Monday, November 10, 2008

Too Much Hearsay

In several recent posts, I’ve explained what hearsay is and written about how courts apply the exceptions to the rule . . . exceptions that let certain types of hearsay be admitted into evidence.

This post is about a case in which the prosecution admitted too much hearsay into evidence, which led to the reversal of a murder conviction.


The case is Thomas v. State, 2008 WL 4629572 (Florida Court of Appeals 2008). Here’s how the Court of Appeals summarized the facts and what happened at trial:
Chaka Baldwin, [Steven]Thomas's girlfriend of four years, was stabbed to death. No physical evidence tied him to the crime, but the State presented circumstantial evidence in support of its contention that Mr. Thomas was the murderer. One piece of circumstantial evidence was an email written by Natalie Zepp to Michelle McCord, both employees of the apartment complex where Ms. Baldwin and Mr. Thomas shared an apartment. Defense counsel made hearsay objections, not only to the introduction of the email as a whole, but also to the introduction of statements within the email that Ms. Zepp, the employee who wrote the email, reported Ms. Baldwin made to her.
Thomas v. State, supra.
Here’s the text of that email:
This resident called and says that she's had someone (Steven Thomas) living in her ap[artmen]t for the past year that is not on the lease and now she wants him out but he refuses to leave. What can we do? [H]er number is (754)2241958, but I asked that she call you back tomorrow morning as well.
Thomas v. State, supra. The italicized portions of the email are the parts the defense particularly objected to, as being inadmissible hearsay. The rest of the email consists of statements describing matters of which Ms. Zepp had first-hand knowledge and could, had the prosecution so desired, have testified to those matters at trial. These portions of the email did, and could, come in under the business records exception to the hearsay rule, which I wrote about in an earlier post. As the Court of Appeals explained,
Michelle McCord, the recipient of the email, testified that one of her duties as the property manager of Campus Walk Apartments was to keep track of records pertaining to the individual apartments. She inspected the email written by Ms. Zepp, and testified that it was a record kept in the ordinary course of business at Campus Walk Apartments. She testified that the record was made at or near the time the information it contained was provided by a person with knowledge. Finally, she testified it was a regular practice of Campus Walk Apartments to keep records such as the email. . . . After the trial judge determined that `clearly this email is within the firsthand knowledge of Ms. Zepp’ and `it's clearly within her duty to try to assist tenants,’ the trial judge ruled: `assuming the other requirements for the business record are met, I will admit that part of the record.’
Thomas v. State, supra.

The defense strongly objected to the inclusion of the underlined statements, arguing that “Ms. Baldwin's statement [to Ms. Zepp] constituted a separate layer of hearsay -- hearsay within hearsay-which could not come in without qualifying under an exception of its own.” Thomas v. State, supra. In making that argument, the defense relied on a Florida statute which says “[h]earsay within hearsay is not excluded . . . provided each part of the combined statements conforms with an exception to the hearsay rule”. Florida Statutes § 90.805.


According to the defense, while the rest of the email could come in under the business records exception, the underlined statements could not; the only way they could come in, the defense said, was if another exception to the hearsay rule applied to these statements . . . and it did not. The prosecution argued that all of the information in the email was “within the personal knowledge of Ms. Zepp”, so it did not constitute hearsay within hearsay. Thomas v. State, supra.

The Court of Appeals agreed with the defense: “The trial court erred in admitting the underlined portions of the email. While the employee who wrote the email had firsthand knowledge of Ms. Baldwin's desire to evict -- and could presumably . . . have so testified -- there was no evidence that she had personal knowledge of any of the surrounding circumstances.” Thomas v. State, supra. That is, there was no evidence showing she had personal knowledge of the relationship and living arrangements between Ms. Baldwin and Mr. Stevens and whether he was refusing to leave her apartment. As the Court of Appeals explained, the email contained two levels of hearsay:
The email is itself hearsay because it is an out-of-court statement being offered for the truth of the matters asserted. . . . It is Ms. Zepp's account of what Ms. Baldwin told her. Its accuracy depends both on Ms. Zepp's veracity and on Ms. Baldwin's veracity. Within the email -- the first tier of hearsay -- lies another layer of hearsay: the statement made by Ms. Baldwin to Ms. Zepp, viz., `that she's had someone (Steven Thomas) living in her ap[artmen]t for the past year that is not on the lease and . . . refuses to leave.’ There was no evidence Ms. Zepp had firsthand knowledge of these matters. Rather, her `knowledge’ that Ms. Baldwin `had someone (Steven Thomas) living in her ap[artmen]t for the past year . . . and . . . refuses to leave’ was hearsay. She was recounting statements she said she heard Ms. Baldwin make. Ms. Baldwin's statements were not . . . business records themselves. As recounted by Ms. Zepp, they were not admissible, because they did not qualify for an exception to the hearsay rule in their own right.
Thomas v. State, supra.

The Court of Appeals not only found that the admission of the email was error, it also found that it constituted reversible error, i.e., error requiring the reversal of Thomas’ murder conviction:
The hearsay was used . . . to prove motive, a critical component of the State's case, a case that relied solely on circumstantial evidence. The State used hearsay to show a possible reason for Mr. Thomas's wanting to kill his live-in girlfriend of four years. No other evidence tended to show that Ms. Baldwin had asked him to move out and that he had refused to leave.

Not even Ms. Baldwin's `best friend[ ] . . . testified . . . to any problems in the couple's relationship. In fact, the best friend testified she was scheduled to take Mr. Thomas to an appointment the morning after Ms. Baldwin was murdered. The State's . . . argument on appeal rings hollow against the background of its argument to the jury emphasizing that Ms. Baldwin wanted Mr. Thomas to move out but he refused, thus making the hearsay `a feature of its . . .closing argument.’ . . . Because there is a reasonable possibility that admission of Ms. Baldwin's hearsay statement that `[Mr. Thomas] refuses to leave’ contributed to Mr. Thomas's conviction, we are constrained to reverse for a new trial.
Thomas v. State, supra.

This decision issued on October 21, 2008, so there obviously has not been time for a new trial. From what the court says about the evidence the prosecution relied on in this trial, it sounds as if the loss of these parts of Ms. Zepp’s email may make it difficult for the prosecution to get a conviction if it tries again.

Friday, November 07, 2008

"Transmit"

Section 1030(a)(5)(A) of Title 18 of the U.S. Code makes it a federal crime “knowingly" to cause the transmission of "a program, information, code, or command. and as a result" intentionally cause "damage" to a computer.

(Until September 26, this provision was codified as 18 U.S. Code § 1030(a)(5)(A)(i). An Act that went into effect last month reordered some of the sections of § 1030 and made some substantive changes to the statute, but didn’t alter the substance of this one.)

This provision was at issue in International Airport Centers, L.L.C. v. Citrin, 440 F.3d 418 (7th Circuit Court of Appeals 2006). As I noted in an earlier post, § 1030(g) lets one who has been the victim of a violation of the criminal provisions of § 1030 bring a civil suit to recover damages for the injury he/she/it sustained. In the Citrin case, Jacob Citrin’s former employer sued him to recover damages for his allegedly violating what is now § 1030(a)(5)(A).

Here is how the Seventh Circuit Court of Appeals described the facts in the case:
Citrin was employed by the plaintiffs -- affiliated companies engaged in the real estate business we'll treat as one . . . and call `IAC’ -- to identify properties IAC might want to acquire, and to assist in any ensuing acquisition. IAC lent Citrin a laptop to use to record data that he collected in the course of his work in identifying potential acquisition targets.

Citrin decided to quit IAC and go into business for himself, in breach of his employment contract. Before returning the laptop to IAC, he deleted all the data in it -- not only the data that he had collected but also data that would have revealed to IAC improper conduct in which he had engaged before he decided to quit. Ordinarily, pressing the `delete’ key on a computer (or using a mouse click to delete) does not affect the data sought to be deleted; it merely removes the index entry and pointers to the data file so that the file appears no longer to be there, and the space allocated to that file is made available for future write commands. Such `deleted’ files are easily recoverable. But Citrin loaded into the laptop a secure-erasure program, designed, by writing over the deleted files, to prevent their recovery. . . . IAC had no copies of the files Citrin erased.
International Airport Centers, L.L.C. v. Citrin, supra. Citrin moved to dismiss IAC’s § 1030(a)(5)(A) cause of action for what the law calls “failure to state a claim.” When a defendant makes such a motion, the court assumes the facts set out in the complaint (the pleading that starts the case) are true, and then decides whether those facts show a violation of the statute on which the plaintiff’s claim is based.

In his motion to dismiss, Citrin argued that “merely erasing a file from a computer is not a `transmission” under § 1030(a)(5)(A). The Illinois federal district court agreed with him, and dismissed the suit. IAC appealed to the Seventh Circuit Court of Appeals which, at least initially, seemed to agree with the lower court: ”Pressing a delete . . . key in fact transmits a command, but it might be stretching the statute too . . . to consider any typing on a computer keyboard to be a . . . `transmission’ just because it transmits a command to the computer.” International Airport Centers, L.L.C. v. Citrin, supra.

The Seventh Circuit then proceeded to consider whether deleting files is a “transmission” within the compass of what is now § 1030(a)(5)(A):
There is more here, however: the transmission of the secure-erasure program to the computer. We do not know whether the program was downloaded from the Internet or copied from a floppy disk (or the equivalent of a floppy disk, such as a CD) inserted into a disk drive that was either inside the computer or attached to it by a wire. Oddly, the complaint doesn't say; maybe IAC doesn't know -- maybe all it knows is that when it got the computer back, the files in it had been erased. But we don't see what difference the precise mode of transmission can make. In either the Internet download or the disk insertion, a program intended to cause damage (not to the physical computer, of course, but to its files -- but `damage’ includes `any impairment to the integrity or availability of data, a program, a system, or information, 18 U.S.Code § 1030(e)(8)) is transmitted to the computer electronically. The only difference, so far as the mechanics of transmission are concerned, is that the disk is inserted manually before the program on it is transmitted electronically to the computer. The difference vanishes if the disk drive into which the disk is inserted is an external drive, connected to the computer by a wire, just as the computer is connected to the Internet by a telephone cable or a broadband cable or wirelessly.

There is the following contextual difference between the two modes of transmission, however: transmission via disk requires that the malefactor have physical access to the computer. By using the Internet, Citrin might have erased the laptop's files from afar by transmitting a virus. Such long-distance attacks can be more difficult to detect and thus to deter or punish than ones that can have been made only by someone with physical access, usually an employee. The inside attack, . . . while easier to detect may also be easier to accomplish. Congress was concerned with both types of attack: attacks by virus and worm writers . . . which come mainly from the outside, and attacks by disgruntled programmers who . . . trash the employer's data system on the way out (or threaten to do so . . . to extort payments), on the other. If the statute is to reach the disgruntled programmer, . . . it can't make any difference that the destructive program comes on a physical medium, such as a floppy disk or CD.
International Airport Centers, L.L.C. v. Citrin, supra.

IMHO, the Court of Appeals then makes a wrong turn. It bases its conclusion that § 1030(a)(5)(A) was intended to reach "the disgruntled programmer” on two other provisions of § 1030: the ones that criminalize “outsider” hacking (obtaining unauthorized access to a computer system) and “insider” hacking (exceeding one’s authorized access to a computer system). The court decides Citrin exceeded his authorized access to the IAC-provided laptop:
Citrin's breach of his duty of loyalty terminated his agency relationship (more precisely, terminated any rights he might have claimed as IAC's agent -- he could not by unilaterally terminating any duties he owed his principal gain an advantage!) and with it his authority to access the laptop, because the only basis of his authority had been that relationship. `Violating the duty of loyalty, or failing to disclose adverse interests, voids the agency relationship’. . . .
International Airport Centers, L.L.C. v. Citrin, supra.


The court reaches this conclusion even though, as Citrin pointed out, his “employment contract authorized him to `return or destroy’ data in the laptop when he ceased being employed by IAC”. It reaches this conclusion by deciding “it is unlikely, to say the least, that the provision was intended to authorize him to destroy data he knew the company had no duplicates of and would have wanted to have -- if only to nail Citrin for misconduct.” International Airport Centers, L.L.C. v. Citrin, supra. At that point, the court decides this isn’t an “exceeding authorized access” (“insider” hack) case at all; it decides it’s really an “unauthorized access” case because Citrin had lost his right to access the IAC computer.

That, I think, was the court’s first error. As I pointed out in an earlier post, the task of deciding precisely when an “insider” exceeds his or her access to a computer system can be a difficult one. Usually, courts look to written policies the victim company has in place, policies that define what the employee can and cannot do while on the company’s computer system.

Here, the employment contract says Citrin could destroy data before returning the IAC laptop, and that is precisely what he did. We may think a reasonable person would know not to destroy so MUCH data, but as I explained in my
earlier post, it can be difficult to tell precisely when an employee steps over the line. And since this suit is brought under a criminal statute, the court, I submit, should adhere strictly to the mens rea set out in the statute . . . which is “intentionally”. Intentionally is the mens rea for both the “unauthorized access” and “exceeds authorized access” crimes, so it applies regardless of which crime the Court of Appeals decides Citrin committed. And you simply cannot prove someone acted “intentionally” if all you can show is that he SHOULD have known that what he did violated his employment contract; you have to show he actually knew that. ("Should have known" is a negligence standard and, as such, is a much lower level of mens rea than intentionally.)

The other error I think the court made is that it didn’t consider what this particular crime – the now § 1030(a)(5)(A) crime – was meant to encompass. I found a Senate report that explains what this new section of § 1030 (which is also known as the Computer Fraud and Abuse Act, or CFAA) was meant to do:
Computer abuse crimes under the current statute must be predicated upon the violator's gaining `unauthorized access’ to the . . . computers. However, . . . the most severe forms of computer damage are often inflicted upon remote computers to which the violator never gained `access’ in the commonly understood sense of that term. Instead, those computers are damaged when a malicious program or code is replicated and transmitted to them by other computers infected by the violator's original transmission.

The new subsection 1030(a)(5) of the CFAA . . . makes it clear that one who transmits a destructive program or code with harmful intent is criminally responsible for the resultant damage to all affected computers, without regard to . . . `unauthorized access.’ . . .
Senate Report No. 101-544, The Computer Abuse Amendments Act of 1990 (October 19, 1990), 101ST Cong., 2d Sess. 1990, 1990 WL 201793. It seems to me the language in this report clearly establishes that § 1030(a)(5)(A) was not intended to be any kind of “access” crime but, instead, a transmission of malware crime.

Wednesday, November 05, 2008

PCTDD & the 4th Amendment

Last year, I did a post in which I talked about the Supreme Court’s decision in Smith v. Maryland, 442 U.S. 735 (1979).

In Smith, the government put a pen register -- a device that captures the numbers dialed on a telephone -- on Smith’s home phone. They were investigating him for making harassing calls, and used the data collected by the pen register against him in a prosecution for doing so.


Smith argued that the use of the pen register was a 4th Amendment “search” because he had a reasonable expectation of privacy in the numbers he dialed from his home phone.

As I explained in an earlier post, to have a reasonable expectation of privacy in something (i) you must think it is private (subjective) and (ii) society must regard your expectation as “reasonable” (objective). The Court said Smith (a) could not have had a subjective expectation of privacy in that data because he knew he was giving it to the phone company and (b) even if he had such an expectation, it is not one society would accept as objectively reasonable because, the Court said, we all know that if we give information to a third party it is no longer private.


After Smith, Congress enacted a statute that establishes the procedure law enforcement officers must use to get a pen register. Basically, they have to certify “that the information likely to be obtained is relevant to an ongoing criminal investigation being conducted by” the agency for which they work. 18 U.S. Code § 3122. If the court to which such an application is submitted find that the government has shown this is, in fact, likely, it must issue the order allowing the pen register to be installed.

Technology has evolved since that statute was adopted so in 2001 the “Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism,” Pub.L. No. 107-56, 115 Stat. 272, commonly known as the Patriot Act modernized the Pen/Trap Statute to accommodate wireless and internet-based technology. The Patriot Act updated the definition of pen register from “a device which records or decodes electronic or other impulses which identify the numbers dialed or otherwise transmitted on the telephone line” to “a device or process which records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted . . . .” 18 U.S.Code § 3127(3) (as amended).

The Patriot Act also added a clause at the end of the definition this definition: “provided, however, that such information shall not include the contents of any communication”. That operationalizes the distinction I noted in my earlier post – the distinction between the numbers dialed to initiate a phone call and the contents of the conversation. The latter is private under the 4th Amendment, so intercepting contents is, in fact, a “search.”

Last year, a New York federal district court was asked to decide whether a pen register can constitutionally be used to obtain what are called “post-cut-through dialed digits” or whether they fall within the scope of the 4th Amendment. The case is In re U.S. for Orders (1) Authorizing Use of Pen Registers and Trap and Trace Devices, 515 F.Supp.2d 325 (E.D.N.Y. 2007). I’m going to refer to it as In re U.S.

The issue arose because the U.S. Attorney for the Eastern District of New York filed an application for the installation of a pen register. “In the application, the Government requested access to all dialed digits, including post-cut-through dialed digits, even if such digits may contain the contents of a telephone communication.” The issue was whether the government could constitutionally obtain that information by using the pen register statute (instead of a search warrant or wiretap authorization, both of which comply with the 4th Amendment. This is how the court described the issue before it:
Telephone use has expanded rapidly since the constitutionality of pen registers was examined in 1979. Today, Americans regularly use their telephones not just to dial a phone number, but to manage bank accounts, refill prescriptions, check movie times, and so on.

Dialed digits can now be categorized in a number of ways. `Post-cut-through dialed digits’ (`PCTDD’), the subject of the instant application, “are any numbers dialed from a telephone after the call is initially setup or ‘cut-through.”’ . . . In most instances, any digit dialed after the first ten is a PCTDD. `Sometimes these digits transmit real information, such as bank account numbers, Social Security numbers, prescription numbers, and the like.’ . . . In such circumstances, PCTDD contain the `contents of communication.’ . . . At other times, PCTDD `are other telephone numbers, as when a party places a credit card call by first dialing the long distance carrier access number and then the phone number of the intended party,’ . . . or when an extension number is dialed. . . .

The Government contends that pen register authorization entitles it to all digits dialed from a target telephone, including PCTDD that may include content. The Government maintains that federal law requires it only to minimize the collection of content using reasonably available technology. If no technology exists that can sort content from non-content, the Government argues it is entitled to access all digits dialed subject only to Department of Justice (“DOJ”) guidelines, which forbid the use of content gathered with a pen register absent extenuating circumstances, and federal wiretap laws. . . . . For the sake of clarity, I will refer to the Government's position as the `minimization theory.’
In re U.S. supra.

The issue of minimization comes from a provision the 1994 Communications Assistance for Law Enforcement Act (CALEA) added to the pen register statute. CALEA was meant “to preserve the Government's ability . . . to intercept communications involving advanced technologies such as digital or wireless transmission modes, or features and services such as call forwarding, speed dialing and conference calling, while protecting the privacy of communications”.” H.R. Rep. 103-827(I), 103d Cong., 2d Sess. at 9 (Oct. 4, 1994). As the In re U.S. court noted, the new provision imposes a “limitation on the Government's use of a pen register.” It requires that a government “agency authorized to install . . . a pen register . . . use technology reasonably available to it that restricts the recording. . . to the dialing and signaling information utilized in call processing.” 18 U.S.Code § 3121(c). Here, as in other cases, the government said that since there is no technology that can distinguish PCTDD from the digits legitimately captured by a pen register, it is, by default, entitled to both.

Th In re U.S. court disagreed. It held, first of all, that we have a 4th Amendment, reasonable expectation of privacy in PCTDD:
While individuals may not have a reasonable expectation of privacy in the numbers they dial to connect a phone call, the content they communicate over a phone line in the form of PCTDD is different. Technology has transformed the way Americans use phone lines. Now, instead of a human operator, individuals are asked to relay information to a machine by way of PCTDD to process requests and obtain information. When this communication includes content, it is the functional equivalent of voice communication and is protected by Katz and its progeny as such. Moreover, the information is often transmitted via PCTDD is often sensitive and personal. Bank account numbers, pin numbers and passwords, prescription identification numbers, social security numbers, credit card numbers, and so on, all encompass the kind of information that an individual wants and reasonably expects to be kept private.
In re U.S. supra.

The court also held that we do not assume the risk of the government’s getting this information by sharing it, in effect, with the phone company. It essentially found that these numbers are different from the numbers we dial in order to place a call; the latter are a direct communication with the phone company for its own purposes. The others may go through the phone company, but they are not intended as a communication with the phone company. It also noted that allowing the government to obtain PCTDD would be “highly intrusive” on our privacy:
Government installed pen registers were held to be permissible warrantless searches in Smith because, by their nature (their inability to collect content), they were minimally intrusive. Today's pen registers, as advocated by the Government in the instant application, have the potential to be much more intrusive than when their constitutionality was first examined. The evolution of technology and the potential degree of intrusion changes the analysis.
In re U.S., supra. The court therefore denied the government’s application for access to all post-cut-through dialed digits, though it ackowledged the problem the government faces:
I am sympathetic to the Government's pleas of necessity. That there is no technology . . . that can sort content from non-content is unfortunate, but it is not for this Court to fashion a solution. Rather, this is an issue for Congress to address, particularly in light of sophisticated criminals who will soon be wise, if they are not already, to this investigative loophole. Despite the investigative benefit which would come from access to all PCTDD, the Government cannot bootstrap the content of communications, protected by the Fourth Amendment, into the grasp of a device authorized only to collect call-identifying information. Until the Government can separate PCTDD that do not contain content from those that do, pen register authorization is insufficient for the Government to obtain any PCTDD.
In re U.S. supra.

Monday, November 03, 2008

Hashing = 4th Amendment Search

On October 22, a federal district court issued what may be a notable opinion in U.S. v. Crist, 2008 WL 4682806 (U.S. District Court - Middle District of Pennsylvania 2008).

The issues the opinion addresses were raised by Crist’s motion to suppress evidence seized from his computer.


Here’s a summary of the facts – as described by the court – that resulted in Crist’s being charged with possessing child pornography and his moving to suppress evidence taken from his computer:

Crist rented a house in Camp Hill but was late with rental payments. After he fell two months behind, his landlord hired Jeremy and Kirk Sell to move Crist's stuff out of the house. Crist had made arrangements to move some of his things and most of his furniture, but had not moved everything by the time the Sells showed up at his house. According to the court, “[s]cattered throughout the nearly vacant rooms were Crist's possessions, including a keyboard, a PlayStation gaming console, and a personal computer. . . . [T]he Sells began removing Crist's possessions and placing them on the curb for trash pickup." U.S. v. Crist, supra.


A few days later, Jeremy “called his friend Seth Hipple, who . . . was looking for a computer,” to tell him he would be putting Crist's computer out for trash pickup. Hipple showed up and took it. Later, Crist came to the house and found the Sells removing his things. After they explained what they were doing, he “`went in the house, started going through bags out in the street. And he . . . asked, where is my computer?'” U.S. v. Crist, supra. Though the Sells knew Hipple had it, they “professed ignorance.” U.S. v. Crist, supra. Crist called the police “to complain of the theft of his computer, and Officer Adam Shope took a report.” U.S. v. Crist, supra.

Hipple took the computer to a friend's house, where they “`tried to get it running, tried to . . . clean it up.’” U.S. v. Crist, supra. He then took it home and began going “`through it to see what [he] could delete.’” After looking through a “`bunch of songs’” on a media folder,” he opened “a couple of video files depicting children performing sexual acts.’” Hipple “`freaked out,’ deleted the entire folder . . . and turned off the computer.” U.S. v. Cris, supra. A few days later, he called the police; when an officer arrived, he said he found “the computer and . . . discovered child pornography on it. Hipple `reported that he deleted the file right away.’ A report was taken, and the computer was logged into evidence.” U.S. v. Crist, supra. A detective contacted the Pennsylvania Attorney General's Office (AG’s Office) to have the it forensically examined.

This is where we come to the critical part of the case. A special agent with the AG Office’s computer forensics department conducted an examination of the computer:
Agent Buckwash created an `MD5 hash value’ of Crist's hard drive. An MD5 hash value is a unique alphanumeric representation of the data, a sort of . . . `digital DNA. When creating the hash value, Agent Buckwash used a `software write protect’ . . . to ensure that `nothing can be written to that hard drive.’ . . . Next, he ran a virus scan. . . . After that, he created an `image, or exact copy, of all the data on Crist's hard drive.

Agent Buckwash then opened up the image . . . in a software program called EnCase. . . . He explained that EnCase does not access the hard drive . . . through the computer's operating system. Rather, EnCase . . . . reads every file --bit by bit, cluster by cluster -- and creates a index of the files contained on the hard drive. . . .

Once in EnCase, Agent Buckwash ran a `hash value and signature analysis on all of the files on the hard drive.’ In doing so, he was able to `fingerprint’ each file in the computer. . . . [H]e compared those hash values to the hash values of files that are known or suspected to contain child pornography. [He] discovered five videos containing known . . . . [and] 171 videos containing suspected child pornography. . . .

Agent Buckwash `switch[ed] over to a gallery view, which gives us all the pictures on the computer,’ and was able to `mark every picture that [he] believe[d] is notable, whether it be child pornography or . . . something specific.’ Ultimately, he discovered almost 1600 images of child pornography or suspected child pornography.

Finally, [he] conducted an internet history examination by reviewing . . . `index [dot] dat’ files, which . . . amount to a history of websites the computer user visited. After extracting the index [dot] dat files, [he] used . . . NetAnalysis, which `allows you to sort for suspected child pornography.’ After [he] completed the forensic examination, he generated a report of his findings and presented it to Detective Cotton.
U.S. v. Crist, supra. Crist was indicted for possessing child pornography and moved to suppress the evidence obtained from his computer. The motion raised two issues: (i) whether Agent Buckwash’s examination exceeded the scope of the Hipple’s search of the computer; and (ii) whether the use of EnCase was a 4th Amendment “search.”

As I’ve noted before, the 4th Amendment only applies to actions by law enforcement officers – to what is called “state action.” So Hipple’s looking through the files on Crist’s computer was not a 4th Amendment search; he was acting on his own, not as an agent of the police. That means police can look at everything Hipple looked at – but ONLY what he looked at – without violating the 4th Amendment. Crist argued that Agent Buckwash’s EnCase examination exceeded the scope of Hipple’s private search AND itself constituted a “search” under the 4th Amendment.

The prosecution argued (i) that because Hipple had been “into” Crist’s computer, Crist no longer had a 4th Amendment expectation of privacy in the computer itself and (ii) that the Encase examination was not a search because “Agent Buckwash never `accessed the computer,’ but `simply ran hash values on’” it. U.S. v. Crist, supra. As to the first issue, the court relied on a Fifth Circuit Court of Appeals case (Runyan) which held that simply because private citizens examined SOME disks belonging to the suspect did not mean he lost his 4th Amendment expectation of privacy in the disks they did not examine.

That set up the second issue: whether the EnCase examination was a 4th Amendment search; if it was, it exceeded the scope of what Hipple had done and was, therefore, unconstitutional. U.S. v. Crist, supra. The district court found it was a search:
Computers are composed of many compartments, among them a `hard drive, . . . composed of many `platters,’ or disks. To derive the hash values of Crist's computer, the Government physically removed the hard drive from the computer, created a duplicate image of the hard drive . . . and applied the EnCase program to each compartment, disk, file, folder, and bit. By subjecting the entire computer to a hash value analysis-every file, internet history, picture, and `buddy list’ became available for Government review. Such examination constitutes a search.

Moreover, the EnCase analysis is a search different in character from the one conducted by Hipple, and thus it cannot be defended on the grounds that it did not exceed the private party search. As noted above, the rationale . . . is that the private search was so complete, no privacy interest remained. That is not the case here.

Hipple opened `a couple of videos’ and deleted them, a far different scenario from the search in Jacobsen, wherein the opening of a package . . . necessarily obviated any expectation of privacy. Here, the Hipple private search represented a discrete intrusion into a vast store of unknown electronic information. While Crist's privacy interest was lost as to the `couple of videos’ opened by Hipple, it is no foregone conclusion that his privacy interest was compromised as to all the computer's remaining contents.

. . . . Comparing a disk containing multiple files to the opened package breached in Jacobsen, the Runyan court found that no privacy interest remained in a disk once some of its contents had been viewed. As to the unopened disks, the court found privacy rights intact, and held unlawful a warrantless search of such disks. Where, as here, substantial privacy rights remained after the private search and the government actors had reason to know the EnCase program would likely reveal more information than they had learned from Hipple's brief search, . . . the scope of the private search was exceeded. . . .

[T]he Court specifically rejects the Government's . . . asking the Court to compare Crist's entire computer to a single closed container which was breached by the Hipple search. A hard drive is not analogous to an individual disk. Rather, a hard drive is comprised of many platters, or magnetic data storage units, mounted together. Each platter, as opposed to the hard drive in its entirety, is analogous to a single disk as discussed in Runyan. As such, the EnCase search implicates Crist's Fourth Amendment rights.
U.S. v. Crist, supra. The court therefore ordered the evidence obtained through the forensic examination of Crist’s computer to be suppressed, which might well end the case.

I absolutely agree with this court, and hope that if the government appeals, the Court of Appeals affirms what this judge has done.

I saw a comment someone – someone technologically sophisticated, unlike me – posted somewhere. It wondered why no one has come up with software that would change a few values of every image and movie file on a hard drive to frustrate this kind of hash matching. I have no idea why not, or if this is feasible, but it sounds like an interesting idea.

If someone would come up with such a program, we’d then have to decide if it’s a 4th Amendment “search” to use EnCase (and similar programs) on a hard drive if the owner of the hard drive had not used this hash-altering software. In other words, the issue would perhaps become whether, by not using this hypothetical hash-altering software, you had assumed the risk the government would be able to find evidence on your hard drive.

Friday, October 31, 2008

Not-Hearsay

As I noted in an earlier post, every state and the federal system have rules of evidence that bar the use of what’s called “hearsay.” Rule 801(c) of the Federal Rules of Evidence defines hearsay as “a statement, other than one made by the declarant while testifying at the trial or hearing, offered in evidence to prove the truth of the matter asserted.”

As I also explained in that earlier post, courts bar the use of hearsay – unless it falls within one of a few exceptions to the rule barring its use – because it’s presumptively unreliable.

As I noted there, allowing hearsay as a general matter would mean John Doe could take the stand and say he’d heard that the defendant – Jane Smith – had committed all kinds of crimes. It then becomes difficult for Jane or her attorney to rebut what John Doe had told the jury; they can’t cross-examine the person who allegedly said these things about Jane. So aside from its inherent unreliability, hearsay can deny the party against whom it is introduced the right to confront witnesses against them, a right guaranteed under the U.S. Constitution in criminal constitution.


Sometimes, though, a record or other item that seems to be hearsay is, in fact, not. That’s what this post is about. It comes from a decision by the Washington Court of Appeals: State v. Nordquist, 2008 WL 642615 (2008). Here are the facts in the case:
Scott Nordquist possessed a check drawn on Jodi Hamer's checking account from Fibre Federal Credit Union. On July 11, 2006, he walked into the credit union and presented the check for payment, with two pieces of identification, to credit union employee Kendra Thompson. Thompson took the check . . ., entered the check's information into the credit union's computer, and received an electronic bank memo alert on her computer that `this particular series of check numbers may have been stolen and to use caution when verifying the signature.”

Thompson excused herself . . . to compare the signature on the check with Hamer's signatures on past checks and her account card. Unable to match the signature on Nordquist's check with the signatures on Hamer's account, Thompson contacted her supervisor, who called the Longview Police Department. Meanwhile, Nordquist waited for about 15 minutes, until two police officers arrived.

After verifying Nordquist's identity, the officers took him to a room at the credit union, where they conducted an investigation. Nordquist told the officers that `he received the check from a girl named Amy.’ But after Officer Jennifer Jolly continued to question Nordquist about how he had obtained the check, he finally responded, `[W]ell, now that you put it that way, it doesn't make any sense.’ The officers arrested Nordquist for forgery.
State v. Nordquist, supra.

Nordquist was tried for, and convicted of, forgery. He appealed his conviction, arguing in part that the
trial court abused its discretion when, over his objection, it allowed the following testimony from Thompson: `There was a memo stating that this particular series of check numbers may have been stolen and to use caution when verifying the signature.’ Nordquist argues that the memo's statement was inadmissible hearsay evidence under [Washington Rule of Evidence] 801(c).
State v. Nordquist, supra.

The Washington Court of Appeals began its analysis of Nordquist’s argument by noting that hearsay can “`be admitted if offered for purposes other than to prove the truth of the matter asserted.’” The court then found that
Thompson's testimony about the bank's computer alert conveyed her rationale for excusing herself from Nordquist, checking the account holder's signature against the signature on the check that Nordquist had presented, and then calling her manager. Thompson did not testify that the check Nordquist presented and that she examined was stolen. Nor did the State charge Nordquist with possessing stolen checks or stealing the checks. Thus, the bank memo did not serve to prove the truth of a matter asserted in Thompson's testimony.

On the contrary, . . . the trial court allowed Thompson's testimony as an explanation for her actions, not as substantive evidence that some checks from this account had been stolen. Thus, her bank memo testimony was not hearsay under [Washington Rule of Evidence] 801 and, therefore, not excludable. . . . Accordingly, we hold that the trial court did not abuse its discretion in admitting Thompson's testimony about the computer alert.
State v. Nordquist, supra. So, not-hearsay = no problem.

Wednesday, October 29, 2008

Unlawful Use of Encryption

I’ve written a few times about encryption issues; those posts were about legal rules that facilitate or restrict your ability to use encryption to protect your data. This post is about something different: making it a crime to use encryption.

Six states – Arkansas, Illinois, Iowa, Minnesota, Nevada and Virginia – have statutes that make the “unlawful use of encryption” a crime. The statutes are relatively new; a couple of them date from 1999, others were adopted between 2001 and 2005 and Illinois’ statute is brand new. It goes into effect on January 1, 2009.

Illinois’ adding such a statute makes me wonder if we will see more states doing the same.


Perhaps because Illinois’ statute is the most recent, it is the most detailed. Since it is the most detailed, I’m going to use it to illustrate what these statutes do; then I’ll speculate a bit about why they’re being adopted and how effective they are likely to be in doing whatever it is they’re supposed to do. So here’s the Illinois statute (sans the boilerplate definitions in section (a)):
(b) A person shall not knowingly use or attempt to use encryption, directly or indirectly, to:

(1) commit, facilitate, further, or promote any criminal offense;
(2) aid, assist, or encourage another person to commit any criminal offense;
(3) conceal evidence of the commission of any criminal offense; or
(4) conceal or protect the identity of a person who has committed any criminal offense.

(c) Telecommunications carriers and information service providers are not liable under this Section, except for willful and wanton misconduct, for providing encryption services used by others in violation of this Section.

(d) A person who violates this Section is guilty of a Class A misdemeanor, unless the encryption was used or attempted to be used to commit an offense for which a greater penalty is provided by law. If the encryption was used or attempted to be used to commit an offense for which a greater penalty is provided by law, the person shall be punished as prescribed by law for that offense.

(e) A person who violates this Section commits a criminal offense that is separate and distinct from any other criminal offense and may be prosecuted and convicted under this Section whether or not the person or any other person is or has been prosecuted or convicted for any other criminal offense arising out of the same facts as the violation of this Section.
720 Illinois Compiled Statutes § 16D-5.5.

(The Arkansas, Minnesota and Nevada statutes are similar, but shorter. The Iowa and Virginia statutes consist of a single sentence, like this “Any person who willfully uses encryption to further any criminal activity shall be guilty of an offense which is separate . . . from the predicate criminal activity and punishable as a Class 1 misdemeanor.” Virginia Code § 18.2-152.15.)

Let’s begin by parsing what I consider to be the essential provisions of the statute: (b) and (e). Note that section (b) not only makes it a crime to use encryption in committing, aiding and abetting or concealing a crime, it makes it a crime to ATTEMPT to do any of these things.

As I’ve noted before, the primary reason we criminalize attempts – crimes that were, by definition, never actually committed -- is to give law enforcement the ability to step in and make an arrest without having to wait until the criminal actually carries out his or her evil plans. How would that work here? I’m having a little difficulty coming up with situations in which law enforcement could step in and arrest you for using encryption in an attempt to commit a crime.
There are two kinds of attempts: In one, police interrupt you before you commit your target crime (murder, theft, etc.); in the other, you do everything you can do commit the crime but fail.

The second category of attempts are known as “impossible” attempts; you fail because something makes it impossible for you to actually inflict the “harm” you tried to inflict. The classic example of that is someone who, say, wants to kill his neighbor (with whom he’s feuding); our perpetrator sneaks over to the neighbor’s house with a rifle, sees the neighbor sitting on the couch and shoots him. The shot would have killed the neighbor had he not died of a heart attack a few hours before; here, the perpetrator did everything he could to commit murder but failed. He can only be charged with an attempt to commit murder.


How would that work with attempts to use encryption to commit a crime? Assume John X works for a government agency that handles classified information; he decides to steal some of the information and sell it to whoever would be willing to buy it (A spy? A terrorist?). He copies what he believes to be classified information onto a thumb drive and encrypts the data to ensure no one can read it when he takes the thumb drive with him on his way home. He puts the thumb drive in his bad as he leaves work; FBI agents arrest him on his way out. What he doesn’t know is that the FBI has been suspicious of him for some time, and the “classified information”on the thumb drive is, in fact, not classified. He therefore can’t be charged with stealing classified information; he is charged with attempting to steal classified information AND with using encryption in his attempt to commit that crime.

Does that make sense? Does anyone have a better example of what the use encryption in an attempt to commit a crime offense might encompass? (I am not, by the way, even going to attempt to parse out what “indirectly using encryption in an attempt to commit a crime” might mean. I have neither the space nor the patience to do that here; maybe another time.)

I can see how the attempt option might apply to concealing a crime. Here’s an example: You encrypt your hard drive to keep police from finding the child pornography you then download onto it. Officers show up with warrants, arrest you and seize your computer. They find the encryption key, search the hard drive and find the child pornography. Your goal was to use encryption to conceal the commission of the crime of possessing child pornography; you didn’t succeed, so you could be charged with attempting to use it for that purpose.

I can also see how the using encryption in an attempt to aid and abet the commission of a crime option might work. Assume you and I are old friends; you’re broke and I work in a bank. You ask me to help you rob the bank; you want me to get you codes you can use, say, to access the bank vault at a time when it is not normally open. I agree. So over the course of a couple of workdays I locate and copy the codes; I save them in an encrypted file and email the file to you.

Unfortunately for us, I send it to the wrong email address; I send it to your old email address, the one you and your former husband (with whom you are involved in a very contentious divorce) use. He gets the email, figures out what we’re up to, goes to the police and turns us in. I did my best to aid and abet your robbing the bank, but I failed. So I could be charged with using encryption in an attempt to aid and abet bank robbery, as well with an attempt to aid and abet the robbery.


That brings me to the other notable aspect of the Illinois statute (and the other, similar statutes): section (e). It reiterates what I would argue is already clearly established: The “unlawful use of encryption” crime is a crime separate and distinct from other crimes; I think the purpose of this provision is to make it clear that this crime doesn’t merge into a completed substantive crime.

Some crimes merge, others do not. An attempt to commit a crime (murder, say) merges into the completed crime (murder) because an attempt has fewer elements and inflicts less “harm” than the completed crime the attempt was trying to achieve. So you cannot be charged with both (i) attempt to commit murder and (ii) committing murder if you kill someone. You can only be charged with murder; the attempt merges into the completed crime.

Section (e) of the Illinois statute (and comparable provisions in the other state statutes) is apparently intended to make it very clear that if you use encryption to commit, abet or conceal a crime that becomes an additional charge that can be brought against you. I assume it is intended to underscore the fact that using encryption ratchets up the liability and penalties you face if you are apprehended and prosecuted.

All this is speculation because I can’t find any cases in which someone was charged with violating one of these statutes. The Illinois statute hasn’t gone into effect yet, so it obviously hasn’t been used but some of the statutes are nearly a decade old. You’d think someone would have been prosecuted under one of them by now. Maybe the lack of prosecutions to date is due to people’s – criminals’ and aspiring criminals’ – not using encryption. I suspect that will change, if it has not already changed.

One more scenario before I quit: I did a post last year about a district court’s holding that a man could take the 5th Amendment and refuse to give up his encryption key. The man’s laptop was seized when he crossed the U.S.-Canadian border. Federal agents suspected there was child pornography on the laptop, but its hard drive was encrypted. So, the man can take the 5th Amendment and refuse to give them the key, which means they can’t access the files to confirm that child pornography is on the laptop. They know he encrypted his hard drive, which MAY contain child pornography. If they had access to a statute like the Illinois statute, could prosecutors charge him with using encryption to conceal his possession of child pornography?

The answer is no: If they have probable cause to believe there’s child pornography on the hard drive, prosecutors could charge him; but unless they can get into the hard drive, they would not be able to prove beyond a reasonable doubt that he actually used encryption to conceal his possession of child pornography. There would, therefore, be no point in charging him.

I came up with that scenario when I was trying to figure out if these “unlawful use of encryption” statutes would give prosecutors a way to go after someone who has encrypted evidence or contraband (something it is a crime to possess). By encrypting the evidence or contraband, she has effectively prevented the state from being able to use that data to prosecute her for a substantive crime (child pornography, terrorism, fraud). The prosecution can prove beyond any reasonable doubt that she encrypted the data; the problem, insofar as using the “unlawful use of encryption” laws is concerned, is that the prosecution suspects – but cannot prove – that the encrypted data proves she committed, attempted to commit, abetting, attempted to abet, concealed or attempted to conceal the commission of a crime.

Monday, October 27, 2008

Textual Child Pornography?

About a month ago, I did a post on textual obscenity, which is at least a conceptual possibility under U.S. law.

This post is about something different: textual child pornography . . . which I suspect is not a crime under U.S. law.


The question came up in the course of a conversation I had a couple of days ago with a reporter from Detroit. He said a prosecutor there – state or federal, I’m not sure which – is prosecuting pimps who apparently used Craiglist and other websites to prostitute children. I don’t know anything about the case, if such a case is in progress, but the reporter said something I found interesting.

He mentioned that a possible charge might be the distribution of child pornography. When I asked what such a charge would be based on, he said he thought it would be based on the pimps’ posting nude and/or sexually suggestive photos of children online along with text describing the sexual services they could, and would, provide. I found that interesting, because it raised the issue (in my mind, anyway) as to whether text can constitute child pornography.

I want to analyze that possibility, but I don’t want to use the possible-Detoit prosecution as the factual basis for our analysis. Instead, I want to focus on the ultimate issue: whether pure text could constitute child pornography. If it can, then someone who writes stories about children engaged in sexual activity (presumably with adults) could perhaps (we’ll come back to that later) be creating child pornography (a crime under state and federal law); if they posted it online or shared with others, they could be charged with disseminating child pornography.

The federal statute that defines the terms used in the child pornography and child exploitation statutes 18 U.S. Code § 2256. It defines “child pornography” as
any visual depiction, including any photograph, film, video, picture, or computer or computer-generated image or picture, whether made or produced by electronic, mechanical, or other means, of sexually explicit conduct, where--
(A) the production of such visual depiction involves the use of a minor engaging in sexually explicit conduct;
(B) such visual depiction is a digital image, computer image, or computer-generated image that is, or is indistinguishable from, that of a minor engaging in sexually explicit conduct; or
(C) such visual depiction has been created, adapted, or modified to appear that an identifiable minor is engaging in sexually explicit conduct.
18 U.S. Code § 2256(8). It defines “visual depiction” as including “undeveloped film and videotape, and data stored on computer disk or by electronic means which is capable of conversion into a visual image and data which is capable of conversion into a visual image that has been transmitted by any means, whether or not stored in a permanent format". 18 U.S. Code § 2256(5).

I can’t find a definition of “visual image” in the U.S. Code or in any of the state criminal statutes. It seems reasonable to me, though to assume the term means what it clearly denotes, i.e., a picture of some kind, a graphical versus textual depiction of a person or persons. That would make sense given the reasons why we began criminalizing child pornography. As I explained in an earlier post, the U.S. Supreme Court has said there are two reasons why we criminalize child pornography: Its creation involves the victimization of childre and it preserves their victimization essentially forever. As I also explained, the Supreme Court said both rationales only justify the criminalization of child pornography the creation of which involves victimizing real children.

The question then becomes, do the rationales also mean that in criminalizing child pornography we only criminalize graphical depictions of the victimization of children . . . or should it also extend to textual depictions of such victimization? That’s a good question, and I’m not sure can answer it. I’ve done some thinking and some research on the issue, and I’m going to share what I’ve come up with, and found, with you . . . maybe you have some good ideas on all this.

Let’s start with the only reported case I know of in which someone was prosecuted for possessing child pornography based on his possessing textual material. In Regina v. Sharpe, 2001 CarswellBC 82 (Supreme Court of Canada 2002), John Sharpe was charged with possession of child pornography after Canadian Customs officers seized “computer discs containing a text entitled `Sam Paloc's Boyabuse -- Flogging, Fun and Fortitude: A Collection of Kiddiekink Classics” from his possession. Regina v. Sharpe, supra.

Sharpe moved to dismiss the charge, arguing that it violated the right to freedom of expression guaranteed in § 2(b) of the Canadian Charter of Rights and Freedoms. Regina v. Sharpe, supra. The prosecution – the Crown – conceded that the statute under which he was charged -- § 163.1(4) of the Canadian Criminal Code – infringed that right. The issue then became

whether this limitation of freedom of expression is justifiable under § 1 of the Charter, given the harm possession of child pornography can cause to children. Mr. Sharpe accepts that harm to children justifies criminalizing possession of some forms of child pornography. The. . . question therefore is whether §163.1(4) of the Criminal Code goes too far and criminalizes possession of an unjustifiable range of material.
Regina v. Sharpe, supra. Section 1 of the Canadian Charter of Rights says the Charter “guarantees the rights and freedoms set out in it subject only to such reasonable limits prescribed by law as can be demonstrably justified in a free and democratic society.” So the issue was whether criminalizing Sharpe’s possession of textual child pornography could be upheld under this provision.

The Canadian Supreme Court began its analysis of the issue by noting that the Criminal Code defined child pornography in terms of “visual representations.” Under the Criminal Code, a visual representation can constitute child pornography in three ways: (i) “By showing a person who is, or is depicted as, being under . . . 18 years and is engaged in, or is depicted as engaged in, explicit sexual activity; (ii) by ”having, as its dominant characteristic, the depiction, for a sexual purpose, of a sexual organ or the anal region of a person under the age of 18”; or (iii) by “advocating or counselling sexual activity with a person under the age of 18 years that would be an offence under the Criminal Code”. Regina v. Sharpe, supra. The court noted that “[w]ritten material can constitute child pornography in only the last of these ways”. Regina v. Sharpe, supra.

Its opinion is almost 100 pages long, so I can’t begin to go into the analysis in detail. I’ll just note that its primary concern was the fact that the statute criminalized
Self-created works of the imagination . . . intended solely for private use by the creator. The intensely private, expressive nature of these materials deeply implicates § 2(b) freedoms, engaging the values of self-fulfilment and self-actualization and engaging the inherent dignity of the individual. . . . Personal journals and writings. . . may well be of importance to self-fulfilmen. . . . The fact that many might not favour such forms of expression does not lessen the need to insist on strict justification for their prohibition.
Regina v. Sharpe, supra. The court therefore read an exception into § 163.1(4); it “protects the possession of expressive material created through the efforts of a single person and held by that person alone, exclusively for his or her own personal use.” Regina v. Sharpe, supra.

I am only aware of one somewhat similar case in the United States. In 2001, 22-year-old Brian Dalton of Columbus, Ohio pled guilty to a pandering obscenity charge that was based on fantasies – stories – he had written. According to news reports, the stories described the sexual molestation and torture of three children (10 and 11) who were kept in a case in a basement. Dalton pled guilty to one pandering obscenity count to avoid being brought to trial on a second charge; if he had been convicted on both charges, he would have faced 16 years in prison. As it was, he was sentenced to 10 years in prison.

In 2003, an Ohio Court of Appeals held that Dalton should be allowed to withdraw his guilty plea because he received ineffective assistance from his counsel. State v. Dalton, 793 N.E.2d 509 (Ohio App. 2003). The court held that Dalton would have had a good argument as to the unconstitutionality of the charges against him:
Because there is constitutional significance to the distinction between pornographic depictions of real children and similar depictions of fictional children, understanding the factual basis for the charges against appellant was particularly important. It is uncontested that the children depicted in appellant's journal and the repugnant acts described therein were creations of appellant's imagination. Therefore, this case raises a substantial question concerning the constitutionality of a statute prohibiting the creation and private possession of purely fictitious written depictions of fictional children. One court in Ohio has held that [Ohio statutes] cannot constitutionally criminalize the private possession of an obscene but possibly fictitious letter involving children. `Otherwise, the legislature would in effect be punishing an individual for his/her thoughts.’

Because appellant's trial counsel did not understand that both counts were based solely upon the purely fictional personal journal, she could not have adequately advised appellant of the potential constitutional defense.
State v. Dalton, supra. The Court of Appeals relied on the decision I discussed in my earlier post, in which the Supreme Court held that the First Amendment bars the criminalization of child pornography the creation of which does not involve victimizing a real child. Dalton’s attorney apparently thought the stories at least in part depicted the sexual molestation of an actual child. State v. Dalton, supra. The Ohio Supreme Court declined to review the Court of Appeals’ decision, so it’s final. I have no idea what happened to Dalton; I assume the prosecutor did not try to charge him with anything after he was released from prison.

I agree with the decisions of both courts . . . but I wonder what would (will) happen if someone is charged with possession of child pornography based on his or her having textual accounts describing the sexual molestation of real, identifiable children. The accounts themselves would be purely fictitious, i.e., they would not describe the actual molestation of the children; they would, instead, record the writer’s fantasies of engaging in such activity. Would stories like that, I wonder, be treated any differently from the ones in the Dalton and Sharpe cases?

Friday, October 24, 2008

Virtual Divorce = Virtual Murder

You’ve probably seen the news stories about the recent virtual murder in Maple Story, a Second Life-style MMORPG.

According to these stories, a 43-year-old Japanese woman was “so angry” about being divorced by her virtual Maple Story husband she murdered his avatar. The news stories say the virtual murderess – a piano teacher in the real world – was furious because he divorced her “without a word of warning.”

How did she kill him, you ask? In some worlds -- like Second Life -- that could be quite difficult; I don’t know if killing “real” avatars is a standard part of Maple Story or not. I checked out the game’s North American (English) portal, but I couldn’t find an easy answer to that question.

My guess is that you can’t just kill another avatar, a theory I base on the method the piano teacher used to kill her faithless avatar spouse. According to news stories, she got him to tell her his Maple Story username and password when they were happily conjugal and when he divorced her, used that information to log into his account and kill him off, virtually, of course.

I find the “victim’s” response interesting: He went to the police in Sapporo, where he lives, and complained about his virtual ex-wife’s killing his avatar. I wonder how he phrased his complaint: Did he complain of virtual murder . . . or of a loss of virtual property? (I wonder if he could argue that her killing his avatar constituted a threat . . . on the premise that it implicitly communicated her intent to do something similar to him in the real world? I truly doubt that argument would fly, but it’s a thought.)

The police, naturally, didn’t go with virtual murder (or a loss of virtual property, for that matter). Instead, they arrested her on suspicion of illegally accessing a computer and manipulating electronic data; the news stories say that if she were charged with and convicted of this offense, she could face up to 5 years in prison or a $5,000 fine.

The charge would be brought under Japan’s Unauthorized Computer Access Law (Law No. 28 of 1999). You can find an English version of it here. Article 3(1) of the Act first states that “[n]o person shall conduct an act of unauthorized computer access.” It then defines “unauthorized computer access” as
(1) An act of making available a specific use which is restricted by an access control function by making in operation a specific computer having that access control function through inputting into that specific computer, via telecommunication line, another person’s identification code for that access control function (to exclude such acts conducted by the access administrator . . );

(2) An act of making available a restricted specific use by making in operation a specific computer having that access control function through inputting into it, via telecommunication line, any information (excluding an identification code) or command that can evade the restrictions placed by that access control function on that specific use (to exclude such acts conducted by the access . . .);

(3) An act of making available a restricted specific use by making in operation a specific computer, whose specific use is restricted by an access control function installed into another specific computer which is connected, via a telecommunication line, to that specific computer, through inputting into it, via a telecommunication line, any information or command that can evade the restrictions concerned.
Unauthorized Computer Access Law, Article 3(2). The Act defines “access control function” as a function that is
added, by the access administrator governing a specific use, to a specific computer or to another specific computer which is connected to that specific computer through a telecommunication line in order to automatically control the specific use concerned of that specific computer, and that removes all or part of restrictions on that specific use after confirming that a code inputted into a specific computer having that function by a person who is going to conduct that specific use is the identification code. . . .
Unauthorized Computer Access Law, Article 2(3). It defines “identification code” as a code that is granted to someone (known as “authorized user”) who has been
authorized by the access administrator governing a specific use of a specific computer to conduct that specific use, or to that access administrator (hereafter . . . authorized user and access administrator being referred to as “authorized user, etc.”) to enable that access administrator to identify that authorized user, etc., distinguishing the latter from another authorized user, etc.; and that falls under any of the following items or that is a combination of a code which falls under any of the following items and any other code:
(1) A code the content of which the access administrator concerned is required not to make known to a third party wantonly;
(2) A code that is compiled in such ways as are defined by the access administrator concerned using an image of the body, in whole or in part, of the authorized user, etc., concerned, or his or her voice;
(3) A code that is compiled in such ways as are defined by the access administrator concerned using the signature of the authorized user, etc., concerned.
Unauthorized Computer Access Law, Article 2(2). Finally, the Act defines “access administrator” as “a person who administers the operations of a computer (hereafter . . . “specific computer”) which is connected to a telecommunication line, with regard to its use (limited to such use . . . hereafter referred to as “specific use”). Unauthorized Computer Access Law, Article 2(2).

I must admit, I find the language of the Act a little hard to follow; it’s more technically grounded than the language you see in comparable U.S. statutes. It looks to me, though, like the charge against the piano teacher would properly be brought under Article 3(1) (which outlaws unauthorized access) coupled with Article 3(2)(1) (which defines “unauthorized computer access” as inputting someone else’s identification code in order to make a computer or computer system do what you want it to do).

I don’t see any requirement in the Act that the unauthorized computer access have caused “damage,” which is a requirement under the general federal cybercrime statute, 18 U.S. Code § 1030. Section 1030(a)(5)(B) makes it a federal crime to intentionally access a computer “without authorization, and as a result of such conduct, recklessly” cause “damage.” The statute defines “damage” as “any impairment to the integrity or availability of data, a program, a system, or information”. 18 U.S. Code § 1030(e)(8).

The piano teacher’s conduct would certainly constitute a U.S. federal crime under this statute because she (i) intentionally accessed a computer (the Maple Story computer and, specifically, her virtual husband’s account on that system) and (ii) caused damage (killing his avatar certainly qualifies as impairing the availability of data or a program). As I said, I don’t know if damage is a requirement under the Japanese statute; it is not required under some U.S. state unauthorized access statutes, on the theory that simply getting “into” a computer system without being authorized to do so is a crime, a virtual analogue of trespass. I suspect the damage element may come into play if and when the lady is being sentenced.

Last year I did a post on virtual murder in which I speculated on whether CONSENSUAL virtual murder in online worlds might someday be criminalized. As I explained there (and explain in a law review article that should be published soon), I don’t think it should be a crime, just as I don’t think any consensual acts that take place in a purely virtual world should become the focus of real-world criminal law. As long as it’s consensual, it’s part of a game and I don’t see why anyone should care (regardless of how bizarre the conduct becomes).

This case, though, raises a different issue, equally interesting. Should we make it a crime to commit real murder (nonconsensual murder) in virtual worlds? Let’s assume for the sake of analysis that the man whose avatar was killed in Maple Story won’t be able to resuscitate it; he’ll have to start over with a new avatar. Not being a serious gamer, I’m not sure how important that is; I know it can be very important in goal-directed games like World of Warcraft, and it looks a like Maple Story might be one of those.

For the purposes of analysis, again, let’s assume he DID lose a great deal when he lost that avatar; he lost, say, skills and property he will have to work very hard in-game to restore. The question, as far as criminal law is concerned, is should we treat this just as a type of unauthorized access w/damage (what some U.S. states define as aggravated hacking) or should we go further and treat it as analogous to a real world crime like theft or even murder?

It couldn’t be theft because she didn’t take the property we are assuming his avatar acquired during its brief lifespan; if we’re trying for a property crime analog, it would have to be some kind of property damage offense. As to whether we should create a crime of virtual murder – avatar murder – I really don’t know. I suppose the answer to that question will depend on how much time we come to spend in virtual worlds; if we come to spend a great deal of our time in these virtual environments – so that we invest much of our personal, emotional and professional lives in them – we might decide some virtual analog of murder is essential.


Can you imagine the dialog if and when this woman goes to prison? “What’d you do? I killed an avatar.” Chicago comes to Second Life.

Thursday, October 23, 2008

Not Cybercrime But . . .

Someone was kind enough to send me a link to a news story about a recent decision from a federal district court in Connecticut.

It is not a cybercrime case, as such, but it does touch on issues I’ve written about before, so I’d like to review it here.


The case is Spanierman v. Hughes, 2008 WL 4224483 (D. Conn. 2008). Here, according to the court, are the facts that resulted in this litigation:
On January 2, 2003, the State of Connecticut, Department of Education (“DOE”) hired the Plaintiff to be an English teacher at Emmett O'Brien High School. . . . (1) Hughes was . . . the Superintendent of the Connecticut Technical High School system, of which Emmett O'Brien is a part; (2) Druzolowski was . . . the Assistant Superintendent of the Connecticut Technical High School system; and (3) Hylwa was . . . the principal of Emmett O'Brien. . . .

The Plaintiff originally began to use MySpace because students asked him to look at their MySpace pages. [He] subsequently opened his own MySpace account, creating several different profiles. One. . . was called `Mr. Spiderman,’ which he maintained . . . from the summer of 2005 to the fall of 2005. [He] . . . used his MySpace account to communicate with students about homework, to learn more about the students so he could relate to them better, and conduct casual, non-school related discussions.

Elizabeth Michaud was a guidance counselor at Emmett O'Brien. In the fall of 2005, Michaud spoke with. . . a teacher . . . who informed Michaud that the Plaintiff had a profile on MySpace. Michaud alleges that she also received student complaints about the Plaintiff's profile page. After her conversation with Ford, Michaud viewed the . . . `Mr. Spiderman’ profile page. . . . Michaud . . . was disturbed by what she saw. . . . According to Michaud, the Plaintiff's profile page included a picture of the Plaintiff when he was ten years younger, under which were pictures of Emmett O'Brien students. In addition, Michaud stated that, near the pictures of the students were pictures of naked men with what she considered `inappropriate comments’ underneath them. Michaud . . . was disturbed by the conversations the Plaintiff was conducting on his profile page. Michaud stated [his] conversations with . . . students were `very peer-to-peer like,’ with students talking to him about what they did over the weekend at a party, or about their personal problems. Michaud felt that the Plaintiff's profile page would be disruptive to students. . . .

Michaud spoke with the Plaintiff about his email communications with students about things . . . not related to school, and suggested he use the school email system for the purpose of educational topics and homework. Michaud also told the Plaintiff that some of the pictures on his profile page were inappropriate. After Michaud spoke with the Plaintiff, he deactivated the `Mr. Spiderman’ profile page. The Plaintiff then created a new MySpace profile on October 14, 2005 called `Apollo68.’

[A teacher] . . . discovered the Plaintiff's new profile page and informed Michaud of it. The Defendants also allege that . . . students complained . . . about the Apollo68 profile. Michaud . . .separately viewed the . . . profile and came to the conclusion that it was nearly identical to the `Mr. Spiderman’ profile. The Plaintiff admits that the “Mr. Spiderman” profile and the “Apollo68” profile had the same people as friends and included the same types of communications.

Michaud reported . . . the “Apollo68” profile page to her supervisor. . . . [and] was told to report the situation to Hylwa. . . . In November 2005, Hylwa met with the Plaintiff, explained there would be an investigation, and placed the Plaintiff on administrative leave with pay. The Plaintiff deactivated the “Apollo68” profile when he was placed on administrative leave.
Spanierman v. Hughes, supra.

To summarize what followed, the school conducted an investigation and then told Spanierman “he had exercised poor judgment as a teacher” and “the DOE would not renew his contract”. Spanierman v. Hughes, supra. He brought a civil rights suit, claiming the school and its officials had violated his Fourteenth Amendment rights to due process and equal protection of the laws and his First Amendment rights to freedom of speech and association. Spanierman v. Hughes, supra. He lost.

The district court held, essentially, that he (i) had not shown he had an interest protected by the due process clause (his interest in having his contract renewed was not enough, according to the court); (ii) had not shown he was selectively prosecuted for what he did (that is, had not shown he was singled out for conduct others engaged in without having their employment terminated)l and (iii) had not shown that what the DOE did violated his rights under the First Amendment. Spanierman v. Hughes, supra. It can be difficult to prevail on these kinds of claims.

I thought this case was interesting, given some of the things I’ve posted about, because here we have postings on MySpace (or Facebook) coming back to haunt a teacher, not a student. I don’t know anything about education law, but sites like MySpace and Facebook obviously open up a whole new dimension in student-teacher interaction, which I’m sure schools will want to control. Seems to me –as a lawyer who knows nothing about the legal issues or practicalities involved here – that it would be a really good idea for schools to adopt policies specifying what are, and are not, appropriate uses of MySpace and Facebook by teachers in their professional capacity.

In law schools we have access to services offered by Westlaw and Lexis, both of which let us create websites and email groups and communicate with out students online and outside of class; I don’t know of any law schools that have adopted policies defining the appropriate uses of these sites, presumably because they don’t offer the opportunities for creative expression one finds on MySpace and Facebook. I don’t know what was going on with Mr. Spanierman, but he could have been a very well-meaning, enthusiastic teacher who was trying to interact with his students in new ways but ran afoul of formal or informal norms governing student-teacher interactions at the high school level.