Tuesday, July 17, 2007

Forthwith subpoenas

"`Forthwith' subpoenas should be used only when an immediate response is justified and then only with the prior approval of the United States Attorney."

U.S. Department of Justice, U.S. Attorney’s Manual section 9-11.140.

Following up on a my relatively-recent post about grand jury subpoenas for computer hardware and data, I want to talk a bit about a different kind of grand jury subpoena: a forthwith subpoena.

A forthwith grand jury subpoena looks pretty much like any grand jury subpoena and, like the “regular” grand jury subpoenas I discussed last time, is issued by a grand jury to obtain evidence the grand jury believes will be relevant to its investigation of federal criminal activity. A forthwith subpoena is a subpoena duces tecum, that is, it orders the recipient to produce physical evidence (files, guns, computer equipment, data, etc.) to the grand jury.

What is different about a forthwith subpoena lies not in the way it is issued or in what it commands the subpoena recipient to do. What is different is the time frame the recipient is given in which to comply with the subpoena’s demands. As its name suggests, a forthwith subpoena orders the recipient to product the evidence described in the subpoena “forthwith,” or immediately.

What does that mean in practice? Well, to understand what it means and why this is significant, let’s talk about what a normal, non-forthwith grand jury subpoena duces tecum requires of the recipient. A regular grand jury subpoena duces tecum will order the recipient to produce evidence to the grand jury on or before a specified date; it will give the subpoena recipient some time, which can vary between, say, one week to several weeks to comply with the subpoena’s demands. There are at least two reasons for giving the recipient a substantial amount of time to comply.

One is purely practical; if, say, a grand jury issues a subpoena to a company that orders it to produce its business records for the last two years, the company will need time to comply with the request. If the records, or some of them, are only available in hard copy, the company will need to copy those records and find out from the prosecutor if the grand jury will accept the copies or wants the originals. Either way, the company won’t want to give away its only copies of the records. It will do something similar for its electronic records, being sure to provide, and retain, a copy of them.

Another reason why recipients are given time to comply is that the subpoena may ask for records concerning particular events or transactions, often over a large time frame, and it will take some time for the business to identity the records that are, and are not, responsive to the subpoena. An attorney advising a company dealing with a subpoena like this will tell the company to be sure to provide every record that is responsive to the subpoena’s demands, but not to provide information that has not been asked for. The attorney will also tell the business to be sure to keep careful, precise track of what was, and was not, provided.


The other reason why subpoena duces tecum recipients are given time in which to comply with the subpoena is that they can, as I noted in my last post, challenge the subpoena by filing a motion to quash it. The motion to quash asks the court to void the subpoena for legal reasons, such as that producing what it asks for would violate the recipient’s Fifth Amendment rights or violate a valid privilege, like attorney-client or doctor-patient privilege. The subpoena recipient’s ability to challenge the validity of the subpoena before complying with it is an essential aspect of the due process of law; it ensures that people can have illegal or overbroad subpoenas quashed and, in so doing, protects our privacy and other civil rights.

Forthwith subpoenas eliminate this window of time to comply with the subpoena. As I noted above, a forthwith subpoena tells the person to comply “forthwith,” or immediately. Sometimes, that means the person must produce the evidence the day the subpoena is served or the day after it is served. Sometimes it means what it says. A few years ago, FBI agents served a forthwith subpoena on a law office in Detroit that ordered the lawyer to whom it was directed to “`forthwith, provide all requested items immediately to . . . the grand jury” by handing them over to the FBI agents.

A forthwith subpoena was used several years ago to obtain a laptop, in what I think is a cautionary tale on how one should deal with these subpoenas.

A federal grand jury in Connecticut was investigating possible racketeering and other criminal activity carried out by Triumph Capital Group, Inc., an investment firm with its principal place of business in Boston, certain of its officers and agents and certain state officers and employees. U.S. v. Triumph Capital Group, Inc., 211 F.R.D. 31 (D. Conn. 2002). According to the opinion, after the grand jury had subpoenaed records from the company, an informant told the FBI agent working with the grand jury, Charles Urso, that Triumph had not produced records that were relevant to the subpoena; according to the informant, Charles Spadoni, Triumph’s Vice President and General Counsel, said the records which had not bee produced needed to be “purged” and that he had bought a shredder program to purge or “blow out” data on a computer. U.S. v. Triumph Capital Group, Inc., supra.

The informant didn’t know what computer or records, if any, Spadoni was talking about, so Urso did some checking. With the assistance of agents who were specially trained in computer forensics, Urso discovered that records which seemed responsive to the grand jury’s subpoena had not been produced; instead, they had been downloaded from the company’s computers into a laptop. All the FBI agents knew about this laptop was that it had existed and had been used primarily by Spadoni. U.S. v. Triumph Capital Group, Inc., supra. They were very concerned that Spadoni might have the laptop and might be intending to use the shredder program the informant mentioned to delete all the data it contained, which could obstruct the investigation.

So, they needed to get the laptop as soon as possible. The obvious thing would have been to get a search warrant for the laptop, because they clearly had probable cause to believe there was evidence of a crime on its hard drive. The problem lay in another aspect of the Fourth Amendment: It requires that any search warrant particularly describe the place to be searched and the thing(s) to be seized. They could describe the laptop itself with a fair degree of particularity, but they had no idea where it was. As far as they knew, if it still existed “it could be in Triumph's Boston office, its Hartford office, Spadoni's home, Spadoni's car, or the place where Spadoni stayed when he worked at Triumph's Boston office” or somewhere else. U.S. v. Triumph Capital Group, Inc., supra.

They could have had the grand jury issue a regular subpoena duces tecum for the laptop, but they were afraid that would give Spadoni (or whomever) time to destroy its contents. So, instead, on
April 11, 2000, [Agent] Urso appeared before the grand jury and requested a forthwith subpoena directing Triumph to produce the laptop computer by 4:30 p.m. that day. In support of his request, S.A. Urso told the grand jury that a forthwith subpoena was necessary because a real danger existed that more evidence, or even the laptop computer itself could be destroyed if Triumph had advance notice that the government wanted to search it.

U.S. v. Triumph Capital Group, Inc., supra.

The grand jury issued the forthwith subpoena and Nora Dannehy, an Assistant U.S. Attorney working with the grand jury served it on Triumph by handing it to Tracy Miner, a lawyer with the firm of Mintz, Levin and one of Triumph's attorneys. She was served while waiting outside the grand jury room with a Triumph employee who had been subpoenaed to testify that day. Ms. Miner was told Triumph should deliver the laptop “immediately.”
Ms. Miner . . . called Triumph's Hartford office and learned that neither Spadoni nor the laptop computer were there. She then called Spadoni's attorney and McCarthy and learned that the laptop computer was at Triumph's Boston office. She asked Triumph to deliver the laptop computer to Mintz Levin's Boston office.

Ms. Miner . . . asked Ms. Dannehy for additional time to comply with the subpoena. . .

Ms. Dannehy denied Ms. Miner's request for more time and instructed her to produce the laptop computer by 5:00 p.m. that day.

U.S. v. Triumph Capital Group, Inc., supra. After the laptop arrives at Mintz Levin’s office in Boston, it was given to a courier service to be delivered to the grand jury in Hartford. The courier service delivered it to agent Urso, in the federal courthouse, at approximately 4:45 p.m., fifteen minutes before the deadline. The FBI agents got a search warrant before they analyzed the contents of the laptop.

When the laptop was analyzed, federal agents found incriminating evidence they sought to use against Triumph Capital, Spadoni and a number of other people whom the grand jury had charged in a lengthy indictment. The defendants later moved to suppress the evidence found on the laptop arguing that (i) the use of the forthwith subpoena was improper and (ii) the procedure used to obtain custody of the laptop violated their Fourth and/or Fifth Amendment rights (for reasons I won’t go into).

Forthwith subpoenas are controversial because, as I noted above, they don’t conform to the usual reasonable-time-to-comply aspect of subpoenas duces tecum. As you saw at the beginning of this post, the U.S. Department of Justice recognizes that, and has adopted a policy that says they should be used “only when an immediate response is justified and then only with the prior approval of the United States Attorney.” U.S. Department of Justice, U.S. Attorney’s Manual section 9-11.140. The district court found that an immediate response was justified here, and the U.S. Attorney apparently approved the subpoena.

What about the constitutional claims? Well, the individual defendants might well have had viable claims under the Fourth and Fifth Amendments (corporations have no Fifth Amendment privilege against self-incrimination and a reduced level of protection under the Fourth Amendment) . . . but there was a problem. See, U.S. law says, with regard to constitutional protections, “use it or lose it.” In other words, raise your objection before you do anything – confess, hand over evidence in response to a subpoena – or you will be deemed to have waived your right to raise that constitutional objection.

And that is precisely what the district court held in this case. The court noted that Ms. Miner did not file a motion challenging the forthwith subpoena before complying, and that this was not due to any threats or coercion by the government. Instead, she and her client voluntarily complied with the subpoena. U.S. v. Triumph Capital Group, Inc., supra. At the suppression hearing, she said “she believed that it would be contemptuous to not comply with the subpoena and that she did not have sufficient time or opportunity to consult with her client or Spadoni's counsel to discuss what was on the laptop computer and prepare a motion before the 5:00 p.m. deadline.” U.S. v. Triumph Capital Group, Inc., supra. The district court pointed out that she was an “experienced” criminal defense attorney and, therefore, knew or should have known that by complying she waived her client’s right to raise certain objections.

The Sixth Circuit Court of Appeals reached the same result in that case I mentioned earlier, the one in which the forthwith subpoena was served on the lawyer at the law firm. He said pretty much what Ms. Miner said – that he didn’t know he could challenge the forthwith subpoena, since it required him to produce the evidence “immediately” to the FBI agents standing in the office.

That is why this is a cautionary tale: Should you ever receive a forthwith subpoena, for a computer or data or a television set or a gun or anything else, remember that if you comply instead of challenging the subpoena, you may well have given up the right ever to challenge the legality of that subpoena.

Monday, July 09, 2007

Owning "hacker tools" is now a crime in Germany

As you may have seen, the German Parliament made certain revisions to the German criminal code, one of which added a new section 212c StGB.

According to the only (unofficial) translation I can find right now, it provides roughly as follows:

Whoever prepares a crime according to §202a or §202b and who creates, obtains or provides access to, sells, yields, distributes or otherwise allows access to

* passwords or other access codes, that allow access to data or
* computer programs whose aim is to commit a crime

will be punished with up to one year jail or a fine.

I assume, though I have not seen this in the few stories I’ve seen about the new German law, that the German Parliament passed it as part of the country’s effort eventually to ratify the Council of Europe’s Convention on Cybercrime. Germany signed the treaty back in 2001, but like many countries that have signed it, they have not yet ratified the Convention.

The usual reason for the delay in ratifying is that a country needs to get its local law up to the standards required by the Convention, and Article 6 (“misuse of devices”) of the Convention requires that:
Each Party shall adopt such legislative and other measures as may be necessary to establish as criminal offences under its domestic law, when committed intentionally and without right:

a the production, sale, procurement for use, import, distribution or otherwise making available of:

i a device, including a computer program, designed or adapted primarily for the purpose of committing any of the offences established in accordance with Articles 2 through 5;

ii a computer password, access code, or similar data by which the whole or any part of a computer system is capable of being accessed,

with intent that it be used for the purpose of committing any of the offences established in Articles 2 through 5; and

b the possession of an item referred to in paragraphs a.i or ii above, with intent that it be used for the purpose of committing any of the offences established in Articles 2 through 5. A Party may require by law that a number of such items be possessed before criminal liability attaches.

Article 6(2) of the Convention notes, though, that the provisions set out above
Shall not be interpreted as imposing criminal liability where the production, sale, procurement for use, import, distribution or otherwise making available or possession referred to in paragraph 1 of this article is not for the purpose of committing an offence established in accordance with Articles 2 through 5 of this Convention, such as for the authorised testing or protection of a computer system.

Articles 2-5 of the Convention define unauthorized access to computer systems and related offenses. I don’t know if the new German law includes a provision that restates the exclusion given in Article 6(2) or not.

So what is the point of all this? As I think I’ve said before, laws like this are, as far as I can tell, analogues of laws many U.S. states have which make it illegal to possess what are called “burglar’s tools.” They’re all pretty much the same. Here is Colorado’s possession of burglar’s tools statute:
A person commits possession of burglary tools if he possesses any explosive, tool, instrument, or other article adapted, designed, or commonly used for committing or facilitating the commission of an offense involving forcible entry into premises or theft by a physical taking, and intends to use the thing possessed, or knows that some person intends to use the thing possessed, in the commission of such an offense.

Colorado Revised Statutes Annotated section 18-4-205(1). Possessing burglar’s tools is a Class 5 felony in Colorado, which is apparently punishable by imprisonment for 1-2 years followed by one year of parole. Colorado Revised Statutes Annotated section 18-1.3-401(1)(a). I suspect the sentence is pretty much the same in all the states that have this crime.

As I think I’ve mentioned before, the reason for having this crime is to let law enforcement officers step in and interrupt a crime before (presumably) it’s about to be committed. So if they stop someone in a car or someone sneaking down an alley and find they’re carrying burglar’s tools as defined above, the officer can arrest that person for possessing the burglar’s tools. This does two things: First, it means the officer doesn’t have to hang around and wait until the person actually breaks into a house or business in order to be able to make an arrest; law long ago decided that’s not a good way to go, since it radically increases the danger to those who may be inside the burgled building, as well as maybe the officer, too.

Now, even without a possession of burglar’s tools offense, an officer could arrest the person sneaking around with what are clearly tools intended to be used to burgle for the distinct crime of attempted burglary. Attempt crimes were invented, at least in the Anglo-American legal system, purely to let officers interrupt criminal activity before the criminal had gone all the way and was actually involved in the commission of what laws calls the substantive crime. Burglary (like murder, homicide, any crime with a completed “harm) is a substantive offense, while attempt is an incomplete, or inchoate crime.

So where does this leave us with the new German law? Well, I assume the immediate driver was the country’s desire to be able to ratify the Convention on Cybercrime. And I assume the reason for including this provision in the Convention was a version of the burglar’s tools rationale.

The very long Explanatory Report for the Convention adds another rationale:
This provision establishes as a separate and independent criminal offence the intentional commission of specific illegal acts regarding certain devices or access data to be misused for the purpose of committing the above-described offences against the confidentiality, the integrity and availability of computer systems or data. As the commission of these offences often requires the possession of means of access ("hacker tools") or other tools, there is a strong incentive to acquire them for criminal purposes which may then lead to the creation of a kind of black market in their production and distribution. To combat such dangers more effectively, the criminal law should prohibit specific potentially dangerous acts at the source, preceding the commission of offences under Articles 2 – 5.

Explanatory Report, Convention on Cybercrime, paragraph 71.
I find the uproar in Germany particularly interesting given that I’ve never noticed anything similar here . . . and we not only signed the Convention on Cybercrime in 2001, we ratified it last year. To ratify it, of course, we, too, have to have law implementing the provisions of Article 6(1). You can find those provisions in sections 1029 and 1030 of title 18 of the U.S. Code – the federal criminal code, in other words.

Wednesday, July 04, 2007

Subpoenas for computers and data

I’ve talked a lot about Fourth Amendment constraints on law enforcement officers’ ability to search for and seize computer equipment and data. That’s one of the two models of criminal investigation we have in the United States.

Today, I want to talk about the other model and how it operates with regard to the government’s obtaining computer equipment and data stored on that equipment.


The “other” model is the grand jury model. The United States is the only country that uses grand juries. The Fifth Amendment to the U.S. Constitution requires that charges for all serious crimes (felonies, essentially) be brought by indictment, and only a grand jury can bring an indictment.

An indictment is a set of charges “returned” by a grand jury. A grand jury is a group of people, who are summoned just like regular trial jurors and sit to determine not guilt or innocence of charges that have been brought, but to decide if there is probable cause to charge someone with a crime, a federal crime, so far. So, the federal system has to use grand juries to charge people; that’s one grand jury function. Part of deciding whether there is probable cause to charge someone with a crime is investigating the possibility that a crime occurred, and that brings me to the second grand jury function. Grand juries, especially at the federal level actively investigate crime by requiring witnesses to appear and testify, under oath (think Scooter Libby), and by requiring individuals and/or corporations to produce evidence, such as records, for the grand jurors to review.

The way a grand jury requires witnesses to show up and testify and individuals or corporations to produce evidence is by issuing a subpoena. Subpoenas (grand jury and otherwise) are of two basic types: A subpoena ad testificandum requires someone to show up and testify; in grand jury practice, it requires someone to appear before the grand jury issuing the subpoena and ask questions put to them by the prosecutor working with the grand jury and by the grand jurors, if they wish to ask the witness questions. A subpoena duces tecum is used to obtain evidence; it requires the person or entity to which it is issued to produce specified evidence to the grand jury on or before a certain date.

Failure to comply with either type of subpoena means that the person or entity that was subpoenaed will be held in contempt. For individuals, this means they will be locked up until they choose to comply. A few years ago, Susan McDougal served 18 months in jail for refusing to testify before the White Water grand jury, and I’m sure we all remember Judith Miller, who spent 85 days in jail before deciding to testify before the Plamegate grand jury. Since corporations and other artificial entities (partnerships) cannot be locked up, they will be required to pay heavy fines (thousands of dollars a day) for each day they refuse to comply with a grand jury subpoena.

Okay, just a little more background and I’ll get to grand jury subpoenas for computers.

If a subpoena recipient does not want to comply with a subpoena, the proper thing to do is to challenge it by filing a motion to quash (not squash, when I was in practice in Chicago I had a client who wanted me to “squash that grand jury subpoena”) with the court that supervises the grand jury. The motion to quash says, essentially, that the subpoena should not be enforced for particular reasons. An attorney might argue, say, that the subpoena would require her to violate attorney-client privilege by testifying or by producing records.

Another basis for challenging a subpoena that requires the production of evidence is to argue that it is overbroad, i.e., asks for too much . . and that brings us to computer subpoenas. Since the whole issue of subpoenas tends to be very complex, I’m going to focus on only one issue in this post, and try to use a couple of cases to illustrate how that issue comes up and why it can be important.

The first case is a state case. States use grand juries, too, in the same ways the federal system does. Most states have county grand juries to investigate and bring charges for local crimes; some states have also statewide grand juries, which investigate larger-scale criminal activity. The first case – In re Twenty-Fourth Statewide Investigating Grand Jury, 589 Pa. 89, 907 A.2d 505 (Pennsylvania Supreme Court 2006) – involves a newspaper’s challenge to a statewide grand jury subpoena.

Here are the essential facts in that case:
In February and July 2006, Lancaster Newspapers, Inc. was served with two subpoenas issued under the authority of the Twenty-Fourth Statewide Investigating Grand Jury, commanding it to produce four computer workstations (Subpoena 314) and two additional computer hard drives (Subpoena 686). . . .The newspaper maintains that . . . , it agreed to provide the Attorney General's office with all available documentation deriving from the hard drives related to the subject of the investigation and to make the computer hardware available for inspection at Lancaster Newspapers' office in the presence of newspaper personnel. Upon rejection of such conditions by the Office of Attorney General, the newspaper initiated proceedings before the judge supervising the grand jury proceedings, seeking to quash Subpoena 314. The newspaper contended, inter alia, that the subpoena was overbroad because it required production of information that was not relevant to the grand jury investigation. . . .

In re Twenty-Fourth Statewide Investigating Grand Jury, supra. The judge supervising the grand jury denied the motion to quash, and the newspaper appealed.

On appeal to the Pennsylvania Supreme Court, the newspaper argued that the subpoena in question was
overbroad, in that it obviously requires production and potential disclosure of information beyond that which is relevant to the grand jury inquiry. The newspaper discusses a “chilling effect” that the surrender of entire computer hard drives to the government by the media will have on its ability to utilize confidential sources and to gather news information. According to the newspaper, less intrusive means were available to be utilized by the government and/or grand jury to accomplish their investigative purposes.

In re Twenty-Fourth Statewide Investigating Grand Jury, supra. This is a good argument because the U.S. Supreme Court and state courts have read a “reasonableness” requirement into subpoenas requiring the production of evidence.

The reasonableness requirement means, for example, that the government can’t just issue a subpoena asking for “everything” a business has and expect to prevail, at least not unless it can show why it really, truly needs “everything” the business has. The reasonableness requirement is intended to protect subpoena recipients by ensuring that they do not have to expend impossible and/or unreasonably expensive efforts to comply with subpoenas. It tries to strike a balance between what the government really needs and what is fair to the person or entity that has to locate and produce all this evidence. It also, as you can see from the argument above, tries to ensure that subpoenas are no more intrusive than they have to be.


The novel issue that’s come up in the few reported computer subpoena cases is whether the government (i) can simply require a person or a business to produce their computer equipment (hard drives, computers, data storage devices) or (ii) must instead focus the subpoena’s demands on producing particular information that is relevant to the grand jury’s inquiry. In an early computer evidence case – In re Grand Jury Subpoena Duces Tecum, 846 F. Supp. 11 (Southern District of New York 1994) – a federal court bought the subpoena recipient’s argument that requiring someone to produce hard drives and other computer hardware, simply to give the government access to some of the data stored in those devices, was unreasonable because it was analogous to requiring a business to produce all its file cabinets, with all the documents contained in them, so the government could gain access to the subset of documents that were actually relevant to the grand jury’s investigation. The New York court granted the subpoena recipient’s motion to quash and told the grand jury to try again, this time with a subpoena that only required the production of information relevant to its investigation.

And that’s essentially what the Pennsylvania Supreme Court did. It found that the subpoena at issue in that case was in fact overbroad and vacated the lower court’s order enforcing it, without prejudice . . . which means the state Attorney General’s office could try again with another subpoena. The court noted that one way to resolve the problem would be for the lower court to appoint a neutral expert who would review the data on the hard drives and decide what should, and what should not, be produced to the Attorney General. It also noted there might be valid reasons why the Attorney General’s office would need the hard drives – one being to have them forensically examined.

The Pennsylvania court explained, however, that “any direct and compelled transfer to the executive branch of general-use media computer hardware should be pursuant to a due and proper warrant, issued upon probable cause.” In re Twenty-Fourth Statewide Investigating Grand Jury, supra. Requiring the government to obtain a search warrant further protects the subpoena recipient (the newspaper, here) because it means the government has to show specific reasons why it needs particular evidence being held by the subpoena recipient.

That raises the bar for the government and, in so doing, protects citizens, because subpoenas issue with no showing of probable cause or any other reason to believe relevant evidence will be produced. Earlier, I talked about the two U.S. models of criminal investigation; each has its own way of trying to protect individual rights of privacy and possession of property: The traditional law enforcement model does that by requiring police to obtain a search warrant based on probable cause or otherwise satisfy the requirements of the Fourth Amendment before they go out and get evidence. The grand jury model does that by allowing the recipient of a subpoena to go to court and move to quash the subpoena. Here, the Pennsylvania Supreme Court was playing Solomon, to some extent by holding that some evidence just may not be obtainable by grand jury subpoena; if and when that is the case, the Fourth Amendment gives the government another way to go about trying to obtain that evidence.

The bottom line here is that if you or anyone you know ever receives a grand jury subpoena requiring the production of hard drives and other computer hardware, it might be a good idea to consult a lawyer and see if the terms of the subpoena seem to be overbroad. That can be very important because once someone produces evidence to a grand jury, they waive their rights under the Fourth and Fifth Amendments to claim that the evidence was obtained
illegally.

Sunday, July 01, 2007

Making customers responsible for security


Maybe you saw this? New Zealand banks have adopted a new Code of Practice which, among other things, makes customers using online banking responsible for losses that occur if they did not take appropriate precautions to secure the computer they used to do their banking.

The New Zealand Bankers’ Association’s Code of Banking Practice [“CBP”] (4th ed. 2007) begins by advising online banking customers that “[y]our computer . . . is not part of our system therefore we cannot control and are not responsible for, its security.” CBP page 33. It follows this disavowal of institutional responsibility with reassurances that “we will inform you . . . how best to safeguard your online information and the steps you should take to protect yourself and your own computer from fraud, scams or unauthorized banking transactions.” CBP page 33.

As to the latter, the CBP says the financial institution will have available online “information and advice” on the benefits of installing and maintaining protection, in respect of, for example” anti-virus software, firewalls, anti-spyware and operating system security updates. CBP page 33. It also says the financial institution will tell you where to find this information “[w]hen we first give you access to our Internet Banking services.” CBP page 33. And the CBP goes on in that vein for another page or two, mostly telling customers what it will and will not do (such as sending emails asking for personal or account data). CBP page 33-34.


The next page or so explains that customers will not be held liable for “Unauthorised Transactions” under various circumstances, such as that you promptly inform the bank that you password or other access information has been compromised. CBP page 36-37. Nothing unusual so far.

But then we get to the section entitled “Your Liability (Responsibility). CBP page 35. This section advises online bank customers that “[y]ou may be liable if an Unathorised Transaction occurs” under any of the following circumstances:
  • You have a PIN or a password “of a type you have been warned not to choose (this goes back to earlier advice about not using family names, birthdates, pet names, etc.).
  • You either voluntarily disclosed your PIN or password to someone else or you wrote it down or recorded it electronically.
  • You used computer equipment “that does not have appropriate protective software and operating system installed and up to date.”
CBP page 37. There are several other circumstances that trigger customer liability for an unauthorized transaction, including leaving “your computer unattended when logged on to the Internet Banking service”. CBP page 37. (I wonder how they can tell when that happened?)

If any of the circumstances listed in this section of the CBP existed when your account was compromised, then your “maximum liability will be the lesser of” (i) the actual loss at the time you notified the bank of the problem or (ii) the amount that would have been available from withdrawal from your account “between the time any unauthorised access was made and the time you notified” your bank. CBP page 37. If you used or allowed your account to be used to access fraudulent or unauthorized transactions, then you “may be liable for some or all of the loss suffered by the party who has been defrauded, regardless of the balance available in your account.” CBP page 37.

And, finally, we come to the section of the CBP that has been creating quite a lot of discussion:
We reserve the right to request access to your computer . . . in order to verify that you have taken all reasonable steps to protect your computer . . . and safeguard your secure information in accordance with this Code. If you refuse our request for access then we may refuse your claim.

CBP page 37.

I want to comment briefly on two aspects of the CBP.

The first is the idea of imposing some responsibility on civilians – regular people – to secure their computers and be cautious when online. I have written about why I think this is a good idea elsewhere, and so won’t belabor the point here.

In the articles I have written on this topic, I explain in detail that the traditional system of crime control – law enforcement’s reacting to completed crimes by apprehending the criminals, who are then convicted and punished – neither is nor will be an adequate strategy for keeping online crime under control. As I explain elsewhere, the traditional model, which works adequately for real-world crime, is based on the premise that if you find and conviction someone who committed a crime, you control the commission of future crimes by (i) taking that offender out of circulation for some period of time (or permanently, if the death penalty applies) and/or (ii) discouraging others from following her example, because they see that the costs of committing crimes outweighs the benefits.

Implicit in this strategy, however, are the premises that (i) you can find the perpetrators of enough crime to have the desired effect and (ii) having found them, you can get custody of them for prosecution, conviction and sentencing. As I demonstrate in detail elsewhere, criminals’ ability to use cyberspace frustrates law enforcement’s ability to apprehend cybercriminals because it becomes difficult, if not impossible, to identify them. And even if law enforcement can identify certain perpetrators, it may not be possible to extradite them for prosecution where the crimes (or some of them) were committed. These difficulties are further exacerbated by the tremendous resource costs entailed by online investigations, costs that must be added to the costs needed to pursue real-world criminals because, after all, people will continue to “harm” each other in various ways in the real, physical world.

Okay, so I think we – the “users” of cyberspace – need to learn that we must assume some level of responsibility for protecting ourselves while online. And elsewhere, I’ve outlined some ideas as to how we go about changing societal norms (which currently tend to assume that crime is the police’s problem and that they will always catch the criminals) to make this one of the endemic, implicit assumptions we all share. So I really don’t have any problem with that aspect of the CBP.

My problem lies with the other aspect of the CBP provisions on “user” responsibilities. The articles I’ve seen about the CBP all focus on what they see as an invasion of privacy that results from the bank’s reserving the right to check the security on your system, apparently after an unauthorized transaction has taken place and you are seeking reimbursement for the losses.

The invasion of privacy concern doesn’t bother me all that much. It seems to me to fall in what the law calls “assumption of risk.” I get what I contract for, in other words. We see this in air travel. I may find airport screening of me and my bags very intrusive, a real invasion of privacy, but the law’s response to is, simply, that I have a choice. I can submit to those procedures, I can travel by other means or I can choose not to travel.

I’m sure some will point out that if all banking institutions starting using codes of this type (as is apparently now true in New Zealand), I won’t have a choice. I wonder. I tend to suspect that a market would grow up for financial institutions that would give their customers alternatives, in the same way bank secrecy became a marketable item in Switzerland and, later, in other countries.

But I don’t want to talk about what doesn’t interest me that much about the CBP. What I find interesting, and flawed, about it is that they seem to be relying on bank inspection of people’s computers as the incentive for customers’ beefing up security on their computers. As I’ve written in elsewhere, I don’t think this kind of enforcement system is the way to go to achieve the result I noted above, i.e., to change our culture so that we all begin to assume a level of responsibility for protecting ourselves online.

I don’t think it’s the way to go for several reasons. One is that customers may conclude (as the authors of articles about the CBP already seem to have concluded) that the tactic is high-handed and overreaching. As we all know, when people (me, included) perceive they’re being treated like that, their response is either to abandon ship (head for another bank) or be passive-aggressive, comply at some minimal level and then argue about it if and when a problem occurs.

The other problem I have with this tactic is the one I’ve written about before in analyzing somewhat comparable schemes (online driver’s license, security checks generally) that would seek to achieve the same thing. Some have argued that we should approach online security the way U.S. states dealt with seatbelts: Seatbelts have apparently been available in cars since the 1960s, but no one really started to use them till roughly twenty years later, when states started adopting “click it or ticket” laws, i.e., laws that made it a very minor offense (like a speeding violation) not to wear a seatbelt. That approach worked for seatbelts, but I don’t think it could ever work for citizen computer security.

Seatbelt laws are easy to enforce because it’s easy for a police officer to tell if you’re wearing on. And seatbelts are easy to use; citizens don’t have to keep adding patches to their seatbelts or upgrade to better seatbelts or any of that.

Why is that important? It goes to the efficacy of enforcement. If people don’t understand WHY they’re supposed to do something, something that isn’t easy for most people today, then they’ll be resistant. Resistance requires pouring more resources into enforcement (think alcohol prohibition in the 1920s and the war on drugs more recently), which, in and of itself, is not ever likely to be effective in getting people to do that “something” you want them to do.

So, I applaud the New Zealand bankers for trying to do something to encourage people to secure their computers and themselves when online. I just don’t think they’ve chosen a very good approach to the task.

Saturday, June 23, 2007

Caller ID spoofing

You may have read about this: Someone, using easily available technology, spoof the caller ID information that appears on your phone when a call comes in. Indeed, there are websites that make it very easy for you to do this.

So to use an odd example I saw on TV, your phone rings, you check the caller ID and instead of giving an unknown name and set of numbers, you see “The White House” and a set of phone numbers that are, in fact, for the White House. I’m not sure why anyone would want to use the White House’s number in caller ID spoofing, but you certainly could do so, if you were so inclined.

The spoofing is being used to commit identity theft and other types of fraud, though, as I note below, it’s also been used for some other undesirable purposes. For fraud and identity theft, the would-be perpetrator spoofs the caller ID so the person taking the call believes they are talking to their bank, credit card company or some other source with which they would feel free to share personal information, such as their Social Security number. The caller persuades the person to give up as much information as seems useful, hangs up and identity theft or some other kind of fraud is set in motion, with the person duped by the caller ID spoofing as the victim.

It’s also been used, at least occasionally, for other purposes. Back in April a column in the Washington Post described how SWAT teams have been sent to empty buildings or other places after someone called police, using spoofed caller ID, and reported a crime in progress. According to the Washington Post article, a SWAT team was sent to an apartment after police received a call from a woman who said she was being held hostage there; there was no hostage, the caller ID was spoofed to make it look like the call came from that location.

I can see where spoofing caller ID could become a very useful tool for stalkers and others bent on “harming” someone; it would, for example, be very easy to trick a murder victim into showing up at the place where the perpetrator was prepared to commit the crime. All the would-be killer would have to do is, say, to call someone and tell them they needed to come to a particular, no doubt remote, location because their spouse or their child had been injured or some other emergency. (It’s also possible to alter the sound of one’s voice, which would probably help in orchestrating this kind of scenario.)

Last Wednesday, the House of Representatives approved the Truth in Caller ID Act of 2007, which makes it “unlawful for any person within the United States . . . to cause any caller identification service to transmit misleading or inaccurate caller identification information, with the intent to defraud or cause harm.” H.R. 251. A version of the bill has gone to the Senate, so we’ll see what they do with it. It looks like both versions make caller ID spoofing a crime, which is what I really want to write about.

Not to sound like a broken record, but do we need a law like this?

I started thinking about that because someone I saw interviewed in a news story about caller ID spoofing pointed out that it’s like falsifying the return address on an envelope, and we don’t make that a crime. Instead, we fold that kind of misrepresentation, which is merely one step in the ultimate infliction of “harm,” into the charges for the target crime or crimes . . . fraud or stalking or theft or extortion or whatever the misrepresentation is intended to promote.

So I started thinking (and I’ve just started) about why it should be different for spoofing caller ID. Spoofing caller ID is a slimy, devious trick, one that, like most slimy, devious tricks, is optimally calculated to exploit the vulnerable among us – our less sophisticated, more trusting neighbors.

It’s also calculated to exploit what I see as an increasing tendency among us: to trust what technology tells us. Why is spoofing caller ID any more deserving of criminalization than the practice of misidentifying or otherwise misrepresenting yourself when you call someone? Fraudsters have used misidentification and misrepresentation for centuries, probably longer. Misidentification is a tool of the trade for fraudsters; fraud is defined as deceiving someone to get them to give you their property or other valuables. So a law like the one I note above is criminalizing the use of a tool to commit what is already a crime, which may be redundant.

Some states criminalize the possession of burglar’s tools, and you might analogize the caller ID crime statute to those statutes. Both would be tool crimes. The burglar’s tools statutes are arguably redundant when and if they’re used to charge someone who has already broken into a house or business for the purpose of committing, say, theft; at that point, the person could be charged with both burglary and possessing burglar’s tools (if a prosecutor wanted to do that). Burglar’s tools statutes are not so clearly redundant when they’re used to charge someone who’s arrested before they break into a house or building to commit burglary; indeed, this is the whole point.

They let police do something when they encounter someone who is carrying what the law says are unambiguous tools for committing a particular crime. That gives police an advantage: they can prevent the commission of the crime by arresting the person on the lesser charge of possessing burglar’s tools. Of course, they could do the same thing by charging the person with attempting to commit burglary, a charge that could be based on having burglar’s tools and, say, being in the alley behind a house or a business. Attempt charges work if the facts support the inference that the person was headed toward committing the crime. Burglar’s tools statutes just make that easier, and push the time frame back a bit.

So, okay, maybe the proposed caller ID spoofing crime is a burglar’s tools crime, and maybe there isn’t anything wrong with that. I think the difficulty I’m having with this proposed law is that it says something about our relationship with technology. We’ve never criminalized falsifying the return address on an envelope, as such; we criminalize committing fraud and using the mails to commit fraud. Why, then, criminalize caller ID spoofing?

I wonder if the drive to criminalize caller ID spoofing is implicitly based on the premise that falsifying caller ID information is somehow more reprehensible, more “harmful,” than falsifying the return address on a letter. Why might it be more “harmful” than falsifying information on a snail mail item?

Well, and I’m just speculating here, I suspect we’re a little more skeptical of addressing and other information on snail mail, because we – the general public -- all know how easy it is to falsify documents. We, the general public, know that because we know it’s people who put addresses on mail and we know how easy it is for a person to put incorrect information on mail. We know all that because it’s embedded in our culture; we know people lie and fabricate, and we know people create addressing information on snail mail (with, of course, the help of some basic technology).

I suspect things are different for caller ID. When we look at the caller ID screen on our phone, we don’t think we’re getting information from a person (who can lie); we think we’re getting information from a technology (which can’t lie, so far, anyway). I may be wrong, but I think that’s why people (me, included) are finding caller ID spoofing to be particularly obnoxious.

There’s an implicit breach of trust there that I don’t think we’d find, or at least not find in the same degree, if we learned that, say, the letter which seemed to come from our bank or credit card company was a fake, a fraud. We’d be angry when we found out the letter was a fake, but we wouldn’t be . . . offended, for lack of a better term . . . because that would fit into what we know of the world. Crooks are out there, crooks fake things to take our money.

Maybe I’m crazy, but I think we trust technology more than we do each other.

Friday, June 22, 2007

Outing "rats"

You may have heard about Who’s A Rat?, the website that claims to offer (and probably does) the “largest online database of informants and agents!” According to the site, it is
"a database driven website designed to assist attorneys and criminal defendants with few resources. The purpose of this website is for individuals and attorneys to post, share and request any and all information that has been made public at some point to at least 1 person of the public prior to posting it on this site pertaining to local, state and federal Informants and Law Enforcement Officers. This includes an Informant who makes his or her Informant status known to any person."


The website, which was created in 2004, is a paid subscription service and explicitly disavows any intent to “promote or condone violence or illegal activity against informants or law enforcement officers.” It also specifically notes that it does not portray “Agents or Law enforcement officers as rats or informants.”

You may have seen news stories about Who’s A Rat?, since many in the criminal justice system find it controversial, and threatening. As one news story explained, judges and prosecutors around the country are afraid the site will “cripple investigations and hang targets on witnesses.”

I haven’t seen reports of any efforts to shut the site down through litigation, presumably because it’s clearly protected by the First Amendment. There’s actually a federal district court opinion which reached precisely that result with regard to a completely different website.

In 2003, Leon Carmichael, Sr. was charged in the U.S. District Court for the Middle District of Alabama with drug conspiracy and money laundering. U.S v. Carmichael, 342 F.Supp.2d 1070 (M.D. Alabama 2004). Not long after he was arrested, Carmichael created a website dealing with his case:
After the site was altered . . . to display the names of four `informants’ and four `agents,’ as well as photographs of the four `informants,’ the government renewed an earlier motion for a protective order directing Carmichael to remove his website from the internet. On July 20, 2004, following an evidentiary hearing and after careful consideration of the issues involved, this court denied the government's motion, reasoning that such an order would impermissibly infringe on Carmichael's First, Fifth, and Sixth Amendment rights.

U.S v. Carmichael, supra.

The federal district court found, basically, that the site was protected by the First Amendment because it did not constitute a “threat” to anyone. United States v. Carmichael, 326 F.Supp.2d 1267 (M.D. Alabama 2004). The information on the site was clearly speech within the scope of the First Amendment, which means it is protected unless it falls into a problematic category of speech, such as what courts call a “true threat” to harm someone or child pornography.

Based on the evidence presented at the hearing cited above, the district court held that the testimony of informants, who said Carmichael’s posting their pictures and requests for their addresses on his site made them “fearful,” was insufficient to establish that the site posed a “true threat” to them. As I explained in an earlier post, a “true threat” is exactly what you think it would be: a communication directed at the would-be victim which says, in effect, “I am going to do you harm” of some kind. Here, just as in the case I talked about in my earlier post on this, there was no direct communication with a potential victim and no statement threatening to do them harm.

(The court also found, as you can see in the quoted excerpt above, that forcing Carmichael to take down the site would violate his Fifth Amendment right to due process and his Sixth Amendment right to prepare a defense to the charges against him, since the site sought information directly relevant to his case. I’m not sure either of those rationales would apply to Who’s A Rat?, though, since it’s not operated by a specific person asking for help in preparing her defense to a particular case. It might, I’m just not sure.)

After the district court refused to take the site down, DEA Agent David DeJohn, one of the agents listed on the site did something very unusual: He asked the court to let him intervene in the criminal case so he could, on is own behalf, ask the federal district court to order that his photograph be taken off Carmichael’s website. U.S v. Carmichael, 342 F.Supp.2d 1070 (M.D. Alabama 2004). DeJohn alleged that “the website is not only interfering with his ability to pursue his profession as an undercover agent, it is putting him in danger.” U.S v. Carmichael, 342 F.Supp.2d 1070 (M.D. Alabama 2004).

The federal district court denied DeJohn’s motion to intervene. It began by noting that allowing someone to intervene in a criminal proceeding is “limited to those instances in which a third party's constitutional or other federal rights are implicated by the resolution of a particular motion, request, or other issue during the course of a criminal case.” U.S v. Carmichael, 342 F.Supp.2d 1070 (M.D. Alabama 2004). The court found, basically, that DeJohn really had no “stake” in the criminal proceeding against Carmichael:
Although he asserts that he has a `personal stake in this litigation as it is his photograph that was stolen and posted,’ DeJohn has not . . . shown that he has an interest that will be affected by Carmichael's conviction or acquittal in this criminal case or . . . by any proceeding in this criminal case leading up to such. DeJohn may have been personally affected by Carmichael's use of his picture on his website, but the website itself is not the issue in this case. The sole purpose of this criminal action is the adjudication of Carmichael's guilt or innocence. . . . .

DeJohn does not claim the infringement of any interest conferred on him by any provision of the United States Constitution or any federal statute. To be sure, DeJohn would have benefitted had the court ordered the removal of the website from the internet at the government's request. But any interest DeJohn has in the website's removal is not based on a legal entitlement specifically belonging to him in Carmichael's criminal case. Rather, his motion to intervene is an effort to resolve what is essentially a private dispute based, if anything, on state law.

U.S v. Carmichael, 342 F.Supp.2d 1070 (M.D. Alabama 2004). So the federal court denied his motion to intervene and told DeJohn to sue Carmichael in an Alabama state court if he wanted to try to have his photograph removed from Carmichael’s website.

I have no idea if Agent DeJohn ever sued Carmichael or not. I can’t find any news stories or reported cases involving such a suit.

Carmichael’s website – http://www.carmichaelcase.com -- is still online, but seems to have been abandoned. According to a relatively recent news story, Carmichael was convicted in 2005 of drug trafficking and money laundering and was sentenced last March to serve 480 months in prison. Montgomery Businessman Sentenced to 40 Years for Drug Trafficking, U.S. Federal News, 2007 WLNR 5923762 (March 23, 2007).

Tuesday, June 19, 2007

Court upholds email privacy

About a year ago I wrote about a Cincinnati federal district court’s decision which held that we have a Fourth Amendment expectation of privacy in emails being stored by ISPs.

That decision was important because the current federal statutory framework governing law enforcement access to stored emails (and emails in transmission, but that’s not what we’re concerned with here) is based on the premise that data we “knowingly” share with third-parties, like ISPs, is NOT protected by the Fourth Amendment. If it is not, then law enforcement officers don’t have to get a search warrant to gain access to emails, etc.

The Sixth Circuit Court of Appeals just affirmed the district court’s decision: Warshak v. U.S. (docket # 06-4092, opinion # 07a0225p.06). You can find it here.

The government will almost certainly ask the Sixth Circuit to rehear the case, with all the judges of the circuit sitting on the panel (this was the usual three-judge panel). If they lose again, they’ll almost certainly try to take the case to the Supreme Court which, I think, will probably take it.

Monday, June 18, 2007

Be careful what you consent to

In this post, I want to talk, again, about how courts are struggling to define the permissible scope of a consent search when that search involves a computer or other digital storage media.

More precisely, I want to use a Michigan case to illustrate the issues that can arise when someone consents to a search of their property.

As I’ve said before, the Fourth Amendment’s default position is that police must obtain a search warrant (actually a search and seizure warrant, since it lets police seize any evidence they find while searching) before they can lawfully search a place in which someone has a reasonable expectation of privacy.

As I’ve also said before, this default position is subject to a number of exceptions, each of which eliminates the need for police to obtain a search (and seizure) warrant.


One of these exceptions, which I’ve talked about before, is consent. Consent is basically a waiver of your Fourth Amendment right to privacy. If a police officer, say, stops you as you are walking down the street carrying an opaque bag and says, “Hey, can I search your bag?” and you say “sure,” then you’ve waived your Fourth Amendment right to privacy in the bag. You’ve also implicitly consented to let the officer seize any evidence of a crime he finds there. Evidence of a crime conceptually falls into two categories: contraband (things, like drugs and child pornography, the possession of which is prohibited, so they are illegal in themselves) and non-contraband items that are evidence of the commission of a particular crime (a murder weapon, for example).

So, if you consent to a search of a thing or a place under your possession and control, your consent substitutes for a search (and seizure) warrant). Consent, though, works a little differently than the other exceptions (and search warrants too, for that matter). The other exceptions (and search warrants) are based on probable cause, and that defines the scope of a search. So, if an officer has a warrant to search your home for 2 stolen big-screen TVs (of a particular, described type), she can search your home (i) only for those TVs and (ii) only until she finds both of them. So probable cause both authorizes and limits the scope of the search.

Consent is different, and can be trickier. Consent is basically a contract between you and the state. The officer, representing the state, asks for consent to conduct a specific search, as in my example above. In that example, the police officer asked for consent to search the bag and you, hypothetically, said “yes” (often a bad idea, btw). The contract that arose between you and the government allowed the officer to search this bag, and only this bag, and to search it for . . . whatever, basically, . . . since the object of the search was not specified.

And that’s an important aspect of consent. If you decide to consent to a search, you should think about precisely what you are consenting to. You can set limits on a search. If, say, an officer asks for consent to search your car, you can say something like, “all right, but you can only search the passenger compartment.” By doing that, you’ve limited how far the officer can go. And, too, remember that you can always call off the contract. That is, you can always revoke your consent to search (at least, until they find something, then other exceptions might kick in).

Okay, with that as background, let’s talk about a car consent search.

Here are the essential initial facts in People v. Dagwan, 269 Mich. App. 338, 711 N.W.2d 386 (Mich. App. 2005):
[Michael Dagwan] entered the Michigan State Police post in St. Ignace and asked Sergeant Amy Pendergraff how he could transfer his Michigan sex offender registration to Massachusetts. Pendergraff contacted Trooper Elaine Bitner at the State Police post in Sault Ste. Marie. Trooper Bitner told Sergeant Pendergraff that [Dagwan] was being investigated for a possible sex offender registry violation. . . .Trooper Bitner asked Sergeant Pendergraff to detain [Dagwan], so she searched [him[ for weapons, then placed him in a holding cell. Soon thereafter, Trooper Bitner told Sergeant Pendergraff that the Chippewa County prosecutor had authorized a complaint for an arrest warrant charging [Dagwan] with a sex offender registry violation and asked her to arrest [him] on the basis of this probable cause

People v. Dagwan, supra.

Sergeant Pendergraff told Dagwan he was under arrest and, according to the opinion, he “then consented to a search of his car. Sergeant Pendergraff stated that when she asked [Dagwan] if he was freely giving consent and . . . would sign a written consent form, he said yes. . . . Sergeant Pendergraff testified [at the suppression hearing that]: `He said yes. I got the form, filled it out. He read it over. He signed it.’” People v. Dagwan, supra. The consent form Dagwan signed gave the Michigan State Police his consent to “`conduct a complete search of the motor vehicle owned by me and/or under my care, custody, and control, including the interior, trunk, engine compartment, and all containers therein[.]’” People v. Dagwan, supra.

Sergeant Pendergraff took Dagwan outside; he unlocked the car so she could search it. She found a laptop in the car and gave it to Detective Sergeant Robin Sexton to search. People v. Dagwan, supra. Detective Sexton, “who had special training in computer data recovery,” did a quick search of the contents of the laptop and found child pornography on it. People v. Dagwan, supra. This, of course, resulted in Dagwan’s being charged with possessing child pornography, which only compounded the legal problems he had to face.

Dagwan moved to suppress the child pornography, arguing that the search of his computer exceeded the scope of his consent to search the car. In other words, he argued that his “consent contract” encompassed only the car, not the laptop. And the trial court agreed. It “granted the motion, concluding, in essence, that `containers,’ as referred to in the consent form, did not include `the inner workings of the computer.’” People v. Dagwan, supra.

The prosecution appealed, and the Michigan Court of Appeals reversed the trial court’s decision. Here is the appellate court’s reasoning:
[W]e conclude that it was objectively reasonable for the police to believe that defendant's consent included consent to examining data stored within the laptop found in defendant's car. First, the object of the police search was broad: to look for anything illegal, including stolen property. We conclude that a reasonable person would know that computers may be used to commit crimes. . . . Further, we conclude that a reasonable person would know that computers can contain illegal child sexually abusive material in the form of stored electronic images. . . . Second, the written consent to search that defendant signed. . . . agreed to permit the police to `conduct a complete search of [his] motor vehicle ..., including the interior, trunk, engine compartment, and all containers therein[.]’

The wording of the written consent is plain and unambiguous, so the police were objectively reasonable in believing that defendant consented to their examining data stored on the laptop. . . . `Complete’ is defined as “having all parts or elements; lacking nothing; whole; entire; full; ... thorough; total; undivided, uncompromised, or unqualified[.]” Random House Webster's College Dictionary (1992). A `container’ is “`anything that contains or can contain something. . . .’ Id. . . . Because a computer can store data in its memory, and thus act as a container, here of illegal child sexually abusive material, it was objectively reasonable for the police to believe that the scope of defendant's consent permitted them to examine the contents of the computer found inside the automobile. . . . Consequently, we conclude that a reasonable person would have understood that defendant's consent was broad enough to encompass a review of the computer's stored data. . . .

People v. Dagwan, supra. The appellate court also found it significant that Dagwan never either revoked the consent he had given to search the car or tried to limit the scope of the search. So, it reversed the trial court, which means the images found on the laptop could be used against him.

I don’t know what happened to Dagwan, other than that the prosecution apparently was resumed.

What I think is interesting, and instructive, about this case is that it illustrates the difficulties courts are having with the concept of computers as “containers.” Courts generally agree that computers are “containers” of a sort, as indeed they are. They contain “data.” Courts struggle, though, with whether computers are “containers” like the traditional, tangible, real-world containers we’ve always dealt with or whether they are different, somehow. . . . whether, basically, they represent an incremental container, one that encompasses a greater level of privacy than do conventional, physical containers. You can see that theory in the trial court’s opinion, noted above.

The other, I think, instructive aspect of this case goes back to the title of this post: Be careful about consenting to a search under any circumstances, but be particularly careful if a search could encompass a laptop or other computer device. If you have no problem with police’s searching your laptop or desktop computer or Blackberry or cell phone or whatever, then go ahead. But if you are at all concerned about their doing so, keep this decision in mind. The decision to consent, or not to consent, is entirely up to you, as is the scope and the duration of the search that results from your consent.

Wednesday, June 13, 2007

Corporate victimization . . . ?

Corporate victimization . . .

A recent story reminded me of an issue that came up several years ago – the question of whether corporate and other artificial entities can be the victims of certain crimes.

Corporations and other legally-created entities (such as partnerships) can, of course, be the victims of crimes. We often read, for example, about a company’s being the victim of theft or extortion, and I imagine we don’t give much, if any, thought to the fact that it’s a thing, a fictive construct, that is being victimized instead of a real, flesh-and-blood person.

I think this kind of corporate/artificial entity victimization has never been a conceptual problem either for the law or for the public because these are theft crimes. Theft, fraud, extortion, embezzlement and other financial crimes can all involve taking tangible (e.g., gold, silver, other physical assets) or intangible (e.g., data, proprietary information) from a corporate or other entity, and when that happens the entity suffers precisely the same “harm” a real human being would. The legally-created entity, like the victimized human being, loses all or a portion of their property.

But what about identity theft?

In 2004, Phoebe Nicholson, a paralegal who worked for Honeywell International, was generically accused of corporate identity theft. The law firm of Fish & Neave had done work for Honeywell in the past, so Nicholson allegedly “forged her boss’ signature on seven phony bills from the firm, then persuaded Honeywell to send the checks to her for delivery instead of mailing them to Fish & Neave.” She had sent up a bank account in a name that was “nearly identical” to the firm’s name and was able to divert almost $600,000 to that account before being caught. At the time, the local district attorney said that Nicholson “`basically stole the identity of this law firm’”, which made me think.

A law firm is usually either a partnership or a professional corporation. Can you steal the identity of an artificial entity? I believe most, if not all, identity theft statutes assume the victim is an individual.

The basic federal identity theft provision, for example, makes it a crime knowingly to possess and/or use an “identification document” that does not belong to you. 18 U.S. Code section 1028(a). It defines “identification document” as
a document made or issued by or under the authority of the United States Government, a State, political subdivision of a State, a sponsoring entity of an event designated as a special event of national significance, a foreign government, political subdivision of a foreign government, an international governmental or an international quasi-governmental organization which, when completed with information concerning a particular individual, is of a type intended or commonly accepted for the purpose of identification of individuals.. . .

18 U.S. Code 1028(d)(3). Under this statute, therefore, I don’t see how assuming the identify of a corporation or a partnership could ever be prosecuted as identity theft, and I think the same holds for state identity theft statutes, as well.

We could, of course, broaden existing identity theft statutes so they encompass the misappropriation of the identity of a corporate or other artificial entity . . . if we thought it was necessary to do so. I’m not at all sure it is. In the Fish & Neave case, Phoebe Nicholson was charged for what she really did: steal money that did not belong to her. More precisely, she was charged with grand larceny under New York law. She pled guilty to these charges and to separate charges stemming from using a similar scam to steal money from a mortgage company, and was sentenced to serve 3-9 years in state prison. Laura Williams, Guilty Plea in $1M ID Theft, New York Daily News (February 28, 2005).

So I’m not sure we need a corporate identity theft crime, at least not one that merely targets conduct that can be prosecuted as theft or embezzlement. And if we decide those laws are inadequate, it seems to me we can simply address the problem by simply expanding the scope of our existing theft and, if necessary, identity theft laws.

This brings me to the very recent case I read about and a very different kind of corporate victimization.

I saw a news story today, which is dated Tuesday, that comes from Cincinnati. It seems there’s a fellow there who is neither a student at the University of Cincinnati nor is employed there, but who keeps coming back to campus. The story says police have arrested him 22 times in the last 5 years for trespassing there (which is not something I’ve ever heard of, but maybe it doesn’t come up much). Last month the university got a temporary restraining order barring him from campus, and on Monday a local court held a hearing, at which lawyers for the university said he should never be allowed back on campus.

Specifically, a lawyer from the Ohio Attorney General’s office who was representing the university said this gentleman has been “`stalking an institution’”, which really gave me pause. I’m not sure how you “stalk” a corporate entity (universities being artificial legal entities, specifically, non-profit corporate entities).

According to the lawyers for the university, the man has “become too great a drain on the resources of police, who've spent `hundreds of hours’ locating him, cuffing him, writing reports, testifying in court.” He apparently attends classes on occasion, uses the library, and has been found in various positions and in various states of sobriety all over campus.

I’m sure the lawyer from the Ohio AG’s office was only speaking figuratively when he said this man is stalking the university, but I still found it an intriguing notion. I suppose it is possible (isn’t anything possible?) that someone could stalk a corporate entity, but I find the notion of that kind of corporation victimization problematic.

The “harm” stalking and harassment laws are intended to address is someone’s using a repeated course of non-threatening conduct (if the conduct is threatening, then it can be prosecuted on that basis, instead) to inflict emotional and/or psychic distress on an individual. We have the first component in this case; the gentleman at issue here has, according to the story I saw, engaged in a lengthy, repetitive course of non-threatening (but aggravating) conduct directed at the university.

The problem, IMHO, with ever construing this kind of incident (assuming this one is not unique, which is probably is not) as corporate stalking comes with the second element of a stalking or harassment offense – the requirement that the conduct inflict emotional or psychic injury on a victim. Being soulless, artificial entities, I do not see how a corporate entity can suffer psychic or emotional injury. It seems to me the injury they sustain, if any, is the injury encompassed by the harm of trespass: someone goes where they are not legally authorized to go, thereby violating a property owner’s rights to exclude persons from the occupation and use of their property. So I can’t imagine why we would ever really need a corporate stalking offense.

As I said, though, I’m sure the Ohio AG lawyer was only speaking figuratively.

Monday, June 04, 2007

Fourth Amendment privacy and operating systems

I ran across some interesting language in an Air Force court’s decision from last December: United States v. Larson, 64 M.J. 559 (Air Force Court of Criminal Appeals 2006).

Basically, Larson was caught up in a “To Catch A Predator”-type sting.

He thought he was emailing with, and setting up a meet with, 14 year-old Kristin when he was really corresponding with an undercover police officer. When he showed up to meet “Kristin,” Larson was arrested by local police officers.

After they heard of the arrest, the Air Force opened its own investigation and Larson’s commanding officer gave the investigating Air Force Office of Special Investigations (AFOSI) agents access to the office Larson used on the base.

The AFOSI agents seized the computer in the office, the one Larson had used to correspond with “Kristin.” “A search of the computer hard drive turned up data files, stored automatically by the Microsoft Windows operating system during [Larson’s] Internet browsing sessions” and the activity that led to his being charged with attempting to entice a minor for sexual purposes and related crimes. United States v. Larson, supra.

Larson moved to suppress the evidence seized from the computer he used at work, arguing that the search of the computer violated the Fourth Amendment. The AFOSI agents do not seem to have obtained a search warrant before they examined the computer’s hard drive. The appellate and lower Air Force courts might have disposed of the issue on some other grounds, such as that his commanding officer could consent to the search or, maybe, that he had no expectation of privacy at all in the contents of the computer because it was a government computer which he was supposed to use only for work.

The Air Force Court of Criminal Appeals didn’t take that approach, though. To understand what this court did, let me recap a bit how Fourth Amendment analysis works: To successfully suppress evidence, you have to show the government conducted an illegal “search” (or seizure, but we’re not dealing with that here). A “search, as I’ve explained before, violated a “reasonable expectation of privacy” in someplace or something.

To have a reasonable expectation of privacy in a place or thing, you have to meet two requirements, which come from the Supreme Court’s decision in Katz v. United States, 389 U.S. 347 (1967): (1) You have to have a subjective expectation of privacy (you, personally, think it’s private); and (2) if, and only if, you had a subjective expectation of privacy (you actually thought it was private), your subjective expectation must be objectively reasonable, that is, society must agree with you that it was private.

So, for example, if I use my cell phone while in a public place (an airport, say) to chat about robbing a bank, I can’t claim it was a search for a police officer to overhear what I said. I would probably say (being an idiot, in this hypothetical) that I thought my conversation was private; even if a court agreed that I did have this expectation it was private, the court would hold there was no search because it would say, correctly, that society would not consider my expectation of privacy in my conversation on a cell phone in a public place “reasonable.”

Courts usually accept that a defendant had a subjective expectation that a place or thing was private, but reject a defendant’s Fourth Amendment argument (if, indeed, they do reject the argument) on the second basis – by finding that the person’s expectation was not reasonable, was not one society will accept as valid.

That, though, is not what happened in the Larson case. The court rejected his Fourth Amendment argument on the first basis – it found that he did not have a subjective expectation of privacy in the data in question:
This appears to us to be a case of first impression in some respects. In military jurisprudence, the focus of Fourth Amendment litigation involving computers has primarily been on the expectation of privacy to be afforded to e-mail: personal communications between users, sent via computers using networks or the Internet. . . . The search of the government computer here did not focus on such communications. Instead, the AFOSI searched for certain data files, created as part of the `normal operating procedure’ of the Microsoft Windows operating system, which record the date, time, and Internet address of web sites visited by the computer user, as well as information about the user account in use on the computer at the time the sites were visited. . . .

The military judge concluded the appellant had no expectation of privacy in the contents of the computer. We find no abuse of discretion in his ruling. There is no evidence the appellant was aware the Internet history files existed, and we are unconvinced the appellant could entertain a subjective expectation of privacy in them without such knowledge.

United States v. Larson, supra.

(The court also, for good measure, held that he would not have had an objectively reasonable expectation even if he had had a subjective expectation of privacy in data on the computer: Larson “could not expect to keep private automatically-recorded data stored on government property he would reasonably have known would be turned over to another officer on that officer's return from deployment.”)

The court’s rejection of Larson’s subjective expectation of privacy in files generated by the operating system is quite interesting, since it’s not predicated on the fact that the computer was not “his” computer, but the government’s. Instead, it seems to be a blanket rejection of the idea that we can have a Fourth Amendment expectation of privacy in data generated by computer processes which we do not realize are going on and/or do not understand.