of disorder, anarchy. There were no nation-states to maintain order within a demarcated territory; indeed, there were no functional territorial boundaries. Crime control was purely a civilian function; members of communities shared responsibility for apprehending criminals. In medieval England, male adults were required to possess weapons they could use in apprehending and subduing a criminal; the practice was for someone to raise the “hue and cry” when a crime had been committed, after which men in the local community attempted to catch the perpetrator, who would then face certain, rough justice. This model prevailed until the 19th century, when Sir Robert Peel invented the modern police force and eliminated civilian involvement in security.We need to restore civilian involvement, at least in securing cyberspace. We need a culture change; we need for people to understand that cyberspace is not like the safe, predictable environment many of us inhabit; it is, instead, analogous to the out of control world Europeans confronted after the fall of Rome. It was up to them to take care of themselves, and it is up to those of us who inhabit cyberspace to do the same thing.I have written extensively about this, but I have not seen it mentioned in the popular press or anywhere else . . . except for the National Strategy to Secure Cyberspace. The White House released the National Strategy in 2003. It calls for civilians – individuals and entities – to assume responsibility for protecting themselves online and thereby helping to prevent cybercrime. It makes this assumption of responsibility a purely voluntary act; there are not consequences if one does not assume responsibility and does not make an effort to prevent cybercrime. Perhaps for that reason, the National Strategy rather quickly disappeared from public view and public discourse.As I have argued elsewhere , we cannot rely on a voluntary approach to achieve civilian involvement in controlling crime in cyberspace. We need a culture change, and while that might occur on its own if we pursue a voluntary approach, it will take a very long time for the process to be complete. I do not think we have a very long time; I think cybercrime (and cyberterrorism) will only become more pervasive and more destructive, since there is little chance a clever cybercriminal will be apprehended and sanctioned. I have written extensively about how we can use law, notably criminal law, to jump-start this culture shift. I do not claim to have devised the perfect solution for this problem; all I really want is to bring it into public consciousness and see us making some serious effort to address it.

“. . . all I could see in London's packed Olympia conference centre was an industry united in a profitable celebration of the failure of our society to properly protect itself from the dangers of living an increasingly online existence.”Simon Moores, What’s the Point of Security?, Silicon.com (April 26, 2006).
Moores is describing his reaction to the speakers and displays at a recent British computer security conference. As I have noted in earlier posts (e.g., "Treaty," April 16, 2006), I agree with him that our society notably (some might say "criminally") unsuccessful in protecting itself from online dangers. As I have explained elsewhere, our failure is due to our continuing reliance on an outdated model . . . the reactive model of law enforcement we use to control real-world crime. As I have also explained elsewhere, that model is ineffective, at least as our sole crime control methodology, for cybercrime because cybercrime differs in several critical respects from real-world crime, the type of crime the model evolved to control.
I agree with Moores that we are doing a miserable job of protecting ourselves online. And I can understand his reaction to the conference that prompted it -- while I tend to avoid commercial cybersecurity conferences, I, too, have on occasion found myself discouraged by the overt commercialization of efforts to secure our activities online . . . efforts, I might note, that are not proving particularly successful. I tend to have the same reaction to this that I did several years ago, when I went to a Homeland Security Conference in the US . . . and visited the Exhibition Hall where commerical vendors were displaying what I regarded as a parade of horribles: Huge supplies of body bags, portable radiation detectors and protective gear, devices for dealing with the outbreak of hideous, exotice diseases, etc. It was horrible because of the spectres it raised and it was horrible because people were dedicated to profiting from the anticipation (if not the realization) of these spectres.
I differ slightly from Moores in that I believe, as I have explained elsewhere, that a critical first step in changing the current status quo, in improving our ability to protect ourselves online, is effecting a sea change in our culture: We must inculcate the realization that we all -- schools, businesses, religious organizations, individuals, charities, government agencies, etc., etc. -- now bear a significant portion of the responsibility to control online crime. If these commercial events help inculcate that realization, then I think they are accomplishing something . . . aside from enriching the companies that participate.
The problem I see with these events (and analogous events that target only government officials and agencies) is that they do nothing to help the general public realize that they are, in effect, our frontline in controlling cybercrime. One of the currently more exploited tools of cybercrime is the botnet . . . a assemblage of "civilian" computers that have been taken over by cybercriminals and turned into zombies which do the cybercriminals' bidding. Botnets are used for various activities; they are advantageous because of the expanded power they give cybercriminals, and because they serve as an effective buffer between cybercriminal and police. If police track down the source of an attack, they will find the "civilian" computers that constituted the botnet, not the actual perpetrators of the attack.
We desperately need to make the civilians who participate in cyberspace aware of the dangers that lurk there, including the danger (and consequences) of having their computer turned into a botnet. The conferences Moores writes about do nothing to accomplish that, which I see as the real tragedy. I agree with him that commercial motives are so far driving the efforts to develop "civilian" cybersecurity, efforts which are notably unsuccessful. My primary concern, however, is that because these commercial motives focus only on large organizations, the general populace, which is the true Achilles heel of any modern, online society, is going ignored.
In my last post and in many earlier posts, I address various specific issues but in all of them I am really talking about a single theme: Computer technology lets us do things we could never do before: defraud someone on the other side of the world without leaving our armchair; feature our neighbor in violent fantasies we publish online; track someone's movements without having anyone actually follow them, and so on.
Technology lets us do things we could never do before, but law is still focusing on the old ways, on the things we have always been able to do. That is the nature of law -- it tends to be conservative, which is probably a good thing. We do not, after all, want to find ourselves dealing with the "law of the day" -- a statute the legislature threw together in haste to address what seemed a critical, and immediate, new problem.
As I noted in my last post ("Tracking Devices"), our judicial and legislative processes move very slowly, which becomes problematic when technology -- all kinds of technology -- evolves very rapidly. We need to figure out how we can reconcile law-making as a conservative, deliberative process with technological advancements that change the very fabric of society by letting us do things we could never have done fifty or even ten years ago.
How can we do this? Should we revise our law-making processes to, say, implement a "rocket docket" in our judicial systems that speeds cases through the levels of the system more swiftly, the result being that we generate more opinions dealing with the consequences of emerging technology? We could, I am sure, do something similar with our legislative processes, as well.
The problem is that simply speeding up the system would no doubt give us more law, but there is no reason to believe it would give us better law. Emphasizing accelerated law-making would probably give us "laws of the day" (or "laws of the week") . . . hastily assembled legislation or judicial opinions that react to specific issues, instead of articulating broad, flexible standards that have a broader application and therefore a much longer half-life.
IMHO, instead of trying to speed up the law-making process, we need to focus on what laws -- at least criminal laws -- really need to be concerned with. As I have explained elsewhere, laws are devices societies use to maintain order; laws tell us which behaviors are acceptable and which are not. "Civil" laws ensure that various processes -- e.g., traffic flow and the transfer of title to property -- proceed in an organized, predictable manner. "Criminal" rules prevent members of the society from preying on each other, fiscally, physically and emotionally.
Laws are therefore directed at human behavior. Although technology vastly expands the ways in which we can manifest human behavior, I do not think it fundamentally alters the nature of human behavior. If that is true, then it seems to me we can adapt law to changing technologies by focusing on the behaviors we want to encourage or discourage, instead of on the technology. The technology only serves as a vector for a particular behavior; our concern, therefore, is not with outlawing the technology, but with outlawing unacceptable uses of that technology.
How do we decide what is, and is not, an "unacceptable" use of a technology? My field is criminal law, so I shall focus on how this decision should be made with regard to criminalizing certain uses of technology.
Substantive criminal law -- the law that defines offenses -- focuses on a particular "harm." So, rape inflicts the "harm" of forced sexual intercourse, murder inflicts the "harm" of taking one's life, theft inflicts the "harm" of taking someone's property, and so on. If we focus on the "harm," and not on the technology, we stand a better chance of adopting laws that will have a more general applicability. This, after all, is what we have done for millennia; our criminal laws have always been behavior-based, not implement-based.
This all depends, of course, upon whether the range of human behaviors is stable enough that the emergence of new technologies will not significantly expand it. I think it is, and I think there is a correlation between behaviors and "harms."
To understand why I say that, we need to consider why people commit crimes. Basically, I think people commit crimes for two reasons: (i) rational goals; and (ii) passion.
Robbery is a classic example of a rational-goal crime; the goal is to enrich oneself by taking money or other property from someone else. The same is true of most property and white-collar crimes, such as fraud, forgery, blackmail, extortion, embezzlement, bribe-giving and -receiving, etc. It is also true of crimes like drug-dealing, which are not really property crimes but which share the same premise. In all these crimes, the infliction of "harm" on another is the product of a simple rational calculation: the (illicit) transfer of money or property from the victim to me enriches me, which I regard as a desirable outcome. Not surprisingly, most criminal activity in a society consists, and has always consisted, of rational-goal crimes; and that will continue to be true as long as the enhanced possession of wealth is seen as desirable because it gives one access to increased opportunities for pleasure, for status, for travel, for whatever one desires.
I define "passion" crimes more broadly than some. The press tends to use the term "crime of passion" to refer to a crime in which one person killed another in a highly emotional state; a good example of this is the case in Houston several years ago, when a wife ran her husband down after she realized he was still seeing his mistress. I would certainly include that crime, and comparable crimes, in my "passion crime" category. But I would also include the activities of pedophiles, necrophiles, cannibals and others with, shall we say, unconventional sexual drives in that category. I define "passion crimes" as the antonym of rational-goal crimes; I see them as crimes the commission of which results from an emotional calculus, not a rational calculus.
If all of this is true, and crime is the product of a limited range of human motivations, then I think we will tend to see technology used to commit crimes that, ultimately, are very similar to what we have seen historically. Some of this is already evidence: I occasionally see a press story about an "Internet murder," which always refers to an instance in which someone used cyberspace to set up a meeting with a potential victim whom the perpetrator then killed. I don't see this as a cybercrime; I see this as murder, nothing more. The same is true of cyberfraud, cyberextortion, cyberblackmail, etc.
Not all undesirable online activity falls within traditional crime categories, of course. In my posting on "Fantasy" a few weeks ago, I explained how cyberspace lets someone publish fantasies -- explicit sexual or violent fantasies -- online in which they feature, say, a friend, a neighbor or an ex-lover as the victim of the fantasized activity. Imagine this happened to you: Imagine someone was publishing an ongoing series about raping, torturing and/or murdering you, and someone brought the series to your attention. It disturbs you, of course. But what is your recourse? You can try to sue the person responsible for . . . I'm not sure what. It's not really defamation (it's "art") or invasion of privacy or libel. It might constitute infliction of emotional distress, if you are in a jurisdiction that recognizes that cause of action . . . but even if you can sue, do sue and win, it's probably a Pyrrhic victory. The perpetrator probably has no money, so you will be stuck with your legal fees. And the perpetrator may simply transfer the fantasies (and perhaps himself) to another jurisdiction, one in which your civil judgment is irrelevant.
So maybe this is an area in which we need new law. I suspect it will be. If we decide to develop law in this area, we need to focus not on the use of a particular technology but on the infliction of a particular "harm." This, as I noted earlier, is a passion crime. The passion may be to torment the victim, to "control" the victim in a sense or some other emotional calculus that eludes me but that is, in the end, irrelevant. We need to remember our goal: To maintain order in our society by preventing people from inflicting "harm" on others. To do that, we need to craft a rule, a good, general rule, that criminalizes behavior that inflicts this type of non-physical "harm" on someone.
I hope this has made some sense. It's part of something I have actually been thinking a lot about and have written some about. It is, as you can probably tell, still very much a work in progress.
The Fourth Amendment is the constitutional provision that protects citizens from having their privacy arbitrarily invaded by the government. The Fourth Amendment requires the government to get a warrant or invoke an exception to the warrant requirement before it can invade your privacy by, say, searching your home or office.
In my posts "Cartapping" (February 12, 2006) and "Can You Trust Your Car?" (April 19, 2006), I talked about the extent to which the Fourth Amendment applies to the government's using technology installed in your vehicle to eavesdrop on what you say while in the vehicle.
In this post I want to talk about something different: whether the Fourth Amendment applies to the government's using computer technology to track your movements in public areas. Until relatively recently, the only way the government could do this was to have police officers follow someone, and the Supreme Court has held that following someone is not a "search" under the Fourth Amendment. Searches invade a reasonable expectation of privacy, and it is simply not "reasonable" to say that my driving down city streets or on a highway is "private," since anyone who happens to be in the area, or who is inclined to follow me, can where I am and infer where I am going. And in United States v. Knotts, 460 U.S. 276 (1983), the Supreme Court held that it was not a "search" for law enforcement officers to use a beeper installed in a vat of chemicals to follow a car; the vat was in the car, and the signal it transmitted helped the officers to follow the car to its final destination. All the beeper did was to send out an audible signal that became stronger when the officers were closer to the car and weaker as they fell behind.
Beepers have become antiques. Today, police use one of two techniques to track someone's movements:
- Use an individual's cell phone to track her movements: If the cell phone is on (and maybe even if it is not), the cellular phone service provider can tell where the person carrying the cell phone is. This can be done in two ways: The older method is to use signals from cell phone towers to identify where a particular cell phone is located; cell phones continually send out registration messages to cell phone towers in the area. It is possible, using a technique called triangulation, to use these messages to pinpiint the location of a specific cell phone, and track its movements. The newer method is to use GPS receivers installed in the cell phone; several years ago, the Federal Communications Commission mandated that, by the end of 2005, new cell phones have GPS technology installed. The purpose was to make it easier to find someone who had been injured in say, a car accident, and could call for help but could not explain where he was.
- Install a GPS tracking device on someone's vehicle and use it to track her movements: The tracking devices are small, and can easily be installed on a vehicle without the owner's knowing it. Unlike the beeper at issue in Knotts, they do more than simply send out a signal that helps humans follow a vehicle. GPS devices track a vehicle's movements automatically, sending the information to a receiving unit in a police station or other central facility. This means, of course, that no officer actually has to follow the vehicle; the GPS device automates the process. It also means, as some courts have noted, that the process of tracking the vehicle is vastly improved; the GPS device tracks the vehicle's movements on an uninterrupted 24/7 basis for as long as it is installed . . . for weeks, say. As some judges have noted, this type of tracking is realistically impossible for law enforcement agencies with limited resources.
The issue that is currently being litigated by federal prosecutors, privacy advocates and defense attorneys is whether the use of either of these tracking techniques constitutes a "search" under the Fourth Amendment. If it does, then the agents who want to use one of the techniques must obtain a search warrant from a duly authorized magistrate, and must ensure that the tracking stays within the scope of the warrant. If it does not, then the agents may have to get an order from a court authorizing the installation and use of the device, but they will be proceeding under statutory provisions that are far less demanding than the Fourth Amendment.
These tracking techniques illustrate a major problem we are facing with regard to privacy: How do we maintain the balance between privacy and legitimate law enforcement activity in the face of rapidly-evolving technology?
As I noted above, the only Supreme Court case on point for the use of these tracking techniques is Knotts . . . a 23-year-old decision that dealt with comparatively primitive technology. We do have, as I also noted, a number of decades-old federal statutes that establish processes agents must use to, for example, have a telephone company install a device that captures the numbers dialed from a phone, but they really do not apply to the use of cell phone GPS technology.
Nor is it clear whether the installation of a GPS tracking device on a vehicle is constitutional under Knotts. As I said, the use of such a device clearly results in the collection of information that far exceeds what a typical police department could accomplish by using human resources. Courts are struggling with whether that takes the use of a GPS tracking device out of the holding in Knotts and transforms it into a Fourth Amendment "search" that can only be conducted with a warrant.
So, what should we do? How should we resolve these issues?
Traditionally, we would (a) wait until the issue had made its way through the lower courts to the Supreme Court, which would issue a definitive opinion; and/or (b) adopt legislation that dealt with the problem. (Congress has, in this general area, tended to adopt statutes that implement and sometimes exceed the requirements of the Fourth Amendment.)
There are two problems with following this traditional approach in an era of rapidly-evolving technology:
- It can take forever for a case to make its way to the Supreme Court, be argued, and then decided. (And this Supreme Court takes very few cases -- roughly 75 a term, I believe.) If that decision enunciates a broad standard, then that standard can be extrapolated to help us deal with issues other than the specific issue (and technology) that went to the Court. But if the Court issues a very limited decision, that decision, and this whole process, will be of little help as we attempt to sort out the rapidly emerging legal issues generated by new technologies. The Court did precisely this, i.e., issued a very limited decison, in Kyllo v. United States, its 2001 pronouncement on the Fourth Amendment's applicability to law enforcement use of technology. In Kyllo, the Court was asked to decide if the use of a thermal imager to detect heat emanating from a structure is a Fourth Amendment "search." In a majority opinion written by Justice Scalia, 5 Justices said it was. More precisely, they said it is a "search" (i) to use technology that is not in general public use to (ii) detect information from inside a home, information an officer could not get otherwise except by going into the home. This holding is limited and inherently ambiguous (what happens when technology is in general public use? what happens if it's not a home?) . . . which means it is of little assistance in sorting out issues generated by law enforcement's use of evolving technologies. Unless the Supreme Court changes its approach to deciding cases like Kyllo, this alternative is not likely to be particularly helpful in resolving the dilemma I am writing about today.
- It can take a very long time (maybe not forever) for a legislature (Congress or a state legislature) to adopt statutes that address issues such as the cell phone or GPS tracking. And when a legislature does act, it tends to adopt technologically-specific legislation . . . like the statute I mentioned above, the one that governs the use of a device that captures the numbers dialed on a traditional landline phone. This, of course, means that the statute may well be out of date by the time it goes into effect.
I am not going to propose a solution to this problem today. This happens to be the area in which I am currently writing; I have a very long law review article coming out that deals with these and other issues generated by our need to apply legal standards to new technologies. I will try to summarize that article in another, later post.
This is Klaus Fuchs. During the 1940's, he gave the Soviet Union, a US-British ally, information about the United States and British efforts to develop nuclear weapons. Fuchs' efforts finally came to light, and in 1950 he was convicted of espionage -- supplying military secrets to a country with which neither the U.S. nor Britain was, or had been, at war.
Basically, treason consists of giving "aid and comfort" to the enemies of the United States. Fuchs could not be convicted of treason because the U.S. was not at war with the Soviet Union when he passed on its nuclear secrets; indeed, for much of the period, the U.S. and the Soviet Union were allies in the struggle against the Axis powers.
Espionage is similar to treason, in that it also involves collecting evidence which a country wants to keep secret.
In 1951, Julius and Ethel Rosenberg were convicted of espionage for transmitting "information relating to the national defense" to a foreign government -- the Soviet Union (again). Like Fuchs, they supplied information about the U.S.' nuclear weapons program; like Fuchs, their convictions were predicated on a traditional form of espionage, one that involved information that could be used to gain tactical advantage in the case of an armed conflict between two nations. Espionage offenses were historically a derivative form of treason.
In 1996, the U.S. adopted the Economic Espionage Act (18 U.S. Code sectons 1831-1839), which expanded the concept of espionage to include the surreptitious gathering of information that could be used to gain economic, rather than military, advantage. The Act is unique; not only do other countries lack such legislation, but many countries actively engage in economic espionage. This includes countries that are otherwise allies of the United States, such as France and Israel; each year, a report is submitted to Congress which documents the extent of these activities.
The Economic Espionage Act was intended to combat these activities by criminalizing them. It prohibits the theft of "trade secrets," which are defined as a "formula, practice, process, design, instrument, pattern, or compilation of information used by a business to obtain an advantage over competitors within the same industry or profession." Unlike treason or conventional espionage, economic espionage focuses on "civilian" information; it is predicated on the recognition that countries compete economically as well as militarily. Indeed, many argue that we are currently engaged in economic warfare with various countries, including China.
I discuss this and other aspects of economic espionage in a law review article this will soon be published by the Houston Journal of International Law. The article should be available online at their website. If you want to read more about this, I suggest you read the article ("State-Sponsored Crime: The Futility of the Economic Espionage Act") . . . which should be online soon.
The Economic Espionage Act creates two distinct crimes: 18 U.S. Code section 1831 criminalizes "economic espionage," which consists of stealing U.S. trade secrets in order to benefit a foreign government. So, a section 1831 offense occurs when, say, an Israeli agent steals confidential proprietary information from a U.S. drug company and transmits that information to sources in Israel, the goal being to improve Israel's ability to compete in this area. 18 U.S. Code section 1832 makes the theft of trade secrets a crime; it focuses on domestic activities, thefts that are intended to benefit individuals or entities within the United States. A section 1832 offense would occur if, say, research scientists working for Company A stole secret proprietary information from that company and used it to open their own, rival company.
Economic espionage, the type of activity criminalized by 18 U.S. Code section 1831, is the more serious of the two for at least two reasons:
- It results in the transfer of proprietary information to a foreign power, which erodes the U.S.' ability to compete in the global marketplace. The U.S. loses a tactical advantage in the evolving economic war among nations, just as it lost a tactical advantage to the Soviet Union when Fuchs and the Rosenbergs transmitted nuclear secrets to agents of that country. The point here is that economic espionage directly damages the country, while the theft of trade secrets generally damages a company.
- It is MUCH more difficult to control. In 1996, the U.S. decided that stealing trade secrets, or economic espionage, was of such significance that it warranted creating new criminal offenses -- criminal prosecution being the traditional means we use to control undesirable behaviors. As I have explained elsewhere, however, criminal prosecution is effective only against traditional, real-world crime. The domestic offense the Act created -- the theft of trade secrects -- is sufficiently analogous to real-world crime that criminal prosecution may be an effective means of dealing with it. (Though even here I have reservations, for reasons I explain in the forthcoming article I noted above). The economic espionage offense is very different, however, for several reasons . . . the most important of which being that it is state-sponsored crime.
As I explain in the article I cited above, state-sponsored crime is not amenable to criminal prosecution even when it comports with the empiricial model of real-world crime, that is, even when it is committed by an individual agent of a foreign government who is physically present in the United States, physically misappropriates proprietary information from an entity in the U.S. and physically transports that information abroad. Criminal prosecution is generally futile in this scenario because the agent's activities are sponsored by a foreign government, which will almost certainly decline to return the agent to the U.S. for criminal prosecution.
The futility of pursuing criminal prosecution becomes even more evidence when economic espionage is conducted remotely . . . when the agent of the foreign government hacks into a U.S. business' computer system, extracts data containing proprietary information and downloads it to a computer in the foreign country. Here, the U.S. has absolutely no chance of apprehending the perpetrator while she is conducting her nefarious activities. Its only chance to pursue criminal prosecution depends upon the agent's own country's being willing to surrender her for prosectution which, again, is extremely unlikely.
It is unlikely because the agent was, after all, operating on behalf of the foreign government; it is therefore as unlikely that the foreign government would give this civilian spy up to be prosecuted as it is that the U.S. would surrender a CIA agent who had been operating covertly in another country to be prosecuted for espionage by that country.
It is also unlikely because, as I noted at the outset of this post, economic espionage is not regarded as a crime in most countries. It is a basic principle of international law that countries will not, and do not have to, surrender their citizens to be prosecuted in Country X for activity they conducted while they were in their own country and that was legal in their own country.
This is a very long post, and this is a very complex issue. I think I will come back to it again, in another post. In the interim, you might want to check out that article.
This post is essentially a fusion of the ideas I threw out in my post on "Cartapping" (February 12, 2006) and the 1996 paper, Information Terrorism: Can You Trust Your Toaster?, written by Matthew G. Devost, Brian K. Houghton & Neal A. Pollard.
In my cartapping post, I explained how the FBI had used a cellular connection that was a component of an emergency services system -- analogous to if not precisely the GM OnStar system -- to eavesdrop on conversations held in a car. My point there was how embedded environmental technology can be deliberately exploited by law enforcement for evidence-gathering purposes. The greater issue, of course, is how technology can, and will, erode our privacy IF we cling to what I call a bricks-and-mortar conception of privacy, i.e., a conception of privacy which says that if I do not use physical barriers to shield my activities from law enforcement scrutiny, then they are not "private" under the Fourth Amendment.
(As I've explained before, if something is "private" under the Fourth Amendment, then law enforcement officers have to satisfy the Amendment's requirements by getting a search warrant or relying on an exception to the search warrant requirement before they eavesdrop or conduct other invasions of privacy. If something is not "private" under the Fourth Amendment, then they do not need to rely on a warrant or an exception -- the person who did not maintain the privacy of his or her activities bears the risk that law enforcement will scruntinize them.)
So, "Cartapping" was about how law enforcement can deliberately exploit technology embedded in our environments. The DeVost article is about how embedded technologies can be exploited by terrorists and others who wish to do us harm . . . hence, the issue of regarding one's toaster with a level of distrust.
My post and the DeVost article are both about how embedded technology -- technology we take for granted and so ignore -- can be exploited to (i) cause direct physical harm to citizens or (ii) to inflict a more indirect harm by subjecting them to law enforcement scrutiny without their knowledge or consent. Both are about direct, positive action by directed at a target . . . a target of terrorists for the authors of the DeVost article and a target of law enforcement for my "Cartapping" post.
A relatively recent news story highlights an additional, and equally interesting possibility: Ralph Gomez of St. Augustine, Florida, bought a new Cadillac and was showing the car and its OnStar system off to his girlfriend. Something went horribly awry -- the OnStar operator for some reason tried to contact Gomez, but the volume on his OnStar was set so low he couldn't hear the operator calling him. Concerned (and no doubt following standard operating procedure), the operator called police, who stopped Gomez' car to see if there was any emergency.
There was no emergency . . . but there was, according to the wire story, cocaine in plain view on the car's console. That resulted in Gomez' being arrested for illegal drug possession AND his car and cash he had in the car's being seized, presumably for forfeiture.
I find this case an very interesting twist on the issue the DeVost authors and I both raised, i.e., the deliberate exploitation of technology to the disadvantage of a citizen (investigation) or citizens (terrorism). Here, no one deliberately exploited the OnStar system. Instead of being highjacked for law enforcement eavesdropping or used for terrorism, it functioned precisely as it was intended to . . . and, in the course of doing so, ratted out Mr. Gomez.
So, can you trust your car?
As I have explained elsewhere, the major problem law enforcement faces in dealing with cybercrime is the lack of cybercrime laws in some countries and the inconsistencies that exist between cybercrime laws in other countries.
Cybercriminals can, and are, exploiting these gaps and inconsistencies to their advantage: If there is no law criminalizing, , say, the dissemination of a computer virus, then the person responsible for the virus cannot be prosecuted in his home country and cannot be extradited to be prosecuted in other countries harmed by the virus. (It is a basic principle of international law that someone cannot be handed over by Country X to Country Z for prosecution unless the conduct at issue was a crime both in Country X and Country Z; this is known as the principle of "double criminality".)
Other problems arise in the investigation of cybercrimes. Basically, under international law, Country X is not obligated to assist Country Z with the investigation of a crime committed in Country Z unless there is an agreement -- a mutual legal assistance treaty -- in effect between the two. (There are other methods by which Country Z can request assistance from Country X, but they are cumbersome and time-consuming.) Cybercriminals can exploit the lack of a treaty between two countries: A cybercriminal can set up operations in Country Z and victimize citizens of Country X, knowing that the authorities in Country Z cannot assist police from Country X in their investigation of these cybercrimes. This is a very simple example, but I hope it makes the point.
In an effort to address this problem, the Council of Europe created a committee and assigned it the task of drafting a cybercrime treaty. After some years of work, the committee produced the Convention on Cybercrime. The Convention is a lengthy document, the goal of which is to harmonize the national penal law (the law governing the definition of criminal offenses) and procedural law (the law governing criminal investigations) that deals with cybercrime. Countries that sign and ratify the Convention (a country must do both to be bound to implement the treaty) pledge to ensure that (i) their law criminalizes a baseline of cybercrime offenses, (ii) their law allows them to assist other parties to the Convention with the investigation of cybercrimes and to extradite cybercriminals in their custody and (iii) their law allows them to provide other mutual assistance to countries in the investigation and prosecution of cybercrime.
I think the Convention on Cybercrime is a very impressive document. And it seems the logical solution to the problems I noted above.
Why then, I wonder, has it been ratified by so few countries? The Convention as opened for signature on November 23, 2001. As I write this, approximately four and a half years later, it has been signed by 42 countries but only ratified by 13. The Convention does not become binding on a country until it signed and ratifies it.
Until this year, the Convention had not been ratified by any of the major European countries. I t had been ratified by smaller countries, such as Albania and Croatia, but not by the major players in Europe, the countries one would expect to have been among the first to ratify the Convention. France and Denmark finally ratified the Convention this year, but the Italy, Spain, Belgium the United Kingdom and a number of other countries still have not ratified it.
The Convention is open to non-European countries under certain conditions, one being that they were involved in its drafting. Four non-European countries -- the United States, Canada, Japan and South Africa -- signed the Convention under this condition. None of them have ratified it.
This is particularly surprising with regard to the United States, because the U.S. Department of Justice was a prime mover in the creation and drafting of the Convention on Cybercrime. The US is a major target of cybercriminals, and therefore has good reason to want global cybercrime law to become a seamless web that facilitates the investigation and prosecution of cyber-perpetrators. Indeed, the U.S. Department of Justice has for years conducted programs for countries in Asia and South America; the programs are intended to encourage them to sign and ratify the Convention by explaining the benefits of doing so and providing assistance with the legal issues involved in adopting the legislation required to implement the Convention.
So, why is the Convention languishing? I don't know. I don't know why we have not ratified it, given the effort we put into its creation. The President recommended ratification to the Senate almost two years ago, and the Senate Foreign Relations Committee recommended ratification last summer. I can only assume our failure to ratify is due, in part, to the fact that the White House is and has for some time been occupied with other matters (Iraq, Al Qaeda, Katrina, etc.). I suspect it is also due to the fact that several entities -- including the ACLU, the EFF and EPIC -- oppose ratification, on the grounds that certain provisions of the Convention are inconsistent with the civil liberties guaranteed by our Constitution.
I also wonder if the general dereliction of duty with regard to the Convention is due to the same phenomenon that happens to most of us at some point in time . . . you have to fix something around the house, fixing it will be a pain, you don't really want to do it but you go out and buy the materials you need to do the job. Then they sit . . . because you really don't want to deal with the problem . . . and you have, after all, taken the first step by picking up the materials you need.
Maybe the Convention on Cybercrime is languishing because those who care about the issues it addresses worked very hard to get the Convention drafted . . . and are now assuming it will go into effect, somewhen, and take care of the problem.
(Image courtesty of the Council of Europe.)
Despite my best intentions (when I started this blog I swore I'd post, if not every day, at least 4 or 5 times a week), I've not posted anything for several weeks.
That is due to a combination of circumstances: business travel plus I came down with the flu and bronchitis (plus I sprained my thumb when my little-more-than-a-puppy pulled me into a tree chasing a squirrel).
So, I'm back, and I swear to due better . . . and to watch the dog much more carefully when we're in squirrel world.